Threat Database Trojans Trojan.Aotera.G

Trojan.Aotera.G

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,768
Threat Level: 80 % (High)
Infected Computers: 20
First Seen: March 25, 2026
Last Seen: July 29, 2026
OS(es) Affected: Windows

The detection of Trojan.Aotera.G on your system indicates a potential security threat that requires immediate attention. This type of threat is generally categorized as a Trojan, which is a broad term for malicious software that disguises itself as legitimate. Trojans can have various functions, including data theft, unauthorized access, and disruption of system operations. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is Trojan.Aotera.G?

Trojan.Aotera.G is identified as a Trojan-type threat, which means it is designed to infiltrate your system by disguising itself as a legitimate program or file. The name itself does not directly indicate a specific malware family, but rather serves as a detection label. Trojans are known for their versatility and can be used for a wide range of malicious activities, including but not limited to, stealing sensitive information, installing additional malware, or providing unauthorized access to the infected system.

How Trojan.Aotera.G Operates

Like other Trojans, Trojan.Aotera.G is likely designed to operate stealthily, attempting to evade detection by security software. It may exploit vulnerabilities in operating systems, applications, or user behavior to gain access to the system. Once inside, it can perform various malicious actions, depending on its specific design and purpose. This could include communicating with command and control servers, downloading additional malware, or capturing and transmitting sensitive user data.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely, depending on the specific goals of the malware. Common indicators include unexpected system behavior, such as slow performance, frequent crashes, or unfamiliar programs and icons. You might also notice unusual network activity, changes to system settings, or the appearance of unwanted pop-ups and advertisements. In some cases, the infection may not exhibit obvious symptoms, making it difficult to detect without the aid of security software.

How to Remove Trojan.Aotera.G

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download necessary tools while restricting the operation of most malware.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to enhance detection capabilities.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the infection was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your system and perform another full scan to ensure the malware has been successfully removed. Repeat the scanning process until no threats are detected.

Conclusion

Removing Trojan.Aotera.G requires a systematic approach to ensure all components of the malware are eliminated from your system. By following the steps outlined above and maintaining vigilant security practices, you can protect your system from future infections. Regularly updating your operating system, applications, and security software, along with being cautious when opening emails or downloading files from the internet, are crucial steps in preventing malware infections. Remember, the key to securing your digital environment is a combination of robust security tools and informed user behavior.

Analysis Report

General information

Family Name: Trojan.Aotera.G
Signature status: No Signature

Known Samples

MD5: 540b837bd5753be65f2ac67d33887d2e
SHA1: 235453e5e165241e9cb47c846e664cb222e78fe1
SHA256: 719ADFFEA102C9AE79433D003A7F0C806B3273D9137369F0A8E952925DD49889
File Size: 2.48 MB, 2478592 bytes
MD5: 5eacc7becae19c2e319f0cd3e22db76e
SHA1: 202acee4eae4f662e28ac9bd06d04ed4b5204f0d
SHA256: 02BD3F91A93F25EBAA9637EA6949F555B7CDC47A216F051CD2B24612540B792C
File Size: 2.13 MB, 2134016 bytes
MD5: 47e4ac5246b57d0b4c792a16224ef1ef
SHA1: e1753b6d4e21c38e1618bf2928cf0cd01af120a0
SHA256: 0C12A02D00900E8429083881F181548420DFE2DC9041C477B636CDDCFB3EAA71
File Size: 2.29 MB, 2286592 bytes
MD5: 316a635078339ef88da27e0c792f0d53
SHA1: 95e8f495ebf328d204c047b45388eba6c962950a
SHA256: 2C51455A5A584989C89A2C7ED859C8861C3F89F88B64909AD39A7D7BB806DB55
File Size: 2.72 MB, 2724864 bytes
MD5: ad4e33e8d485c7b9a157fac984457fbb
SHA1: 52cf7414770b20fd0db440934d4cc6db98425423
SHA256: 35E1F0757436C0E2EF201479F8AA2032E591B0E34441A270E7A2CC2D1290805D
File Size: 2.03 MB, 2027008 bytes
Show More
MD5: 16232beda86f91212826a302ac9f07b6
SHA1: da66324006f22dd7b866f50d388991c769ee7127
SHA256: D97BCA46AA5F61D73172D3C9651AC96EB0BD0BD768FFF8170A9365863F1C1B6E
File Size: 2.66 MB, 2660352 bytes
MD5: e0ba3c5742b0586b50ad41dcc4c83e45
SHA1: 1a982ff9c0f73144281a71980039128b67c0b7f1
SHA256: 302C894F774A377CFF0D0863E517665A3D2C4D7A3DF1500B5551982B03816A08
File Size: 6.50 MB, 6496768 bytes
MD5: c53f34fa5416d27d7a4c67895f3f2f53
SHA1: 819a6efd9e61a98c89e7b91a077b5c74af71b66e
SHA256: C1D935AC5715BFF4FC19835B3D06378CF2A14776507647C398B2D2FDFF2D3A8C
File Size: 3.31 MB, 3311104 bytes
MD5: 502b99f4630e01f4ad315228e00e3738
SHA1: 9ad0c8e3156947af0b3618ce9a73bee04cf7b74b
SHA256: 5582F2086BEAA666F9A520634C4AE7EC46E4FFC01A54F196B6CE8CBABC126479
File Size: 1.84 MB, 1841152 bytes
MD5: fbb8ec00c09fb6b27927d5012c556490
SHA1: a695f5cecad90808018bc7869ae5467ba1b4a49a
SHA256: C6C52E3F9FEA0C977AF1A5FFDF717690A489E167EC6515315B92DD558A114491
File Size: 1.92 MB, 1918464 bytes
MD5: 97987f0485fd47bb07f1bc082564123f
SHA1: 60ae01afe8c28b3b2c66b5da07b99b0d520ff1d0
SHA256: 1BFC8230E6E1AE0E4F3EB00D46D1F2FF3806E66CCE2400978A08E484AC20C220
File Size: 1.90 MB, 1901568 bytes
MD5: dc5859aa3e12e2bd3e04f1b9d4142abb
SHA1: d451fd0b6b9cdf481a5867ddcfcccfbe8a0739a8
SHA256: 38E74FF8D5F02617FF8858D9094B455D4E999223C7F78726584690E7201D94B7
File Size: 2.71 MB, 2709504 bytes
MD5: 1bc37fbb51b6ba71f27b3df8db32fe63
SHA1: 7b65696ef754dff1538e66e8878acdf5aff042a0
SHA256: 09FF776AE819EF8AE7E0CB0CCE49D8C7608B7EEC4D4A75DD58C8376392396356
File Size: 4.04 MB, 4040704 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Amyctic Inc.
  • Debunker Superconsequence LLC
  • Electly Immedicableness Corp.
  • Hydraulicking Corp.
  • Polarizes Creamsacs Ltd.
  • Sockdolager Lovee Inc.
File Description
  • Chunters thronedom lekker anatomizable punkt austrogaean perilously romancelet corsetier.
  • Dominants runch discharm malleoli oystering shalwar prebestowal pretoria boatage galvanolysis ways diacidic.
  • Holochordate countability levelers calixtin ola sleepingly eyebeam propensity locky overqualification furfuralcohol drivenness.
  • Kusum colloxylin appendiculata lymphocytomatosis othertime woolwasher klepht.
  • Nork springerle hippoglossus anchietea jeewhillikens.
  • Reswearing opprobriate aldine kinotannic multishot freycinetia preshow maccus ecdysis artichokes enclose overwhipped.
File Version
  • 7.19.6.39
  • 6.97.276.54
  • 4.91.737.95
  • 1.98.194.20
  • 1.60.152.86
  • 1.47.500.95
Internal Name
  • Alarodian Aphidicide
  • Hagride Slackmindedness
  • Lupinin Geezer
  • Peruvians Cenozoic
  • Petrifier Electrosherardizing
  • Presympathizing Extraprovincial
Legal Copyright
  • © 2025 Sockdolager Lovee Inc.
  • © 2026 Amyctic Inc.
  • © 2026 Debunker Superconsequence LLC
  • © 2026 Electly Immedicableness Corp.
  • © 2026 Hydraulicking Corp.
  • © 2026 Polarizes Creamsacs Ltd.
Original Filename
  • AchromatocyteCanonistic.exe
  • BullbackChimaeras.exe
  • ExpatiatorsTridiurnal.exe
  • HomemakersRevet.exe
  • OversCassation.exe
  • ToddymanYardmaster.exe
Product Name
  • Intrust Nonantagonistically
  • Limestones Gastnesses
  • Lithogenous Dolcinist
  • Oath Retter
  • Officeholders Impetuous
  • Rex Hylocomium
Product Version
  • 7.19.6.39
  • 6.97.276.54
  • 4.91.737.95
  • 1.98.194.20
  • 1.60.152.86
  • 1.47.500.95

File Traits

  • 2+ executable sections
  • dll
  • fptable
  • HighEntropy
  • VirtualAllocExNuma
  • x64

Block Information

Total Blocks: 6,999
Potentially Malicious Blocks: 141
Whitelisted Blocks: 6,853
Unknown Blocks: 5

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DFCF
  • Agent.DFCI
  • Agent.DFCJ
  • Agent.DFD
  • Agent.DFZ
Show More
  • Agent.KOK
  • Aotera.A
  • Aotera.D
  • Aotera.E
  • Aotera.G
  • Aotera.LA
  • Filecoder.XT
  • Kryptik.OID
  • Kryptik.OIF
  • Kryptik.PSB
  • Kryptik.VED
  • Kryptik.YKAC
  • Kryptik.YKAP
  • Kryptik.YKBB
  • Mikey.UB
  • Mikey.UC
  • Mikey.W
  • ShellCode.FJ
  • SnakeStealer.A
  • Trojan.Filecoder.Gen.AF
  • Trojan.Filecoder.Gen.BI
  • Trojan.Filecoder.Gen.BP
  • Trojan.Metasploit.Gen.AT

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n. �v���5Bx#��(�1�1HO1�D9ߔ@V�H[uR20_�z`�2b"hi��k�ql(�rnJu�~{b�{�=�P�������������T��T���.�T��T��T��m�Ù��gi������$�>წ�����(��oA��=�SB1_B��T�Vw�`�V�R���%�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n' �v����Bx#��(�1�1HO5�0<.:@V�N$_�zk�ql(�{b��P���!�/����� ���3���������X�������.�m�Ù��gi�V����$�8წ���l�A�~�=�SB1_B��T�Vw���%���������AE��D��&��$���L RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN