Detections

Yara:

AgentTeslaV2

Analysis

Category Package Started Completed Duration Options Log
FILE exe 2020-06-23 06:01:36 2020-06-23 06:06:54 318 seconds Show Options Show Log
route = tor
2020-05-13 09:13:49,922 [root] INFO: Date set to: 20200623T06:00:27, timeout set to: 200
2020-06-23 06:00:27,031 [root] DEBUG: Starting analyzer from: C:\tmpq_mrpfl7
2020-06-23 06:00:27,031 [root] DEBUG: Storing results at: C:\XrrYEy
2020-06-23 06:00:27,031 [root] DEBUG: Pipe server name: \\.\PIPE\CvaFbsn
2020-06-23 06:00:27,031 [root] DEBUG: Python path: C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32
2020-06-23 06:00:27,031 [root] DEBUG: No analysis package specified, trying to detect it automagically.
2020-06-23 06:00:27,046 [root] INFO: Automatically selected analysis package "exe"
2020-06-23 06:00:27,046 [root] DEBUG: Trying to import analysis package "exe"...
2020-06-23 06:00:27,062 [root] DEBUG: Imported analysis package "exe".
2020-06-23 06:00:27,062 [root] DEBUG: Trying to initialize analysis package "exe"...
2020-06-23 06:00:27,078 [root] DEBUG: Initialized analysis package "exe".
2020-06-23 06:00:27,140 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.browser"...
2020-06-23 06:00:27,156 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser".
2020-06-23 06:00:27,156 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.curtain"...
2020-06-23 06:00:27,296 [root] DEBUG: Imported auxiliary module "modules.auxiliary.curtain".
2020-06-23 06:00:27,296 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.digisig"...
2020-06-23 06:00:27,312 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig".
2020-06-23 06:00:27,312 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.disguise"...
2020-06-23 06:00:27,328 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise".
2020-06-23 06:00:27,328 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.human"...
2020-06-23 06:00:27,343 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human".
2020-06-23 06:00:27,343 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.procmon"...
2020-06-23 06:00:27,343 [root] DEBUG: Imported auxiliary module "modules.auxiliary.procmon".
2020-06-23 06:00:27,343 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.screenshots"...
2020-06-23 06:00:27,359 [modules.auxiliary.screenshots] DEBUG: Importing 'time'
2020-06-23 06:00:27,359 [modules.auxiliary.screenshots] DEBUG: Importing 'StringIO'
2020-06-23 06:00:27,359 [modules.auxiliary.screenshots] DEBUG: Importing 'Thread'
2020-06-23 06:00:27,359 [modules.auxiliary.screenshots] DEBUG: Importing 'Auxiliary'
2020-06-23 06:00:27,359 [modules.auxiliary.screenshots] DEBUG: Importing 'NetlogFile'
2020-06-23 06:00:27,359 [modules.auxiliary.screenshots] DEBUG: Importing 'Screenshot'
2020-06-23 06:00:27,375 [lib.api.screenshot] DEBUG: Importing 'math'
2020-06-23 06:00:27,375 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2020-06-23 06:00:29,249 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2020-06-23 06:00:29,281 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2020-06-23 06:00:29,312 [modules.auxiliary.screenshots] DEBUG: Imports OK
2020-06-23 06:00:29,328 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots".
2020-06-23 06:00:29,328 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.sysmon"...
2020-06-23 06:00:29,328 [root] DEBUG: Imported auxiliary module "modules.auxiliary.sysmon".
2020-06-23 06:00:29,328 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.usage"...
2020-06-23 06:00:29,328 [root] DEBUG: Imported auxiliary module "modules.auxiliary.usage".
2020-06-23 06:00:29,328 [root] DEBUG: Trying to initialize auxiliary module "Browser"...
2020-06-23 06:00:29,328 [root] DEBUG: Initialized auxiliary module "Browser".
2020-06-23 06:00:29,328 [root] DEBUG: Trying to start auxiliary module "Browser"...
2020-06-23 06:00:29,328 [root] DEBUG: Started auxiliary module Browser
2020-06-23 06:00:29,343 [root] DEBUG: Trying to initialize auxiliary module "Curtain"...
2020-06-23 06:00:29,343 [root] DEBUG: Initialized auxiliary module "Curtain".
2020-06-23 06:00:29,343 [root] DEBUG: Trying to start auxiliary module "Curtain"...
2020-06-23 06:00:29,343 [root] DEBUG: Started auxiliary module Curtain
2020-06-23 06:00:29,343 [root] DEBUG: Trying to initialize auxiliary module "DigiSig"...
2020-06-23 06:00:29,343 [root] DEBUG: Initialized auxiliary module "DigiSig".
2020-06-23 06:00:29,343 [root] DEBUG: Trying to start auxiliary module "DigiSig"...
2020-06-23 06:00:29,343 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature.
2020-06-23 06:00:29,687 [modules.auxiliary.digisig] DEBUG: File is not signed.
2020-06-23 06:00:29,687 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2020-06-23 06:00:29,703 [root] DEBUG: Started auxiliary module DigiSig
2020-06-23 06:00:29,703 [root] DEBUG: Trying to initialize auxiliary module "Disguise"...
2020-06-23 06:00:29,703 [root] DEBUG: Initialized auxiliary module "Disguise".
2020-06-23 06:00:29,703 [root] DEBUG: Trying to start auxiliary module "Disguise"...
2020-06-23 06:00:29,734 [root] DEBUG: Started auxiliary module Disguise
2020-06-23 06:00:29,734 [root] DEBUG: Trying to initialize auxiliary module "Human"...
2020-06-23 06:00:29,734 [root] DEBUG: Initialized auxiliary module "Human".
2020-06-23 06:00:29,734 [root] DEBUG: Trying to start auxiliary module "Human"...
2020-06-23 06:00:29,750 [root] DEBUG: Started auxiliary module Human
2020-06-23 06:00:29,750 [root] DEBUG: Trying to initialize auxiliary module "Procmon"...
2020-06-23 06:00:29,750 [root] DEBUG: Initialized auxiliary module "Procmon".
2020-06-23 06:00:29,750 [root] DEBUG: Trying to start auxiliary module "Procmon"...
2020-06-23 06:00:29,750 [root] DEBUG: Started auxiliary module Procmon
2020-06-23 06:00:29,750 [root] DEBUG: Trying to initialize auxiliary module "Screenshots"...
2020-06-23 06:00:29,750 [root] DEBUG: Initialized auxiliary module "Screenshots".
2020-06-23 06:00:29,750 [root] DEBUG: Trying to start auxiliary module "Screenshots"...
2020-06-23 06:00:29,765 [root] DEBUG: Started auxiliary module Screenshots
2020-06-23 06:00:29,765 [root] DEBUG: Trying to initialize auxiliary module "Sysmon"...
2020-06-23 06:00:29,765 [root] DEBUG: Initialized auxiliary module "Sysmon".
2020-06-23 06:00:29,765 [root] DEBUG: Trying to start auxiliary module "Sysmon"...
2020-06-23 06:00:29,765 [root] DEBUG: Started auxiliary module Sysmon
2020-06-23 06:00:29,765 [root] DEBUG: Trying to initialize auxiliary module "Usage"...
2020-06-23 06:00:29,765 [root] DEBUG: Initialized auxiliary module "Usage".
2020-06-23 06:00:29,765 [root] DEBUG: Trying to start auxiliary module "Usage"...
2020-06-23 06:00:29,765 [root] DEBUG: Started auxiliary module Usage
2020-06-23 06:00:29,765 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2020-06-23 06:00:29,765 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2020-06-23 06:00:29,781 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2020-06-23 06:00:29,781 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2020-06-23 06:00:30,187 [lib.api.process] INFO: Successfully executed process from path "C:\Users\Rebecca\AppData\Local\Temp\mulqBW.exe" with arguments "" with pid 1784
2020-06-23 06:00:30,187 [lib.api.process] INFO: Monitor config for process 1784: C:\tmpq_mrpfl7\dll\1784.ini
2020-06-23 06:00:30,187 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\ESHTTPN.dll, loader C:\tmpq_mrpfl7\bin\zBkUsNq.exe
2020-06-23 06:00:30,421 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\CvaFbsn.
2020-06-23 06:00:30,421 [root] DEBUG: Loader: Injecting process 1784 (thread 3948) with C:\tmpq_mrpfl7\dll\ESHTTPN.dll.
2020-06-23 06:00:30,421 [root] DEBUG: Process image base: 0x00A40000
2020-06-23 06:00:30,421 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2020-06-23 06:00:30,421 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2020-06-23 06:00:30,421 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\ESHTTPN.dll.
2020-06-23 06:00:30,437 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 1784
2020-06-23 06:00:32,437 [lib.api.process] INFO: Successfully resumed process with pid 1784
2020-06-23 06:00:33,031 [root] DEBUG: Python path set to 'C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32'.
2020-06-23 06:00:33,031 [root] DEBUG: Dropped file limit defaulting to 100.
2020-06-23 06:00:33,031 [root] DEBUG: CAPE initialised: 32-bit monitor loaded in process 1784 at 0x6b650000, image base 0xa40000, stack from 0x1b6000-0x1c0000
2020-06-23 06:00:33,046 [root] DEBUG: Commandline: C:\Users\Rebecca\AppData\Local\Temp\"C:\Users\Rebecca\AppData\Local\Temp\mulqBW.exe".
2020-06-23 06:00:33,046 [root] INFO: Loaded monitor into process with pid 1784
2020-06-23 06:00:33,062 [root] DEBUG: set_caller_info: Adding region at 0x000C0000 to caller regions list (advapi32::RegQueryInfoKeyW).
2020-06-23 06:00:33,093 [root] DEBUG: set_caller_info: Adding region at 0x01800000 to caller regions list (ntdll::RtlDispatchException).
2020-06-23 06:00:33,171 [root] DEBUG: DLL loaded at 0x75B30000: C:\Windows\system32\cryptbase (0xc000 bytes).
2020-06-23 06:00:33,171 [root] DEBUG: DumpMemory: Exception occured reading memory address 0x1800000
2020-06-23 06:00:33,171 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x01800000 size 0x400000.
2020-06-23 06:00:33,781 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\1784_33087530833201023262020 (size 0xf1e)
2020-06-23 06:00:33,781 [root] DEBUG: DumpRegion: Dumped stack region from 0x01800000, size 0x1000.
2020-06-23 06:00:33,781 [root] DEBUG: set_caller_info: Failed to dumping calling PE image at 0x000C0000.
2020-06-23 06:00:33,796 [root] DEBUG: set_caller_info: Adding region at 0x00550000 to caller regions list (kernel32::FindFirstFileExW).
2020-06-23 06:00:34,312 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\1784_13946595233201023262020 (size 0x100099)
2020-06-23 06:00:34,312 [root] DEBUG: DumpRegion: Dumped stack region from 0x00550000, size 0x101000.
2020-06-23 06:00:34,312 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xb8 amd local view 0x71720000 to global list.
2020-06-23 06:00:34,312 [root] DEBUG: DLL loaded at 0x71720000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x7d000 bytes).
2020-06-23 06:00:34,328 [root] DEBUG: DLL unloaded from 0x76A30000.
2020-06-23 06:00:34,343 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xd4 amd local view 0x003F0000 to global list.
2020-06-23 06:00:34,343 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xd0 amd local view 0x003F0000 to global list.
2020-06-23 06:00:34,343 [root] DEBUG: DLL loaded at 0x750B0000: C:\Windows\system32\VERSION (0x9000 bytes).
2020-06-23 06:00:34,375 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x68450000 for section view with handle 0xd0.
2020-06-23 06:00:34,375 [root] DEBUG: DLL loaded at 0x68450000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks (0x5b1000 bytes).
2020-06-23 06:00:34,375 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x6B5B0000 for section view with handle 0xd4.
2020-06-23 06:00:34,390 [root] DEBUG: DLL loaded at 0x6B5B0000: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\MSVCR80 (0x9b000 bytes).
2020-06-23 06:00:34,406 [root] DEBUG: OpenProcessHandler: Injection info created for Pid 1784, handle 0xe0.
2020-06-23 06:00:34,406 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xdc amd local view 0x000A0000 to global list.
2020-06-23 06:00:34,406 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xe4 amd local view 0x000B0000 to global list.
2020-06-23 06:00:34,406 [root] INFO: Disabling sleep skipping.
2020-06-23 06:00:34,406 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 1784.
2020-06-23 06:00:34,421 [root] DEBUG: DLL loaded at 0x76AE0000: C:\Windows\system32\shell32 (0xc4c000 bytes).
2020-06-23 06:00:34,437 [root] DEBUG: DLL loaded at 0x75BE0000: C:\Windows\system32\profapi (0xb000 bytes).
2020-06-23 06:00:34,453 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 1784.
2020-06-23 06:00:34,468 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1a0 amd local view 0x672E0000 to global list.
2020-06-23 06:00:34,468 [root] DEBUG: DLL loaded at 0x672E0000: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f8420d8c6ede777377fcff48a4beaa2a\mscorlib.ni (0xafe000 bytes).
2020-06-23 06:00:34,484 [root] DEBUG: DLL unloaded from 0x763A0000.
2020-06-23 06:00:34,515 [root] DEBUG: set_caller_info: Adding region at 0x034C0000 to caller regions list (kernel32::SetErrorMode).
2020-06-23 06:00:34,531 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x34fffff
2020-06-23 06:00:34,531 [root] DEBUG: DumpMemory: Nothing to dump at 0x034C0000!
2020-06-23 06:00:34,531 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x034C0000 size 0x40000.
2020-06-23 06:00:34,531 [root] DEBUG: DumpPEsInRange: Scanning range 0x34c0000 - 0x34c1000.
2020-06-23 06:00:34,531 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x34c0000-0x34c1000.
2020-06-23 06:00:34,578 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\1784_22555701834201023262020 (size 0xffe)
2020-06-23 06:00:34,578 [root] DEBUG: DumpRegion: Dumped stack region from 0x034C0000, size 0x1000.
2020-06-23 06:00:34,578 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1b4 amd local view 0x00400000 to global list.
2020-06-23 06:00:34,593 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1b0 amd local view 0x00800000 to global list.
2020-06-23 06:00:34,890 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x6B550000 for section view with handle 0x1b0.
2020-06-23 06:00:34,890 [root] DEBUG: DLL loaded at 0x6B550000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit (0x5b000 bytes).
2020-06-23 06:00:35,093 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1c4 amd local view 0x66B30000 to global list.
2020-06-23 06:00:35,109 [root] DEBUG: DLL loaded at 0x66B30000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0a65164b17e5c64bacdc694ea2439c43\System.ni (0x7a5000 bytes).
2020-06-23 06:00:35,109 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x682C0000 for section view with handle 0x1c4.
2020-06-23 06:00:35,109 [root] DEBUG: DLL loaded at 0x682C0000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\175df210b784212def386595c25caefb\System.Drawing.ni (0x189000 bytes).
2020-06-23 06:00:35,125 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x654C0000 for section view with handle 0x1c4.
2020-06-23 06:00:35,125 [root] DEBUG: DLL loaded at 0x654C0000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\5669120680b52abf616f3876387ca2cc\System.Windows.Forms.ni (0xbdf000 bytes).
2020-06-23 06:00:35,343 [root] DEBUG: set_caller_info: Adding region at 0x00430000 to caller regions list (ntdll::NtAllocateVirtualMemory).
2020-06-23 06:00:35,343 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x43ffff
2020-06-23 06:00:35,359 [root] DEBUG: DumpMemory: Nothing to dump at 0x00430000!
2020-06-23 06:00:35,359 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x00430000 size 0x10000.
2020-06-23 06:00:35,359 [root] DEBUG: DumpPEsInRange: Scanning range 0x430000 - 0x431000.
2020-06-23 06:00:35,359 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x430000-0x431000.
2020-06-23 06:00:35,390 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\1784_132444868335201023262020 (size 0xb3)
2020-06-23 06:00:35,390 [root] DEBUG: DLL loaded at 0x74790000: C:\Windows\system32\uxtheme (0x40000 bytes).
2020-06-23 06:00:35,390 [root] DEBUG: set_caller_info: Adding region at 0x00340000 to caller regions list (ntdll::LdrGetProcedureAddress).
2020-06-23 06:00:35,406 [root] DEBUG: set_caller_info: Failed to dumping calling PE image at 0x00340000.
2020-06-23 06:00:35,406 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1d0 amd local view 0x66660000 to global list.
2020-06-23 06:00:36,593 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1d8 amd local view 0x74560000 to global list.
2020-06-23 06:00:36,609 [root] DEBUG: DLL loaded at 0x74560000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24308_none_5c028e37a0121035\gdiplus (0x192000 bytes).
2020-06-23 06:00:36,765 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1e8 amd local view 0x00870000 to global list.
2020-06-23 06:00:36,890 [root] INFO: Added new file to list with pid None and path C:\Users\Rebecca\AppData\Local\GDIPFONTCACHEV1.DAT
2020-06-23 06:00:36,906 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1e4 amd local view 0x00450000 to global list.
2020-06-23 06:00:36,906 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1f4 amd local view 0x00800000 to global list.
2020-06-23 06:00:36,984 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:37,015 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x032F0000 for section view with handle 0x1f4.
2020-06-23 06:00:37,031 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:37,046 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x032F0000 for section view with handle 0x1f4.
2020-06-23 06:00:37,093 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:37,265 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:37,359 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x032F0000 for section view with handle 0x1f4.
2020-06-23 06:00:37,406 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:37,609 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:37,765 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:37,796 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x032F0000 for section view with handle 0x1f4.
2020-06-23 06:00:37,828 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:38,234 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:38,312 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:38,343 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:38,718 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:38,765 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x07880000 for section view with handle 0x1f4.
2020-06-23 06:00:38,859 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:38,906 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x07880000 for section view with handle 0x1f4.
2020-06-23 06:00:39,000 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:39,078 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x07880000 for section view with handle 0x1f4.
2020-06-23 06:00:39,296 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:39,328 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:39,453 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:39,656 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:39,750 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x02C10000 for section view with handle 0x1f4.
2020-06-23 06:00:39,765 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:39,828 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:39,953 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:40,343 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:41,140 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:41,265 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:41,390 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:41,437 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:42,484 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:42,625 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:42,843 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:43,015 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:43,078 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:44,593 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:44,609 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:44,687 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:44,859 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:45,218 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:45,531 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:45,703 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:46,500 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:46,515 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:46,546 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:46,593 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:46,796 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:46,812 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:46,828 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:46,859 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:46,890 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:46,968 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:47,015 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:47,046 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:47,140 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:47,218 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:47,437 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:47,484 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x02C10000 for section view with handle 0x1f4.
2020-06-23 06:00:47,515 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:48,562 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:48,609 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:48,828 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:48,875 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:48,890 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:49,046 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:49,078 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:49,296 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:49,328 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:49,375 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:49,406 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:49,484 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:49,515 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:49,562 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:49,578 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:49,593 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:49,625 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:49,750 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:49,859 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:49,906 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:49,953 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,093 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,125 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,218 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,234 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,375 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,421 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,468 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,484 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,515 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,546 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,562 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,625 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,703 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,750 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,765 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,812 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,812 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:50,953 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:50,984 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,015 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:51,093 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:51,203 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,234 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:51,265 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,281 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:51,328 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,343 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:51,359 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,453 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:51,531 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,546 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:51,593 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,625 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:51,687 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,703 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05930000 for section view with handle 0x1f4.
2020-06-23 06:00:51,750 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,812 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:51,968 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:51,984 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x08850000 for section view with handle 0x1f4.
2020-06-23 06:00:52,312 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:52,328 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:52,359 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:52,390 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:52,453 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:52,468 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:52,500 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05AF0000 for section view with handle 0x1f4.
2020-06-23 06:00:52,546 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:52,828 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:52,843 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:52,875 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00800000 for section view with handle 0x1f4.
2020-06-23 06:00:52,890 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00870000 for section view with handle 0x1f4.
2020-06-23 06:00:53,031 [root] DEBUG: set_caller_info: Adding region at 0x00450000 to caller regions list (ntdll::memcpy).
2020-06-23 06:00:53,031 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x45ffff
2020-06-23 06:00:53,031 [root] DEBUG: DumpMemory: Nothing to dump at 0x00450000!
2020-06-23 06:00:53,031 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x00450000 size 0x10000.
2020-06-23 06:00:53,046 [root] DEBUG: DumpPEsInRange: Scanning range 0x450000 - 0x451000.
2020-06-23 06:00:53,046 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x450000-0x451000.
2020-06-23 06:00:53,109 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\1784_23406730453201023262020 (size 0xdb)
2020-06-23 06:00:53,125 [root] DEBUG: DumpRegion: Dumped stack region from 0x00450000, size 0x1000.
2020-06-23 06:00:53,171 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05D90000 for section view with handle 0x1f4.
2020-06-23 06:00:53,203 [root] DEBUG: DLL loaded at 0x73E10000: C:\Windows\system32\WindowsCodecs (0x131000 bytes).
2020-06-23 06:00:53,265 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x200 amd local view 0x00880000 to global list.
2020-06-23 06:00:53,281 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x208 amd local view 0x00890000 to global list.
2020-06-23 06:00:53,359 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x210 amd local view 0x73820000 to global list.
2020-06-23 06:00:53,359 [root] DEBUG: DLL loaded at 0x73820000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\culture (0x8000 bytes).
2020-06-23 06:00:53,375 [root] DEBUG: DLL unloaded from 0x73820000.
2020-06-23 06:00:53,375 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x02C10000 for section view with handle 0x210.
2020-06-23 06:00:53,500 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x20c amd local view 0x68120000 to global list.
2020-06-23 06:00:53,500 [root] DEBUG: DLL loaded at 0x68120000: C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4ac828c8c4c76f3ba59f8f9c7dab1cb3\Microsoft.VisualBasic.ni (0x19b000 bytes).
2020-06-23 06:00:53,515 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x009F0000 for section view with handle 0x210.
2020-06-23 06:01:03,718 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00A00000 for section view with handle 0x210.
2020-06-23 06:01:03,718 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00A10000 for section view with handle 0x210.
2020-06-23 06:01:03,718 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x00A20000 for section view with handle 0x210.
2020-06-23 06:01:04,046 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x02D90000 for section view with handle 0x20c.
2020-06-23 06:01:04,406 [root] INFO: Announced 32-bit process name: mulqBW.exe pid: 5540
2020-06-23 06:01:04,406 [lib.api.process] INFO: Monitor config for process 5540: C:\tmpq_mrpfl7\dll\5540.ini
2020-06-23 06:01:04,406 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\ESHTTPN.dll, loader C:\tmpq_mrpfl7\bin\zBkUsNq.exe
2020-06-23 06:01:04,437 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\CvaFbsn.
2020-06-23 06:01:04,453 [root] DEBUG: Loader: Injecting process 5540 (thread 5448) with C:\tmpq_mrpfl7\dll\ESHTTPN.dll.
2020-06-23 06:01:04,453 [root] DEBUG: Process image base: 0x00A40000
2020-06-23 06:01:04,453 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2020-06-23 06:01:04,453 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2020-06-23 06:01:04,453 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\ESHTTPN.dll.
2020-06-23 06:01:04,468 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 5540
2020-06-23 06:01:04,468 [root] DEBUG: DLL loaded at 0x75AE0000: C:\Windows\system32\apphelp (0x4c000 bytes).
2020-06-23 06:01:04,500 [root] DEBUG: CreateProcessHandler: Injection info set for new process 5540, ImageBase: 0x00A40000
2020-06-23 06:01:04,500 [root] INFO: Announced 32-bit process name: mulqBW.exe pid: 5540
2020-06-23 06:01:04,500 [lib.api.process] INFO: Monitor config for process 5540: C:\tmpq_mrpfl7\dll\5540.ini
2020-06-23 06:01:04,500 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\ESHTTPN.dll, loader C:\tmpq_mrpfl7\bin\zBkUsNq.exe
2020-06-23 06:01:04,515 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\CvaFbsn.
2020-06-23 06:01:04,515 [root] DEBUG: Loader: Injecting process 5540 (thread 5448) with C:\tmpq_mrpfl7\dll\ESHTTPN.dll.
2020-06-23 06:01:04,531 [root] DEBUG: Process image base: 0x00A40000
2020-06-23 06:01:04,531 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2020-06-23 06:01:04,531 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2020-06-23 06:01:04,531 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\ESHTTPN.dll.
2020-06-23 06:01:04,531 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 5540
2020-06-23 06:01:04,531 [root] DEBUG: WriteMemoryHandler: Executable binary injected into process 5540 (ImageBase 0x400000)
2020-06-23 06:01:04,546 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2020-06-23 06:01:04,546 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x04ACE980.
2020-06-23 06:01:04,578 [root] DEBUG: DumpPE: PE file in memory dumped successfully - dump size 0x46400.
2020-06-23 06:01:04,578 [root] DEBUG: WriteMemoryHandler: Dumped PE image from buffer at 0x4ace980, SizeOfImage 0x4c000.
2020-06-23 06:01:04,593 [root] INFO: Announced 32-bit process name: mulqBW.exe pid: 5540
2020-06-23 06:01:04,593 [lib.api.process] INFO: Monitor config for process 5540: C:\tmpq_mrpfl7\dll\5540.ini
2020-06-23 06:01:04,593 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\ESHTTPN.dll, loader C:\tmpq_mrpfl7\bin\zBkUsNq.exe
2020-06-23 06:01:04,609 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\CvaFbsn.
2020-06-23 06:01:04,609 [root] DEBUG: Loader: Injecting process 5540 (thread 0) with C:\tmpq_mrpfl7\dll\ESHTTPN.dll.
2020-06-23 06:01:04,609 [root] DEBUG: Error 0 (0x0) - GetProcessInitialThreadId: Remote PEB 0x7FFD8000 Local PEB 0x7FFDF000 Local TEB 0x7FFD7000: The operation completed successfully.
2020-06-23 06:01:04,609 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID -17, handle 0x0
2020-06-23 06:01:04,625 [root] DEBUG: Python path set to 'C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32'.
2020-06-23 06:01:04,625 [root] DEBUG: Dropped file limit defaulting to 100.
2020-06-23 06:01:04,640 [root] INFO: Disabling sleep skipping.
2020-06-23 06:01:04,640 [root] DEBUG: CAPE initialised: 32-bit monitor loaded in process 5540 at 0x6b650000, image base 0xa40000, stack from 0x3f6000-0x400000
2020-06-23 06:01:04,656 [root] DEBUG: Commandline: C:\Users\Rebecca\AppData\Local\Temp\"{path}".
2020-06-23 06:01:04,671 [root] INFO: Loaded monitor into process with pid 5540
2020-06-23 06:01:04,671 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2020-06-23 06:01:04,671 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2020-06-23 06:01:04,671 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\ESHTTPN.dll.
2020-06-23 06:01:04,687 [root] DEBUG: WriteMemoryHandler: shellcode at 0x0482C710 (size 0x45c00) injected into process 5540.
2020-06-23 06:01:04,734 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\1784_194254398527211023262020 (size 0x45a12)
2020-06-23 06:01:04,734 [root] DEBUG: WriteMemoryHandler: Dumped injected code/data from buffer.
2020-06-23 06:01:04,734 [root] DEBUG: WriteMemoryHandler: shellcode at 0x037EFB88 (size 0x400) injected into process 5540.
2020-06-23 06:01:04,765 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\1784_148916221427211023262020 (size 0x2f8)
2020-06-23 06:01:04,765 [root] DEBUG: WriteMemoryHandler: Dumped injected code/data from buffer.
2020-06-23 06:01:04,765 [root] DEBUG: WriteMemoryHandler: shellcode at 0x037EFF94 (size 0x200) injected into process 5540.
2020-06-23 06:01:04,781 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\1784_9335168827211023262020 (size 0x9)
2020-06-23 06:01:04,781 [root] DEBUG: WriteMemoryHandler: Dumped injected code/data from buffer.
2020-06-23 06:01:04,796 [root] DEBUG: SetThreadContextHandler: Hollow process entry point reset via NtSetContextThread to 0x00047A0E (process 5540).
2020-06-23 06:01:04,796 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5540.
2020-06-23 06:01:04,796 [root] DEBUG: set_caller_info: Adding region at 0x00030000 to caller regions list (ntdll::LdrLoadDll).
2020-06-23 06:01:04,812 [root] DEBUG: set_caller_info: Adding region at 0x01700000 to caller regions list (kernel32::GetSystemTime).
2020-06-23 06:01:04,812 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 1784.
2020-06-23 06:01:04,828 [root] DEBUG: DLL loaded at 0x75600000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2020-06-23 06:01:04,828 [root] DEBUG: DLL loaded at 0x75B30000: C:\Windows\system32\cryptbase (0xc000 bytes).
2020-06-23 06:01:04,828 [root] DEBUG: DumpMemory: Exception occured reading memory address 0x1700000
2020-06-23 06:01:04,828 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x01700000 size 0x400000.
2020-06-23 06:01:04,843 [root] DEBUG: DumpPEsInRange: Scanning range 0x1700000 - 0x1701000.
2020-06-23 06:01:04,843 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x1700000-0x1701000.
2020-06-23 06:01:04,843 [root] DEBUG: DLL loaded at 0x75390000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2020-06-23 06:01:04,859 [root] DEBUG: DLL loaded at 0x75BD0000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2020-06-23 06:01:04,859 [root] DEBUG: NtTerminateProcess hook: Attempting to dump process 1784
2020-06-23 06:01:04,859 [root] DEBUG: GetHookCallerBase: thread 3948 (handle 0x0), return address 0x00433983, allocation base 0x00430000.
2020-06-23 06:01:04,875 [root] DEBUG: DoProcessDump: Dumping Imagebase at 0x00A40000.
2020-06-23 06:01:04,875 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\5540_19435912824211023262020 (size 0xffe)
2020-06-23 06:01:04,875 [root] DEBUG: LooksLikeSectionBoundary: Exception occured reading around suspected boundary at 0x00A42000
2020-06-23 06:01:04,875 [root] DEBUG: DumpRegion: Dumped stack region from 0x01700000, size 0x1000.
2020-06-23 06:01:04,875 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2020-06-23 06:01:04,875 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x00A40000.
2020-06-23 06:01:04,875 [root] DEBUG: DumpPE: Empty or inaccessible last section, file image seems incomplete (from 0x00AAB000 to 0x00AAB200).
2020-06-23 06:01:04,906 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\5540_1225634214211023262020 (size 0x12a)
2020-06-23 06:01:04,906 [root] DEBUG: DumpRegion: Dumped stack region from 0x00030000, size 0x1000.
2020-06-23 06:01:04,906 [root] DEBUG: DumpPE: Error: Cannot dump PE file from memory.
2020-06-23 06:01:04,906 [root] DEBUG: DumpImageInCurrentProcess: Failed to dump 'raw' PE image from 0x00A40000, dumping memory region.
2020-06-23 06:01:04,921 [root] DEBUG: DLL loaded at 0x002F0000: C:\tmpq_mrpfl7\dll\ESHTTPN (0xd5000 bytes).
2020-06-23 06:01:04,921 [root] DEBUG: DLL unloaded from 0x72490000.
2020-06-23 06:01:04,921 [root] DEBUG: DLL unloaded from 0x76650000.
2020-06-23 06:01:04,921 [root] DEBUG: DLL unloaded from 0x72490000.
2020-06-23 06:01:04,921 [root] DEBUG: DLL unloaded from 0x76650000.
2020-06-23 06:01:04,921 [root] DEBUG: DLL unloaded from 0x002F0000.
2020-06-23 06:01:04,937 [root] DEBUG: DLL unloaded from 0x76730000.
2020-06-23 06:01:04,937 [root] DEBUG: set_caller_info: Adding region at 0x00070000 to caller regions list (ntdll::LdrLoadDll).
2020-06-23 06:01:04,937 [root] DEBUG: DLL unloaded from 0x68450000.
2020-06-23 06:01:04,937 [root] DEBUG: DLL unloaded from 0x71720000.
2020-06-23 06:01:04,953 [root] DEBUG: NtTerminateProcess hook: Attempting to dump process 1784
2020-06-23 06:01:05,000 [root] DEBUG: GetHookCallerBase: thread 3948 (handle 0x0), return address 0x00433983, allocation base 0x00430000.
2020-06-23 06:01:05,000 [root] DEBUG: DoProcessDump: Dumping Imagebase at 0x00A40000.
2020-06-23 06:01:05,015 [root] DEBUG: LooksLikeSectionBoundary: Exception occured reading around suspected boundary at 0x00A42000
2020-06-23 06:01:05,015 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\XrrYEy\CAPE\5540_13837751774211023262020 (size 0x12a)
2020-06-23 06:01:05,015 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2020-06-23 06:01:05,015 [root] DEBUG: DumpRegion: Dumped stack region from 0x00070000, size 0x1000.
2020-06-23 06:01:05,015 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x00A40000.
2020-06-23 06:01:05,031 [root] DEBUG: DumpPE: Empty or inaccessible last section, file image seems incomplete (from 0x00AAB000 to 0x00AAB200).
2020-06-23 06:01:05,031 [root] DEBUG: DLL loaded at 0x002F0000: C:\tmpq_mrpfl7\dll\ESHTTPN (0xd5000 bytes).
2020-06-23 06:01:05,031 [root] DEBUG: DLL unloaded from 0x72490000.
2020-06-23 06:01:05,046 [root] DEBUG: DLL unloaded from 0x76650000.
2020-06-23 06:01:05,046 [root] DEBUG: DumpPE: Error: Cannot dump PE file from memory.
2020-06-23 06:01:05,046 [root] DEBUG: DumpImageInCurrentProcess: Failed to dump 'raw' PE image from 0x00A40000, dumping memory region.
2020-06-23 06:01:05,078 [root] DEBUG: DLL unloaded from 0x72490000.
2020-06-23 06:01:05,078 [root] INFO: Process with pid 1784 has terminated
2020-06-23 06:01:05,156 [root] DEBUG: DLL unloaded from 0x76650000.
2020-06-23 06:01:05,171 [root] DEBUG: DLL unloaded from 0x002F0000.
2020-06-23 06:01:05,218 [root] DEBUG: set_caller_info: Adding region at 0x00170000 to caller regions list (advapi32::RegQueryInfoKeyW).
2020-06-23 06:01:05,234 [root] DEBUG: DumpPE: Error: Cannot dump PE file from memory.
2020-06-23 06:01:05,249 [root] DEBUG: DumpImageInCurrentProcess: Failed to dump 'raw' PE image from 0x00A40000, dumping memory region.
2020-06-23 06:01:05,281 [root] DEBUG: DoProcessDump: Dumping 'new' Imagebase at 0x00400000.
2020-06-23 06:01:05,281 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2020-06-23 06:01:05,296 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x00400000.
2020-06-23 06:01:05,328 [root] DEBUG: DumpProcess: Module entry point VA is 0x00047A0E.
2020-06-23 06:03:52,843 [root] INFO: Analysis timeout hit, terminating analysis.
2020-06-23 06:03:52,875 [lib.api.process] ERROR: Failed to open terminate event for pid 5540
2020-06-23 06:03:52,890 [root] INFO: Terminate event set for process 5540.
2020-06-23 06:03:52,890 [root] INFO: Created shutdown mutex.
2020-06-23 06:03:53,890 [root] INFO: Shutting down package.
2020-06-23 06:03:53,890 [root] INFO: Stopping auxiliary modules.
2020-06-23 06:03:54,593 [lib.common.results] WARNING: File C:\XrrYEy\bin\procmon.xml doesn't exist anymore
2020-06-23 06:03:54,593 [root] INFO: Finishing auxiliary modules.
2020-06-23 06:03:54,593 [root] INFO: Shutting down pipe server and dumping dropped files.
2020-06-23 06:03:54,640 [root] WARNING: Folder at path "C:\XrrYEy\debugger" does not exist, skip.
2020-06-23 06:03:54,656 [root] INFO: Analysis completed.

Machine

Name Label Manager Started On Shutdown On
win7_4 win7_4 KVM 2020-06-23 06:01:36 2020-06-23 06:06:54

File Details

File Name mulqBW
File Size 438784 bytes
File Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
PE timestamp 2020-06-22 03:27:06
MD5 a0ced2f523a067a34595d6f6c4bdf5f3
SHA1 fa8fa92907c88b55b4ea60506aab2f6d723c12e5
SHA256 2f2bdec90ddd4f85ccc62251a610e0166411b5715690ef16b7add2b1a8221eb4
SHA512 c377ebe44687fbdcc89ab2fc09dcbceb3981881409c04af171d2f1af5b810c2116352ca8b3847d4571bee4989b3a4ab13cbd4cd7f716133a5e9c51ee7395700c
CRC32 738C5080
Ssdeep 6144:iO8Q9Oj/lQisabFwV7ffKoCx9zvkf5K9stiCtLY+BMscASNqetC0yW7vmz/gB+L:i2i3ZS7ffKohM9sFYEcietCZr
Download Download ZIP Resubmit sample

Signatures

SetUnhandledExceptionFilter detected (possible anti-debug)
Behavioural detection: Executable code extraction - unpacking
Yara rule detections observed from a process memory dump/dropped files/CAPE
Hit: PID 1784 trigged the Yara rule 'AgentTeslaV2'
Hit: PID 1784 trigged the Yara rule 'embedded_win_api'
Creates RWX memory
Guard pages use detected - possible anti-debugging.
Dynamic (imported) function loading detected
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: KERNEL32.dll/FlsAlloc
DynamicLoader: KERNEL32.dll/FlsFree
DynamicLoader: KERNEL32.dll/FlsGetValue
DynamicLoader: KERNEL32.dll/FlsSetValue
DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
DynamicLoader: KERNEL32.dll/CreateEventExW
DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
DynamicLoader: KERNEL32.dll/SetThreadpoolWait
DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
DynamicLoader: KERNEL32.dll/CompareStringEx
DynamicLoader: KERNEL32.dll/GetDateFormatEx
DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
DynamicLoader: KERNEL32.dll/GetTimeFormatEx
DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
DynamicLoader: KERNEL32.dll/IsValidLocaleName
DynamicLoader: KERNEL32.dll/LCMapStringEx
DynamicLoader: KERNEL32.dll/GetCurrentPackageId
DynamicLoader: KERNEL32.dll/GetTickCount64
DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
DynamicLoader: KERNEL32.dll/AcquireSRWLockExclusive
DynamicLoader: KERNEL32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/EventRegister
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: MSCOREE.DLL/
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: mscoreei.dll/RegisterShimImplCallback
DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
DynamicLoader: mscoreei.dll/SetShellShimInstance
DynamicLoader: mscoreei.dll/OnShimDllMainCalled
DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
DynamicLoader: mscoreei.dll/_CorExeMain
DynamicLoader: SHLWAPI.dll/UrlIsW
DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
DynamicLoader: VERSION.dll/GetFileVersionInfoW
DynamicLoader: VERSION.dll/VerQueryValueW
DynamicLoader: KERNEL32.dll/FlsAlloc
DynamicLoader: KERNEL32.dll/FlsGetValue
DynamicLoader: KERNEL32.dll/FlsSetValue
DynamicLoader: KERNEL32.dll/FlsFree
DynamicLoader: KERNEL32.dll/InitializeCriticalSectionAndSpinCount
DynamicLoader: KERNEL32.dll/IsProcessorFeaturePresent
DynamicLoader: msvcrt.dll/_set_error_mode
DynamicLoader: msvcrt.dll/[email protected]@[email protected]
DynamicLoader: msvcrt.dll/_get_terminate
DynamicLoader: KERNEL32.dll/FindActCtxSectionStringW
DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
DynamicLoader: MSCOREE.DLL/GetProcessExecutableHeap
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
DynamicLoader: mscorwks.dll/SetLoadedByMscoree
DynamicLoader: USER32.dll/GetProcessWindowStation
DynamicLoader: USER32.dll/GetUserObjectInformationW
DynamicLoader: mscorwks.dll/_CorExeMain
DynamicLoader: mscorwks.dll/GetCLRFunction
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsW
DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
DynamicLoader: ADVAPI32.dll/GetTraceLoggerHandle
DynamicLoader: ADVAPI32.dll/GetTraceEnableLevel
DynamicLoader: ADVAPI32.dll/GetTraceEnableFlags
DynamicLoader: ADVAPI32.dll/TraceEvent
DynamicLoader: MSCOREE.DLL/IEE
DynamicLoader: mscoreei.dll/IEE_RetAddr
DynamicLoader: mscoreei.dll/IEE
DynamicLoader: mscorwks.dll/IEE
DynamicLoader: MSCOREE.DLL/GetStartupFlags
DynamicLoader: mscoreei.dll/GetStartupFlags_RetAddr
DynamicLoader: mscoreei.dll/GetStartupFlags
DynamicLoader: MSCOREE.DLL/GetHostConfigurationFile
DynamicLoader: mscoreei.dll/GetHostConfigurationFile_RetAddr
DynamicLoader: mscoreei.dll/GetHostConfigurationFile
DynamicLoader: mscoreei.dll/GetCORVersion_RetAddr
DynamicLoader: mscoreei.dll/GetCORVersion
DynamicLoader: MSCOREE.DLL/GetCORSystemDirectory
DynamicLoader: mscoreei.dll/GetCORSystemDirectory_RetAddr
DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
DynamicLoader: mscoreei.dll/CreateConfigStream
DynamicLoader: ntdll.dll/RtlUnwind
DynamicLoader: KERNEL32.dll/IsWow64Process
DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
DynamicLoader: KERNEL32.dll/FlsSetValue
DynamicLoader: KERNEL32.dll/FlsGetValue
DynamicLoader: KERNEL32.dll/FlsAlloc
DynamicLoader: KERNEL32.dll/FlsFree
DynamicLoader: KERNEL32.dll/AddVectoredContinueHandler
DynamicLoader: KERNEL32.dll/RemoveVectoredContinueHandler
DynamicLoader: ADVAPI32.dll/ConvertSidToStringSidW
DynamicLoader: shell32.dll/SHGetFolderPathW
DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
DynamicLoader: KERNEL32.dll/GetWriteWatch
DynamicLoader: KERNEL32.dll/ResetWriteWatch
DynamicLoader: KERNEL32.dll/CreateMemoryResourceNotification
DynamicLoader: KERNEL32.dll/QueryMemoryResourceNotification
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: cryptbase.dll/SystemFunction036
DynamicLoader: KERNEL32.dll/QueryActCtxW
DynamicLoader: ole32.dll/CoGetContextToken
DynamicLoader: KERNEL32.dll/GetFullPathName
DynamicLoader: KERNEL32.dll/GetFullPathNameW
DynamicLoader: KERNEL32.dll/GetVersionEx
DynamicLoader: KERNEL32.dll/GetVersionExW
DynamicLoader: KERNEL32.dll/GetVersionEx
DynamicLoader: KERNEL32.dll/GetVersionExW
DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
DynamicLoader: ADVAPI32.dll/CryptReleaseContext
DynamicLoader: ADVAPI32.dll/CryptCreateHash
DynamicLoader: ADVAPI32.dll/CryptDestroyHash
DynamicLoader: ADVAPI32.dll/CryptHashData
DynamicLoader: ADVAPI32.dll/CryptGetHashParam
DynamicLoader: ADVAPI32.dll/CryptImportKey
DynamicLoader: ADVAPI32.dll/CryptExportKey
DynamicLoader: ADVAPI32.dll/CryptGenKey
DynamicLoader: ADVAPI32.dll/CryptGetKeyParam
DynamicLoader: ADVAPI32.dll/CryptDestroyKey
DynamicLoader: ADVAPI32.dll/CryptVerifySignatureA
DynamicLoader: ADVAPI32.dll/CryptSignHashA
DynamicLoader: ADVAPI32.dll/CryptGetProvParam
DynamicLoader: ADVAPI32.dll/CryptGetUserKey
DynamicLoader: ADVAPI32.dll/CryptEnumProvidersA
DynamicLoader: MSCOREE.DLL/GetMetaDataInternalInterface
DynamicLoader: mscoreei.dll/GetMetaDataInternalInterface_RetAddr
DynamicLoader: mscoreei.dll/GetMetaDataInternalInterface
DynamicLoader: mscorwks.dll/GetMetaDataInternalInterface
DynamicLoader: mscorjit.dll/getJit
DynamicLoader: KERNEL32.dll/IsWow64Process
DynamicLoader: uxtheme.dll/IsAppThemed
DynamicLoader: uxtheme.dll/IsAppThemedW
DynamicLoader: KERNEL32.dll/CreateActCtx
DynamicLoader: KERNEL32.dll/CreateActCtxA
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: USER32.dll/RegisterWindowMessage
DynamicLoader: USER32.dll/RegisterWindowMessageW
DynamicLoader: USER32.dll/GetSystemMetrics
DynamicLoader: USER32.dll/AdjustWindowRectEx
DynamicLoader: KERNEL32.dll/GetCurrentProcess
DynamicLoader: KERNEL32.dll/GetCurrentThread
DynamicLoader: KERNEL32.dll/DuplicateHandle
DynamicLoader: KERNEL32.dll/GetCurrentThreadId
DynamicLoader: KERNEL32.dll/GetCurrentActCtx
DynamicLoader: KERNEL32.dll/ActivateActCtx
DynamicLoader: KERNEL32.dll/lstrlen
DynamicLoader: KERNEL32.dll/lstrlenW
DynamicLoader: KERNEL32.dll/GetModuleHandle
DynamicLoader: KERNEL32.dll/GetModuleHandleW
DynamicLoader: KERNEL32.dll/GetProcAddress
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: GDI32.dll/GetStockObject
DynamicLoader: KERNEL32.dll/GetUserDefaultUILanguage
DynamicLoader: USER32.dll/RegisterClass
DynamicLoader: USER32.dll/RegisterClassW
DynamicLoader: USER32.dll/CreateWindowEx
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/GetWindowLong
DynamicLoader: USER32.dll/GetWindowLongW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/CallWindowProc
DynamicLoader: USER32.dll/CallWindowProcW
DynamicLoader: USER32.dll/GetClientRect
DynamicLoader: USER32.dll/GetWindowRect
DynamicLoader: USER32.dll/GetParent
DynamicLoader: KERNEL32.dll/DeactivateActCtx
DynamicLoader: USER32.dll/GetProcessWindowStation
DynamicLoader: USER32.dll/GetUserObjectInformation
DynamicLoader: USER32.dll/GetUserObjectInformationA
DynamicLoader: KERNEL32.dll/SetConsoleCtrlHandler
DynamicLoader: KERNEL32.dll/SetConsoleCtrlHandlerW
DynamicLoader: KERNEL32.dll/GetModuleHandle
DynamicLoader: KERNEL32.dll/GetModuleHandleW
DynamicLoader: USER32.dll/GetClassInfo
DynamicLoader: USER32.dll/GetClassInfoW
DynamicLoader: USER32.dll/RegisterClass
DynamicLoader: USER32.dll/RegisterClassW
DynamicLoader: USER32.dll/CreateWindowEx
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: USER32.dll/DefWindowProc
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: USER32.dll/SystemParametersInfo
DynamicLoader: USER32.dll/SystemParametersInfoW
DynamicLoader: USER32.dll/GetDC
DynamicLoader: KERNEL32.dll/GetCurrentProcessId
DynamicLoader: KERNEL32.dll/GetCurrentProcessIdW
DynamicLoader: KERNEL32.dll/FindAtom
DynamicLoader: KERNEL32.dll/FindAtomW
DynamicLoader: KERNEL32.dll/AddAtom
DynamicLoader: KERNEL32.dll/AddAtomW
DynamicLoader: MSCOREE.DLL/LoadLibraryShim
DynamicLoader: mscoreei.dll/LoadLibraryShim_RetAddr
DynamicLoader: mscoreei.dll/LoadLibraryShim
DynamicLoader: gdiplus.dll/GdiplusStartup
DynamicLoader: KERNEL32.dll/IsProcessorFeaturePresent
DynamicLoader: USER32.dll/GetWindowInfo
DynamicLoader: USER32.dll/GetAncestor
DynamicLoader: USER32.dll/GetMonitorInfoA
DynamicLoader: USER32.dll/EnumDisplayMonitors
DynamicLoader: USER32.dll/EnumDisplayDevicesA
DynamicLoader: GDI32.dll/ExtTextOutW
DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
DynamicLoader: gdiplus.dll/GdipCreateFontFromLogfontW
DynamicLoader: KERNEL32.dll/RegOpenKeyExW
DynamicLoader: KERNEL32.dll/RegQueryInfoKeyA
DynamicLoader: KERNEL32.dll/RegCloseKey
DynamicLoader: KERNEL32.dll/RegCreateKeyExW
DynamicLoader: KERNEL32.dll/RegQueryValueExW
DynamicLoader: KERNEL32.dll/RegEnumValueW
DynamicLoader: MSCOREE.DLL/ND_RI2
DynamicLoader: mscoreei.dll/ND_RI2_RetAddr
DynamicLoader: mscoreei.dll/ND_RI2
DynamicLoader: MSCOREE.DLL/ND_RU1
DynamicLoader: mscoreei.dll/ND_RU1_RetAddr
DynamicLoader: mscoreei.dll/ND_RU1
DynamicLoader: gdiplus.dll/GdipGetFontUnit
DynamicLoader: gdiplus.dll/GdipGetFontSize
DynamicLoader: gdiplus.dll/GdipGetFontStyle
DynamicLoader: gdiplus.dll/GdipGetFamily
DynamicLoader: USER32.dll/ReleaseDC
DynamicLoader: gdiplus.dll/GdipCreateFromHDC
DynamicLoader: gdiplus.dll/GdipGetDpiY
DynamicLoader: gdiplus.dll/GdipGetFontHeight
DynamicLoader: gdiplus.dll/GdipGetEmHeight
DynamicLoader: gdiplus.dll/GdipGetLineSpacing
DynamicLoader: gdiplus.dll/GdipDeleteGraphics
DynamicLoader: gdiplus.dll/GdipCreateFont
DynamicLoader: USER32.dll/SystemParametersInfo
DynamicLoader: USER32.dll/SystemParametersInfoW
DynamicLoader: KERNEL32.dll/GetSystemDefaultLCID
DynamicLoader: KERNEL32.dll/GetSystemDefaultLCIDW
DynamicLoader: GDI32.dll/GetStockObject
DynamicLoader: GDI32.dll/GetObject
DynamicLoader: GDI32.dll/GetObjectW
DynamicLoader: KERNEL32.dll/RegQueryInfoKeyW
DynamicLoader: gdiplus.dll/GdipDeleteFont
DynamicLoader: gdiplus.dll/GdipCreateFontFamilyFromName
DynamicLoader: gdiplus.dll/GdipGetFamilyName
DynamicLoader: GDI32.dll/CreateCompatibleDC
DynamicLoader: GDI32.dll/GetCurrentObject
DynamicLoader: GDI32.dll/SaveDC
DynamicLoader: GDI32.dll/GetDeviceCaps
DynamicLoader: GDI32.dll/CreateFontIndirect
DynamicLoader: GDI32.dll/CreateFontIndirectW
DynamicLoader: GDI32.dll/GetObject
DynamicLoader: GDI32.dll/GetObjectW
DynamicLoader: GDI32.dll/SelectObject
DynamicLoader: GDI32.dll/GetMapMode
DynamicLoader: GDI32.dll/GetTextMetricsW
DynamicLoader: USER32.dll/DrawTextExW
DynamicLoader: USER32.dll/DrawTextExWW
DynamicLoader: GDI32.dll/GetLayout
DynamicLoader: GDI32.dll/GdiRealizationInfo
DynamicLoader: GDI32.dll/FontIsLinked
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: GDI32.dll/GetFontAssocStatus
DynamicLoader: ADVAPI32.dll/RegQueryValueExA
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: USER32.dll/MonitorFromRect
DynamicLoader: USER32.dll/GetMonitorInfo
DynamicLoader: USER32.dll/GetMonitorInfoW
DynamicLoader: GDI32.dll/CreateDC
DynamicLoader: GDI32.dll/CreateDCW
DynamicLoader: GDI32.dll/GetDeviceCaps
DynamicLoader: GDI32.dll/DeleteDC
DynamicLoader: USER32.dll/GetDoubleClickTime
DynamicLoader: gdiplus.dll/GdipCreateBitmapFromStream
DynamicLoader: WindowsCodecs.dll/DllGetClassObject
DynamicLoader: gdiplus.dll/GdipImageForceValidation
DynamicLoader: gdiplus.dll/GdipGetImageRawFormat
DynamicLoader: gdiplus.dll/GdipGetImageWidth
DynamicLoader: gdiplus.dll/GdipGetImageHeight
DynamicLoader: gdiplus.dll/GdipCreateBitmapFromScan0
DynamicLoader: gdiplus.dll/GdipGetImagePixelFormat
DynamicLoader: gdiplus.dll/GdipGetImageGraphicsContext
DynamicLoader: USER32.dll/GetSysColor
DynamicLoader: USER32.dll/GetSysColorW
DynamicLoader: gdiplus.dll/GdipGraphicsClear
DynamicLoader: gdiplus.dll/GdipCreateImageAttributes
DynamicLoader: gdiplus.dll/GdipSetImageAttributesColorKeys
DynamicLoader: gdiplus.dll/GdipDrawImageRectRectI
DynamicLoader: gdiplus.dll/GdipDisposeImageAttributes
DynamicLoader: gdiplus.dll/GdipDisposeImage
DynamicLoader: KERNEL32.dll/SetErrorMode
DynamicLoader: KERNEL32.dll/GetFileAttributesEx
DynamicLoader: KERNEL32.dll/GetFileAttributesExW
DynamicLoader: culture.dll/ConvertLangIdToCultureName
DynamicLoader: USER32.dll/GetSystemMetrics
DynamicLoader: GDI32.dll/GetDeviceCaps
DynamicLoader: USER32.dll/CreateIconFromResourceEx
DynamicLoader: GDI32.dll/CreateCompatibleDC
DynamicLoader: gdiplus.dll/GdipGetLogFontW
DynamicLoader: MSCOREE.DLL/ND_WU1
DynamicLoader: mscoreei.dll/ND_WU1_RetAddr
DynamicLoader: mscoreei.dll/ND_WU1
DynamicLoader: GDI32.dll/CreateFontIndirect
DynamicLoader: GDI32.dll/CreateFontIndirectW
DynamicLoader: GDI32.dll/SelectObject
DynamicLoader: GDI32.dll/GetTextMetricsW
DynamicLoader: GDI32.dll/GetTextExtentPoint32W
DynamicLoader: USER32.dll/GetCursorPos
DynamicLoader: USER32.dll/MonitorFromPoint
DynamicLoader: gdiplus.dll/GdipLoadImageFromStream
DynamicLoader: gdiplus.dll/GdipGetImageType
DynamicLoader: gdiplus.dll/GdipBitmapGetPixel
DynamicLoader: KERNEL32.dll/OpenMutex
DynamicLoader: KERNEL32.dll/OpenMutexW
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: KERNEL32.dll/ReleaseMutex
DynamicLoader: KERNEL32.dll/CreateMutex
DynamicLoader: KERNEL32.dll/CreateMutexW
DynamicLoader: KERNEL32.dll/CreateProcess
DynamicLoader: KERNEL32.dll/CreateProcessW
DynamicLoader: KERNEL32.dll/GetThreadContext
DynamicLoader: KERNEL32.dll/ReadProcessMemory
DynamicLoader: KERNEL32.dll/VirtualAllocEx
DynamicLoader: KERNEL32.dll/WriteProcessMemory
DynamicLoader: KERNEL32.dll/GlobalMemoryStatusEx
DynamicLoader: KERNEL32.dll/SwitchToThread
DynamicLoader: KERNEL32.dll/SetThreadContext
DynamicLoader: KERNEL32.dll/ResumeThread
DynamicLoader: ole32.dll/CoWaitForMultipleHandles
DynamicLoader: USER32.dll/SetClassLong
DynamicLoader: USER32.dll/SetClassLongW
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: USER32.dll/PostMessage
DynamicLoader: USER32.dll/PostMessageW
DynamicLoader: USER32.dll/UnregisterClass
DynamicLoader: USER32.dll/UnregisterClassW
DynamicLoader: USER32.dll/IsWindow
DynamicLoader: KERNEL32.dll/GetProcAddress
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/SetClassLong
DynamicLoader: USER32.dll/SetClassLongW
DynamicLoader: USER32.dll/DestroyWindow
DynamicLoader: USER32.dll/DestroyWindowW
DynamicLoader: USER32.dll/PostMessage
DynamicLoader: USER32.dll/PostMessageW
DynamicLoader: KERNEL32.dll/DeleteAtom
DynamicLoader: KERNEL32.dll/DeleteAtomW
DynamicLoader: USER32.dll/DestroyIcon
DynamicLoader: GDI32.dll/RestoreDC
DynamicLoader: GDI32.dll/DeleteDC
DynamicLoader: GDI32.dll/DeleteObject
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: ole32.dll/NdrOleInitializeExtension
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: KERNEL32.dll/CreateActCtxW
DynamicLoader: KERNEL32.dll/AddRefActCtx
DynamicLoader: KERNEL32.dll/ReleaseActCtx
DynamicLoader: KERNEL32.dll/ActivateActCtx
DynamicLoader: KERNEL32.dll/DeactivateActCtx
DynamicLoader: KERNEL32.dll/GetCurrentActCtx
DynamicLoader: KERNEL32.dll/QueryActCtxW
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: ADVAPI32.dll/EventUnregister
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: KERNEL32.dll/FlsAlloc
DynamicLoader: KERNEL32.dll/FlsFree
DynamicLoader: KERNEL32.dll/FlsGetValue
DynamicLoader: KERNEL32.dll/FlsSetValue
DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
DynamicLoader: KERNEL32.dll/CreateEventExW
DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
DynamicLoader: KERNEL32.dll/SetThreadpoolWait
DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
DynamicLoader: KERNEL32.dll/CompareStringEx
DynamicLoader: KERNEL32.dll/GetDateFormatEx
DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
DynamicLoader: KERNEL32.dll/GetTimeFormatEx
DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
DynamicLoader: KERNEL32.dll/IsValidLocaleName
DynamicLoader: KERNEL32.dll/LCMapStringEx
DynamicLoader: KERNEL32.dll/GetCurrentPackageId
DynamicLoader: KERNEL32.dll/GetTickCount64
DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
DynamicLoader: KERNEL32.dll/AcquireSRWLockExclusive
DynamicLoader: KERNEL32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/EventRegister
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: MSCOREE.DLL/
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: mscoreei.dll/RegisterShimImplCallback
DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
DynamicLoader: mscoreei.dll/SetShellShimInstance
DynamicLoader: mscoreei.dll/OnShimDllMainCalled
DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
DynamicLoader: mscoreei.dll/_CorExeMain
DynamicLoader: ADVAPI32.dll/EventUnregister
CAPE extracted potentially suspicious content
mulqBW.exe: AgentTeslaV2 Payload: 32-bit executable
mulqBW.exe: AgentTeslaV2
mulqBW.exe: Injected Shellcode/Data
mulqBW.exe: Unpacked Shellcode
mulqBW.exe: Unpacked Shellcode
mulqBW.exe: Unpacked Shellcode
mulqBW.exe: Unpacked Shellcode
mulqBW.exe: AgentTeslaV2 Payload
mulqBW.exe: AgentTeslaV2
mulqBW.exe: Unpacked Shellcode
mulqBW.exe: Unpacked Shellcode
mulqBW.exe: Injected Shellcode/Data
mulqBW.exe: Unpacked Shellcode
mulqBW.exe: Unpacked Shellcode
Queries or connects to DNS-Over-HTTPS/DNS-Over-TLS domain or IP address
ip: 1.1.1.1
The binary likely contains encrypted or compressed data.
section: name: .text, entropy: 7.84, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0006a800, virtual_size: 0x0006a714
Authenticode signature is invalid
authenticode error: No signature found. SignTool Error File not valid C\Users\Rebecca\AppData\Local\Temp\mulqBW
Behavioural detection: Injection (Process Hollowing)
Injection: mulqBW.exe(1784) -> mulqBW.exe(5540)
Executed a process and injected code into it, probably while unpacking
Injection: mulqBW.exe(1784) -> mulqBW.exe(5540)
Behavioural detection: Injection (inter-process)
Network activity detected but not expressed in API logs
CAPE detected the AgentTeslaV2 malware family
File has been identified by 27 Antiviruses on VirusTotal as malicious
FireEye: Generic.mg.a0ced2f523a067a3
McAfee: Artemis!A0CED2F523A0
Sangfor: Malware
CrowdStrike: win/malicious_confidence_90% (W)
APEX: Malicious
Paloalto: generic.ml
Kaspersky: UDS:DangerousObject.Multi.Generic
BitDefender: Trojan.GenericKDZ.68068
DrWeb: Trojan.PackedNET.342
Invincea: heuristic
McAfee-GW-Edition: BehavesLike.Win32.Generic.gc
Trapmine: malicious.moderate.ml.score
Emsisoft: Trojan.GenericKDZ.68068 (B)
Ikarus: Win32.Outbreak
Cyren: W32/MSIL_Agent.BLB.gen!Eldorado
Endgame: malicious (high confidence)
Microsoft: Trojan:Win32/Wacatac.C!ml
ZoneAlarm: HEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTheta: Gen:[email protected]
Malwarebytes: Spyware.AgentTesla
ESET-NOD32: a variant of MSIL/Kryptik.WLU
eGambit: Unsafe.AI_Score_98%
GData: Win32.Trojan-Stealer.AgentTesla.6INCBN
MaxSecure: Trojan.Malware.300983.susgen
AVG: FileRepMalware
Cybereason: malicious.907c88
Panda: Trj/RnkBend.A

Screenshots


Hosts

Direct IP Country Name
Y 8.8.8.8 [VT] United States
Y 1.1.1.1 [VT] Australia

DNS

No domains contacted.


Summary

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Rebecca\AppData\Local\Temp\mulqBW.exe.config
C:\Users\Rebecca\AppData\Local\Temp\mulqBW.exe
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-2.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Rebecca\AppData\Local\Temp\mulqBW.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index38e.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f8420d8c6ede777377fcff48a4beaa2a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Rebecca
C:\Users\Rebecca\AppData
C:\Users\Rebecca\AppData\Local
C:\Users\Rebecca\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
C:\Users\Rebecca\AppData\Local\Temp\mulqBW.config
C:\Users\Rebecca\AppData\Local\Temp\mulqBW.INI
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol224.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0a65164b17e5c64bacdc694ea2439c43\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\175df210b784212def386595c25caefb\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\5669120680b52abf616f3876387ca2cc\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\uxtheme.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24308_none_5c028e37a0121035
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24308_none_5c028e37a0121035\GdiPlus.dll
C:\Users\Rebecca\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\marlett.ttf
C:\Windows\Fonts\arial.ttf
C:\Windows\Fonts\ariali.ttf
C:\Windows\Fonts\arialbd.ttf
C:\Windows\Fonts\arialbi.ttf
C:\Windows\Fonts\batang.ttc
C:\Windows\Fonts\cour.ttf
C:\Windows\Fonts\couri.ttf
C:\Windows\Fonts\courbd.ttf
C:\Windows\Fonts\courbi.ttf
C:\Windows\Fonts\daunpenh.ttf
C:\Windows\Fonts\dokchamp.ttf
C:\Windows\Fonts\estre.ttf
C:\Windows\Fonts\euphemia.ttf
C:\Windows\Fonts\gautami.ttf
C:\Windows\Fonts\gautamib.ttf
C:\Windows\Fonts\Vani.ttf
C:\Windows\Fonts\Vanib.ttf
C:\Windows\Fonts\gulim.ttc
C:\Windows\Fonts\impact.ttf
C:\Windows\Fonts\iskpota.ttf
C:\Windows\Fonts\iskpotab.ttf
C:\Windows\Fonts\kalinga.ttf
C:\Windows\Fonts\kalingab.ttf
C:\Windows\Fonts\kartika.ttf
C:\Windows\Fonts\kartikab.ttf
C:\Windows\Fonts\KhmerUI.ttf
C:\Windows\Fonts\KhmerUIb.ttf
C:\Windows\Fonts\LaoUI.ttf
C:\Windows\Fonts\LaoUIb.ttf
C:\Windows\Fonts\latha.ttf
C:\Windows\Fonts\lathab.ttf
C:\Windows\Fonts\lucon.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\malgunbd.ttf
C:\Windows\Fonts\mangal.ttf
C:\Windows\Fonts\mangalb.ttf
C:\Windows\Fonts\meiryo.ttc
C:\Windows\Fonts\meiryob.ttc
C:\Windows\Fonts\himalaya.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msjhbd.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\msyhbd.ttf
C:\Windows\Fonts\mingliu.ttc
C:\Windows\Fonts\mingliub.ttc
C:\Windows\Fonts\monbaiti.ttf
C:\Windows\Fonts\msgothic.ttc
C:\Windows\Fonts\msmincho.ttc
C:\Windows\Fonts\mvboli.ttf
C:\Windows\Fonts\ntailu.ttf
C:\Windows\Fonts\ntailub.ttf
C:\Windows\Fonts\nyala.ttf
C:\Windows\Fonts\phagspa.ttf
C:\Windows\Fonts\phagspab.ttf
C:\Windows\Fonts\plantc.ttf
C:\Windows\Fonts\raavi.ttf
C:\Windows\Fonts\raavib.ttf
C:\Windows\Fonts\segoesc.ttf
C:\Windows\Fonts\segoescb.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeuib.ttf
C:\Windows\Fonts\segoeuii.ttf
C:\Windows\Fonts\segoeuiz.ttf
C:\Windows\Fonts\seguisb.ttf
C:\Windows\Fonts\segoeuil.ttf
C:\Windows\Fonts\seguisym.ttf
C:\Windows\Fonts\shruti.ttf
C:\Windows\Fonts\shrutib.ttf
C:\Windows\Fonts\simsun.ttc
C:\Windows\Fonts\simsunb.ttf
C:\Windows\Fonts\sylfaen.ttf
C:\Windows\Fonts\taile.ttf
C:\Windows\Fonts\taileb.ttf
C:\Windows\Fonts\times.ttf
C:\Windows\Fonts\timesi.ttf
C:\Windows\Fonts\timesbd.ttf
C:\Windows\Fonts\timesbi.ttf
C:\Windows\Fonts\tunga.ttf
C:\Windows\Fonts\tungab.ttf
C:\Windows\Fonts\vrinda.ttf
C:\Windows\Fonts\vrindab.ttf
C:\Windows\Fonts\Shonar.ttf
C:\Windows\Fonts\Shonarb.ttf
C:\Windows\Fonts\msyi.ttf
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\tahomabd.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\angsa.ttf
C:\Windows\Fonts\angsai.ttf
C:\Windows\Fonts\angsab.ttf
C:\Windows\Fonts\angsaz.ttf
C:\Windows\Fonts\aparaj.ttf
C:\Windows\Fonts\aparajb.ttf
C:\Windows\Fonts\aparajbi.ttf
C:\Windows\Fonts\aparaji.ttf
C:\Windows\Fonts\cordia.ttf
C:\Windows\Fonts\cordiai.ttf
C:\Windows\Fonts\cordiab.ttf
C:\Windows\Fonts\cordiaz.ttf
C:\Windows\Fonts\ebrima.ttf
C:\Windows\Fonts\ebrimabd.ttf
C:\Windows\Fonts\gisha.ttf
C:\Windows\Fonts\gishabd.ttf
C:\Windows\Fonts\kokila.ttf
C:\Windows\Fonts\kokilab.ttf
C:\Windows\Fonts\kokilabi.ttf
C:\Windows\Fonts\kokilai.ttf
C:\Windows\Fonts\leelawad.ttf
C:\Windows\Fonts\leelawdb.ttf
C:\Windows\Fonts\msuighur.ttf
C:\Windows\Fonts\moolbor.ttf
C:\Windows\Fonts\symbol.ttf
C:\Windows\Fonts\utsaah.ttf
C:\Windows\Fonts\utsaahb.ttf
C:\Windows\Fonts\utsaahbi.ttf
C:\Windows\Fonts\utsaahi.ttf
C:\Windows\Fonts\vijaya.ttf
C:\Windows\Fonts\vijayab.ttf
C:\Windows\Fonts\wingding.ttf
C:\Windows\Fonts\modern.fon
C:\Windows\Fonts\roman.fon
C:\Windows\Fonts\script.fon
C:\Windows\Fonts\andlso.ttf
C:\Windows\Fonts\arabtype.ttf
C:\Windows\Fonts\simpo.ttf
C:\Windows\Fonts\simpbdo.ttf
C:\Windows\Fonts\simpfxo.ttf
C:\Windows\Fonts\majalla.ttf
C:\Windows\Fonts\majallab.ttf
C:\Windows\Fonts\trado.ttf
C:\Windows\Fonts\tradbdo.ttf
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\david.ttf
C:\Windows\Fonts\davidbd.ttf
C:\Windows\Fonts\frank.ttf
C:\Windows\Fonts\lvnm.ttf
C:\Windows\Fonts\lvnmbd.ttf
C:\Windows\Fonts\mriam.ttf
C:\Windows\Fonts\mriamc.ttf
C:\Windows\Fonts\nrkis.ttf
C:\Windows\Fonts\rod.ttf
C:\Windows\Fonts\simfang.ttf
C:\Windows\Fonts\simhei.ttf
C:\Windows\Fonts\simkai.ttf
C:\Windows\Fonts\angsau.ttf
C:\Windows\Fonts\angsaui.ttf
C:\Windows\Fonts\angsaub.ttf
C:\Windows\Fonts\angsauz.ttf
C:\Windows\Fonts\browa.ttf
C:\Windows\Fonts\browai.ttf
C:\Windows\Fonts\browab.ttf
C:\Windows\Fonts\browaz.ttf
C:\Windows\Fonts\browau.ttf
C:\Windows\Fonts\browaui.ttf
C:\Windows\Fonts\browaub.ttf
C:\Windows\Fonts\browauz.ttf
C:\Windows\Fonts\cordiau.ttf
C:\Windows\Fonts\cordiaub.ttf
C:\Windows\Fonts\cordiauz.ttf
C:\Windows\Fonts\cordiaui.ttf
C:\Windows\Fonts\upcdl.ttf
C:\Windows\Fonts\upcdi.ttf
C:\Windows\Fonts\upcdb.ttf
C:\Windows\Fonts\upcdbi.ttf
C:\Windows\Fonts\upcel.ttf
C:\Windows\Fonts\upcei.ttf
C:\Windows\Fonts\upceb.ttf
C:\Windows\Fonts\upcebi.ttf
C:\Windows\Fonts\upcfl.ttf
C:\Windows\Fonts\upcfi.ttf
C:\Windows\Fonts\upcfb.ttf
C:\Windows\Fonts\upcfbi.ttf
C:\Windows\Fonts\upcil.ttf
C:\Windows\Fonts\upcii.ttf
C:\Windows\Fonts\upcib.ttf
C:\Windows\Fonts\upcibi.ttf
C:\Windows\Fonts\upcjl.ttf
C:\Windows\Fonts\upcji.ttf
C:\Windows\Fonts\upcjb.ttf
C:\Windows\Fonts\upcjbi.ttf
C:\Windows\Fonts\upckl.ttf
C:\Windows\Fonts\upcki.ttf
C:\Windows\Fonts\upckb.ttf
C:\Windows\Fonts\upckbi.ttf
C:\Windows\Fonts\upcll.ttf
C:\Windows\Fonts\upcli.ttf
C:\Windows\Fonts\upclb.ttf
C:\Windows\Fonts\upclbi.ttf
C:\Windows\Fonts\kaiu.ttf
C:\Windows\Fonts\l_10646.ttf
C:\Windows\Fonts\ariblk.ttf
C:\Windows\Fonts\calibri.ttf
C:\Windows\Fonts\calibrii.ttf
C:\Windows\Fonts\calibrib.ttf
C:\Windows\Fonts\calibriz.ttf
C:\Windows\Fonts\comic.ttf
C:\Windows\Fonts\comicbd.ttf
C:\Windows\Fonts\framd.ttf
C:\Windows\Fonts\framdit.ttf
C:\Windows\Fonts\Gabriola.ttf
C:\Windows\Fonts\georgia.ttf
C:\Windows\Fonts\georgiai.ttf
C:\Windows\Fonts\georgiab.ttf
C:\Windows\Fonts\georgiaz.ttf
C:\Windows\Fonts\pala.ttf
C:\Windows\Fonts\palai.ttf
C:\Windows\Fonts\palab.ttf
C:\Windows\Fonts\palabi.ttf
C:\Windows\Fonts\segoepr.ttf
C:\Windows\Fonts\segoeprb.ttf
C:\Windows\Fonts\trebuc.ttf
C:\Windows\Fonts\trebucit.ttf
C:\Windows\Fonts\trebucbd.ttf
C:\Windows\Fonts\trebucbi.ttf
C:\Windows\Fonts\verdana.ttf
C:\Windows\Fonts\verdanai.ttf
C:\Windows\Fonts\verdanab.ttf
C:\Windows\Fonts\verdanaz.ttf
C:\Windows\Fonts\webdings.ttf
C:\Windows\Fonts\coure.fon
C:\Windows\Fonts\serife.fon
C:\Windows\Fonts\sserife.fon
C:\Windows\Fonts\smalle.fon
C:\Windows\Fonts\smallf.fon
C:\Windows\Fonts\calibrili.ttf
C:\Windows\Fonts\CALIBRILI.TTF
C:\Windows\Fonts\calibril.ttf
C:\Windows\Fonts\AGENCYB.TTF
C:\Windows\Fonts\AGENCYR.TTF
C:\Windows\Fonts\ALGER.TTF
C:\Windows\Fonts\ANTQUAB.TTF
C:\Windows\Fonts\ANTQUABI.TTF
C:\Windows\Fonts\ANTQUAI.TTF
C:\Windows\Fonts\ARIALN.TTF
C:\Windows\Fonts\ARIALNB.TTF
C:\Windows\Fonts\ARIALNBI.TTF
C:\Windows\Fonts\ARIALNI.TTF
C:\Windows\Fonts\ARLRDBD.TTF
C:\Windows\Fonts\BASKVILL.TTF
C:\Windows\Fonts\BAUHS93.TTF
C:\Windows\Fonts\BELL.TTF
C:\Windows\Fonts\BELLB.TTF
C:\Windows\Fonts\BELLI.TTF
C:\Windows\Fonts\BERNHC.TTF
C:\Windows\Fonts\BKANT.TTF
C:\Windows\Fonts\BOD_B.TTF
C:\Windows\Fonts\BOD_BI.TTF
C:\Windows\Fonts\BOD_BLAI.TTF
C:\Windows\Fonts\BOD_BLAR.TTF
C:\Windows\Fonts\BOD_CB.TTF
C:\Windows\Fonts\BOD_CBI.TTF
C:\Windows\Fonts\BOD_CI.TTF
C:\Windows\Fonts\BOD_CR.TTF
C:\Windows\Fonts\BOD_I.TTF
C:\Windows\Fonts\BOD_PSTC.TTF
C:\Windows\Fonts\BOD_R.TTF
C:\Windows\Fonts\BRADHITC.TTF
C:\Windows\Fonts\BRITANIC.TTF
C:\Windows\Fonts\BRLNSB.TTF
C:\Windows\Fonts\BRLNSDB.TTF
C:\Windows\Fonts\BRLNSR.TTF
C:\Windows\Fonts\BROADW.TTF
C:\Windows\Fonts\BRUSHSCI.TTF
C:\Windows\Fonts\CALIFB.TTF
C:\Windows\Fonts\CALIFI.TTF
C:\Windows\Fonts\CALIFR.TTF
C:\Windows\Fonts\CALIST.TTF
C:\Windows\Fonts\CALISTB.TTF
C:\Windows\Fonts\CALISTBI.TTF
C:\Windows\Fonts\CALISTI.TTF
C:\Windows\Fonts\CASTELAR.TTF
C:\Windows\Fonts\CENSCBK.TTF
C:\Windows\Fonts\CENTAUR.TTF
C:\Windows\Fonts\CHILLER.TTF
C:\Windows\Fonts\COLONNA.TTF
C:\Windows\Fonts\COOPBL.TTF
C:\Windows\Fonts\COPRGTB.TTF
C:\Windows\Fonts\COPRGTL.TTF
C:\Windows\Fonts\CURLZ___.TTF
C:\Windows\Fonts\DUBAI-BOLD.TTF
C:\Windows\Fonts\DUBAI-LIGHT.TTF
C:\Windows\Fonts\DUBAI-MEDIUM.TTF
C:\Windows\Fonts\DUBAI-REGULAR.TTF
C:\Windows\Fonts\ELEPHNT.TTF
C:\Windows\Fonts\ELEPHNTI.TTF
C:\Windows\Fonts\ENGR.TTF
C:\Windows\Fonts\ERASBD.TTF
C:\Windows\Fonts\ERASDEMI.TTF
C:\Windows\Fonts\ERASLGHT.TTF
C:\Windows\Fonts\ERASMD.TTF
C:\Windows\Fonts\FELIXTI.TTF
C:\Windows\Fonts\FORTE.TTF
C:\Windows\Fonts\FRABK.TTF
C:\Windows\Fonts\FRABKIT.TTF
C:\Windows\Fonts\FRADM.TTF
C:\Windows\Fonts\FRADMCN.TTF
C:\Windows\Fonts\FRADMIT.TTF
C:\Windows\Fonts\FRAHV.TTF
C:\Windows\Fonts\FRAHVIT.TTF
C:\Windows\Fonts\FRAMDCN.TTF
C:\Windows\Fonts\FREESCPT.TTF
C:\Windows\Fonts\FRSCRIPT.TTF
C:\Windows\Fonts\FTLTLT.TTF
C:\Windows\Fonts\GADUGI.TTF
C:\Windows\Fonts\GADUGIB.TTF
C:\Windows\Fonts\GIGI.TTF
C:\Windows\Fonts\GILBI___.TTF
C:\Windows\Fonts\GILB____.TTF
C:\Windows\Fonts\GILC____.TTF
C:\Windows\Fonts\GILI____.TTF
C:\Windows\Fonts\GILLUBCD.TTF
C:\Windows\Fonts\GILSANUB.TTF
C:\Windows\Fonts\GIL_____.TTF
C:\Windows\Fonts\GLECB.TTF
C:\Windows\Fonts\GLSNECB.TTF
C:\Windows\Fonts\GOTHIC.TTF
C:\Windows\Fonts\GOTHICB.TTF
C:\Windows\Fonts\GOTHICBI.TTF
C:\Windows\Fonts\GOTHICI.TTF
C:\Windows\Fonts\GOUDOS.TTF
C:\Windows\Fonts\GOUDOSB.TTF
C:\Windows\Fonts\GOUDOSI.TTF
C:\Windows\Fonts\GOUDYSTO.TTF
C:\Windows\Fonts\HARLOWSI.TTF
C:\Windows\Fonts\HARNGTON.TTF
C:\Windows\Fonts\HATTEN.TTF
C:\Windows\Fonts\HTOWERT.TTF
C:\Windows\Fonts\HTOWERTI.TTF
C:\Windows\Fonts\IMPRISHA.TTF
C:\Windows\Fonts\INFROMAN.TTF
C:\Windows\Fonts\ITCBLKAD.TTF
C:\Windows\Fonts\ITCEDSCR.TTF
C:\Windows\Fonts\ITCKRIST.TTF
C:\Windows\Fonts\JOKERMAN.TTF
C:\Windows\Fonts\JUICE___.TTF
C:\Windows\Fonts\KUNSTLER.TTF
C:\Windows\Fonts\LATINWD.TTF
C:\Windows\Fonts\LBRITE.TTF
C:\Windows\Fonts\LBRITED.TTF
C:\Windows\Fonts\LBRITEDI.TTF
C:\Windows\Fonts\LBRITEI.TTF
C:\Windows\Fonts\LCALLIG.TTF
C:\Windows\Fonts\LFAX.TTF
C:\Windows\Fonts\LFAXD.TTF
C:\Windows\Fonts\LFAXDI.TTF
C:\Windows\Fonts\LFAXI.TTF
C:\Windows\Fonts\LHANDW.TTF
C:\Windows\Fonts\LSANS.TTF
C:\Windows\Fonts\LSANSD.TTF
C:\Windows\Fonts\LSANSDI.TTF
C:\Windows\Fonts\LSANSI.TTF
C:\Windows\Fonts\LTYPE.TTF
C:\Windows\Fonts\LTYPEB.TTF
C:\Windows\Fonts\LTYPEBO.TTF
C:\Windows\Fonts\LTYPEO.TTF
C:\Windows\Fonts\MAGNETOB.TTF
C:\Windows\Fonts\MAIAN.TTF
C:\Windows\Fonts\MATURASC.TTF
C:\Windows\Fonts\MISTRAL.TTF
C:\Windows\Fonts\MOD20.TTF
C:\Windows\Fonts\MSUIGHUB.TTF
C:\Windows\Fonts\MTCORSVA.TTF
C:\Windows\Fonts\NIAGENG.TTF
C:\Windows\Fonts\NIAGSOL.TTF
C:\Windows\Fonts\NIRMALA.TTF
C:\Windows\Fonts\NIRMALAB.TTF
C:\Windows\Fonts\OCRAEXT.TTF
C:\Windows\Fonts\OLDENGL.TTF
C:\Windows\Fonts\ONYX.TTF
C:\Windows\Fonts\PALSCRI.TTF
C:\Windows\Fonts\PAPYRUS.TTF
C:\Windows\Fonts\PARCHM.TTF
C:\Windows\Fonts\PERBI___.TTF
C:\Windows\Fonts\PERB____.TTF
C:\Windows\Fonts\PERI____.TTF
C:\Windows\Fonts\PERTIBD.TTF
C:\Windows\Fonts\PERTILI.TTF
C:\Windows\Fonts\PER_____.TTF
C:\Windows\Fonts\PLAYBILL.TTF
C:\Windows\Fonts\POORICH.TTF
C:\Windows\Fonts\PRISTINA.TTF
C:\Windows\Fonts\RAGE.TTF
C:\Windows\Fonts\RAVIE.TTF
C:\Windows\Fonts\ROCCB___.TTF
C:\Windows\Fonts\ROCC____.TTF
C:\Windows\Fonts\ROCK.TTF
C:\Windows\Fonts\ROCKB.TTF
C:\Windows\Fonts\ROCKBI.TTF
C:\Windows\Fonts\ROCKEB.TTF
C:\Windows\Fonts\ROCKI.TTF
C:\Windows\Fonts\SCHLBKB.TTF
C:\Windows\Fonts\SCHLBKBI.TTF
C:\Windows\Fonts\SCHLBKI.TTF
C:\Windows\Fonts\SCRIPTBL.TTF
C:\Windows\Fonts\SEGOEUISL.TTF
C:\Windows\Fonts\SHOWG.TTF
C:\Windows\Fonts\SNAP____.TTF
C:\Windows\Fonts\STENCIL.TTF
C:\Windows\Fonts\TCBI____.TTF
C:\Windows\Fonts\TCB_____.TTF
C:\Windows\Fonts\TCCB____.TTF
C:\Windows\Fonts\TCCEB.TTF
C:\Windows\Fonts\TCCM____.TTF
C:\Windows\Fonts\TCMI____.TTF
C:\Windows\Fonts\TCM_____.TTF
C:\Windows\Fonts\TEMPSITC.TTF
C:\Windows\Fonts\VINERITC.TTF
C:\Windows\Fonts\VIVALDII.TTF
C:\Windows\Fonts\VLADIMIR.TTF
C:\Windows\Fonts\MSJH.TTC
C:\Windows\Fonts\MSJHBD.TTC
C:\Windows\Fonts\MSYH.TTC
C:\Windows\Fonts\MSYHBD.TTC
C:\Windows\Fonts\ARIALUNI.TTF
C:\Program Files\Common Files\Microsoft Shared\EQUATION\MTEXTRA.TTF
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\EQUATION\MTEXTRA.TTF
C:\Windows\Fonts\OUTLOOK.TTF
C:\Windows\Fonts\CENTURY.TTF
C:\Windows\Fonts\cambria.ttc
C:\Windows\Fonts\Candara.ttf
C:\Windows\Fonts\consola.ttf
C:\Windows\Fonts\constan.ttf
C:\Windows\Fonts\corbel.ttf
C:\Windows\Fonts\WINGDNG2.TTF
C:\Windows\Fonts\WINGDNG3.TTF
C:\Windows\Fonts\GARA.TTF
C:\Windows\Fonts\BOOKOS.TTF
C:\Windows\Fonts\cambriab.ttf
C:\Windows\Fonts\cambriai.ttf
C:\Windows\Fonts\cambriaz.ttf
C:\Windows\Fonts\Candarab.ttf
C:\Windows\Fonts\Candarai.ttf
C:\Windows\Fonts\Candaraz.ttf
C:\Windows\Fonts\consolab.ttf
C:\Windows\Fonts\consolai.ttf
C:\Windows\Fonts\consolaz.ttf
C:\Windows\Fonts\constanb.ttf
C:\Windows\Fonts\constani.ttf
C:\Windows\Fonts\constanz.ttf
C:\Windows\Fonts\corbelb.ttf
C:\Windows\Fonts\corbeli.ttf
C:\Windows\Fonts\corbelz.ttf
C:\Windows\Fonts\BSSYM7.TTF
C:\Windows\Fonts\REFSAN.TTF
C:\Windows\Fonts\REFSPCL.TTF
C:\Windows\Fonts\GARABD.TTF
C:\Windows\Fonts\GARAIT.TTF
C:\Windows\Fonts\BOOKOSB.TTF
C:\Windows\Fonts\BOOKOSBI.TTF
C:\Windows\Fonts\BOOKOSI.TTF
C:\Windows\Fonts\staticcache.dat
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Rebecca\AppData\Local\Temp\en-US\ZcuXb.resources.dll
C:\Users\Rebecca\AppData\Local\Temp\en-US\ZcuXb.resources\ZcuXb.resources.dll
C:\Users\Rebecca\AppData\Local\Temp\en-US\ZcuXb.resources.exe
C:\Users\Rebecca\AppData\Local\Temp\en-US\ZcuXb.resources\ZcuXb.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en-US\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en-US\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
C:\Windows\Globalization\en.nlp
C:\Users\Rebecca\AppData\Local\Temp\en\ZcuXb.resources.dll
C:\Users\Rebecca\AppData\Local\Temp\en\ZcuXb.resources\ZcuXb.resources.dll
C:\Users\Rebecca\AppData\Local\Temp\en\ZcuXb.resources.exe
C:\Users\Rebecca\AppData\Local\Temp\en\ZcuXb.resources\ZcuXb.resources.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4ac828c8c4c76f3ba59f8f9c7dab1cb3\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Users\Rebecca\AppData\Local\Temp\en-US\ReZer0V2.resources.dll
C:\Users\Rebecca\AppData\Local\Temp\en-US\ReZer0V2.resources\ReZer0V2.resources.dll
C:\Users\Rebecca\AppData\Local\Temp\en-US\ReZer0V2.resources.exe
C:\Users\Rebecca\AppData\Local\Temp\en-US\ReZer0V2.resources\ReZer0V2.resources.exe
C:\Users\Rebecca\AppData\Local\Temp\en\ReZer0V2.resources.dll
C:\Users\Rebecca\AppData\Local\Temp\en\ReZer0V2.resources\ReZer0V2.resources.dll
C:\Users\Rebecca\AppData\Local\Temp\en\ReZer0V2.resources.exe
C:\Users\Rebecca\AppData\Local\Temp\en\ReZer0V2.resources\ReZer0V2.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.1784.24180609
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.1784.24180609
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.1784.24180640
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Rebecca\AppData\Local\Temp\mulqBW.exe.config
C:\Users\Rebecca\AppData\Local\Temp\mulqBW.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index38e.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f8420d8c6ede777377fcff48a4beaa2a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol224.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0a65164b17e5c64bacdc694ea2439c43\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\175df210b784212def386595c25caefb\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\5669120680b52abf616f3876387ca2cc\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24308_none_5c028e37a0121035\GdiPlus.dll
C:\Users\Rebecca\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\marlett.ttf
C:\Windows\Fonts\arial.ttf
C:\Windows\Fonts\ariali.ttf
C:\Windows\Fonts\arialbd.ttf
C:\Windows\Fonts\arialbi.ttf
C:\Windows\Fonts\batang.ttc
C:\Windows\Fonts\cour.ttf
C:\Windows\Fonts\couri.ttf
C:\Windows\Fonts\courbd.ttf
C:\Windows\Fonts\courbi.ttf
C:\Windows\Fonts\daunpenh.ttf
C:\Windows\Fonts\dokchamp.ttf
C:\Windows\Fonts\estre.ttf
C:\Windows\Fonts\euphemia.ttf
C:\Windows\Fonts\gautami.ttf
C:\Windows\Fonts\gautamib.ttf
C:\Windows\Fonts\Vani.ttf
C:\Windows\Fonts\Vanib.ttf
C:\Windows\Fonts\gulim.ttc
C:\Windows\Fonts\impact.ttf
C:\Windows\Fonts\iskpota.ttf
C:\Windows\Fonts\iskpotab.ttf
C:\Windows\Fonts\kalinga.ttf
C:\Windows\Fonts\kalingab.ttf
C:\Windows\Fonts\kartika.ttf
C:\Windows\Fonts\kartikab.ttf
C:\Windows\Fonts\KhmerUI.ttf
C:\Windows\Fonts\KhmerUIb.ttf
C:\Windows\Fonts\LaoUI.ttf
C:\Windows\Fonts\LaoUIb.ttf
C:\Windows\Fonts\latha.ttf
C:\Windows\Fonts\lathab.ttf
C:\Windows\Fonts\lucon.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\malgunbd.ttf
C:\Windows\Fonts\mangal.ttf
C:\Windows\Fonts\mangalb.ttf
C:\Windows\Fonts\meiryo.ttc
C:\Windows\Fonts\meiryob.ttc
C:\Windows\Fonts\himalaya.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msjhbd.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\msyhbd.ttf
C:\Windows\Fonts\mingliu.ttc
C:\Windows\Fonts\mingliub.ttc
C:\Windows\Fonts\monbaiti.ttf
C:\Windows\Fonts\msgothic.ttc
C:\Windows\Fonts\msmincho.ttc
C:\Windows\Fonts\mvboli.ttf
C:\Windows\Fonts\ntailu.ttf
C:\Windows\Fonts\ntailub.ttf
C:\Windows\Fonts\nyala.ttf
C:\Windows\Fonts\phagspa.ttf
C:\Windows\Fonts\phagspab.ttf
C:\Windows\Fonts\plantc.ttf
C:\Windows\Fonts\raavi.ttf
C:\Windows\Fonts\raavib.ttf
C:\Windows\Fonts\segoesc.ttf
C:\Windows\Fonts\segoescb.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeuib.ttf
C:\Windows\Fonts\segoeuii.ttf
C:\Windows\Fonts\segoeuiz.ttf
C:\Windows\Fonts\seguisb.ttf
C:\Windows\Fonts\segoeuil.ttf
C:\Windows\Fonts\seguisym.ttf
C:\Windows\Fonts\shruti.ttf
C:\Windows\Fonts\shrutib.ttf
C:\Windows\Fonts\simsun.ttc
C:\Windows\Fonts\simsunb.ttf
C:\Windows\Fonts\sylfaen.ttf
C:\Windows\Fonts\taile.ttf
C:\Windows\Fonts\taileb.ttf
C:\Windows\Fonts\times.ttf
C:\Windows\Fonts\timesi.ttf
C:\Windows\Fonts\timesbd.ttf
C:\Windows\Fonts\timesbi.ttf
C:\Windows\Fonts\tunga.ttf
C:\Windows\Fonts\tungab.ttf
C:\Windows\Fonts\vrinda.ttf
C:\Windows\Fonts\vrindab.ttf
C:\Windows\Fonts\Shonar.ttf
C:\Windows\Fonts\Shonarb.ttf
C:\Windows\Fonts\msyi.ttf
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\tahomabd.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\angsa.ttf
C:\Windows\Fonts\angsai.ttf
C:\Windows\Fonts\angsab.ttf
C:\Windows\Fonts\angsaz.ttf
C:\Windows\Fonts\aparaj.ttf
C:\Windows\Fonts\aparajb.ttf
C:\Windows\Fonts\aparajbi.ttf
C:\Windows\Fonts\aparaji.ttf
C:\Windows\Fonts\cordia.ttf
C:\Windows\Fonts\cordiai.ttf
C:\Windows\Fonts\cordiab.ttf
C:\Windows\Fonts\cordiaz.ttf
C:\Windows\Fonts\ebrima.ttf
C:\Windows\Fonts\ebrimabd.ttf
C:\Windows\Fonts\gisha.ttf
C:\Windows\Fonts\gishabd.ttf
C:\Windows\Fonts\kokila.ttf
C:\Windows\Fonts\kokilab.ttf
C:\Windows\Fonts\kokilabi.ttf
C:\Windows\Fonts\kokilai.ttf
C:\Windows\Fonts\leelawad.ttf
C:\Windows\Fonts\leelawdb.ttf
C:\Windows\Fonts\msuighur.ttf
C:\Windows\Fonts\moolbor.ttf
C:\Windows\Fonts\symbol.ttf
C:\Windows\Fonts\utsaah.ttf
C:\Windows\Fonts\utsaahb.ttf
C:\Windows\Fonts\utsaahbi.ttf
C:\Windows\Fonts\utsaahi.ttf
C:\Windows\Fonts\vijaya.ttf
C:\Windows\Fonts\vijayab.ttf
C:\Windows\Fonts\wingding.ttf
C:\Windows\Fonts\modern.fon
C:\Windows\Fonts\roman.fon
C:\Windows\Fonts\script.fon
C:\Windows\Fonts\andlso.ttf
C:\Windows\Fonts\arabtype.ttf
C:\Windows\Fonts\simpo.ttf
C:\Windows\Fonts\simpbdo.ttf
C:\Windows\Fonts\simpfxo.ttf
C:\Windows\Fonts\majalla.ttf
C:\Windows\Fonts\majallab.ttf
C:\Windows\Fonts\trado.ttf
C:\Windows\Fonts\tradbdo.ttf
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\david.ttf
C:\Windows\Fonts\davidbd.ttf
C:\Windows\Fonts\frank.ttf
C:\Windows\Fonts\lvnm.ttf
C:\Windows\Fonts\lvnmbd.ttf
C:\Windows\Fonts\mriam.ttf
C:\Windows\Fonts\mriamc.ttf
C:\Windows\Fonts\nrkis.ttf
C:\Windows\Fonts\rod.ttf
C:\Windows\Fonts\simfang.ttf
C:\Windows\Fonts\simhei.ttf
C:\Windows\Fonts\simkai.ttf
C:\Windows\Fonts\angsau.ttf
C:\Windows\Fonts\angsaui.ttf
C:\Windows\Fonts\angsaub.ttf
C:\Windows\Fonts\angsauz.ttf
C:\Windows\Fonts\browa.ttf
C:\Windows\Fonts\browai.ttf
C:\Windows\Fonts\browab.ttf
C:\Windows\Fonts\browaz.ttf
C:\Windows\Fonts\browau.ttf
C:\Windows\Fonts\browaui.ttf
C:\Windows\Fonts\browaub.ttf
C:\Windows\Fonts\browauz.ttf
C:\Windows\Fonts\cordiau.ttf
C:\Windows\Fonts\cordiaub.ttf
C:\Windows\Fonts\cordiauz.ttf
C:\Windows\Fonts\cordiaui.ttf
C:\Windows\Fonts\upcdl.ttf
C:\Windows\Fonts\upcdi.ttf
C:\Windows\Fonts\upcdb.ttf
C:\Windows\Fonts\upcdbi.ttf
C:\Windows\Fonts\upcel.ttf
C:\Windows\Fonts\upcei.ttf
C:\Windows\Fonts\upceb.ttf
C:\Windows\Fonts\upcebi.ttf
C:\Windows\Fonts\upcfl.ttf
C:\Windows\Fonts\upcfi.ttf
C:\Windows\Fonts\upcfb.ttf
C:\Windows\Fonts\upcfbi.ttf
C:\Windows\Fonts\upcil.ttf
C:\Windows\Fonts\upcii.ttf
C:\Windows\Fonts\upcib.ttf
C:\Windows\Fonts\upcibi.ttf
C:\Windows\Fonts\upcjl.ttf
C:\Windows\Fonts\upcji.ttf
C:\Windows\Fonts\upcjb.ttf
C:\Windows\Fonts\upcjbi.ttf
C:\Windows\Fonts\upckl.ttf
C:\Windows\Fonts\upcki.ttf
C:\Windows\Fonts\upckb.ttf
C:\Windows\Fonts\upckbi.ttf
C:\Windows\Fonts\upcll.ttf
C:\Windows\Fonts\upcli.ttf
C:\Windows\Fonts\upclb.ttf
C:\Windows\Fonts\upclbi.ttf
C:\Windows\Fonts\kaiu.ttf
C:\Windows\Fonts\l_10646.ttf
C:\Windows\Fonts\ariblk.ttf
C:\Windows\Fonts\calibri.ttf
C:\Windows\Fonts\calibrii.ttf
C:\Windows\Fonts\calibrib.ttf
C:\Windows\Fonts\calibriz.ttf
C:\Windows\Fonts\comic.ttf
C:\Windows\Fonts\comicbd.ttf
C:\Windows\Fonts\framd.ttf
C:\Windows\Fonts\framdit.ttf
C:\Windows\Fonts\Gabriola.ttf
C:\Windows\Fonts\georgia.ttf
C:\Windows\Fonts\georgiai.ttf
C:\Windows\Fonts\georgiab.ttf
C:\Windows\Fonts\georgiaz.ttf
C:\Windows\Fonts\pala.ttf
C:\Windows\Fonts\palai.ttf
C:\Windows\Fonts\palab.ttf
C:\Windows\Fonts\palabi.ttf
C:\Windows\Fonts\segoepr.ttf
C:\Windows\Fonts\segoeprb.ttf
C:\Windows\Fonts\trebuc.ttf
C:\Windows\Fonts\trebucit.ttf
C:\Windows\Fonts\trebucbd.ttf
C:\Windows\Fonts\trebucbi.ttf
C:\Windows\Fonts\verdana.ttf
C:\Windows\Fonts\verdanai.ttf
C:\Windows\Fonts\verdanab.ttf
C:\Windows\Fonts\verdanaz.ttf
C:\Windows\Fonts\webdings.ttf
C:\Windows\Fonts\coure.fon
C:\Windows\Fonts\serife.fon
C:\Windows\Fonts\sserife.fon
C:\Windows\Fonts\smalle.fon
C:\Windows\Fonts\smallf.fon
C:\Windows\Fonts\CALIBRILI.TTF
C:\Windows\Fonts\calibril.ttf
C:\Windows\Fonts\AGENCYB.TTF
C:\Windows\Fonts\AGENCYR.TTF
C:\Windows\Fonts\ALGER.TTF
C:\Windows\Fonts\ANTQUAB.TTF
C:\Windows\Fonts\ANTQUABI.TTF
C:\Windows\Fonts\ANTQUAI.TTF
C:\Windows\Fonts\ARIALN.TTF
C:\Windows\Fonts\ARIALNB.TTF
C:\Windows\Fonts\ARIALNBI.TTF
C:\Windows\Fonts\ARIALNI.TTF
C:\Windows\Fonts\ARLRDBD.TTF
C:\Windows\Fonts\BASKVILL.TTF
C:\Windows\Fonts\BAUHS93.TTF
C:\Windows\Fonts\BELL.TTF
C:\Windows\Fonts\BELLB.TTF
C:\Windows\Fonts\BELLI.TTF
C:\Windows\Fonts\BERNHC.TTF
C:\Windows\Fonts\BKANT.TTF
C:\Windows\Fonts\BOD_B.TTF
C:\Windows\Fonts\BOD_BI.TTF
C:\Windows\Fonts\BOD_BLAI.TTF
C:\Windows\Fonts\BOD_BLAR.TTF
C:\Windows\Fonts\BOD_CB.TTF
C:\Windows\Fonts\BOD_CBI.TTF
C:\Windows\Fonts\BOD_CI.TTF
C:\Windows\Fonts\BOD_CR.TTF
C:\Windows\Fonts\BOD_I.TTF
C:\Windows\Fonts\BOD_PSTC.TTF
C:\Windows\Fonts\BOD_R.TTF
C:\Windows\Fonts\BRADHITC.TTF
C:\Windows\Fonts\BRITANIC.TTF
C:\Windows\Fonts\BRLNSB.TTF
C:\Windows\Fonts\BRLNSDB.TTF
C:\Windows\Fonts\BRLNSR.TTF
C:\Windows\Fonts\BROADW.TTF
C:\Windows\Fonts\BRUSHSCI.TTF
C:\Windows\Fonts\CALIFB.TTF
C:\Windows\Fonts\CALIFI.TTF
C:\Windows\Fonts\CALIFR.TTF
C:\Windows\Fonts\CALIST.TTF
C:\Windows\Fonts\CALISTB.TTF
C:\Windows\Fonts\CALISTBI.TTF
C:\Windows\Fonts\CALISTI.TTF
C:\Windows\Fonts\CASTELAR.TTF
C:\Windows\Fonts\CENSCBK.TTF
C:\Windows\Fonts\CENTAUR.TTF
C:\Windows\Fonts\CHILLER.TTF
C:\Windows\Fonts\COLONNA.TTF
C:\Windows\Fonts\COOPBL.TTF
C:\Windows\Fonts\COPRGTB.TTF
C:\Windows\Fonts\COPRGTL.TTF
C:\Windows\Fonts\CURLZ___.TTF
C:\Windows\Fonts\DUBAI-BOLD.TTF
C:\Windows\Fonts\DUBAI-LIGHT.TTF
C:\Windows\Fonts\DUBAI-MEDIUM.TTF
C:\Windows\Fonts\DUBAI-REGULAR.TTF
C:\Windows\Fonts\ELEPHNT.TTF
C:\Windows\Fonts\ELEPHNTI.TTF
C:\Windows\Fonts\ENGR.TTF
C:\Windows\Fonts\ERASBD.TTF
C:\Windows\Fonts\ERASDEMI.TTF
C:\Windows\Fonts\ERASLGHT.TTF
C:\Windows\Fonts\ERASMD.TTF
C:\Windows\Fonts\FELIXTI.TTF
C:\Windows\Fonts\FORTE.TTF
C:\Windows\Fonts\FRABK.TTF
C:\Windows\Fonts\FRABKIT.TTF
C:\Windows\Fonts\FRADM.TTF
C:\Windows\Fonts\FRADMCN.TTF
C:\Windows\Fonts\FRADMIT.TTF
C:\Windows\Fonts\FRAHV.TTF
C:\Windows\Fonts\FRAHVIT.TTF
C:\Windows\Fonts\FRAMDCN.TTF
C:\Windows\Fonts\FREESCPT.TTF
C:\Windows\Fonts\FRSCRIPT.TTF
C:\Windows\Fonts\FTLTLT.TTF
C:\Windows\Fonts\GADUGI.TTF
C:\Windows\Fonts\GADUGIB.TTF
C:\Windows\Fonts\GIGI.TTF
C:\Windows\Fonts\GILBI___.TTF
C:\Windows\Fonts\GILB____.TTF
C:\Windows\Fonts\GILC____.TTF
C:\Windows\Fonts\GILI____.TTF
C:\Windows\Fonts\GILLUBCD.TTF
C:\Windows\Fonts\GILSANUB.TTF
C:\Windows\Fonts\GIL_____.TTF
C:\Windows\Fonts\GLECB.TTF
C:\Windows\Fonts\GLSNECB.TTF
C:\Windows\Fonts\GOTHIC.TTF
C:\Windows\Fonts\GOTHICB.TTF
C:\Windows\Fonts\GOTHICBI.TTF
C:\Windows\Fonts\GOTHICI.TTF
C:\Windows\Fonts\GOUDOS.TTF
C:\Windows\Fonts\GOUDOSB.TTF
C:\Windows\Fonts\GOUDOSI.TTF
C:\Windows\Fonts\GOUDYSTO.TTF
C:\Windows\Fonts\HARLOWSI.TTF
C:\Windows\Fonts\HARNGTON.TTF
C:\Windows\Fonts\HATTEN.TTF
C:\Windows\Fonts\HTOWERT.TTF
C:\Windows\Fonts\HTOWERTI.TTF
C:\Windows\Fonts\IMPRISHA.TTF
C:\Windows\Fonts\INFROMAN.TTF
C:\Windows\Fonts\ITCBLKAD.TTF
C:\Windows\Fonts\ITCEDSCR.TTF
C:\Windows\Fonts\ITCKRIST.TTF
C:\Windows\Fonts\JOKERMAN.TTF
C:\Windows\Fonts\JUICE___.TTF
C:\Windows\Fonts\KUNSTLER.TTF
C:\Windows\Fonts\LATINWD.TTF
C:\Windows\Fonts\LBRITE.TTF
C:\Windows\Fonts\LBRITED.TTF
C:\Windows\Fonts\LBRITEDI.TTF
C:\Windows\Fonts\LBRITEI.TTF
C:\Windows\Fonts\LCALLIG.TTF
C:\Windows\Fonts\LFAX.TTF
C:\Windows\Fonts\LFAXD.TTF
C:\Windows\Fonts\LFAXDI.TTF
C:\Windows\Fonts\LFAXI.TTF
C:\Windows\Fonts\LHANDW.TTF
C:\Windows\Fonts\LSANS.TTF
C:\Windows\Fonts\LSANSD.TTF
C:\Windows\Fonts\LSANSDI.TTF
C:\Windows\Fonts\LSANSI.TTF
C:\Windows\Fonts\LTYPE.TTF
C:\Windows\Fonts\LTYPEB.TTF
C:\Windows\Fonts\LTYPEBO.TTF
C:\Windows\Fonts\LTYPEO.TTF
C:\Windows\Fonts\MAGNETOB.TTF
C:\Windows\Fonts\MAIAN.TTF
C:\Windows\Fonts\MATURASC.TTF
C:\Windows\Fonts\MISTRAL.TTF
C:\Windows\Fonts\MOD20.TTF
C:\Windows\Fonts\MSUIGHUB.TTF
C:\Windows\Fonts\MTCORSVA.TTF
C:\Windows\Fonts\NIAGENG.TTF
C:\Windows\Fonts\NIAGSOL.TTF
C:\Windows\Fonts\NIRMALA.TTF
C:\Windows\Fonts\NIRMALAB.TTF
C:\Windows\Fonts\OCRAEXT.TTF
C:\Windows\Fonts\OLDENGL.TTF
C:\Windows\Fonts\ONYX.TTF
C:\Windows\Fonts\PALSCRI.TTF
C:\Windows\Fonts\PAPYRUS.TTF
C:\Windows\Fonts\PARCHM.TTF
C:\Windows\Fonts\PERBI___.TTF
C:\Windows\Fonts\PERB____.TTF
C:\Windows\Fonts\PERI____.TTF
C:\Windows\Fonts\PERTIBD.TTF
C:\Windows\Fonts\PERTILI.TTF
C:\Windows\Fonts\PER_____.TTF
C:\Windows\Fonts\PLAYBILL.TTF
C:\Windows\Fonts\POORICH.TTF
C:\Windows\Fonts\PRISTINA.TTF
C:\Windows\Fonts\RAGE.TTF
C:\Windows\Fonts\RAVIE.TTF
C:\Windows\Fonts\ROCCB___.TTF
C:\Windows\Fonts\ROCC____.TTF
C:\Windows\Fonts\ROCK.TTF
C:\Windows\Fonts\ROCKB.TTF
C:\Windows\Fonts\ROCKBI.TTF
C:\Windows\Fonts\ROCKEB.TTF
C:\Windows\Fonts\ROCKI.TTF
C:\Windows\Fonts\SCHLBKB.TTF
C:\Windows\Fonts\SCHLBKBI.TTF
C:\Windows\Fonts\SCHLBKI.TTF
C:\Windows\Fonts\SCRIPTBL.TTF
C:\Windows\Fonts\SEGOEUISL.TTF
C:\Windows\Fonts\SHOWG.TTF
C:\Windows\Fonts\SNAP____.TTF
C:\Windows\Fonts\STENCIL.TTF
C:\Windows\Fonts\TCBI____.TTF
C:\Windows\Fonts\TCB_____.TTF
C:\Windows\Fonts\TCCB____.TTF
C:\Windows\Fonts\TCCEB.TTF
C:\Windows\Fonts\TCCM____.TTF
C:\Windows\Fonts\TCMI____.TTF
C:\Windows\Fonts\TCM_____.TTF
C:\Windows\Fonts\TEMPSITC.TTF
C:\Windows\Fonts\VINERITC.TTF
C:\Windows\Fonts\VIVALDII.TTF
C:\Windows\Fonts\VLADIMIR.TTF
C:\Windows\Fonts\MSJH.TTC
C:\Windows\Fonts\MSJHBD.TTC
C:\Windows\Fonts\MSYH.TTC
C:\Windows\Fonts\MSYHBD.TTC
C:\Windows\Fonts\ARIALUNI.TTF
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\EQUATION\MTEXTRA.TTF
C:\Windows\Fonts\OUTLOOK.TTF
C:\Windows\Fonts\CENTURY.TTF
C:\Windows\Fonts\cambria.ttc
C:\Windows\Fonts\Candara.ttf
C:\Windows\Fonts\consola.ttf
C:\Windows\Fonts\constan.ttf
C:\Windows\Fonts\corbel.ttf
C:\Windows\Fonts\WINGDNG2.TTF
C:\Windows\Fonts\WINGDNG3.TTF
C:\Windows\Fonts\GARA.TTF
C:\Windows\Fonts\BOOKOS.TTF
C:\Windows\Fonts\cambriab.ttf
C:\Windows\Fonts\cambriai.ttf
C:\Windows\Fonts\cambriaz.ttf
C:\Windows\Fonts\Candarab.ttf
C:\Windows\Fonts\Candarai.ttf
C:\Windows\Fonts\Candaraz.ttf
C:\Windows\Fonts\consolab.ttf
C:\Windows\Fonts\consolai.ttf
C:\Windows\Fonts\consolaz.ttf
C:\Windows\Fonts\constanb.ttf
C:\Windows\Fonts\constani.ttf
C:\Windows\Fonts\constanz.ttf
C:\Windows\Fonts\corbelb.ttf
C:\Windows\Fonts\corbeli.ttf
C:\Windows\Fonts\corbelz.ttf
C:\Windows\Fonts\BSSYM7.TTF
C:\Windows\Fonts\REFSAN.TTF
C:\Windows\Fonts\REFSPCL.TTF
C:\Windows\Fonts\GARABD.TTF
C:\Windows\Fonts\GARAIT.TTF
C:\Windows\Fonts\BOOKOSB.TTF
C:\Windows\Fonts\BOOKOSBI.TTF
C:\Windows\Fonts\BOOKOSI.TTF
C:\Windows\Fonts\staticcache.dat
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4ac828c8c4c76f3ba59f8f9c7dab1cb3\Microsoft.VisualBasic.ni.dll
C:\Users\Rebecca\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.1784.24180609
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.1784.24180609
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.1784.24180640
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mulqBW.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v2.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-479431668-4257340731-3059248302-1002
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\16dd3437\1f4f9f5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\DotNetClient\v3.5
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index224
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_CURRENT_USER\EUDC\1252
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
\x2250\x190EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\281bf84e\4fa9c356
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-479431668-4257340731-3059248302-1002\Installer\Assemblies\C:|Users|Rebecca|AppData|Local|Temp|mulqBW.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Rebecca|AppData|Local|Temp|mulqBW.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Rebecca|AppData|Local|Temp|mulqBW.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-479431668-4257340731-3059248302-1002\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\281bf84e\6961a356
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\25fd5cf0\fe3ad34
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\25fd5cf0\21bb12f8
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\mulqBW.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\580F3090
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index224
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
\x2250\x190EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\580F3090
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.SetDefaultDllDirectories
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
kernel32.dll.AcquireSRWLockExclusive
kernel32.dll.ReleaseSRWLockExclusive
advapi32.dll.EventRegister
advapi32.dll.EventSetInformation
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
[email protected]@[email protected]
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationW
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
kernel32.dll.QueryActCtxW
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
uxtheme.dll.IsAppThemed
kernel32.dll.CreateActCtxA
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
user32.dll.RegisterWindowMessageW
user32.dll.GetSystemMetrics
user32.dll.AdjustWindowRectEx
kernel32.dll.GetCurrentProcess
kernel32.dll.GetCurrentThread
kernel32.dll.DuplicateHandle
kernel32.dll.GetCurrentThreadId
kernel32.dll.GetCurrentActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
kernel32.dll.GetModuleHandleW
kernel32.dll.GetProcAddress
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
kernel32.dll.GetUserDefaultUILanguage
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
user32.dll.CallWindowProcW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
kernel32.dll.DeactivateActCtx
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
user32.dll.GetClassInfoW
user32.dll.SystemParametersInfoW
user32.dll.GetDC
kernel32.dll.GetCurrentProcessId
kernel32.dll.FindAtomW
kernel32.dll.AddAtomW
mscoree.dll.LoadLibraryShim
mscoreei.dll.LoadLibraryShim
gdiplus.dll.GdiplusStartup
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipCreateFontFromLogfontW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryInfoKeyA
kernel32.dll.RegCloseKey
kernel32.dll.RegCreateKeyExW
kernel32.dll.RegQueryValueExW
kernel32.dll.RegEnumValueW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
gdiplus.dll.GdipGetFontUnit
gdiplus.dll.GdipGetFontSize
gdiplus.dll.GdipGetFontStyle
gdiplus.dll.GdipGetFamily
user32.dll.ReleaseDC
gdiplus.dll.GdipCreateFromHDC
gdiplus.dll.GdipGetDpiY
gdiplus.dll.GdipGetFontHeight
gdiplus.dll.GdipGetEmHeight
gdiplus.dll.GdipGetLineSpacing
gdiplus.dll.GdipDeleteGraphics
gdiplus.dll.GdipCreateFont
kernel32.dll.GetSystemDefaultLCID
gdi32.dll.GetObjectW
kernel32.dll.RegQueryInfoKeyW
gdiplus.dll.GdipDeleteFont
gdiplus.dll.GdipCreateFontFamilyFromName
gdiplus.dll.GdipGetFamilyName
gdi32.dll.CreateCompatibleDC
gdi32.dll.GetCurrentObject
gdi32.dll.SaveDC
gdi32.dll.GetDeviceCaps
gdi32.dll.CreateFontIndirectW
gdi32.dll.SelectObject
gdi32.dll.GetMapMode
gdi32.dll.GetTextMetricsW
user32.dll.DrawTextExW
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
user32.dll.MonitorFromRect
user32.dll.GetMonitorInfoW
gdi32.dll.CreateDCW
gdi32.dll.DeleteDC
user32.dll.GetDoubleClickTime
gdiplus.dll.GdipCreateBitmapFromStream
windowscodecs.dll.DllGetClassObject
gdiplus.dll.GdipImageForceValidation
gdiplus.dll.GdipGetImageRawFormat
gdiplus.dll.GdipGetImageWidth
gdiplus.dll.GdipGetImageHeight
gdiplus.dll.GdipCreateBitmapFromScan0
gdiplus.dll.GdipGetImagePixelFormat
gdiplus.dll.GdipGetImageGraphicsContext
user32.dll.GetSysColor
gdiplus.dll.GdipGraphicsClear
gdiplus.dll.GdipCreateImageAttributes
gdiplus.dll.GdipSetImageAttributesColorKeys
gdiplus.dll.GdipDrawImageRectRectI
gdiplus.dll.GdipDisposeImageAttributes
gdiplus.dll.GdipDisposeImage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
culture.dll.ConvertLangIdToCultureName
user32.dll.CreateIconFromResourceEx
gdiplus.dll.GdipGetLogFontW
mscoree.dll.ND_WU1
mscoreei.dll.ND_WU1
gdi32.dll.GetTextExtentPoint32W
user32.dll.GetCursorPos
user32.dll.MonitorFromPoint
gdiplus.dll.GdipLoadImageFromStream
gdiplus.dll.GdipGetImageType
gdiplus.dll.GdipBitmapGetPixel
kernel32.dll.OpenMutexW
kernel32.dll.CloseHandle
kernel32.dll.ReleaseMutex
kernel32.dll.CreateMutexW
kernel32.dll.CreateProcessW
kernel32.dll.GetThreadContext
kernel32.dll.ReadProcessMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.WriteProcessMemory
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.SwitchToThread
kernel32.dll.SetThreadContext
kernel32.dll.ResumeThread
ole32.dll.CoWaitForMultipleHandles
user32.dll.SetClassLongW
sechost.dll.LookupAccountNameLocalW
user32.dll.PostMessageW
user32.dll.UnregisterClassW
user32.dll.IsWindow
user32.dll.DestroyWindow
kernel32.dll.DeleteAtom
user32.dll.DestroyIcon
gdi32.dll.RestoreDC
gdi32.dll.DeleteObject
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
cryptsp.dll.CryptReleaseContext
advapi32.dll.EventUnregister
"{path}"
C:\Users\Rebecca\AppData\Local\Temp\mulqBW.exe "{path}"
Global\CLR_CASOFF_MUTEX
uzlRmxOUAnBVwGjISHCT

PE Information

Image Base Entry Point Reported Checksum Actual Checksum Minimum OS Version Compile Time Import Hash
0x00400000 0x0046c66e 0x00000000 0x0006d095 4.0 2020-06-22 03:27:06 f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name RAW Address Virtual Address Virtual Size Size of Raw Data Characteristics Entropy
.text 0x00000200 0x00002000 0x0006a714 0x0006a800 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 7.84
.rsrc 0x0006aa00 0x0006e000 0x000005b4 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.10
.reloc 0x0006b000 0x00070000 0x0000000c 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 0.10

Resources

Name Offset Size Language Sub-language Entropy File type
RT_VERSION 0x0006e090 0x00000324 LANG_NEUTRAL SUBLANG_NEUTRAL 3.29 None
RT_MANIFEST 0x0006e3c4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL 5.00 None

Imports


Assembly Information

Name ZcuXb
Version 1.0.0.0

Assembly References

Name Version
mscorlib 2.0.0.0
System.Windows.Forms 2.0.0.0
System 2.0.0.0
System.Drawing 2.0.0.0
Microsoft.VisualBasic 8.0.0.0

Custom Attributes

Type Name Value
Assembly [mscorlib]System.Reflection.AssemblyTitleAttribute VersiveProje
Assembly [mscorlib]System.Reflection.AssemblyProductAttribute VersiveProje
Assembly [mscorlib]System.Reflection.AssemblyCopyrightAttribute Copyright \xa9 20
Assembly [mscorlib]System.Runtime.InteropServices.GuidAttribute e18d6f71-62a1-4f88-9c11-4beabf6d24
Assembly [mscorlib]System.Reflection.AssemblyFileVersionAttribute 1.0.0

Type References

Assembly Type Name
mscorlib System.Runtime.CompilerServices.CompilationRelaxationsAttribute
mscorlib System.Runtime.CompilerServices.RuntimeCompatibilityAttribute
mscorlib System.Diagnostics.DebuggableAttribute
mscorlib System.Diagnostics.DebuggableAttribute/DebuggingModes
mscorlib System.Reflection.AssemblyTitleAttribute
mscorlib System.Reflection.AssemblyDescriptionAttribute
mscorlib System.Reflection.AssemblyConfigurationAttribute
mscorlib System.Reflection.AssemblyCompanyAttribute
mscorlib System.Reflection.AssemblyProductAttribute
mscorlib System.Reflection.AssemblyCopyrightAttribute
mscorlib System.Reflection.AssemblyTrademarkAttribute
mscorlib System.Runtime.InteropServices.ComVisibleAttribute
mscorlib System.Runtime.InteropServices.GuidAttribute
mscorlib System.Reflection.AssemblyFileVersionAttribute
mscorlib System.Object
System.Windows.Forms System.Windows.Forms.DialogResult
System.Windows.Forms System.Windows.Forms.MessageBoxButtons
mscorlib System.Enum
System.Windows.Forms System.Windows.Forms.Form
System.Windows.Forms System.Windows.Forms.PictureBox
System System.ComponentModel.IContainer
System.Windows.Forms System.Windows.Forms.ToolStrip
System.Windows.Forms System.Windows.Forms.ToolStripButton
System.Windows.Forms System.Windows.Forms.Panel
System.Windows.Forms System.Windows.Forms.ToolStripSplitButton
System.Windows.Forms System.Windows.Forms.ToolStripMenuItem
System.Windows.Forms System.Windows.Forms.ToolStripSeparator
System.Windows.Forms System.Windows.Forms.ToolStripLabel
System.Windows.Forms System.Windows.Forms.ToolStripTextBox
mscorlib System.EventArgs
System.Windows.Forms System.Windows.Forms.ToolStripItemClickedEventArgs
System.Windows.Forms System.Windows.Forms.MouseEventArgs
System.Drawing System.Drawing.Point
System.Drawing System.Drawing.Image
System.Windows.Forms System.Windows.Forms.KeyEventArgs
System.Windows.Forms System.Windows.Forms.PaintEventArgs
System System.ComponentModel.ComponentResourceManager
mscorlib System.STAThreadAttribute
System.Windows.Forms System.Windows.Forms.Label
System.Windows.Forms System.Windows.Forms.Button
mscorlib System.MulticastDelegate
mscorlib System.IAsyncResult
mscorlib System.AsyncCallback
mscorlib System.ValueType
System.Windows.Forms System.Windows.Forms.Keys
mscorlib System.Reflection.Assembly
mscorlib System.AppDomain
System System.Collections.Generic.Queue`1
mscorlib System.Nullable`1
System.Windows.Forms System.Windows.Forms.MenuStrip
System.Windows.Forms System.Windows.Forms.StatusStrip
System.Windows.Forms System.Windows.Forms.ToolStripStatusLabel
System.Windows.Forms System.Windows.Forms.ToolTip
System.Windows.Forms System.Windows.Forms.OpenFileDialog
System.Windows.Forms System.Windows.Forms.SaveFileDialog
mscorlib System.Collections.Generic.Dictionary`2
mscorlib System.Runtime.CompilerServices.CompilerGeneratedAttribute
mscorlib System.Diagnostics.DebuggerBrowsableState
mscorlib System.Diagnostics.DebuggerBrowsableAttribute
mscorlib System.Collections.Generic.List`1
mscorlib System.Random
mscorlib System.DateTime
System System.Diagnostics.Stopwatch
System System.CodeDom.Compiler.GeneratedCodeAttribute
mscorlib System.Diagnostics.DebuggerNonUserCodeAttribute
mscorlib System.Resources.ResourceManager
mscorlib System.Globalization.CultureInfo
System.Drawing System.Drawing.Bitmap
System System.ComponentModel.EditorBrowsableState
System System.ComponentModel.EditorBrowsableAttribute
mscorlib System.IO.File
mscorlib System.String
System.Windows.Forms System.Windows.Forms.MessageBox
mscorlib System.Array
mscorlib System.Int32
mscorlib System.Char
System.Windows.Forms System.Windows.Forms.Control
System.Windows.Forms System.Windows.Forms.MouseButtons
mscorlib System.Math
System.Drawing System.Drawing.SystemColors
System.Drawing System.Drawing.Color
System.Windows.Forms System.Windows.Forms.BorderStyle
System.Drawing System.Drawing.Size
System.Windows.Forms System.Windows.Forms.PictureBoxSizeMode
System.Windows.Forms System.Windows.Forms.MouseEventHandler
System.Windows.Forms System.Windows.Forms.Control/ControlCollection
System.Windows.Forms System.Windows.Forms.ToolStripItem
mscorlib System.IDisposable
mscorlib System.Type
mscorlib System.RuntimeTypeHandle
System.Drawing System.Drawing.Font
System.Windows.Forms System.Windows.Forms.ToolStripItemCollection
System.Windows.Forms System.Windows.Forms.ToolStripItemClickedEventHandler
System.Windows.Forms System.Windows.Forms.CheckState
System.Windows.Forms System.Windows.Forms.ToolStripItemDisplayStyle
System.Windows.Forms System.Windows.Forms.Padding
mscorlib System.EventHandler
System.Windows.Forms System.Windows.Forms.HorizontalAlignment
System.Windows.Forms System.Windows.Forms.KeyEventHandler
System.Windows.Forms System.Windows.Forms.ToolStripControlHost
System.Windows.Forms System.Windows.Forms.ToolStripDropDownItem
System.Windows.Forms System.Windows.Forms.DockStyle
System.Drawing System.Drawing.FontStyle
System.Drawing System.Drawing.GraphicsUnit
System.Windows.Forms System.Windows.Forms.ToolStripItemImageScaling
System.Windows.Forms System.Windows.Forms.TextImageRelation
System.Drawing System.Drawing.SizeF
System.Windows.Forms System.Windows.Forms.ContainerControl
System.Windows.Forms System.Windows.Forms.AutoScaleMode
System.Drawing System.Drawing.Icon
System.Windows.Forms System.Windows.Forms.FormStartPosition
System.Windows.Forms System.Windows.Forms.Application
System.Windows.Forms System.Windows.Forms.ImageLayout
System.Windows.Forms System.Windows.Forms.Cursors
System.Windows.Forms System.Windows.Forms.Cursor
System.Windows.Forms System.Windows.Forms.ButtonBase
System.Windows.Forms System.Windows.Forms.FlatButtonAppearance
System.Windows.Forms System.Windows.Forms.FlatStyle
System.Windows.Forms System.Windows.Forms.FormBorderStyle
System.Windows.Forms System.Windows.Forms.RightToLeft
Microsoft.VisualBasic Microsoft.VisualBasic.CompilerServices.LateBinding
mscorlib System.Environment
mscorlib System.Environment/SpecialFolder
System.Windows.Forms System.Windows.Forms.FileDialog
System.Windows.Forms System.Windows.Forms.CommonDialog
System.Windows.Forms System.Windows.Forms.IWin32Window
System.Windows.Forms System.Windows.Forms.MdiLayout
System System.ComponentModel.Container
System.Windows.Forms System.Windows.Forms.ToolStripLayoutStyle
mscorlib System.NotImplementedException
mscorlib System.Double
mscorlib System.Runtime.CompilerServices.RuntimeHelpers
mscorlib System.RuntimeFieldHandle
mscorlib System.Console

!This program cannot be run in DOS mode.
.text
`.rsrc
@.reloc
#.(+:
#.(+:
v2.0.50727
#Strings
#GUID
#Blob
__StaticArrayInitTypeSize=160
Nullable`1
Queue`1
SortedSet`1
List`1
frame1
_frameSize1
window_size1
toolStripLabel1
label1
panel1
ToolStripMenuItem1
ToolStripMenuItem1
ToolStripMenuItem1
toolStrip1
toolStripSeparator1
MDIParent1
Int32
Dictionary`2
frame2
_frameSize2
window_size2
toolStripLabel2
label2
get_CoreModel2
toolStripMenuItem2
toolStripSeparator2
toolStripSeparator3
toolStripSeparator4
toolStripLabel5
toolStripSeparator5
toolStripLabel6
toolStripSeparator6
toolStripLabel7
toolStripSeparator7
toolStripSeparator8
<Module>
<PrivateImplementationDetails>
9F6E8424AEDC3EE4E136A800BC166ACE250876E8B6697F4AD1242A58761ED2AB
CDCDCDCD
SizeF
System.IO
cell_backUP
AXAXAXAX
get_X
get_Y
value__
get_Magenta
get_Aqua
ZcuXb
FromArgb
mscorlib
InputStreamStub
System.Collections.Generic
Microsoft.VisualBasic
CalculateDonesAndTotals_Statistic
deShowStatistic
add_Load
LabirintForm_Load
SokobanEditor_Load
get_Red
get_Checked
set_Checked
toolStrip1_ItemClicked
add_ItemClicked
set_DoubleBuffered
valid
<Min>k__BackingField
<Max>k__BackingField
get_Hand
get_Millisecond
method
get_ButtonFace
Place
Replace
FlatButtonAppearance
get_FlatAppearance
get_KeyCode
set_AutoScaleMode
set_SizeMode
PictureBoxSizeMode
RbTree
ShitToUpperTree
ShiftToLowTree
set_Image
AddRange
set_AllowMerge
EndInvoke
BeginInvoke
IDisposable
set_Visible
Double
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
LevelFromFile
HowMuchLevelsInFile
OpenFile
Console
DockStyle
set_BorderStyle
set_FormBorderStyle
set_FlatStyle
FontStyle
set_LayoutStyle
ToolStripLayoutStyle
set_DisplayStyle
ToolStripItemDisplayStyle
set_Name
get_FileName
filename
Frame
DateTime
WriteLine
toolDone
toolNone
progressInLevel_done
HowMuchElementsOneType
ValueType
toolHere
CellToPicture
get_Culture
set_Culture
resourceCulture
ButtonBase
Close
Dispose
TryParse
Reverse
MulticastDelegate
DebuggerBrowsableState
EditorBrowsableState
set_CheckState
get_White
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
_queue
Dequeue
Enqueue
get_RoyalBlue
get_Value
CheckValue
get_HasValue
newValue
value
toolSave
toRemove
ZcuXb.exe
set_Size
frameSize
set_ImageScalingSize
set_AutoSize
toolStripTextBoxMapSize
set_BorderSize
_targetSize
set_ClientSize
_currentSize
newLevel_size
add_Resize
LabirintForm_Resize
SokobanEditor_Resize
toolResize
get_Tag
set_Tag
Padding
LateBinding
set_ImageScaling
ToolStripItemImageScaling
ToString
toString
disposing
VersiveProject.Testing
System.Drawing
SaveFileDialog
OpenFileDialog
CommonDialog
ShowDialog
Stopwatch
BinaryMath
GetFolderPath
get_Width
changableNumberOFpicturesONwidth
numberOFpicturesONwidth
numberOfPBs_width
numberOfcells_width
GetLength
LayoutMdi
toolBack
AsyncCallback
callback
get_Black
toolStripLabel1_Click
label1_Click
add_Click
toolDone_Click
toolNone_Click
toolHere_Click
toolSave_Click
toolBack_Click
toolRestartLevel_Click
toolNextLevel_Click
toolPrevLevel_Click
toolWall_Click
toolResizeAdd1Col_Click
toolResizeDel1Col_Click
CascadeToolStripMenuItem_Click
PasteToolStripMenuItem_Click
TileVerticalToolStripMenuItem_Click
TileHorizontalToolStripMenuItem_Click
CloseAllToolStripMenuItem_Click
ToolBarToolStripMenuItem_Click
StatusBarToolStripMenuItem_Click
SaveAsToolStripMenuItem_Click
ArrangeIconsToolStripMenuItem_Click
CutToolStripMenuItem_Click
CopyToolStripMenuItem_Click
ExitToolsStripMenuItem_Click
toolUser_Click
toolResizeAdd5Cols_Click
toolResizeDel5Cols_Click
toolResizeAdd5Rows_Click
toolResizeDel5Rows_Click
buttonStart_Click
toolNext_Click
toolResizeAdd1Row_Click
toolResizeDel1Row_Click
toolBox_Click
pictureBox1_MouseDoubleClick
add_MouseDoubleClick
ShowCellAfterUserDecision_forDoubleClick
pictureBox1_MouseClick
add_MouseClick
set_CheckOnClick
toolStripButton1_ButtonClick
add_ButtonClick
toolResize_ButtonClick
set_Dock
get_ControlDark
numberOfPBs_width_global
numberOfPBs_height_global
get_Coral
progressInLevel_total
actual
ToolStripLabel
ToolStripStatusLabel
toolStripStatusLabel
System.ComponentModel
Panel
LoadLevel
IsGoodLevel
toolNumberOfTimeLevel
SaveLevel
ChangeSkeletonOfLevel
numberOfLevel
toolProgressInLevel
OpenLevel
InitLevel
toolCurrentLevel
currentLevel
toolRestartLevel
toolNextLevel
toolPrevLevel
ShowLevel
level
toolWall
SetUserDecisionCell
CharToCell
userdecision_cell
selectedcell
ContainerControl
ICheckableStream
RandomInputStream
inputStream
input_stream
Program
get_Item
set_Item
ToolStripDropDownItem
ToolStripItem
set_MdiWindowListItem
cascadeToolStripMenuItem
pasteToolStripMenuItem
saveToolStripMenuItem
searchToolStripMenuItem
tileVerticalToolStripMenuItem
tileHorizontalToolStripMenuItem
closeAllToolStripMenuItem
selectAllToolStripMenuItem
openToolStripMenuItem
redoToolStripMenuItem
undoToolStripMenuItem
printSetupToolStripMenuItem
toolBarToolStripMenuItem
statusBarToolStripMenuItem
saveAsToolStripMenuItem
arrangeIconsToolStripMenuItem
optionsToolStripMenuItem
contentsToolStripMenuItem
exitToolStripMenuItem
printToolStripMenuItem
cutToolStripMenuItem
aboutToolStripMenuItem
printPreviewToolStripMenuItem
newToolStripMenuItem
newWindowToolStripMenuItem
indexToolStripMenuItem
copyToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
System
getRandom
WelcomeForm
get_ActiveForm
LabirintForm
ShowNewForm
resourceMan
get_Mean
_mean
get_Median
_median
MyStatsGen
get_MdiChildren
set_TextBoxTextAlign
get_Min
set_Min
AppDomain
get_CurrentDomain
set_Margin
width_min
height_min
set_Icon
ShowCellAfterUserDecision
Application
set_Location
user_location
set_TextImageRelation
System.Globalization
System.Reflection
ControlCollection
ToolStripItemCollection
set_StartPosition
FormStartPosition
get_ActiveCaption
NotImplementedException
get_Button
saveToolStripButton
openToolStripButton
helpToolStripButton
printToolStripButton
printPreviewToolStripButton
newToolStripButton
ToolStripSplitButton
add_KeyDown
toolStripTextBoxMapSize_KeyDown
LabirintForm_KeyDown
get_Brown
CultureInfo
UserStepOnLevelMap
Bitmap
BasicVerifyOfStep
ToolTip
toolTip
ToolStrip
toolStrip
StatusStrip
statusStrip
set_MainMenuStrip
menuStrip
get_Desktop
Clear
CellToChar
childFormNumber
ReadLevelHeader
SpecialFolder
sender
get_ActiveBorder
get_ResourceManager
ComponentResourceManager
MeanTracker
_meanTracker
MedianMaxTracker
_medianMaxTracker
ToolStripItemClickedEventHandler
MouseEventHandler
KeyEventHandler
System.CodeDom.Compiler
IContainer
set_IsMdiContainer
upper
toolUser
set_Filter
get_Silver
lower
curr_level_nr
lastInCurrent_level_nr
set_ForeColor
set_BackColor
set_UseVisualStyleBackColor
set_MouseDownBackColor
set_MouseOverBackColor
set_BorderColor
set_ImageTransparentColor
set_Cursor
ToolStripSeparator
StatisticsGenerator
_generator
.ctor
.cctor
SokobanEditor
prj_s
Statistics
System.Diagnostics
DeleteMethods
notification_endplaces
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
VersiveProject.MDIParent1.resources
prj_s.WelcomeForm.resources
prj_s.LabirintForm.resources
Editor.SokobanEditor.resources
VersiveProject.Properties.Resources.resources
DebuggingModes
VersiveProject.Properties
EnableVisualStyles
ReadAllLines
WriteAllLines
LoadPictures
InitPictures
deShowTextures
getValues
_values
notification_boxes
ToolStripItemClickedEventArgs
MouseEventArgs
PaintEventArgs
KeyEventArgs
get_ElapsedTicks
get_Controls
get_Items
get_DropDownItems
System.Windows.Forms
Contains
set_AutoScaleDimensions
CalculateFactsForNotifications
MouseButtons
MessageBoxButtons
get_Chars
RuntimeHelpers
SystemColors
Cursors
GameProccess
gameproccess
toolFactOfSuccess
TestHarness
printProgress
levelMap_UNmovedObjects
ShowMovedAndUNmovedObjects
levelUser_movedObjects
checkResults
components
set_ShortcutKeys
Concat
Format
GetObject
object
VersiveProject
LateGet
target
set_RightToLeft
get_Height
changableNumberOFpicturesONheight
numberOFpicturesONheight
numberOfPBs_height
numberOfcells_height
get_Highlight
Split
GraphicsUnit
SetCompatibleTextRenderingDefault
IAsyncResult
DialogResult
CheckResult
result
HorizontalAlignment
Environment
InitializeComponent
set_MdiParent
panel2_Paint
Point
set_Font
get_Count
_count
buttonStart
start
ToolStripControlHost
SuspendLayout
set_BackgroundImageLayout
ResumeLayout
MdiLayout
PerformLayout
toolNext
hasNext
getNext
get_Text
set_Text
get_ActiveCaptionText
set_ToolTipText
fileMenu
helpMenu
toolsMenu
windowsMenu
editMenu
viewMenu
get_vFqcrisPaeGTcRnEomQgcw
set_KeyPreview
get_Now
IWin32Window
get_Window
doubleMouseClick_x
step_x
get_Max
set_Max
width_max
height_max
set_TabIndex
MessageBox
PictureBox
set_MaximizeBox
toolBox
ToolStripTextBox
doubleMouseClick_y
step_y
InitializeArray
ToArray
ToCharArray
get_Assembly
set_InitialDirectory
op_Inequality
Empty
WrapNonExceptionThrows
VersiveProject
Copyright
2018
$e18d6f71-62a1-4f88-9c11-4beabf6d2467
1.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
width
height
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
width
height
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADM
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8Oc
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
tyw%9
m_,!8T
s+B/,{\
$Oi9{
.E)HH
Lech2(
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
tyw%9
m_,!8T
s+B/,{\
$Oi9{
.E)HH
Lech2(
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
Iu'[}gJ
{3T[2_
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
Iu'[}gJ
{3T[2_
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
XIDAT8O
o"OgE
)%<QEh|
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
XIDAT8O
o"OgE
)%<QEh|
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
WIDAT8O
2Rw[m
0Cwa&`Bt
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
/R=E(
aae-1
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
/R=E(
aae-1
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
*IDAT8O
Lc(eD
Y!QiQ
ZpT G
NpHvP
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
*IDAT8O
Lc(eD
Y!QiQ
ZpT G
NpHvP
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
/IDAT8O
]t[Sc8
bu/qx
-;d<n
lh:kF
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
/IDAT8O
]t[Sc8
bu/qx
-;d<n
lh:kF
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
$dX_wUFvC
><a`v
~FD\,
RcFJ.D
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
cHRM
IDAT8O
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADC
!This program cannot be run in DOS mode.
.text
`.rsrc
@.reloc
,T&&&&&
,K&+#
*BSJB
v2.0.50727
#Strings
#GUID
#Blob
CoreModel.dll
CoreModel
<Module>
Setup
mscorlib
Object
System
PoweredByAttribute
SmartAssembly.Attributes
Attribute
QSQWDWD
QSQSQSQS
System.Drawing
Bitmap
WDWDW
DeleteSetup
CSCSC
SCSCSC
.ctor
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
Array
List`1
System.Collections.Generic
Image
get_Width
get_Size
get_Height
GetPixel
Color
FromArgb
op_Inequality
get_R
get_G
get_B
AddRange
IEnumerable`1
ToArray
String
Concat
Assembly
GetEntryAssembly
ResourceManager
System.Resources
GetObject
Thread
System.Threading
GetDomain
AppDomain
Microsoft.VisualBasic
Interaction
CallByName
CallType
Int32
Sleep
Environment
WrapNonExceptionThrows
CoreModel
Copyright
2020
$7813e2b4-ad0f-42b4-9c20-58765e008edd
1.0.0.0
#Powered by SmartAssembly 7.3.0.3296
_CorDllMain
mscoree.dll
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
"1mcM
W1s^7,~
{brV3
~Ev?Vn
X3?V\
8.{~%
Wb[ea
/Sxb-
Y=$X/
c^g%q
Gg4/|&
JD(gG
:vWSXfc
'}q2yC
4K!oA
|S8S~
(1d[d
fRwg
=/&[:
lf_C*
<=s\-/
%%hm}
4tB>E\
P/$!/
$];Vt
SD73ep
(SE]z
i0CbO
E8>d#
+sxfo
v1:m+
lk"+2
~c(ZC?
6HYl=UM
_Cci}
,5S^3
c.8?8
eB}js]
OW1\$
adm^@
/91g7^%k
r!sb60
Hq(%C
;0JE,jH1,X
*.v],?
4CE,[
A$3Gy
j$ZZG
7`?b2
{*}^0
$`tb.
7AJ|7
!A*bT
gbJo*E1AB~<zU
VO|}}i
Q)UN?
EN]Q<
j/zy7
+]w\[
XdcRI
H7uUO\
|/!oOG
;L+gbv
OPl[H
vDFcF.Y
S4H-D
gUh_3a
w$gy0
Mz'Eao
q4&fI
G[CFX
o"B d
?K}~{
Ympn<
EdMgm
Y5j+M
|cSNOh
\Yty7S
%$-zA
;=gZ}*
81Kw)Y
i6Q%&
F&'xZ
?W3/k
dstC"g>!
p<]<\"@c
HZLG51
[=z}HAs
`qC;V
Fe3q3;
sTE,y
[)AuA<
r#p#f
tq`Xv7V:x
XyrTQ
_mK}OC
b6|nT
oTdT0
eeNNQW
;nFy]
'0g/c
vlG/x)1
H|#a9Sx
U6vG5h
N*bNE
H*?~U
=SGV|
B^ELu
&Df$0!
Pn<<K
^s6)R
oY)5{
Q\4T0B
o|Iyo
.hLmMeP
@TYgV
@>y=1
>GM&`
aEu!s:
hPl<\ML
J<ZnUO\=
Uo'M+
4q$1^
y5Z6i|
Hdg~S
E;X^>
'!m QE
!RIf24
wn<zE
6IEF
B,pn+:
FH;~Z
u8yLT
WK^w=
9:e7
g\W6\
RQ>|)k
X(M\I
!5gb<3
YJC\D%
"~M0j
@lE'4
~#_<n
"Ds,>+:
%%,/j
6j`%(N
H"Cy[;
M+b%*
?ibmw
JG2cd
j{Sz&
)*Q;tEe
lS'Q#Q
WElSS
dCth]{+5
g0vw&
km|_U
@sG%)
(cC7=
=X$q!
[uEk{L
*4Z))<z
cj`L3
z+:Gw
fo!bx
3j\gy
eg\SJ
uK0:w
t0m,M
j=_F;
b8/n8
,I[=q
q/}B"Y
6^$"w
qyZEPR(VA
)18K}
r~sSb
[Z>da
jc|5r
[ KkH
~]F7W;
!_fpq
!)x1}m
KaT0k,
5PTtrN/
sZD=cr
26=LT
x})Gca]
krROY
D<J7`5
QQ't,M
BTq&D
b35mk0h
Wa<J$
p72X=1
gRGTR
mH'Ws
y(U_)
<g'z8
n7k3p
xxnfP
!>2[*~L"Gg
u!{ec
s}$>Z
j-}')Q
5{l]0}$
m?!/M
]Y+jn
lI4=C
;y"~E
|_00/
pa}2z
X\!gt
KTFgQ3e?K
,$:g<
qmyxn*
:a8dY
|;0fk
f\TSQ
G3o>W
as:->v
C[y0h
(4EUd
0J+&0
_%ML5"
"~3x}<B=
[?L$P
0gRv<{
}`V;{"mO
3oR|z6
T0Ys6
'Y`;W
j`+>Q
4JOh3
\~/?G
>;'3s
lm[50
h!E;+*
7Z)M\i1
(.z_&Zw9
.:q~D{
~qYT2
XBUe2
I8K$9)
{lOaO
;M<V*{
RS6|[N
i9sK#iP
pKGv.
c\&,E
'kS$.
24Nqy
Ac7S_
sd%CKo
Ad+FX
,frh1,
50w57
oIj``Zq4E
ovVOL)'
{=x3}$
y<I$a
tHudkG
^KXwS
\xW`G
&#2Kh
X?x<?
}`DT()
7|D;(
SzR=1
#TO4bC
wf<7c
%`C5y
fbtw1
WFSzM%
eL*elFH
;ROW<
b,oOH
V,*B-
k-{k1s
W&#KO.
ZOJc~`1i
B+/.,
IDAT7
#Z6R.
D|U{s
\{90e
TmAVc_
Atw'V
#U{ZO^
oqVT>
kXMfx
X_[,E%
}$]2Z
?h6^$
Ed-lM
Tn~i#
2JY&~F
/>-(G
]e-D%[
YB^7O
y1/w+
}LHOc
dswV-
'cC=;
Uyui-J
Sr)DY3
$VUUh
GJwu$C
H"-M}
db;wb^}"
'6Wt"
.%)p/
74rEw
frM(1:
#kH<_
1&x1O%
uF#)h
Uc)n7Z
Q?Q<hqvHL
VH6)1Zk
?1rC-^5
hGS3h
E{r!=
`qQ6i
D>Sf~
bZC9c
=1s|I
h>g=v
;\jKKQ
<`whG
b,5q_
oqwkK
{)5MS
l<.v"
"~2v>
%vTWy
g{b7t
i_E"R7b
"XSt:
Dkf:o|3
K)\)e
JR4V`
5w)aR~,
=i9Vt
3{S7z
{7nwXG
f9UJEH
3&t:Zj)
ND>#+Q#
'O-/a
p} 3tu
.3w2s
r:R$I
Rjcq~#
M%kt_
_h1/U
m%(fde
7)D9c(
tgjg?
BD;[M\
M2o&z
tM1#,uz
U(fTy
lnMpn
6hOiOE
32w#o
+Ta[l_
t3Q_7s
iGMF|
N_=8=
Qty.c
LC}uB
E${90
WT[\,
iBPa"
M=y3:
QBiQ{l
\*flBI<b'
6dc2:
E2]wG
,S$r)
mS"'D%
}Z<"'(}.c
n` YO
Grsl?
#/<B)
\i\Bg
f;{bn+
GsiW)
pU|"a
t}\OI
5a'Wr^}8#w
';Pj'ciu
({rU>cLi
u*$9
S\<WR
+~-';
S1w*e
<90Wx
Q/qm{
Z#3V~
ky{X3h
Kh>y!
X3i)zwD
`\9N]
^!ei:
|,g]flr
h*-2Z
obu5d*
J?'Li
73#7C
A$6^(O
HndcR
G'z.;
NPh/Z
G(wjy
0s]O\H
D%Qza
@rc$`
I4Ks/G
"~*D_
RtJ0`
e)'z^
3{#Tg
l,SeC\K,
Q7Y#:1
h?`6$C$
Lff\[
xMc6-
dcl$=r
E)^"y
^^)jp
ly1o!s2
0!/M<
ICkH3
doybi
p_W~'
jDveQo
|+j+s
$Z8Q|
H[6u-b
,r7%J7
79FJz
e`,m{s
M9h):
Hm.h{
Hr3<E
mYy P
'_&3-
Nvtu/e
C}b'fU
PkybH
YUd|{(
Xq=`O?
pu(&~
?LC5V
-)}f-
x\c<K+h(
fNcQ=
yT*uh.
}fck{
YLiy1
0iGVoz>-
?ZEgQ
-ugn&
cXl3P
`p-Rl
zzb>e
a~xeG
^UTmjM
d`-Ve
Upo9\
J8A:0
*S1V->O
yg{W~5
&:i,C
+DYo(
*dF5z&:
;xvx;
ydj.Dk
}6U,!j
/$R+K
1TbpK
+i=M]
1Ug+z
ZS0p]
uj?>,
6S4It
-C1^~
qVwVF
F$ae#
B>xo*
7[C{eS,^F
>#^~e
CQE>n)!
$.u5y
_TR~sy"
bAVFm
*lv}g_
+[k8YO
ai+)Ro
-vr|eK
\QQ;N
\fq+3
Tt[%`c
OQI&NKl
hLB;%3
69y(SM
!O|Ytwa
'Upm9
2`f_J^
erdo,
+&?b|
#ibkf>*
Tq4w''
PrO)8
[3xy_
"u,6}
Jn7]N
=eSF<x
5WT"x
ib]@y
'n=|1[
o(.qr
M_}yG
$J$A+6)
l6C3"
y{ROc
s{BS,
h:l&Cs#
rO+8
8]iGX1
.%D^O
XIjSiG
"~yT7
Ge_|nWb
hJ-vv
L</&+
D^94GkN
tF{x:
:RAGCg
zj%V1
bWibn
,QAJ_G
S'{&{;
)C8}r1
L(XEyz$]jm
G[/>z
1|kOvf
|\q>PL
CE9O3
ZdTEP*
L( $5
WU%`+
z[T_>
e2UgV
SXvW#
f3GUS
+ib.g
apv/r[
qG<{w
}f^H$
}5Kz9p_
NR`Sg3
Gw_#&
5z2i/
Ts]IoW
=99v>=
7u/^T
DU,:zc5
Xt;8N
N36;F`
hw.!r|
X)S0O
?$)=o<>frD
$bf*z
Y,k^v`a
7pi~!
k[Y6,
9Cr=p
(UlOda
=(-YC
FbCg:
*rL<0
'~zo`O
!u,h\
rvV4-
f[u.m
cL(Gt'
Mq/+W
N.`Za
|:>%n$
y+V{u
3cI0j
81n&W
LG_ a
'&~bI
=?T&QI
mJ\QS~
z$=O]C
N|T,T
cOS<N
z{s-Y
4VILu>
+i\lOCs#N
-=_|G
"i<`p
{g}>=
E0isc
Q"f68<
{er|z
@3%1W
S~!MG=f
}b$[P
>uOvgh
m,)3a
JbH.I!&G
GuUs<
v4 b['
33+BYn
@RC{,
.PmAa>
7OwWc
w)o''
e3mn=
[;w$S
P,N<E
KL^21E
%. TI,
_JFD$
-v#~pD
4eK6Q=k>
cQn>y
MjK{q
=J8#^~
2/ZlxF
9OSy&
Jb*1|.
Lg%cZZS
n4Q"A
ZO^D\
j'j2G
#.':0
%qv} K
/I!^dF
FQlKh
C`A\g
AYeC8
7O1sV6
1W\b;
Ux|hM
h=d2o
GW1nw!
mU.,h
&09_F
^<<hK
`5g<U-
^<Z8V
jo"[zv
7=|gQp
'xEof
JIL-i
)HIJQ
%u|i=
Mud-.RP
I;dau8
:|BuB#
L/#j`
V-PLjMLz?
kF&i0
NJbH"
O"fg"5
Ci9jo
T\5fe
(V"6;1
*I6=p
TQv|E
SX\w*
vOf$t
O7oS^
oWk^gtD
g_-AMgS
[|>TP
}17XA
1XSAPI
)sJ+19
=AI,5
l3^;:P
I)eW>.
*-vk`R
FILzN
5"~N(:
_zp.4
5W&~d
\/S'O
IZp>i
xsy|)
[jr*_4'
vCuKkR:
=-Y5H
N1|-iD
rt$br
UmhW{
5x4r%n=2
AS&Sw
g*5=.
Egq->K
f1zp;n
&207O[
B*$*A
cD;o$
G"/}~
@CybuH
3VTB[
]UMW7S
,).E/I
qwkVN
4b )Z
b&Q)zla
+grzv
AL0XAc
G;ws&
:5#8K
A)/()
Y!o#*
#M|mfz
-+<jFt
}Dzk7
?\a*O
$6Tsi
3/d`p
HbMC%Cn
bw>_N
O/1|Cw
Q{3Y~p
MPS:i'u
e>B^E
9p6SD
dMybF
}tg~y
V?Fqyg
QJ|R?
P?@$J
!s{=&
cf?Kz
OtYFU
Hbv.(
4qe0A
;KkOE
4fMB}
O;zb`
+.LuT
)66Nf
S:x7d
1}Z,e
km1!s
_P7kJ6x0
1rq[&w
AC*0\
sMBe`p*
(:*e.+
ctUn8
8t|).E8't
iea_x
PnyJT
buib**
{s<U)*qO
C-3i.
;o?Wg
8k=#W
&ZZwDu
&s9dr
.u&m6
GU&M\
<::OAS
)dE~
j#c[w
Qgp{;
}]d`,2
m0yaL
$>BG:
U"~Jw>>
q&}E%
l7rE5y
Bz9Rp
WDXT[
<q4.]
"S9&ix
<DsQ]:
.m$vA6
P!~~M
20$Q)&
x^;.A#h
2w)3/
s+!:R
qctO's
C~S1i'
hR/F?
\hEl}
!/j|0b
IwNnx
Kp"_9
b4=MT
*SP/L'so
RECoZ
,#nLxGn
q-%kC8
E$Qd>Z
Vc"6>#i
:r&f.G
_[Z6ZGJ
nGsi6
mk_"0
GD74}
;:] @<
77aUp
dQI=%
h/0Ekj
yOR'G
tgLI9
%cmOb
W'0Tq
N7y6p
Sek>G
2FG$Ao
7v?nrX#
;Ztnr
kD['*Y>
}7BJO*
n!20(Q)
e{3K*
?}MACM
&95E%$Q9
oE^;{
h%O\9
}:U0u
cE+lB
YPg9m
|*ew^_
d`&K=
twMJ$`(
?CUPA
@&o:J
F-A$Nm
c<qxI
RO,Gu
<6qM8q
M7i$S!>
kjqY_
*b&_"^
L"I1^
N-?k*
~GT2B
D}<Jw=lE
CmsoyG
X'\"@
VPse$
jib-H
Dz;7zMz
]gg4e`'
$`KTb?SFS#X
C~"IB
6el9oN
`msg:
<E<b7k
/>#HQ
/1U-`
:_$O|
&lXSJU
7:+8tl
M(.%R
FZS\$
bCfiG
z-PLn
f^<\8
g#>r;
}t*D_1S
R^Eh{
/Z1G<~v6
=wb`H
o4gvW`
[Alz#
Y!S)*
'v|u#)
[nP?E
])\j~
GtxDR
Ba'WLg
}|\Br
&J,J+
qL{ u
6e"qS
QMLSir
*mibh
[*?T9(
XISnw
Q>[tV
_n([[
+bU'6
2*e`G
BE%+Q
(f+S>
[/SYF
-S>0=
SD%T.
Y"AH;
ok.k4
3ns'\
|^|(#
:pjq9
t&}S/f
u%uf,
8b,U[~
'f$`M
NY(g?
zn7aQ
KV+GSu
o[B^H
D2}5qzU
'Q8l
{b<o5
~%Qg5
u;p^mK
{yOZK
K;qpW*-cr
Ci}p0
mWr4w
E"jzct
o.ijS
rg15~8[
4#d`PK
\VkBD
_W:K+
d*CMR
v**$`
GCzRa
*q-XO
bW*0Y7
W}})\S
7mX3r
$A|,iu
C3,b%*D7
u!/KU
$rcd4
nDrpI*%AE
.ozGB{w
o?3bJh
iAJF7
Ce`,[
>?sM1
)gyj2
Bdj53E
Km;2I|
j({{gR
8<?#:
W]7fF
]s*yw
:P$:)
kB$KWt
0/84e
aNa6+L
ae'7\\
_QgeS&z
z"~An
2;sJ'
ja8n&q
axL}&
ra\I5
"E;l?
3df//N
JnQMo
v^sH*
r0z_C
iq(ys
%Q)V2
S;i*^
E"~;jrz\
eaWNm
E\`iT.
\>?ibj
O~'/L
]RR3)
3x0`D
JaEg<
o6!x~
RIl}N
I~O>w
f+.j]
W(4mpH[E
c{db,'f()
h$!Y}
Zw*S<-
mXqy7KZT
`*jm$&
#[,|}
hqM$1
#av{z
JZ'xS(
^dIB+
,p/}&
/IizS,
ueei}
hb:f>
*3e)G
FWNpN
Q)K!>
leb)4N"v
MT5_^U
dL5f\
"e<ZWO0
7~-/p
TM1$$
tWG:>xF
>*m"sj
lk?N
Q?ZIv
{g#C,
/TRx~
*)'\f<'
"K!J?X
qg?2V
KqVU2
rGJ[Er
LYJ3|
+hgVBp
81_ 9
mXAT#=
%bm>-_
OB{w7
:FyuF
@gsOf
R9;]"
d},!Z
-w|I3
=C&-G
Dm<E9
H_"VT
fob\3kvG^$
hNhamnK^
u<)~.
^YKrt
G| W A
f#UuS
h{K&V
MEE=('
~G<9'J
s0t;F
oZWgqR'*
:W[HR~
Eh-&6=
BTBZ:
_cZOE
~c+vg
fx5_M
2oq<ym
#{D95?
gdG}_
\fLl.
1#Vzao[
~av(V
Ze,ZW
~D=\H
Z[uImlO
NmMbD
ESEcN
4`_k#
";RAV
%)?%K
x][EW
c69:OQT
l2cw0r
@lmFNe
Y;}3N9
^| L/
H!fIR
&C1w;G
CKk&q
,EX4#
R}M{Y
@RM>`
U]a_5
%R->*=
BVN|N
,)#6b
Gl_[A
BT{ZR
vH:Ib
=F%Zh
tCsy
L,*Ei
Zm97v
#gLF4`
30VT,
82*M
WiFOj7Rz
r"{$`4D
T1sFa?
|XzDk
dHR.'
Z;3P"
6,kCh
qSC+a
ti!iM[
Sg8ZTA
ip/<z
ZS7m7
k%=,!
<?1[$
oaF}{
qX_L'
|<ikM
TvcBO?
(\y>6
,Q5=%
k~_.*83
1hm21qK
EZ<n/6
p0!Ucy
9a?,D
PU/NE
2Orb1
u~6Pa
-%nz]:]\
Z3ci!
YOw;ur
@ibk3
Hb!gY
d<mjK
vto7#
a7_Mn
6l6c~
wHUP!
%`FTR
NaqX6
&C1q7
Kor,YE
r~x5O
>x5bH
^cR74
[;4C5N
>d.^4)LF5
B%ZOm
tJTBqjZI
7BTbR
n(%wfu
mgXM"
;rV{<
D;.<=
l~:'j
z32g=
OqiR:CN[
%SP!*
lyJI<
gQ#_/
Bf6=,*ec
59S}1Y
T&o:@
w2Sh9
"v~Ufb
"Wvdy/99z
XE1qV
K<&u$`l+A
)+5zs
)nR'pRI
c*Xg:
W8zO$
rB]+Y
rqS8Q
P!&HT
Car=B
_kG=ib
|52ibJ
qzp0vj
NQPI>
;ig^s
qtNo~
!}E;{
%F}8`
~ibi 1y
+6&boo
Du?6$
)*iz4
]Z:C'
^4A%O
JdWv`
gTy7"uc>
"FITx
EmV{N
]&`qGtJ
Dea3>
x8a2]
y#Jv}d
+IWYM{a
1eZ;<
*kx0Z
:>D#u
l2ZI[o
vh>^C
hU}^<l
m|'_E
_}FGw
u|G^yOq
R!z>+'p
xN{h(
JLc3g
DJcfp
%'k#&
_ MLy10F
U9aXZ
{y2zE
M3fu;IQ
Mz^]A
gGdC^
%g,{h
wwsQo-m
enFgr)
+>HpnG
g"~k0rl
-{qHo
T=5$-b"
Mn~wVD
l\y{<
'&omE
fG|}u
-#X#Ha
fDd!uc
pKe}a<
qi~|WP
]FgxS
/%`JT
.QQ+M;EY
B>U1q
u%*I-
ijn(c
6N/jhtN
NlLG5
`T5'E
+1R#F
ZIIG9
OwJ&W
[t5:/h
=pwK#n
ht#=U
TJC=J
lz_Dey;
Ke<}7<`TRO
1[e2GZ
uP*Vf
:|KVS
[c:kZe
Z>wpUL
.=x]7
&s*{c\
Se|{h
1pURP
.;*n*&~
RC)y2
sn&xt
p-o&f
q,JYL
W1rRc
;y`!M
gsQI?
k:f!]X
86`4C}
u/~q*
PP!fI
|@%i<
0FNId
=C|Fc5
$.oKx
LEu7~
7D&,Ii
+Fv*'2
]y#kA
,I)N`
2W9S$
x^?t_
bT#h[3
r/U|?
$`r\E9
:]MBr
tIJ$hiG>
%/F/yG
D&h3'u
w*`5*
A?2PV
8tuGQ
+?3aYs
O/b#kY(
g|l%1
)l(Nf
xecX1z
mM~gCn
&S/b#
6/(\i
6W*(P>,
bPEti
JeBeE
`WZD#;}
do&bLU
1oN=eQ]
{,!N-
@5lZT
au~<E
9kL/3
+%wKF
b}d91
Jq1|q
>kJ M
7uAwW}
O&xy76
cmq=w:nu
M7I3R
!Y{.zv
sj(HJ
[u[hV
s0euR
?~j27D
?%t_Ot
gFuHRz
rll9AN
coOE+
o[*b4
#np6s
b"vU9t
D&tx/f
K%kp_
62l*$)
GUlzzc
IFXmLg
}XxVa.
faR)%]<
O*Tp>=zL
_n'BM
tR-"3R
Sm1F=
blyWz
YI{qA6
3{ f]
CMoRxl
ckp<p\dB
1w_bl
Qbma_
#_<"!1
Y"IIz
8n-U\
{cxb=
~%?x>>
uC\^/c
\{R(2
Ne*z\I
xKq87
2/\r_
1GQu:
+s<`"
$+qRS
oEuh)M
AiE}.
XvAdU5'9
gc:N_M^
cicWH
}g!{V
]Y2z.
m/+F&
z`%kD
[ytk
NvnrB)p
l%)GC
cEO7,
1/f4A;'
L'OR%
u?BedC
1'yw<
)f~tkd
A1w9f
mIQv%T
6q"vs
FqKrk
DS&u]E
[(2M9
k gE%e#.
FG!E8
B#T{9S
h<7$b
E>o\O
4cJE%
+zT)z
Gs!{3
ed6)\
H*6Na*
L3FHR
%-D&[G
QzNhX>
bEe(q
_K;*^
$I!zU
}<(XX
c{<^!E9
h*isW
_IQ^#21
},>QOI
mZ}sg
f1T{/_
:SOa7
~<NLf
]!_]U
qt6}5
9jw0y
Bdi4c'y
rZ:][
lh`OK
=bU^1
Vgsf_.
0s2ev
cwUF\0
mbznw
_F$qu
v[{.\
"~^2k
bGXHQ
#*l=Y
yFlN5
0o&w#
y%=f7
.+yz}
4lF$?
t^:o}
:b0It0
fY/lUF
OXcbE
~GtCoTB
-lS`B
@5;sK1
7s .F
4+>O9
$RJnOG
dUe'bZ
5m(Gv
%,o-s
7s;D~ks!
}~><@
WZF<',w
D%xz?
#'ZO2
M6L\L
IDAT\)
)CS6!
6IQ,Xy
/0eqb
!_t#G
[Pvf8
^apL:S
W4SP!
>I91f
F8[b-
DJ72pXk\
0I$Qy
7ct7#J
@>4[E7
81`+'g
R,:]flA
wr omG&
E.*I[a
N\(Q!Ja
v_rVi
{3QI(
H%0'UR9
)/-$a
cn}W9Mv
rng76
@vO7>+
#LeX/
iBei4
+&nzs
L!_KORh+/
:^;*vl
]u./o
U'jBe
p=$wF
MG1nP
{K8K]
Wt2wx
LU'5d
G{sA<
|;slv
|F'2T
HTk.r
gV&[U=0
"|<6P
@lR."
6RvOeGV
o*GS??
.Bvv/
zmU9.}H|
X)Ve~
Pp2Mu
G{:3|
/ie0<u
WJZHc
V/f=m
imRcX
&^79$
3U|?R
ySi0HT
zq<ZJ^
w0iX=&
n(F={
H[N l
d7!?O
)vXNFwK
pjq9k
Fj=E;
Ff^J`j
@lJDW3
s5Fq~
@@wU^:
b:A#.
^Dxs+t
FYR56
%Z5YIe
hs&wP'
aj]I\
q {!{
Nt.{BrI-7
4X0b(
15ABL
6i2-C;
d5E;?
7QnJ`
]m1u{Alq
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
width
height
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
levels.txt
Segoe UI
toolStrip1
toolWall
toolBox
toolHere
toolDone
toolNone
toolUser
toolStripSeparator5
toolStripTextBoxMapSize
toolResize
(Enter)/
ToolStripMenuItem
ToolStripMenuItem
toolStripSeparator3
toolStripMenuItem2
ToolStripMenuItem1
toolStripSeparator1
ToolStripMenuItem
ToolStripMenuItem1
toolStripSeparator2
ToolStripMenuItem
ToolStripMenuItem1
toolStripSeparator4
toolSave
toolStripSeparator6
toolBack
toolNext
toolStripSeparator7
toolStripLabel1
toolStripSeparator8
panel1
notification_boxes
notification_endplaces
$this.Icon
SokobanEditor
SuperSokoban
Microsoft Sans Serif
label1
v.0.8.1
Adobe Heiti Std R
buttonStart
Start
TatianaC
label2
WelcomeForm
SuperSokoban
toolPrevLevel
toolStripButton1
toolNextLevel
toolStripButton2
toolCurrentLevel
toolStripLabel2
toolProgressInLevel
toolStripLabel7
toolNumberOfTimeLevel
toolRestartLevel
toolStripButton3
(Esc)
toolStripLabel5
toolStripLabel6
toolFactOfSuccess
LabirintForm
vFqcrisPaeGTcRnEomQgcw
epy TteG
CoreModel.Setup
doht eMteG
Delet eSetup
eko vnI
VersiveProject
Window
Text Files (*.txt)|*.txt|All Files (*.*)|*.*
menuStrip
MenuStrip
fileMenu
&File
newToolStripMenuItem.Image
newToolStripMenuItem
openToolStripMenuItem.Image
openToolStripMenuItem
&Open
saveToolStripMenuItem.Image
saveToolStripMenuItem
&Save
saveAsToolStripMenuItem
Save &As
printToolStripMenuItem.Image
printToolStripMenuItem
&Print
printPreviewToolStripMenuItem.Image
printPreviewToolStripMenuItem
Print Pre&view
printSetupToolStripMenuItem
Print Setup
exitToolStripMenuItem
E&xit
editMenu
&Edit
undoToolStripMenuItem.Image
undoToolStripMenuItem
&Undo
redoToolStripMenuItem.Image
redoToolStripMenuItem
&Redo
cutToolStripMenuItem.Image
cutToolStripMenuItem
copyToolStripMenuItem.Image
copyToolStripMenuItem
&Copy
pasteToolStripMenuItem.Image
pasteToolStripMenuItem
&Paste
selectAllToolStripMenuItem
Select &All
viewMenu
&View
toolBarToolStripMenuItem
&Toolbar
statusBarToolStripMenuItem
&Status Bar
toolsMenu
&Tools
optionsToolStripMenuItem
&Options
windowsMenu
&Windows
newWindowToolStripMenuItem
&New Window
cascadeToolStripMenuItem
&Cascade
tileVerticalToolStripMenuItem
Tile &Vertical
tileHorizontalToolStripMenuItem
Tile &Horizontal
closeAllToolStripMenuItem
C&lose All
arrangeIconsToolStripMenuItem
&Arrange Icons
helpMenu
&Help
contentsToolStripMenuItem
&Contents
indexToolStripMenuItem.Image
indexToolStripMenuItem
&Index
searchToolStripMenuItem.Image
searchToolStripMenuItem
&Search
aboutToolStripMenuItem
&About ... ...
toolStrip
ToolStrip
newToolStripButton.Image
newToolStripButton
openToolStripButton.Image
openToolStripButton
saveToolStripButton.Image
saveToolStripButton
printToolStripButton.Image
printToolStripButton
Print
printPreviewToolStripButton.Image
printPreviewToolStripButton
Print Preview
helpToolStripButton.Image
helpToolStripButton
statusStrip
StatusStrip
toolStripStatusLabel
Status
MDIParent1
Progress: {0} elements processed
From {0} to {1} {2} should be {3} but is {4}
median
VersiveProject.Properties.Resources
CoreModel2
$this.Icon
$this.Icon
copyToolStripMenuItem.Image
cutToolStripMenuItem.Image
helpToolStripButton.Image
indexToolStripMenuItem.Image
newToolStripButton.Image
newToolStripMenuItem.Image
openToolStripButton.Image
openToolStripMenuItem.Image
pasteToolStripMenuItem.Image
printPreviewToolStripButton.Image
printPreviewToolStripMenuItem.Image
printToolStripButton.Image
printToolStripMenuItem.Image
redoToolStripMenuItem.Image
saveToolStripButton.Image
saveToolStripMenuItem.Image
searchToolStripMenuItem.Image
undoToolStripMenuItem.Image
CoreModel2
vFqcrisPaeGTcRnEomQgcw
j.#s.+
.Cs.K
.Properties.Resources
EntryPoint
Invoke
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
CoreModel
FileVersion
1.0.0.0
InternalName
CoreModel.dll
LegalCopyright
Copyright
2020
LegalTrademarks
OriginalFilename
CoreModel.dll
ProductName
CoreModel
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
$this.Icon
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
VersiveProject
FileVersion
1.0.0.0
InternalName
ZcuXb.exe
LegalCopyright
Copyright
2018
LegalTrademarks
OriginalFilename
ZcuXb.exe
ProductName
VersiveProject
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0

Full Results

Engine Signature Engine Signature Engine Signature
Bkav Clean ClamAV Clean FireEye Generic.mg.a0ced2f523a067a3
CAT-QuickHeal Clean McAfee Artemis!A0CED2F523A0 Cylance Clean
Zillya Clean SUPERAntiSpyware Clean Sangfor Malware
K7AntiVirus Clean Alibaba Clean K7GW Clean
CrowdStrike win/malicious_confidence_90% (W) Arcabit Clean TrendMicro Clean
Baidu Clean F-Prot Clean Symantec Clean
TotalDefense Clean APEX Malicious Paloalto generic.ml
Cynet Clean Kaspersky UDS:DangerousObject.Multi.Generic BitDefender Trojan.GenericKDZ.68068
NANO-Antivirus Clean ViRobot Clean MicroWorld-eScan Clean
Avast Clean Tencent Clean Ad-Aware Clean
Sophos Clean Comodo Clean F-Secure Clean
DrWeb Trojan.PackedNET.342 VIPRE Clean Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.Generic.gc Trapmine malicious.moderate.ml.score CMC Clean
Emsisoft Trojan.GenericKDZ.68068 (B) Ikarus Win32.Outbreak Cyren W32/MSIL_Agent.BLB.gen!Eldorado
Jiangmin Clean Webroot Clean Avira Clean
Fortinet Clean Antiy-AVL Clean Kingsoft Clean
Endgame malicious (high confidence) Microsoft Trojan:Win32/Wacatac.C!ml AegisLab Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen Avast-Mobile Clean TACHYON Clean
AhnLab-V3 Clean Acronis Clean BitDefenderTheta Gen:[email protected]
ALYac Clean MAX Clean VBA32 Clean
Malwarebytes Spyware.AgentTesla Zoner Clean ESET-NOD32 a variant of MSIL/Kryptik.WLU
TrendMicro-HouseCall Clean Rising Clean Yandex Clean
SentinelOne Clean eGambit Unsafe.AI_Score_98% GData Win32.Trojan-Stealer.AgentTesla.6INCBN
MaxSecure Trojan.Malware.300983.susgen AVG FileRepMalware Cybereason malicious.907c88
Panda Trj/RnkBend.A Qihoo-360 Clean
Sorry! No behavior.

Hosts

Direct IP Country Name
Y 8.8.8.8 [VT] United States
Y 1.1.1.1 [VT] Australia

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.1.5 54312 1.1.1.1 53
192.168.1.5 54312 8.8.8.8 53

DNS

No domains contacted.

HTTP Requests

No HTTP requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

ICMP traffic

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No dropped Suricata Extracted files.

JA3

No JA3 hashes found.

Sorry! No dropped files.
Sorry! No CAPE files.
Sorry! No process dumps.
Defense Evasion Privilege Escalation
  • T1116 - Code Signing
    • Signature - invalid_authenticode_signature
  • T1055 - Process Injection
    • Signature - InjectionInterProcess
  • T1045 - Software Packing
    • Signature - packer_entropy
  • T1055 - Process Injection
    • Signature - InjectionInterProcess

    Processing ( 4.754999999999999 seconds )

    • 2.823 BehaviorAnalysis
    • 0.884 Static
    • 0.338 CAPE
    • 0.275 static_dotnet
    • 0.255 VirusTotal
    • 0.043 TargetInfo
    • 0.037 AnalysisInfo
    • 0.03 Deduplicate
    • 0.028 NetworkAnalysis
    • 0.013 Dropped
    • 0.013 Strings
    • 0.008 peid
    • 0.005 Debug
    • 0.002 Suricata
    • 0.001 ProcDump

    Signatures ( 1.7799999999999974 seconds )

    • 0.184 antiav_detectreg
    • 0.105 mimics_filetime
    • 0.076 infostealer_ftp
    • 0.076 territorial_disputes_sigs
    • 0.067 stealth_timeout
    • 0.066 decoy_document
    • 0.063 Doppelganging
    • 0.06 antivm_generic_disk
    • 0.054 api_spamming
    • 0.051 antiav_detectfile
    • 0.049 masquerade_process_name
    • 0.048 NewtWire Behavior
    • 0.045 infostealer_im
    • 0.041 virus
    • 0.039 stealth_file
    • 0.038 reads_self
    • 0.037 infostealer_bitcoin
    • 0.036 antianalysis_detectreg
    • 0.034 bootkit
    • 0.028 injection_createremotethread
    • 0.028 antianalysis_detectfile
    • 0.024 InjectionCreateRemoteThread
    • 0.022 injection_runpe
    • 0.022 antivm_vbox_files
    • 0.02 InjectionInterProcess
    • 0.02 InjectionProcessHollowing
    • 0.02 hancitor_behavior
    • 0.019 antivm_vbox_keys
    • 0.018 infostealer_mail
    • 0.016 Vidar Behavior
    • 0.015 InjectionSetWindowLong
    • 0.015 neshta_files
    • 0.014 ransomware_files
    • 0.012 antivm_vmware_keys
    • 0.011 PlugX
    • 0.01 predatorthethief_files
    • 0.01 qulab_files
    • 0.009 injection_explorer
    • 0.009 antivm_parallels_keys
    • 0.009 antivm_xen_keys
    • 0.009 geodo_banking_trojan
    • 0.008 hawkeye_behavior
    • 0.008 antidbg_devices
    • 0.008 ransomware_extensions
    • 0.008 rat_pcclient
    • 0.007 TransactedHollowing
    • 0.007 antidebug_guardpages
    • 0.007 exploit_heapspray
    • 0.007 h1n1_behavior
    • 0.007 kovter_behavior
    • 0.007 rat_luminosity
    • 0.007 stack_pivot
    • 0.007 antivm_vmware_files
    • 0.006 antiemu_wine_func
    • 0.006 betabot_behavior
    • 0.006 network_tor
    • 0.006 stack_pivot_file_created
    • 0.006 antivm_generic_diskreg
    • 0.006 antivm_vpc_keys
    • 0.005 dynamic_function_loading
    • 0.005 kibex_behavior
    • 0.005 limerat_regkeys
    • 0.005 obliquerat_files
    • 0.005 sniffer_winpcap
    • 0.004 antivm_generic_scsi
    • 0.004 malicious_dynamic_function_loading
    • 0.004 antivm_vbox_devices
    • 0.004 ketrican_regkeys
    • 0.004 recon_fingerprint
    • 0.003 antidbg_windows
    • 0.003 infostealer_browser_password
    • 0.003 kazybot_behavior
    • 0.003 persistence_autorun
    • 0.003 shifu_behavior
    • 0.003 antisandbox_fortinet_files
    • 0.003 antivm_xen_keys
    • 0.003 antivm_hyperv_keys
    • 0.003 bypass_firewall
    • 0.003 codelux_behavior
    • 0.003 dcrat_files
    • 0.003 warzonerat_files
    • 0.003 targeted_flame
    • 0.002 exploit_getbasekerneladdress
    • 0.002 blackrat_registry_keys
    • 0.002 recon_programs
    • 0.002 antisandbox_cuckoo_files
    • 0.002 antisandbox_sunbelt_files
    • 0.002 antisandbox_threattrack_files
    • 0.002 antivm_generic_bios
    • 0.002 antivm_generic_system
    • 0.002 darkcomet_regkeys
    • 0.002 warzonerat_regkeys
    • 0.002 remcos_files
    • 0.002 spreading_autoruninf
    • 0.001 Unpacker
    • 0.001 antiav_avast_libs
    • 0.001 antisandbox_sunbelt_libs
    • 0.001 antivm_generic_services
    • 0.001 antivm_vbox_libs
    • 0.001 exec_crash
    • 0.001 exploit_gethaldispatchtable
    • 0.001 OrcusRAT Behavior
    • 0.001 tinba_behavior
    • 0.001 antisandbox_joe_anubis_files
    • 0.001 antivm_vpc_files
    • 0.001 banker_cridex
    • 0.001 browser_security
    • 0.001 disables_browser_warn
    • 0.001 network_tor_service
    • 0.001 medusalocker_regkeys
    • 0.001 revil_mutexes
    • 0.001 rat_spynet
    • 0.001 remcos_regkeys

    Reporting ( 10.860999999999999 seconds )

    • 10.812 BinGraph
    • 0.048 MITRE_TTPS
    • 0.001 PCAP2CERT