Threat Database Trojans Trojan.Downloader.Agent.BTH

Trojan.Downloader.Agent.BTH

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 6,127
Threat Level: 80 % (High)
Infected Computers: 244
First Seen: August 21, 2023
Last Seen: July 18, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Agent.BTH indicates that your system has been compromised by a type of malicious software. This threat is categorized as a Trojan, which is a broad term for malicious programs that disguise themselves as legitimate software. The term "Downloader" in the detection name suggests that this particular threat may be capable of downloading additional malicious components from the internet. It is essential to take immediate action to remove this threat and prevent further damage to your system.

What Is Trojan.Downloader.Agent.BTH?

Trojan.Downloader.Agent.BTH is a type of malware that can infect your system through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. Once installed, it can perform a range of malicious activities, including downloading and installing additional malware, stealing sensitive information, and disrupting system performance. The "Agent" part of the detection name may indicate that this threat is designed to operate stealthily, evading detection by security software and system administrators.

How Trojan.Downloader.Agent.BTH Operates

Malware like Trojan.Downloader.Agent.BTH typically operates by exploiting weaknesses in system security or user behavior. It may use social engineering tactics to trick users into installing the malware or exploit vulnerabilities in software to gain unauthorized access. Once installed, the malware can communicate with its command and control servers to receive instructions and download additional components. This can lead to a range of malicious activities, including data theft, ransomware attacks, and disruption of system performance.

Symptoms of Infection

Systems infected with Trojan.Downloader.Agent.BTH may exhibit a range of symptoms, including slow system performance, unexpected pop-ups or advertisements, and unauthorized changes to system settings. Users may also notice that their system is behaving erratically, with frequent crashes or freezes. In some cases, the malware may attempt to steal sensitive information, such as login credentials or financial data, which can lead to identity theft or financial loss.

  • Slow system performance or freezes
  • Unexpected pop-ups or advertisements
  • Unauthorized changes to system settings
  • Unexplained crashes or errors
  • Suspicious network activity or data transfers

How to Remove Trojan.Downloader.Agent.BTH

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all threats have been removed.

Conclusion

Removing Trojan.Downloader.Agent.BTH requires a combination of technical expertise and caution. It is essential to follow the steps outlined above and to use reputable anti-malware tools to ensure that all threats are removed. Additionally, users should take steps to prevent future infections, such as keeping their operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads or links. By taking these steps, users can help protect their systems and sensitive information from the risks associated with malware like Trojan.Downloader.Agent.BTH.

Analysis Report

General information

Family Name: Trojan.Downloader.Agent.BTH
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: c2e0206541ca56bd2b86305c8224629d
SHA1: fe9e9b0373a8586935374921194e250cab98bc43
SHA256: 620D50DDDB7B078C15D5588E0449869DFB691FC1AF46D9E982E7DCA7E1716A72
File Size: 2.86 MB, 2859520 bytes
MD5: e6466d291ef09087f128439614f3e08e
SHA1: 2abef5209e7b578f1b52a8603b27a932a0bc6ebf
SHA256: 6CA1E089DA738254C18579E262CC8593BBFD4EE2F1F7848E45A992D9807A8052
File Size: 2.18 MB, 2179584 bytes
MD5: d65f46440b0237519619fcf95e8ccbf3
SHA1: 33f49a0012b979406e8cff2ad0e198405eb615fa
SHA256: A7E07220ABA4B119F83E06DD2105F692F5C8507D2F52582757EBC652A66647C3
File Size: 4.11 MB, 4110848 bytes
MD5: e561409afb2b6010446ba3109e69ef43
SHA1: a723347e8b540c5172ff8004ac0e923b855525e6
SHA256: E8713F75CAD6024AB8C3FB81B93CDD7761F40E96C2030B53BF3D1AC3C4BA4172
File Size: 2.81 MB, 2814464 bytes
MD5: d1687cf9929a01066d5f53ed21e888a1
SHA1: 25b669533aa4e8982c0a9467d198ca63c028dfd8
SHA256: A67A701CCEEAC7C5998FB23BF0FD10CB589ACD93B8EE5273B36BC44FE54E0105
File Size: 2.42 MB, 2416128 bytes
Show More
MD5: 1a23d5cd23a96120d987ffd5544127da
SHA1: b72a5184337c39af7a6d4eaf3b8d90f91b89ab3a
SHA256: E578E10C328FC53DB69DFA3350507C8BB60030F3669D35D31986E14C750BBB30
File Size: 4.49 MB, 4494336 bytes
MD5: 7bbfd52d656b1913ee0002a5ad1a9d6f
SHA1: aad322376f9074464dd0ad7e5b6b29081f0abc2a
SHA256: 96A2F62131B538D758A476EC15DE22C8BB695988F22D49E2EB786E2532445FE7
File Size: 8.16 MB, 8164352 bytes
MD5: f928de0d3fa939883c9a8a3f7b2bc705
SHA1: 2bd97ee257eb374511ab183077625c81c11ad222
SHA256: 8B2C226D5B7B0A6A6F4666A802101D71D468F7FCD929270A5A50D58472D69FE2
File Size: 432.64 KB, 432640 bytes
MD5: 65b366f04905deeb9c390d0e54e4a28c
SHA1: 25f1917c2e6876e4f5ffee8f972de98d6f04fddf
SHA256: A5644E291128539A24D15AA4003E35641A74931452D0FBFE195BBEB1A6AAE96C
File Size: 4.11 MB, 4111872 bytes
MD5: d8dc0eef658872ffad1fa8b5780fbb71
SHA1: 2bddf6ae09475f504e4c3983261efa48faa787e7
SHA256: E78B7A2863D595D629EBD4FD70C2F7641D9B09D2001F021AB55EF039DAAA3FD2
File Size: 4.41 MB, 4413440 bytes
MD5: f94c64d043515f9985df82d351d0bf90
SHA1: 02ea534b18a3243b136724d4b98ab2250f90a4cb
SHA256: 8392ADC598F268EB2252B8ADC4F94F1BBD91B0611CAAC171056D88946DC37CDC
File Size: 2.09 MB, 2089472 bytes
MD5: 77883b1b089663d580f22e1532c260a1
SHA1: 3bfe9ebf97794cb73d6cfefad203ef8a9c9bd679
SHA256: AC3E1AD12B90343579DC6B4B5FE0A2B71C18EBB4841ED432D3C1BC67039B14BB
File Size: 2.50 MB, 2503168 bytes
MD5: fdbee6f5ecdf78bd18c58c9b822dee53
SHA1: f169e4c209e398dadfceae16da32022eb49dc72e
SHA256: ADE0C3D62D97EBA3B743BEAB44AB8A526DC2667969452ED86099ACBEC93149E2
File Size: 2.01 MB, 2011648 bytes
MD5: c72baefce9431a210b0dcd1693aa18d6
SHA1: 99d51249420790a39736c26127bac82fa53f452e
SHA256: CFA622F848704EF4AFB9BD54CE8621C2FB2A716C1E4D14CEC3A6104A164AE5CB
File Size: 2.41 MB, 2412544 bytes
MD5: a8ef4c09e268a8479ddfe78341f61036
SHA1: fc4b7cc9ad46b340390f8191a294c3c5a8f7ef44
SHA256: 077BD4E63B497509C1A3B9A2E7CB601CCE69174DF3D78FE28C0F6024D6CC599C
File Size: 8.28 MB, 8284160 bytes
MD5: c78e18f8520ec9fc421ec8b5a75e5baa
SHA1: 16b5390337d59e684014277e7bd91d49f7ad993f
SHA256: 403C91BE430849A38FFAA0D4ACF5313E262F030363A5DF8EE36DCEFF4EF20A82
File Size: 2.46 MB, 2458112 bytes
MD5: c83bfb2430a37808ad2ef6541fa12572
SHA1: 89891dfd95cdc37f103d30d56df9ffc9fb9690aa
SHA256: 26186CEB1142E1C84298AA528627531E3821B8068E4E777E3975403A272C530E
File Size: 4.67 MB, 4673536 bytes
MD5: a40b91b5b61f577715dcc8ff47cb53dc
SHA1: fda139c1f1e21775ac4d037e9d33d5d069a2726a
SHA256: A639E539C745A3D426BE1BB1F771F1475C2631D5567BC327791F9C996F7CDAB3
File Size: 4.83 MB, 4833280 bytes
MD5: 3e90a65f1ce764d2c1e9b008c71c2c2b
SHA1: dcf8477ef3216af0bef2486bfda26a6f8c3c8ee0
SHA256: BDF4CF3566FA8BFF07244F4CBA243EC4ABCCF0C8BD544C3DCAB2486F66CFA0BD
File Size: 4.40 MB, 4404736 bytes
MD5: 2dd642b505eea62497988cb3edd797b0
SHA1: c5ca30e415779d0f18d1d607453710462497b651
SHA256: F989C3E796CF5719424A8A32661E947E50D509BBB594B3D7D4529BE8BB3C7879
File Size: 4.30 MB, 4300800 bytes
MD5: d85a3dabd17d2341ebcea407daa3b25e
SHA1: f0dc19795cc31458a63f57a83d1943e3e411807b
SHA256: 545618CA751708A0B2F063992A7A539967CBF27FD44E086812FA546918C85ADE
File Size: 1.03 MB, 1025536 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Atooi LLC
File Description
  • Dementium: The Ward
  • JSplitter component for foobar2000
File Version
  • 4.0.4.4-beta
  • 1.1.10.0
  • 0.0.0.0
Internal Name
  • Dementium
  • foo_uie_jsplitter.dll
Legal Copyright
  • (c) 2025 Atooi LLC
  • (c) 2026 Atooi LLC
  • Copyright (C) 2018-2025 LUR
Original Filename
  • Dementium.exe
  • foo_uie_jsplitter.dll
Product Name
  • Dementium: The Ward
  • JSplitter
Product Version
  • 4.0.4.4-beta
  • 1.1.10.0
  • 0.0.0.0

File Traits

  • 2+ executable sections
  • big overlay
  • CryptUnprotectData
  • dll
  • fptable
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • No CryptProtectData
  • No Version Info
Show More
  • ntdll
  • packed
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 5,035
Potentially Malicious Blocks: 349
Whitelisted Blocks: 4,513
Unknown Blocks: 173

Visual Map

0 0 ? x x ? x ? 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 x x 0 x x 0 0 0 x x 0 0 x 0 0 0 0 x x 0 x 0 0 0 1 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 ? x 0 0 0 x x 0 0 1 x 0 x 0 x 0 0 x 0 0 0 0 ? x x 0 0 0 0 x x 0 0 0 0 ? 0 x 0 x 0 0 0 x 0 0 0 0 0 0 x x 1 0 0 0 0 x 0 x 0 0 x 0 x x x 0 0 0 0 0 0 0 ? 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 1 x x 0 x 0 0 0 1 x 0 0 1 0 0 x 0 0 0 x x 0 0 0 x x 0 0 0 1 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 x x x x 0 0 0 x 0 x 0 0 x x x 0 0 0 x x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 1 x x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 x x x 0 0 1 x 0 0 0 0 x 0 0 0 0 0 0 1 0 0 x 0 x 0 ? 0 0 0 0 x 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 x x 0 0 0 0 0 0 0 0 x 0 1 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 x 0 0 1 0 0 1 0 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x 0 x x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 x x 0 x ? x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x x 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x ? ? 0 0 0 x 0 0 x ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 ? 0 0 x 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 x 0 x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 ? 0 ? x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 ? x 0 x 0 x 0 x x ? x 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? x x 0 x x 0 x x x x x x 0 x x x x 0 x x x ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x ? x x 0 x x x ? ? ? x x 0 0 0 x x ? 0 0 0 ? ? 0 ? 0 0 0 ? 0 0 x ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 ? ? ? ? ? 0 ? x ? ? 0 0 x x ? ? ? ? ? 0 ? ? ? 0 ? 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? x x ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 0 x 0 ? 0 ? 0 0 ? 0 0 ? ? ? 0 0 ? x ? ? ? ? ? 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 x 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 x ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 1 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x x 0 ? 0 0 0 1 0 0 0 0 0 0 x ? x 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 1 0 0 0 0 0 ? x 0 1 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x ? x x x x ? 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x x x 0 0 x x 0 0 0 0 x x x x x x 0 0 0 0 x x 0 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\harddisk0\dr0 Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiComputeXformCoefficients
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDdDDICloseAdapter
  • win32u.dll!NtGdiDdDDIEnumAdapters2
  • win32u.dll!NtGdiDdDDIGetDeviceState
  • win32u.dll!NtGdiDdDDIGetMultiPlaneOverlayCaps
  • win32u.dll!NtGdiDdDDIOpenAdapterFromHdc
  • win32u.dll!NtGdiDdDDIQueryAdapterInfo
  • win32u.dll!NtGdiDeleteObjectApp

105 additional items are not displayed above.

Trending

Most Viewed

Loading...