Threat Database Trojans Trojan.Agent.NBO

Trojan.Agent.NBO

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: October 27, 2025
Last Seen: March 26, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.NBO on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your system's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it.

What Is Trojan.Agent.NBO?

Trojan.Agent.NBO is a type of malware that can infect your system without your knowledge or consent. The term "Trojan" refers to a broad category of malware that can disguise itself as legitimate software, allowing it to bypass security measures and gain unauthorized access to your system. The ".Agent.NBO" part of the name suggests that this particular threat may be related to a specific type of malicious activity or behavior.

How Trojan.Agent.NBO Operates

Once installed on your system, Trojan.Agent.NBO can operate in various ways, depending on its intended purpose. It may attempt to connect to remote servers to receive instructions or transmit stolen data. It can also create backdoors, allowing unauthorized access to your system, or install additional malware to further compromise your security. Trojan.Agent.NBO may also try to evade detection by using anti-detection techniques, making it challenging to identify and remove.

Symptoms of Infection

Identifying the symptoms of a Trojan.Agent.NBO infection can be difficult, as it may not always exhibit obvious signs of malicious activity. However, you may notice unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also receive unexpected pop-ups, experience unusual network activity, or find unfamiliar files or folders on your system. If you suspect that your system has been infected with Trojan.Agent.NBO, it is crucial to take immediate action to remove the threat.

How to Remove Trojan.Agent.NBO

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious components related to Trojan.Agent.NBO.
  3. Uninstall any suspicious programs or applications that may be related to the infection, as they may be used to reinstall the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons that may be associated with the infection.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Agent.NBO from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this threat and restore your system's security. It is essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or email attachments.

Analysis Report

General information

Family Name: Trojan.Agent.NBO
Signature status: No Signature

Known Samples

MD5: dad31ad96a061aba24fb553d0bd16829
SHA1: 3e9e1822e76e70fc63f425efd7ec2360cea0cc9b
SHA256: 7E82EE98EB877070B5E5B2C99DB3DE49468989E0C177A1A33C3DF3CC45359339
File Size: 4.79 MB, 4786176 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • imgui
  • x64

Block Information

Total Blocks: 10,789
Potentially Malicious Blocks: 3,809
Whitelisted Blocks: 6,903
Unknown Blocks: 77

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x 0 0 1 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 1 1 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 x 0 x x x x x x x x 0 0 0 0 0 0 0 x 0 0 x 0 ? 0 x 0 0 0 ? 0 0 0 0 1 0 0 x x x 0 0 0 x ? x 0 ? 0 x 0 0 x x 0 0 0 0 ? 0 0 0 x 1 0 0 0 0 0 0 0 0 0 x x x x x 0 x x 0 0 0 0 ? x 0 x 0 x x x x x 0 x x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x x 0 x x 0 x 0 0 0 0 x 0 x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 x x x x 0 0 0 x 0 0 0 0 0 x x 0 0 x x 0 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 x x x 0 0 0 0 x x x 0 x 0 0 x 0 0 x x 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 x 0 x 0 x 0 x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 ? ? 0 0 x x x x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x 0 0 1 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 x x 0 0 x x x x 1 x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 x x x x 0 0 x 0 0 x x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 1 0 x 0 0 0 0 0 0 x 0 x 0 x x x x x x x x x x x x x x 0 x x x x x 0 x x 0 x x x 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x 0 0 x x 0 x 0 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 x 0 0 x x x x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 x x 0 x x 0 x 0 0 0 x 0 x 0 x x x 0 x 0 0 x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x x 0 0 0 x x 0 x x x x x x 0 x x x 0 x 0 x 0 0 x x x 0 x 0 x x 0 x 0 x 0 x x x x x x 0 0 x 0 0 0 0 0 0 0 x 0 x x x x x x 0 x x x x 0 x x x x x x 0 x x x x 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 x 0 x 0 0 x 0 x 1 x x x x 0 0 0 1 0 0 0 x 0 x 0 x 0 x 0 x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.NBO

Files Modified

File Attributes
c:\repos\spyhunter5\sandboxtool\builds\releasenologencrypt-x64\injected-x64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\3e9e1822e76e70fc63f425efd7ec2360cea0cc9b_0004786176.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\advapi32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\apphelp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\bcrypt.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\bcryptprimitives.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\combase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\crypt32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\cryptsp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\d3dcompiler_47.pdb Read Attributes,Synchronize,Write Attributes
Show More
c:\windows\system32\dbghelp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\advapi32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\apphelp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\bcrypt.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\bcryptprimitives.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\combase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\crypt32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\cryptsp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\d3dcompiler_47.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\dbghelp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\gdi32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\gdi32full.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\imagehlp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\imm32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\injected-x64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\kernel32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\kernelbase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\msvcp140.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\msvcp_win.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\msvcrt.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\ntdll.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\rpcrt4.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\sechost.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\shcore.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\shell32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\ucrtbase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\user32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\vcruntime140.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\vcruntime140_1.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\win32u.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\dll\ws2_32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\exe\3e9e1822e76e70fc63f425efd7ec2360cea0cc9b_0004786176.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\exe\rundll32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\gdi32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\gdi32full.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\imagehlp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\imm32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\injected-x64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\kernel32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\kernelbase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\msvcp140.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\msvcp_win.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\msvcrt.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\ntdll.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\rpcrt4.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\rundll32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\sechost.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\shcore.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\shell32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\advapi32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\apphelp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\bcrypt.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\bcryptprimitives.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\combase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\crypt32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\cryptsp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\d3dcompiler_47.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\dbghelp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\gdi32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\gdi32full.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\imagehlp.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\imm32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\injected-x64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\kernel32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\kernelbase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\msvcp140.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\msvcp_win.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\msvcrt.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\ntdll.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\rpcrt4.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\sechost.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\shcore.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\shell32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\ucrtbase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\user32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\vcruntime140.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\vcruntime140_1.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\win32u.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\dll\ws2_32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\exe\3e9e1822e76e70fc63f425efd7ec2360cea0cc9b_0004786176.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\symbols\exe\rundll32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\ucrtbase.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\user32.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\vcruntime140.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\vcruntime140_1.amd64.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\win32u.pdb Read Attributes,Synchronize,Write Attributes
c:\windows\system32\ws2_32.pdb Read Attributes,Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 擩殩뷀ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess

Trending

Most Viewed

Loading...