Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Black"
- [*] MalScore: 10.0
- [*] File Name: "Exes_e27bdc1c79013da1098d22cf06437f23.exe"
- [*] File Size: 12265098
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "cccac4ce557dce36970c15077a73eda37a30c0834f5c21f9bbe8c752e677a6e8"
- [*] MD5: "e27bdc1c79013da1098d22cf06437f23"
- [*] SHA1: "807265a577233164d07dd5bbc640c31bf5d3f707"
- [*] SHA512: "6e0a95fb7d54ddfbe7712660c24d5745e4e0ca2a9e812c86614570347932335c96a1837283a3b610b000f3c30f7764b51e47914ef2861a432c0fdf349aaba9b0"
- [*] CRC32: "A97246F3"
- [*] SSDEEP: "196608:79z/2bK5onZOLWmvMuqa7nXQ2omMeKttmC9d1lfhrf/LjOwn/dFwsWZ2wu1Jr1Ef:7J/s4v7vMuqcXOOO1XDqw/d8MJ/r5cWy"
- [*] Process Execution: [
- "Exes_e27bdc1c79013da1098d22cf06437f23.exe",
- "Exes_e27bdc1c79013da1098d22cf06437f23.tmp"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "Reads data out of its own binary image",
- "Details": [
- {
- "self_read": "process: Exes_e27bdc1c79013da1098d22cf06437f23.exe, pid: 3564, offset: 0x00b76984, length: 0x0000182a"
- },
- {
- "self_read": "process: Exes_e27bdc1c79013da1098d22cf06437f23.exe, pid: 3564, offset: 0x00b78a77, length: 0x00039c13"
- },
- {
- "self_read": "process: Exes_e27bdc1c79013da1098d22cf06437f23.tmp, pid: 3972, offset: 0x00000000, length: 0x000ac000"
- }
- ]
- },
- {
- "Description": "Drops a binary and executes it",
- "Details": [
- {
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\is-RM3HH.tmp\\Exes_e27bdc1c79013da1098d22cf06437f23.tmp"
- }
- ]
- },
- {
- "Description": "Performs some HTTP requests",
- "Details": [
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D"
- },
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
- },
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D"
- }
- ]
- },
- {
- "Description": "Exhibits possible ransomware file modification behavior",
- "Details": [
- {
- "file_modifications": "Performs 86 file moves indicative of a potential file encryption process"
- },
- {
- "appends_new_extension": "Appends a new file extension to multiple modified files"
- },
- {
- "new_appended_file_extension": ".exe"
- },
- {
- "new_appended_file_extension": ".bin"
- },
- {
- "new_appended_file_extension": ".ini"
- },
- {
- "new_appended_file_extension": ".png"
- }
- ]
- },
- {
- "Description": "File has been identified by 20 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "CAT-QuickHeal": "Trojan.Black"
- },
- {
- "Symantec": "Trojan.Gen"
- },
- {
- "Kaspersky": "Packed.Win32.Black.a"
- },
- {
- "NANO-Antivirus": "Trojan.Win32.Black.bdjqqs"
- },
- {
- "AegisLab": "Packer.W32.Black.a!c"
- },
- {
- "Rising": "Trojan.Generic (cloud:WwnxCDlrpDK)"
- },
- {
- "Sophos": "Mal/Behav-374"
- },
- {
- "DrWeb": "Trojan.Packed.650"
- },
- {
- "VIPRE": "Trojan.Win32.Generic!BT"
- },
- {
- "McAfee-GW-Edition": "Artemis"
- },
- {
- "Cyren": "W32/Trojan.XVWW-6420"
- },
- {
- "Webroot": "W32.Malware.Heur"
- },
- {
- "Avira": "TR/Black.Gen2"
- },
- {
- "Antiy-AVL": "Trojan[Packed]/Win32.Black"
- },
- {
- "Microsoft": "VirTool:Win32/Obfuscator"
- },
- {
- "ZoneAlarm": "Packed.Win32.Black.a"
- },
- {
- "GData": "Win32.Application.Agent.3N5HS0"
- },
- {
- "McAfee": "Artemis!E27BDC1C7901"
- },
- {
- "AVware": "Trojan.Win32.Generic!BT"
- },
- {
- "Cylance": "Unsafe"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: [
- "\"C:\\Users\\user\\AppData\\Local\\Temp\\is-RM3HH.tmp\\Exes_e27bdc1c79013da1098d22cf06437f23.tmp\" /SL5=\"$7017C,12020100,54272,C:\\Users\\user\\AppData\\Local\\Temp\\Exes_e27bdc1c79013da1098d22cf06437f23.exe\""
- ]
- [*] Mutexes: [
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "DefaultTabtip-MainUI"
- ]
- [*] Modified Files: [
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-RM3HH.tmp\\Exes_e27bdc1c79013da1098d22cf06437f23.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-LRG04.tmp\\_isetup\\_RegDLL.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-LRG04.tmp\\_isetup\\_setup64.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-LRG04.tmp\\_isetup\\_shfoldr.dll",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\unins000.dat",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-VSN8O.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\unins000.exe",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-H04T4.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\bookinfo.bin",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-7KVH9.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\BookMaker.exe",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-75STA.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\cyclone.exe",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-VLGTM.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\cyclone.ini",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-9N2KS.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\EThinker.exe",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-0T7J2.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\ethinker.ini",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\is-865TA.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\bk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-Q11GP.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\ba.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-UM7JB.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\bb.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-0JQ6D.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\bc.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-TO44T.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\bk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-H6UPO.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\bn.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-4JOF8.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\board.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-LM6SV.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\bp.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-FOTCR.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\br.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-N9TKC.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\dir0.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-2GLJC.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\dir1.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-QC7CJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\focus.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-CTA1R.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\ra.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-6MG0D.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\rb.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-A3GUE.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\rc.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-3TDEU.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\rk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-6SR4M.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\rn.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-LR31I.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\rp.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-OG437.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\rr.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-S7H1R.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\start.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-120A3.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\stop.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-5OSVJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\ba.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-SS68F.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\bb.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-P5U6V.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\bc.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-IFDQQ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\bk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-ITR69.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\bn.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-AH28S.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\board.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-CQ344.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\bp.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-5A2JK.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\br.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-NNG5C.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\dir0.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-3QCJ9.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\dir1.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-I4U32.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\focus.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-4OE59.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\ra.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-OF1GJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\rb.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-JHPAC.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\rc.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-21BHG.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\rk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-J6MKG.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\rn.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-NU5VM.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\rp.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-I7I4T.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\rr.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-3FK17.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\start.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-9VUQ2.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\stop.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-SD3EE.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\ba.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-SOCDL.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\bb.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-J1Q7U.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\bc.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-CCC2M.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\bk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-K9CSJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\bn.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-9VV3B.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\board.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-4P8VE.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\bp.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-V4CF4.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\br.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-I60DS.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\dir0.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-KOOOO.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\dir1.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-C515E.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\focus.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-U8SK5.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\ra.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-VK5A1.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\rb.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-NOLKJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\rc.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-TH7RN.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\rk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-IGDQH.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\rn.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-E59SR.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\rp.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-0QLHL.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\rr.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-4NK80.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\start.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-FPBUV.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\stop.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-M61M2.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\ba.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-95HUM.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\bb.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-K0TK2.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\bc.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-EH3I8.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\bk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-R239C.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\bn.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-7VJUC.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\board.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-N79DK.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\bp.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-P07P3.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\br.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-K16EK.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\focus.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-SVA7I.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\ra.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-U9P6F.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\rb.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-EBOC8.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\rc.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-1D21G.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\rk.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-O8V4U.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\rn.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-R0OKA.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\rp.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-4R7OG.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\rr.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-TGA1O.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\start.png",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-D9EL8.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\stop.png",
- "\\??\\PIPE\\srvsvc",
- "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5.lnk",
- "C:\\Users\\user\\Desktop\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5.lnk"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-RM3HH.tmp\\Exes_e27bdc1c79013da1098d22cf06437f23.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-RM3HH.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-VSN8O.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-H04T4.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-7KVH9.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-75STA.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-VLGTM.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-9N2KS.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\is-0T7J2.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\is-865TA.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-Q11GP.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-UM7JB.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-0JQ6D.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-TO44T.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-H6UPO.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-4JOF8.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-LM6SV.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-FOTCR.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-N9TKC.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-2GLJC.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-QC7CJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-CTA1R.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-6MG0D.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-A3GUE.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-3TDEU.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-6SR4M.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-LR31I.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-OG437.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-S7H1R.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\large\\is-120A3.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-5OSVJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-SS68F.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-P5U6V.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-IFDQQ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-ITR69.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-AH28S.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-CQ344.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-5A2JK.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-NNG5C.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-3QCJ9.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-I4U32.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-4OE59.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-OF1GJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-JHPAC.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-21BHG.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-J6MKG.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-NU5VM.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-I7I4T.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-3FK17.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\medium\\is-9VUQ2.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-SD3EE.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-SOCDL.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-J1Q7U.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-CCC2M.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-K9CSJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-9VV3B.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-4P8VE.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-V4CF4.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-I60DS.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-KOOOO.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-C515E.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-U8SK5.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-VK5A1.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-NOLKJ.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-TH7RN.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-IGDQH.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-E59SR.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-0QLHL.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-4NK80.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\small\\is-FPBUV.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-M61M2.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-95HUM.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-K0TK2.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-EH3I8.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-R239C.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-7VJUC.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-N79DK.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-P07P3.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-K16EK.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-SVA7I.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-U9P6F.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-EBOC8.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-1D21G.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-O8V4U.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-R0OKA.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-4R7OG.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-TGA1O.tmp",
- "C:\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x96\\xc3\\x90\\xc2\\xb9\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5\\scheme\\tiny\\is-D9EL8.tmp",
- "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5.lnk",
- "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5.pif",
- "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5.url",
- "C:\\Users\\user\\Desktop\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5.lnk",
- "C:\\Users\\user\\Desktop\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5.pif",
- "C:\\Users\\user\\Desktop\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5.url",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-LRG04.tmp\\_isetup\\_RegDLL.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-LRG04.tmp\\_isetup\\_setup64.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-LRG04.tmp\\_isetup\\_shfoldr.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-LRG04.tmp\\_isetup",
- "C:\\Users\\user\\AppData\\Local\\Temp\\is-LRG04.tmp"
- ]
- [*] Modified Registry Keys: [
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xef\\xbf\\x8c\\xef\\xbf\\xac\\xef\\xbe\\xbb\\xef\\xbf\\xba\\xef\\xbf\\x8f\\xef\\xbf\\xb3\\xef\\xbf\\x86\\xef\\xbf\\xa5_is1",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\Inno Setup: Setup Version",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\Inno Setup: App Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\InstallLocation",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\Inno Setup: Icon Group",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\Inno Setup: User",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\Inno Setup: Language",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\DisplayName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\DisplayIcon",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\UninstallString",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\QuietUninstallString",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\NoModify",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\NoRepair",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\InstallDate",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\\\xc3\\x8c\\xc3\\xac\\xc2\\xbb\\xc3\\xba\\xc3\\x8f\\xc3\\xb3\\xc3\\x86\\xc3\\xa5_is1\\EstimatedSize"
- ]
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: [
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D HTTP/1.1\r\nCache-Control: max-age = 128165\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 23 Mar 2019 11:02:13 GMT\r\nIf-None-Match: \"5c961235-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D HTTP/1.1\r\nCache-Control: max-age = 143038\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 23 Mar 2019 15:00:07 GMT\r\nIf-None-Match: \"5c9649f7-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- }
- ]
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x40d0b4"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x40d0b8"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x40d0bc"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x40d0c0"
- },
- {
- "name": "VirtualFree",
- "address": "0x40d0c4"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x40d0c8"
- },
- {
- "name": "LocalFree",
- "address": "0x40d0cc"
- },
- {
- "name": "LocalAlloc",
- "address": "0x40d0d0"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x40d0d4"
- },
- {
- "name": "TlsSetValue",
- "address": "0x40d0d8"
- },
- {
- "name": "TlsGetValue",
- "address": "0x40d0dc"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x40d0e0"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x40d0e4"
- },
- {
- "name": "GetLastError",
- "address": "0x40d0e8"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x40d0ec"
- },
- {
- "name": "WriteFile",
- "address": "0x40d0f0"
- },
- {
- "name": "SetFilePointer",
- "address": "0x40d0f4"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x40d0f8"
- },
- {
- "name": "RtlUnwind",
- "address": "0x40d0fc"
- },
- {
- "name": "ReadFile",
- "address": "0x40d100"
- },
- {
- "name": "RaiseException",
- "address": "0x40d104"
- },
- {
- "name": "GetStdHandle",
- "address": "0x40d108"
- },
- {
- "name": "GetFileSize",
- "address": "0x40d10c"
- },
- {
- "name": "GetSystemTime",
- "address": "0x40d110"
- },
- {
- "name": "GetFileType",
- "address": "0x40d114"
- },
- {
- "name": "ExitProcess",
- "address": "0x40d118"
- },
- {
- "name": "CreateFileA",
- "address": "0x40d11c"
- },
- {
- "name": "CloseHandle",
- "address": "0x40d120"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "MessageBoxA",
- "address": "0x40d128"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "VariantChangeTypeEx",
- "address": "0x40d130"
- },
- {
- "name": "VariantCopyInd",
- "address": "0x40d134"
- },
- {
- "name": "VariantClear",
- "address": "0x40d138"
- },
- {
- "name": "SysStringLen",
- "address": "0x40d13c"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x40d140"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x40d148"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x40d14c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x40d150"
- },
- {
- "name": "OpenProcessToken",
- "address": "0x40d154"
- },
- {
- "name": "LookupPrivilegeValueA",
- "address": "0x40d158"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "WriteFile",
- "address": "0x40d160"
- },
- {
- "name": "VirtualQuery",
- "address": "0x40d164"
- },
- {
- "name": "VirtualProtect",
- "address": "0x40d168"
- },
- {
- "name": "VirtualFree",
- "address": "0x40d16c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x40d170"
- },
- {
- "name": "Sleep",
- "address": "0x40d174"
- },
- {
- "name": "SizeofResource",
- "address": "0x40d178"
- },
- {
- "name": "SetLastError",
- "address": "0x40d17c"
- },
- {
- "name": "SetFilePointer",
- "address": "0x40d180"
- },
- {
- "name": "SetErrorMode",
- "address": "0x40d184"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x40d188"
- },
- {
- "name": "RemoveDirectoryA",
- "address": "0x40d18c"
- },
- {
- "name": "ReadFile",
- "address": "0x40d190"
- },
- {
- "name": "LockResource",
- "address": "0x40d194"
- },
- {
- "name": "LoadResource",
- "address": "0x40d198"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x40d19c"
- },
- {
- "name": "IsDBCSLeadByte",
- "address": "0x40d1a0"
- },
- {
- "name": "GetWindowsDirectoryA",
- "address": "0x40d1a4"
- },
- {
- "name": "GetVersionExA",
- "address": "0x40d1a8"
- },
- {
- "name": "GetUserDefaultLangID",
- "address": "0x40d1ac"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x40d1b0"
- },
- {
- "name": "GetSystemDefaultLCID",
- "address": "0x40d1b4"
- },
- {
- "name": "GetProcAddress",
- "address": "0x40d1b8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x40d1bc"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x40d1c0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x40d1c4"
- },
- {
- "name": "GetLastError",
- "address": "0x40d1c8"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x40d1cc"
- },
- {
- "name": "GetFileSize",
- "address": "0x40d1d0"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0x40d1d4"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0x40d1d8"
- },
- {
- "name": "GetEnvironmentVariableA",
- "address": "0x40d1dc"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x40d1e0"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x40d1e4"
- },
- {
- "name": "GetACP",
- "address": "0x40d1e8"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x40d1ec"
- },
- {
- "name": "FormatMessageA",
- "address": "0x40d1f0"
- },
- {
- "name": "FindResourceA",
- "address": "0x40d1f4"
- },
- {
- "name": "DeleteFileA",
- "address": "0x40d1f8"
- },
- {
- "name": "CreateProcessA",
- "address": "0x40d1fc"
- },
- {
- "name": "CreateFileA",
- "address": "0x40d200"
- },
- {
- "name": "CreateDirectoryA",
- "address": "0x40d204"
- },
- {
- "name": "CloseHandle",
- "address": "0x40d208"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "TranslateMessage",
- "address": "0x40d210"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x40d214"
- },
- {
- "name": "PeekMessageA",
- "address": "0x40d218"
- },
- {
- "name": "MsgWaitForMultipleObjects",
- "address": "0x40d21c"
- },
- {
- "name": "MessageBoxA",
- "address": "0x40d220"
- },
- {
- "name": "LoadStringA",
- "address": "0x40d224"
- },
- {
- "name": "ExitWindowsEx",
- "address": "0x40d228"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x40d22c"
- },
- {
- "name": "DestroyWindow",
- "address": "0x40d230"
- },
- {
- "name": "CreateWindowExA",
- "address": "0x40d234"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x40d238"
- },
- {
- "name": "CharPrevA",
- "address": "0x40d23c"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "InitCommonControls",
- "address": "0x40d244"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "AdjustTokenPrivileges",
- "address": "0x40d24c"
- }
- ],
- "dll": "advapi32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00bb4532",
- "overlay": {
- "size": "0x00ba528a",
- "offset": "0x0000d400"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x00409c40",
- "timestamp": "1992-06-19 22:22:17",
- "osversion": "1.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00009400",
- "entropy": "6.56",
- "raw_address": "0x00000400",
- "virtual_size": "0x00009364",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000b000",
- "size_of_data": "0x00000400",
- "entropy": "2.75",
- "raw_address": "0x00009800",
- "virtual_size": "0x0000024c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000c000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00009c00",
- "virtual_size": "0x00000e4c",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000d000",
- "size_of_data": "0x00000a00",
- "entropy": "4.43",
- "raw_address": "0x00009c00",
- "virtual_size": "0x00000950",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000e000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0000a600",
- "virtual_size": "0x00000008",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0000f000",
- "size_of_data": "0x00000200",
- "entropy": "0.20",
- "raw_address": "0x0000a600",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00010000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00000000",
- "virtual_size": "0x000008b4",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00011000",
- "size_of_data": "0x00002c00",
- "entropy": "4.46",
- "raw_address": "0x0000a800",
- "virtual_size": "0x00002c00",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000d000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000950"
- },
- {
- "virtual_address": "0x00011000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00002c00"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000f000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "884310b1928934402ea6fec1dbd3cf5e",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 8,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.SetDllDirectoryW",
- "kernel32.dll.SetSearchPathMode",
- "kernel32.dll.SetProcessDEPPolicy",
- "kernel32.dll.Wow64DisableWow64FsRedirection",
- "kernel32.dll.Wow64RevertWow64FsRedirection",
- "kernel32.dll.GetUserDefaultUILanguage",
- "comctl32.dll.RegisterClassNameW",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "uxtheme.dll.EnableThemeDialogTexture",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoUninitialize",
- "cryptbase.dll.SystemFunction036",
- "ole32.dll.CoRegisterInitializeSpy",
- "ole32.dll.CoRevokeInitializeSpy",
- "uxtheme.dll.OpenThemeData",
- "uxtheme.dll.CloseThemeData",
- "uxtheme.dll.DrawThemeBackground",
- "uxtheme.dll.DrawThemeText",
- "uxtheme.dll.GetThemeBackgroundContentRect",
- "uxtheme.dll.GetThemePartSize",
- "uxtheme.dll.GetThemeTextExtent",
- "uxtheme.dll.GetThemeTextMetrics",
- "uxtheme.dll.GetThemeBackgroundRegion",
- "uxtheme.dll.HitTestThemeBackground",
- "uxtheme.dll.DrawThemeEdge",
- "uxtheme.dll.DrawThemeIcon",
- "uxtheme.dll.IsThemePartDefined",
- "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
- "uxtheme.dll.GetThemeColor",
- "uxtheme.dll.GetThemeMetric",
- "uxtheme.dll.GetThemeString",
- "uxtheme.dll.GetThemeBool",
- "uxtheme.dll.GetThemeInt",
- "uxtheme.dll.GetThemeEnumValue",
- "uxtheme.dll.GetThemePosition",
- "uxtheme.dll.GetThemeFont",
- "uxtheme.dll.GetThemeRect",
- "uxtheme.dll.GetThemeMargins",
- "uxtheme.dll.GetThemeIntList",
- "uxtheme.dll.GetThemePropertyOrigin",
- "uxtheme.dll.SetWindowTheme",
- "uxtheme.dll.GetThemeFilename",
- "uxtheme.dll.GetThemeSysColor",
- "uxtheme.dll.GetThemeSysColorBrush",
- "uxtheme.dll.GetThemeSysBool",
- "uxtheme.dll.GetThemeSysSize",
- "uxtheme.dll.GetThemeSysFont",
- "uxtheme.dll.GetThemeSysString",
- "uxtheme.dll.GetThemeSysInt",
- "uxtheme.dll.IsThemeActive",
- "uxtheme.dll.IsAppThemed",
- "uxtheme.dll.GetWindowTheme",
- "uxtheme.dll.IsThemeDialogTextureEnabled",
- "uxtheme.dll.GetThemeAppProperties",
- "uxtheme.dll.SetThemeAppProperties",
- "uxtheme.dll.GetCurrentThemeName",
- "uxtheme.dll.GetThemeDocumentationProperty",
- "uxtheme.dll.DrawThemeParentBackground",
- "uxtheme.dll.EnableTheming",
- "user32.dll.NotifyWinEvent",
- "shell32.dll.SHCreateItemFromParsingName",
- "shell32.dll.SHPathPrepareForWriteA",
- "kernel32.dll.VerSetConditionMask",
- "kernel32.dll.VerifyVersionInfoW",
- "kernel32.dll.GetNativeSystemInfo",
- "kernel32.dll.IsWow64Process",
- "kernel32.dll.GetSystemWow64DirectoryA",
- "advapi32.dll.RegDeleteKeyExA",
- "user32.dll.DisableProcessWindowsGhosting",
- "advapi32.dll.CheckTokenMembership",
- "user32.dll.ShutdownBlockReasonDestroy",
- "user32.dll.ShutdownBlockReasonCreate",
- "shfolder.dll.SHGetFolderPathA",
- "comctl32.dll.HIMAGELIST_QueryInterface",
- "comctl32.dll.DrawShadowText",
- "comctl32.dll.DrawSizeBox",
- "comctl32.dll.DrawScrollBar",
- "comctl32.dll.SizeBoxHwnd",
- "comctl32.dll.ScrollBar_MouseMove",
- "comctl32.dll.ScrollBar_Menu",
- "comctl32.dll.HandleScrollCmd",
- "comctl32.dll.DetachScrollBars",
- "comctl32.dll.AttachScrollBars",
- "comctl32.dll.CCSetScrollInfo",
- "comctl32.dll.CCGetScrollInfo",
- "comctl32.dll.CCEnableScrollBar",
- "comctl32.dll.QuerySystemGestureStatus",
- "uxtheme.dll.#49",
- "user32.dll.ChangeWindowMessageFilterEx",
- "gdi32.dll.GetTextExtentExPointWPri",
- "user32.dll.MonitorFromRect",
- "user32.dll.GetMonitorInfoA",
- "imm32.dll.ImmIsIME",
- "shlwapi.dll.SHAutoComplete",
- "ole32.dll.CoCreateInstance",
- "comctl32.dll.#411",
- "comctl32.dll.#410",
- "ole32.dll.CLSIDFromString",
- "comctl32.dll.#413",
- "uxtheme.dll.BufferedPaintInit",
- "uxtheme.dll.BufferedPaintRenderAnimation",
- "uxtheme.dll.GetThemeTransitionDuration",
- "uxtheme.dll.BeginBufferedAnimation",
- "uxtheme.dll.EndBufferedAnimation",
- "uxtheme.dll.DrawThemeParentBackgroundEx",
- "uxtheme.dll.BeginBufferedPaint",
- "uxtheme.dll.EndBufferedPaint",
- "imm32.dll.ImmGetContext",
- "imm32.dll.ImmLockIMC",
- "imm32.dll.ImmUnlockIMC",
- "imm32.dll.ImmReleaseContext",
- "imm32.dll.ImmSetCompositionFontW",
- "imm32.dll.ImmGetCompositionWindow",
- "imm32.dll.ImmSetCompositionWindow",
- "kernel32.dll.GetDiskFreeSpaceExA",
- "imm32.dll.ImmAssociateContext",
- "uxtheme.dll.BufferedPaintStopAllAnimations",
- "sfc.dll.SfcIsFileProtected",
- "setupapi.dll.PnpIsFilePnpDriver",
- "kernel32.dll.RegOpenKeyExW",
- "kernel32.dll.RegCloseKey",
- "devrtl.dll.DevRtlGetThreadLogToken",
- "propsys.dll.PSCreateMemoryPropertyStore",
- "comctl32.dll.#328",
- "comctl32.dll.#334",
- "shell32.dll.#102",
- "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
- "advapi32.dll.InitializeSecurityDescriptor",
- "advapi32.dll.SetEntriesInAclW",
- "ntmarta.dll.GetMartaExtensionInterface",
- "advapi32.dll.SetSecurityDescriptorDacl",
- "setupapi.dll.CM_Get_Device_Interface_List_ExW",
- "advapi32.dll.IsTextUnicode",
- "comctl32.dll.#332",
- "comctl32.dll.#338",
- "sechost.dll.ConvertSidToStringSidW",
- "profapi.dll.#104",
- "ole32.dll.CoTaskMemFree",
- "linkinfo.dll.CreateLinkInfoW",
- "comctl32.dll.#386",
- "user32.dll.IsCharAlphaW",
- "user32.dll.CharPrevW",
- "ntshrui.dll.GetNetResourceFromLocalPathW",
- "srvcli.dll.NetShareEnum",
- "cscapi.dll.CscNetApiGetInterface",
- "slc.dll.SLGetWindowsInformationDWORD",
- "shlwapi.dll.PathRemoveFileSpecW",
- "linkinfo.dll.DestroyLinkInfo",
- "comctl32.dll.#412",
- "comctl32.dll.#388",
- "uxtheme.dll.BufferedPaintUnInit",
- "oleaut32.dll.#500",
- "netutils.dll.NetApiBufferFree",
- "advapi32.dll.UnregisterTraceGuids",
- "comctl32.dll.#321"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x40d0b4"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x40d0b8"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x40d0bc"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x40d0c0"
- },
- {
- "name": "VirtualFree",
- "address": "0x40d0c4"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x40d0c8"
- },
- {
- "name": "LocalFree",
- "address": "0x40d0cc"
- },
- {
- "name": "LocalAlloc",
- "address": "0x40d0d0"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x40d0d4"
- },
- {
- "name": "TlsSetValue",
- "address": "0x40d0d8"
- },
- {
- "name": "TlsGetValue",
- "address": "0x40d0dc"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x40d0e0"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x40d0e4"
- },
- {
- "name": "GetLastError",
- "address": "0x40d0e8"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x40d0ec"
- },
- {
- "name": "WriteFile",
- "address": "0x40d0f0"
- },
- {
- "name": "SetFilePointer",
- "address": "0x40d0f4"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x40d0f8"
- },
- {
- "name": "RtlUnwind",
- "address": "0x40d0fc"
- },
- {
- "name": "ReadFile",
- "address": "0x40d100"
- },
- {
- "name": "RaiseException",
- "address": "0x40d104"
- },
- {
- "name": "GetStdHandle",
- "address": "0x40d108"
- },
- {
- "name": "GetFileSize",
- "address": "0x40d10c"
- },
- {
- "name": "GetSystemTime",
- "address": "0x40d110"
- },
- {
- "name": "GetFileType",
- "address": "0x40d114"
- },
- {
- "name": "ExitProcess",
- "address": "0x40d118"
- },
- {
- "name": "CreateFileA",
- "address": "0x40d11c"
- },
- {
- "name": "CloseHandle",
- "address": "0x40d120"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "MessageBoxA",
- "address": "0x40d128"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "VariantChangeTypeEx",
- "address": "0x40d130"
- },
- {
- "name": "VariantCopyInd",
- "address": "0x40d134"
- },
- {
- "name": "VariantClear",
- "address": "0x40d138"
- },
- {
- "name": "SysStringLen",
- "address": "0x40d13c"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x40d140"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x40d148"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x40d14c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x40d150"
- },
- {
- "name": "OpenProcessToken",
- "address": "0x40d154"
- },
- {
- "name": "LookupPrivilegeValueA",
- "address": "0x40d158"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "WriteFile",
- "address": "0x40d160"
- },
- {
- "name": "VirtualQuery",
- "address": "0x40d164"
- },
- {
- "name": "VirtualProtect",
- "address": "0x40d168"
- },
- {
- "name": "VirtualFree",
- "address": "0x40d16c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x40d170"
- },
- {
- "name": "Sleep",
- "address": "0x40d174"
- },
- {
- "name": "SizeofResource",
- "address": "0x40d178"
- },
- {
- "name": "SetLastError",
- "address": "0x40d17c"
- },
- {
- "name": "SetFilePointer",
- "address": "0x40d180"
- },
- {
- "name": "SetErrorMode",
- "address": "0x40d184"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x40d188"
- },
- {
- "name": "RemoveDirectoryA",
- "address": "0x40d18c"
- },
- {
- "name": "ReadFile",
- "address": "0x40d190"
- },
- {
- "name": "LockResource",
- "address": "0x40d194"
- },
- {
- "name": "LoadResource",
- "address": "0x40d198"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x40d19c"
- },
- {
- "name": "IsDBCSLeadByte",
- "address": "0x40d1a0"
- },
- {
- "name": "GetWindowsDirectoryA",
- "address": "0x40d1a4"
- },
- {
- "name": "GetVersionExA",
- "address": "0x40d1a8"
- },
- {
- "name": "GetUserDefaultLangID",
- "address": "0x40d1ac"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x40d1b0"
- },
- {
- "name": "GetSystemDefaultLCID",
- "address": "0x40d1b4"
- },
- {
- "name": "GetProcAddress",
- "address": "0x40d1b8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x40d1bc"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x40d1c0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x40d1c4"
- },
- {
- "name": "GetLastError",
- "address": "0x40d1c8"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x40d1cc"
- },
- {
- "name": "GetFileSize",
- "address": "0x40d1d0"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0x40d1d4"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0x40d1d8"
- },
- {
- "name": "GetEnvironmentVariableA",
- "address": "0x40d1dc"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x40d1e0"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x40d1e4"
- },
- {
- "name": "GetACP",
- "address": "0x40d1e8"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x40d1ec"
- },
- {
- "name": "FormatMessageA",
- "address": "0x40d1f0"
- },
- {
- "name": "FindResourceA",
- "address": "0x40d1f4"
- },
- {
- "name": "DeleteFileA",
- "address": "0x40d1f8"
- },
- {
- "name": "CreateProcessA",
- "address": "0x40d1fc"
- },
- {
- "name": "CreateFileA",
- "address": "0x40d200"
- },
- {
- "name": "CreateDirectoryA",
- "address": "0x40d204"
- },
- {
- "name": "CloseHandle",
- "address": "0x40d208"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "TranslateMessage",
- "address": "0x40d210"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x40d214"
- },
- {
- "name": "PeekMessageA",
- "address": "0x40d218"
- },
- {
- "name": "MsgWaitForMultipleObjects",
- "address": "0x40d21c"
- },
- {
- "name": "MessageBoxA",
- "address": "0x40d220"
- },
- {
- "name": "LoadStringA",
- "address": "0x40d224"
- },
- {
- "name": "ExitWindowsEx",
- "address": "0x40d228"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x40d22c"
- },
- {
- "name": "DestroyWindow",
- "address": "0x40d230"
- },
- {
- "name": "CreateWindowExA",
- "address": "0x40d234"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x40d238"
- },
- {
- "name": "CharPrevA",
- "address": "0x40d23c"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "InitCommonControls",
- "address": "0x40d244"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "AdjustTokenPrivileges",
- "address": "0x40d24c"
- }
- ],
- "dll": "advapi32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00bb4532",
- "overlay": {
- "size": "0x00ba528a",
- "offset": "0x0000d400"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x00409c40",
- "timestamp": "1992-06-19 22:22:17",
- "osversion": "1.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00009400",
- "entropy": "6.56",
- "raw_address": "0x00000400",
- "virtual_size": "0x00009364",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000b000",
- "size_of_data": "0x00000400",
- "entropy": "2.75",
- "raw_address": "0x00009800",
- "virtual_size": "0x0000024c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000c000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00009c00",
- "virtual_size": "0x00000e4c",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000d000",
- "size_of_data": "0x00000a00",
- "entropy": "4.43",
- "raw_address": "0x00009c00",
- "virtual_size": "0x00000950",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000e000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0000a600",
- "virtual_size": "0x00000008",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0000f000",
- "size_of_data": "0x00000200",
- "entropy": "0.20",
- "raw_address": "0x0000a600",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00010000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00000000",
- "virtual_size": "0x000008b4",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00011000",
- "size_of_data": "0x00002c00",
- "entropy": "4.46",
- "raw_address": "0x0000a800",
- "virtual_size": "0x00002c00",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000d000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000950"
- },
- {
- "virtual_address": "0x00011000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00002c00"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000f000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "884310b1928934402ea6fec1dbd3cf5e",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 8,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement