Threat Database Trojans Trojan.MSIL.Krypt.ZCTFG

Trojan.MSIL.Krypt.ZCTFG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,107
Threat Level: 80 % (High)
Infected Computers: 428
First Seen: October 28, 2023
Last Seen: July 13, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.ZCTFG indicates that a potentially malicious threat has been identified on your system. This name suggests a Trojan-type threat, which is a broad category of malware designed to deceive users about its true intentions. Trojans can cause significant harm by allowing unauthorized access to a computer, stealing sensitive information, or disrupting system operations. Understanding what Trojan.MSIL.Krypt.ZCTFG is and how it operates is crucial for taking effective removal steps and preventing future infections.

What Is Trojan.MSIL.Krypt.ZCTFG?

Trojan.MSIL.Krypt.ZCTFG, as mentioned, falls under the category of Trojan malware. Trojans are known for their ability to disguise themselves as legitimate software, making them difficult to detect. They can be spread through various means, including but not limited to, downloading infected software, opening malicious email attachments, or visiting compromised websites. The name Trojan.MSIL.Krypt.ZCTFG itself does not specify a known malware family, but its detection signifies a potential threat that requires immediate attention.

How Trojan.MSIL.Krypt.ZCTFG Operates

Once installed on a system, Trojan.MSIL.Krypt.ZCTFG can operate in several ways, depending on its intended purpose. It may create backdoors for remote access, allowing attackers to control the infected computer. It could also be designed to steal personal data, such as login credentials, credit card numbers, or sensitive business information. Some Trojans are used to spread other types of malware, like viruses or ransomware, further complicating the security situation. Understanding the operational mechanisms of such threats is key to developing effective removal and prevention strategies.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Krypt.ZCTFG infection can vary widely. Common indicators include unusual system behavior, such as unexpected crashes, slow performance, or unfamiliar programs running in the background. You might also notice changes in your browser settings, unexpected pop-ups, or new toolbars that you did not install. In some cases, the infection might not display any noticeable symptoms, making it harder to detect without proper scanning tools.

How to Remove Trojan.MSIL.Krypt.ZCTFG

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download removal tools if necessary.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the threat.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time you suspect the infection occurred. Be cautious and only remove programs you are sure are malicious or unnecessary.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This step can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan to ensure the threat has been successfully removed. Repeat the scanning process until no threats are detected.

Conclusion

Removing Trojan.MSIL.Krypt.ZCTFG requires a systematic approach to ensure the malware is completely eradicated from your system. By understanding the nature of Trojan-type threats and following the removal steps outlined, you can protect your computer and personal data from potential harm. It's also crucial to adopt preventive measures, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading files or clicking on links from unknown sources. Staying informed and vigilant is key to maintaining a secure digital environment.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.ZCTFG
Signature status: No Signature

Known Samples

MD5: 88603e846f34a5e4400f76bed922e686
SHA1: 853a619948f279487cfd9bed12741abf035c0597
File Size: 305.66 KB, 305664 bytes
MD5: f24e0ca623a5ce48d6079582a73ea6f9
SHA1: ecd0b933c97a866af87597b5ef01952fd3b3cdaf
SHA256: F0053E6DE7267C33F819879FEC57D302D06A98E1BF26ACCEF990DCAA13C17971
File Size: 1.40 MB, 1396736 bytes
MD5: af1a2ec596a04ea0fb7ae8d0573b66e9
SHA1: 1a310f02c3cfbaa0b341d4a4009783c7ddd88e01
SHA256: FCC2350CEFDE558787D63DDC7AFE2F4E318575389A6434F38B57D56F8041F62E
File Size: 1.80 MB, 1799312 bytes
MD5: 7e9d1773cff4ca52f8fa18f28346b76a
SHA1: 7073c50560fe48ef3c238798d08934abc1911f71
SHA256: 8BBD0021A3A433AF5080AC6BFEDB2FE9BEE5204BF29718C4627AE995E1D90239
File Size: 669.18 KB, 669184 bytes
MD5: a7efc2d751cc337c0eb30e24e1ba788d
SHA1: 24987ad512255f6ba8a7078284aaca896dbf8a58
SHA256: 36BD427E2C91023B5EB1AB6143FA96A7134B2D2EE91E1A6BE1192E35E5404C75
File Size: 6.35 MB, 6353408 bytes
Show More
MD5: 7a5bfe0b2b5dbc58b6f63c87efa25d53
SHA1: 508019cd0e6a08d8d27bbe4f092d3ed1295d1f37
SHA256: 43B86EF574C7FA27218C9B8FE1B8BE334AE14ED18DE1472269798222FC136E9B
File Size: 1.54 MB, 1539189 bytes
MD5: 1acff41b3fd00fc17a8757c882eb073f
SHA1: 09b96873e2ddda0b82edd40b5da614926f75347a
SHA256: 99626CB29A8CED2D99A4D48619B7E867F94CE3818B0266C13533C7DED87A7F4C
File Size: 4.38 MB, 4378112 bytes
MD5: 1ada3e27060d65cfe95b517b86538dca
SHA1: c3a0418ddade4dd72684a10240d9ef2af3e8d038
SHA256: 7551287407112FAF459D9CEBFCD2DE676C3CA5265A95798C88018C8EF5B256A9
File Size: 4.39 MB, 4387413 bytes
MD5: 83cc65b0e5da98aab01e1b8a1305923e
SHA1: 3fa588805522f457ca0b8dd7162d6c45aa541cff
SHA256: 38C0A81E79D15ACBC1DC2EF32B1DFE8A726D1302A5366DB85A54FCE76C280C9C
File Size: 4.09 MB, 4091904 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 5.2.3.0
  • 1.0.2340.26088
  • 1.0.0.2
  • 1.0.0.1
  • 1.0.0.0
  • 0
Comments
  • Nihon - Lua Scripting Utility (Built By Developers, For Developers).
  • rhythm just a *click* away!
  • WinGup for Notepad++
Company Name
  • Don HO don.h@free.fr
  • Nihon Softworks™
  • ppy
File Description
  • Euhohvlssi
  • Guerra Installer
  • Nihon
  • osu!
  • TheMagicRemote
  • WinGup for Notepad++
File Version
  • 5.2.3.0
  • 1.3.3.8
  • 1.3.3.7
  • 1.00
  • 1.0.2346.11418
  • 1.0.0.2
  • 1.0.0.1
  • 1.0.0.0
Internal Name
  • Euhohvlssi.exe
  • Guerra Installer.exe
  • Nihon.exe
  • osu!.exe
  • TheRemoteTool.exe
  • TJprojMain
  • Wwtzkura.exe
Legal Copyright
  • Copyright 2018 by Don HO
  • Copyright © 2020 - 2025
  • Copyright © 2023
  • Copyright © FAmilia Guerra 2024
  • Copyright © Guerratool 2024
  • ppy 2007-2015
  • ppy 2007-2019
Legal Trademarks Nihon Softworks™
Original Filename
  • Euhohvlssi.exe
  • Guerra Installer.exe
  • Nihon.exe
  • osu!.exe
  • TheRemoteTool.exe
  • TJprojMain.exe
  • Wwtzkura.exe
Product Name
  • Euhohvlssi
  • Guerra Installer
  • Nihon
  • osu!
  • Project1
  • TheMagicRemote
  • WinGup for Notepad++
Product Version
  • 5.2.3.0
  • 1.3.3.8
  • 1.3.3.7
  • 1.00
  • 1.0.2346.11418
  • 1.0.0.2
  • 1.0.0.1
  • 1.0.0.0

Digital Signatures

Signer Root Status
Dean Herbert COMODO RSA Code Signing CA Hash Mismatch
Notepad++ DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • .NET
  • CryptUnprotectData
  • HighEntropy
  • Installer Version
  • msil.krypt
  • ntdll
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 12,598
Potentially Malicious Blocks: 84
Whitelisted Blocks: 11,404
Unknown Blocks: 1,110

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 ? ? x 0 0 0 ? ? 0 0 ? ? 0 ? ? 0 ? ? 0 ? 0 x ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? 0 ? ? ? ? x x ? 0 0 x 0 0 0 0 ? ? ? 0 0 ? 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.HGC
  • MSIL.Agent.JI
  • MSIL.Agent.XY
  • MSIL.CsdiMonetize.WB
  • MSIL.CsdiMonetize.WD
Show More
  • MSIL.Downloader.Agent.TWE
  • MSIL.Krypt.GEEVA
  • MSIL.SnakeLogger.CE
  • Wacatac.Q

Files Modified

File Attributes
c:\users\user\appdata\local\temp\dc60ad8099494c828193b74f42fe3072\webview2loader.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Zbbfqyzs\AppData\Local\Temp\dc60ad8099494c828193b74f42fe3072\WebView2Loader.dll RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Zbbfqyzs\AppData\Local\Temp\dc60ad8099494c828193b74f42fe3072\WebView2Loader.dll\??\C:\Users\Zbbfqyzs\AppData\Loca RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ݌ᷭ瘹ǜ RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareObjects
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetContextThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory

6 additional items are not displayed above.

Process Terminate
  • TerminateProcess

Related Posts

Trending

Most Viewed

Loading...