Edit tour

Windows Analysis Report
setup-lightshot.exe

Overview

General Information

Sample Name:setup-lightshot.exe
Analysis ID:1285697
MD5:a1f6923e771b4ff0df9fec9555f97c65
SHA1:545359cd68d0ee37f4b15e1a22c2c9a5fda69e22
SHA256:928c2808421dfd487ffa697379548cbe682c0e13aeb595eb89973ba9c515b8a1
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Drops PE files
Tries to load missing DLLs
Creates files inside the system directory
Queries keyboard layouts
Stores files to the Windows start menu directory
Uses taskkill to terminate processes
Creates job files (autostart)
Found dropped PE file which has not been started or loaded
Creates a process in suspended mode (likely to inject code)
Searches for user specific document files
Enables debug privileges

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis
  • System is w10x64_ra
  • setup-lightshot.exe (PID: 6568 cmdline: C:\Users\user\Desktop\setup-lightshot.exe MD5: A1F6923E771B4FF0DF9FEC9555F97C65)
    • setup-lightshot.tmp (PID: 748 cmdline: "C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp" /SL5="$70054,2148280,486912,C:\Users\user\Desktop\setup-lightshot.exe" MD5: C6BFFD4DA620B07CB214F1BD8E7F21D2)
      • taskkill.exe (PID: 6064 cmdline: "C:\Windows\System32\taskkill.exe" /f /im lightshot.exe MD5: 07D18817187E87CFC6AB2A4670061AE0)
        • conhost.exe (PID: 2480 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • taskkill.exe (PID: 3544 cmdline: "taskkill.exe" /F /IM lightshot.exe MD5: 07D18817187E87CFC6AB2A4670061AE0)
        • conhost.exe (PID: 3688 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • Lightshot.exe (PID: 6708 cmdline: C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe MD5: 62EB961457DF016FA3949E9601A1A845)
        • Lightshot.exe (PID: 6764 cmdline: "C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe" MD5: 1E1C83B9680029AD4A9F8D3B3AC93197)
          • splwow64.exe (PID: 8160 cmdline: C:\Windows\splwow64.exe 12288 MD5: 7FE20527607797A8DADE19838B8B1573)
      • setupupdater.exe (PID: 3644 cmdline: "C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe" /verysilent MD5: 843D23F6AAB075A3C032B06D30CE9C5D)
        • setupupdater.tmp (PID: 3424 cmdline: "C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp" /SL5="$7035C,490430,120832,C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe" /verysilent MD5: 3613E29D2A7B90C1012EC676819CC1CD)
          • net.exe (PID: 6368 cmdline: "C:\Windows\system32\net.exe" START SCHEDULE MD5: 2D09708A2B7FD7391E50A1A8E4915BD7)
            • conhost.exe (PID: 6392 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
            • net1.exe (PID: 6284 cmdline: C:\Windows\system32\net1 START SCHEDULE MD5: DACD2D80B3942C3064B29BC0D0382EF3)
          • Updater.exe (PID: 6744 cmdline: "C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addsystask MD5: FBE0664E1C333E36E3CE73D8BD5CC8A1)
          • Updater.exe (PID: 3496 cmdline: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\Updater\info.xml MD5: 3EC8F4BD54EF439A8FAB6467122DA0C4)
            • Updater.exe (PID: 3520 cmdline: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\Updater\info.xml MD5: FBE0664E1C333E36E3CE73D8BD5CC8A1)
          • Updater.exe (PID: 3684 cmdline: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true MD5: 3EC8F4BD54EF439A8FAB6467122DA0C4)
            • Updater.exe (PID: 5184 cmdline: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true MD5: FBE0664E1C333E36E3CE73D8BD5CC8A1)
      • Updater.exe (PID: 3120 cmdline: "C:\Program Files (x86)\Skillbrains\Updater\updater.exe" -runmode=addtask MD5: 3EC8F4BD54EF439A8FAB6467122DA0C4)
        • Updater.exe (PID: 6336 cmdline: "C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\updater.exe" -runmode=addtask MD5: FBE0664E1C333E36E3CE73D8BD5CC8A1)
      • Updater.exe (PID: 1280 cmdline: C:\Program Files (x86)\Skillbrains\Updater\updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\lightshot\info.xml MD5: 3EC8F4BD54EF439A8FAB6467122DA0C4)
        • Updater.exe (PID: 6160 cmdline: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\lightshot\info.xml MD5: FBE0664E1C333E36E3CE73D8BD5CC8A1)
      • chrome.exe (PID: 3352 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://app.prntscr.com/thankyou_desktop.html#install_source=default MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
        • chrome.exe (PID: 236 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1776,i,8368913202449086638,2137170749968665542,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: setup-lightshot.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Copyright 2009-2020 Skillbrains. All rights reserved.User is not allowed to upload anything that can be remotely construed as porn copyrighted material harassment or spam. The following types of files constitute "abuse" and may not be uploaded under any circumstances: 1. Pornography adult or mature content 2. Violent content 3. Content related to racial intolerance or advocacy against any individual group or organisation 4. Excessive profanity 5. Hacking/cracking content 6. Illicit drugs and drug paraphernalia content 7. Sales of beer or hard alcohol 8. Sales of tobacco or tobacco-related products 9. Sales of prescription drugs 10. Sales of weapons or ammunition (e.g. firearms firearm components fighting knives stun guns. 11. Sales of products that are replicas or imitations of designer or other goods 12. Sales or distribution of coursework or student essays 13. Content regarding programs which compensate users for clicking ads or offers performing searches surfing websites or reading emails 14. Any other content that is illegal promotes illegal activity or infringes on the legal rights of othersRedistribution in binary forms without modification are permitted provided that the following conditions are met: 1. Redistributions in binary form must reproduce the above copyright notice this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 2. Redistributions should have linkback to app.prntscr.com website. 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the Skillbrains. THIS SOFTWARE IS PROVIDED BY SKILLBRAINS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL SKILLBRAINS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE DATA OR PROFITS; OR BUSINESS INTERRUPTION. HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY WHETHER IN CONTRACT STRICT LIABILITY OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE. ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Copyright 2009-2020 Skillbrains. All rights reserved.User is not allowed to upload anything that can be remotely construed as porn copyrighted material harassment or spam. The following types of files constitute "abuse" and may not be uploaded under any circumstances: 1. Pornography adult or mature content 2. Violent content 3. Content related to racial intolerance or advocacy against any individual group or organisation 4. Excessive profanity 5. Hacking/cracking content 6. Illicit drugs and drug paraphernalia content 7. Sales of beer or hard alcohol 8. Sales of tobacco or tobacco-related products 9. Sales of prescription drugs 10. Sales of weapons or ammunition (e.g. firearms firearm components fighting knives stun guns. 11. Sales of products that are replicas or imitations of designer or other goods 12. Sales or distribution of coursework or student essays 13. Content regarding programs which compensate users for clicking ads or offers performing searches surfing websites or reading emails 14. Any other content that is illegal promotes illegal activity or infringes on the legal rights of othersRedistribution in binary forms without modification are permitted provided that the following conditions are met: 1. Redistributions in binary form must reproduce the above copyright notice this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 2. Redistributions should have linkback to app.prntscr.com website. 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the Skillbrains. THIS SOFTWARE IS PROVIDED BY SKILLBRAINS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL SKILLBRAINS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE DATA OR PROFITS; OR BUSINESS INTERRUPTION. HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY WHETHER IN CONTRACT STRICT LIABILITY OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE. ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Copyright 2009-2020 Skillbrains. All rights reserved.User is not allowed to upload anything that can be remotely construed as porn copyrighted material harassment or spam. The following types of files constitute "abuse" and may not be uploaded under any circumstances: 1. Pornography adult or mature content 2. Violent content 3. Content related to racial intolerance or advocacy against any individual group or organisation 4. Excessive profanity 5. Hacking/cracking content 6. Illicit drugs and drug paraphernalia content 7. Sales of beer or hard alcohol 8. Sales of tobacco or tobacco-related products 9. Sales of prescription drugs 10. Sales of weapons or ammunition (e.g. firearms firearm components fighting knives stun guns. 11. Sales of products that are replicas or imitations of designer or other goods 12. Sales or distribution of coursework or student essays 13. Content regarding programs which compensate users for clicking ads or offers performing searches surfing websites or reading emails 14. Any other content that is illegal promotes illegal activity or infringes on the legal rights of othersRedistribution in binary forms without modification are permitted provided that the following conditions are met: 1. Redistributions in binary form must reproduce the above copyright notice this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 2. Redistributions should have linkback to app.prntscr.com website. 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the Skillbrains. THIS SOFTWARE IS PROVIDED BY SKILLBRAINS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL SKILLBRAINS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE DATA OR PROFITS; OR BUSINESS INTERRUPTION. HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY WHETHER IN CONTRACT STRICT LIABILITY OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE. ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Copyright 2009-2020 Skillbrains. All rights reserved.User is not allowed to upload anything that can be remotely construed as porn copyrighted material harassment or spam. The following types of files constitute "abuse" and may not be uploaded under any circumstances: 1. Pornography adult or mature content 2. Violent content 3. Content related to racial intolerance or advocacy against any individual group or organisation 4. Excessive profanity 5. Hacking/cracking content 6. Illicit drugs and drug paraphernalia content 7. Sales of beer or hard alcohol 8. Sales of tobacco or tobacco-related products 9. Sales of prescription drugs 10. Sales of weapons or ammunition (e.g. firearms firearm components fighting knives stun guns. 11. Sales of products that are replicas or imitations of designer or other goods 12. Sales or distribution of coursework or student essays 13. Content regarding programs which compensate users for clicking ads or offers performing searches surfing websites or reading emails 14. Any other content that is illegal promotes illegal activity or infringes on the legal rights of othersRedistribution in binary forms without modification are permitted provided that the following conditions are met: 1. Redistributions in binary form must reproduce the above copyright notice this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 2. Redistributions should have linkback to app.prntscr.com website. 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the Skillbrains. THIS SOFTWARE IS PROVIDED BY SKILLBRAINS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL SKILLBRAINS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE DATA OR PROFITS; OR BUSINESS INTERRUPTION. HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY WHETHER IN CONTRACT STRICT LIABILITY OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE. ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: setup-lightshot.exeStatic PE information: certificate valid
Source: unknownHTTPS traffic detected: 77.88.21.119:443 -> 192.168.2.3:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 87.250.251.119:443 -> 192.168.2.3:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 93.158.134.119:443 -> 192.168.2.3:49762 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.23.139.12:443 -> 192.168.2.3:49799 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.23.139.12:443 -> 192.168.2.3:49801 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.23.139.12:443 -> 192.168.2.3:49802 version: TLS 1.2
Source: setup-lightshot.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: mc.yandex.ru
Source: global trafficHTTP traffic detected: GET /getver/updater?ping=true HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: updater.prntscr.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /thankyou_desktop.html HTTP/1.1Host: app.prntscr.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownHTTPS traffic detected: 77.88.21.119:443 -> 192.168.2.3:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 87.250.251.119:443 -> 192.168.2.3:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 93.158.134.119:443 -> 192.168.2.3:49762 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.23.139.12:443 -> 192.168.2.3:49799 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.23.139.12:443 -> 192.168.2.3:49801 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.23.139.12:443 -> 192.168.2.3:49802 version: TLS 1.2
Source: setup-lightshot.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeSection loaded: d3dx9_32.dll
Source: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exeFile created: C:\Windows\Tasks\update-sys.job
Source: C:\Users\user\Desktop\setup-lightshot.exeFile read: C:\Users\user\Desktop\setup-lightshot.exe
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\Desktop\setup-lightshot.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: unknownProcess created: C:\Users\user\Desktop\setup-lightshot.exe C:\Users\user\Desktop\setup-lightshot.exe
Source: C:\Users\user\Desktop\setup-lightshot.exeProcess created: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp "C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp" /SL5="$70054,2148280,486912,C:\Users\user\Desktop\setup-lightshot.exe"
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im lightshot.exe
Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "taskkill.exe" /F /IM lightshot.exe
Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
Source: C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exeProcess created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe "C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe"
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe "C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe" /verysilent
Source: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exeProcess created: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp "C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp" /SL5="$7035C,490430,120832,C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe" /verysilent
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Windows\SysWOW64\net.exe "C:\Windows\system32\net.exe" START SCHEDULE
Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 START SCHEDULE
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe "C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addsystask
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\Updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\Updater\info.xml
Source: C:\Program Files (x86)\Skillbrains\Updater\Updater.exeProcess created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\Updater\info.xml
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true
Source: C:\Program Files (x86)\Skillbrains\Updater\Updater.exeProcess created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im lightshot.exe
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe "C:\Program Files (x86)\Skillbrains\Updater\updater.exe" -runmode=addtask
Source: C:\Program Files (x86)\Skillbrains\Updater\Updater.exeProcess created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe "C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\updater.exe" -runmode=addtask
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\lightshot\info.xml
Source: C:\Program Files (x86)\Skillbrains\Updater\Updater.exeProcess created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\lightshot\info.xml
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://app.prntscr.com/thankyou_desktop.html#install_source=default
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1776,i,8368913202449086638,2137170749968665542,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Users\user\Desktop\setup-lightshot.exeProcess created: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp "C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp" /SL5="$70054,2148280,486912,C:\Users\user\Desktop\setup-lightshot.exe"
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "taskkill.exe" /F /IM lightshot.exe
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe "C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe" /verysilent
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe "C:\Program Files (x86)\Skillbrains\Updater\updater.exe" -runmode=addtask
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\lightshot\info.xml
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://app.prntscr.com/thankyou_desktop.html#install_source=default
Source: C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exeProcess created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe "C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe"
Source: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exeProcess created: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp "C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp" /SL5="$7035C,490430,120832,C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe" /verysilent
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Windows\SysWOW64\net.exe "C:\Windows\system32\net.exe" START SCHEDULE
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe "C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addsystask
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\Updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\Updater\info.xml
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true
Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 START SCHEDULE
Source: C:\Program Files (x86)\Skillbrains\Updater\Updater.exeProcess created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\Updater\info.xml
Source: C:\Program Files (x86)\Skillbrains\Updater\Updater.exeProcess created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3688:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3688:120:WilError_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2480:304:WilStaging_02
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeMutant created: \Sessions\1\BaseNamedObjects\LightshotStandAloneAppMainMutex
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeMutant created: \Sessions\1\BaseNamedObjects\COOL_SCREENSHOT_MUTEX_YARRR
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6392:120:WilError_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6392:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2480:120:WilError_02
Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "lightshot.exe")
Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "lightshot.exe")
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Users\user\AppData\Local\Programs
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp
Source: classification engineClassification label: clean3.winEXE@43/166@14/140
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile read: C:\Users\user\Desktop\desktop.ini
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLL
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow found: window name: TSelectLanguageForm
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeWindow detected: Number of UI elements: 12
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Copyright 2009-2020 Skillbrains. All rights reserved.User is not allowed to upload anything that can be remotely construed as porn copyrighted material harassment or spam. The following types of files constitute "abuse" and may not be uploaded under any circumstances: 1. Pornography adult or mature content 2. Violent content 3. Content related to racial intolerance or advocacy against any individual group or organisation 4. Excessive profanity 5. Hacking/cracking content 6. Illicit drugs and drug paraphernalia content 7. Sales of beer or hard alcohol 8. Sales of tobacco or tobacco-related products 9. Sales of prescription drugs 10. Sales of weapons or ammunition (e.g. firearms firearm components fighting knives stun guns. 11. Sales of products that are replicas or imitations of designer or other goods 12. Sales or distribution of coursework or student essays 13. Content regarding programs which compensate users for clicking ads or offers performing searches surfing websites or reading emails 14. Any other content that is illegal promotes illegal activity or infringes on the legal rights of othersRedistribution in binary forms without modification are permitted provided that the following conditions are met: 1. Redistributions in binary form must reproduce the above copyright notice this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 2. Redistributions should have linkback to app.prntscr.com website. 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the Skillbrains. THIS SOFTWARE IS PROVIDED BY SKILLBRAINS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL SKILLBRAINS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE DATA OR PROFITS; OR BUSINESS INTERRUPTION. HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY WHETHER IN CONTRACT STRICT LIABILITY OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE. ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Copyright 2009-2020 Skillbrains. All rights reserved.User is not allowed to upload anything that can be remotely construed as porn copyrighted material harassment or spam. The following types of files constitute "abuse" and may not be uploaded under any circumstances: 1. Pornography adult or mature content 2. Violent content 3. Content related to racial intolerance or advocacy against any individual group or organisation 4. Excessive profanity 5. Hacking/cracking content 6. Illicit drugs and drug paraphernalia content 7. Sales of beer or hard alcohol 8. Sales of tobacco or tobacco-related products 9. Sales of prescription drugs 10. Sales of weapons or ammunition (e.g. firearms firearm components fighting knives stun guns. 11. Sales of products that are replicas or imitations of designer or other goods 12. Sales or distribution of coursework or student essays 13. Content regarding programs which compensate users for clicking ads or offers performing searches surfing websites or reading emails 14. Any other content that is illegal promotes illegal activity or infringes on the legal rights of othersRedistribution in binary forms without modification are permitted provided that the following conditions are met: 1. Redistributions in binary form must reproduce the above copyright notice this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 2. Redistributions should have linkback to app.prntscr.com website. 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the Skillbrains. THIS SOFTWARE IS PROVIDED BY SKILLBRAINS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL SKILLBRAINS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE DATA OR PROFITS; OR BUSINESS INTERRUPTION. HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY WHETHER IN CONTRACT STRICT LIABILITY OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE. ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Copyright 2009-2020 Skillbrains. All rights reserved.User is not allowed to upload anything that can be remotely construed as porn copyrighted material harassment or spam. The following types of files constitute "abuse" and may not be uploaded under any circumstances: 1. Pornography adult or mature content 2. Violent content 3. Content related to racial intolerance or advocacy against any individual group or organisation 4. Excessive profanity 5. Hacking/cracking content 6. Illicit drugs and drug paraphernalia content 7. Sales of beer or hard alcohol 8. Sales of tobacco or tobacco-related products 9. Sales of prescription drugs 10. Sales of weapons or ammunition (e.g. firearms firearm components fighting knives stun guns. 11. Sales of products that are replicas or imitations of designer or other goods 12. Sales or distribution of coursework or student essays 13. Content regarding programs which compensate users for clicking ads or offers performing searches surfing websites or reading emails 14. Any other content that is illegal promotes illegal activity or infringes on the legal rights of othersRedistribution in binary forms without modification are permitted provided that the following conditions are met: 1. Redistributions in binary form must reproduce the above copyright notice this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 2. Redistributions should have linkback to app.prntscr.com website. 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the Skillbrains. THIS SOFTWARE IS PROVIDED BY SKILLBRAINS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL SKILLBRAINS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE DATA OR PROFITS; OR BUSINESS INTERRUPTION. HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY WHETHER IN CONTRACT STRICT LIABILITY OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE. ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Copyright 2009-2020 Skillbrains. All rights reserved.User is not allowed to upload anything that can be remotely construed as porn copyrighted material harassment or spam. The following types of files constitute "abuse" and may not be uploaded under any circumstances: 1. Pornography adult or mature content 2. Violent content 3. Content related to racial intolerance or advocacy against any individual group or organisation 4. Excessive profanity 5. Hacking/cracking content 6. Illicit drugs and drug paraphernalia content 7. Sales of beer or hard alcohol 8. Sales of tobacco or tobacco-related products 9. Sales of prescription drugs 10. Sales of weapons or ammunition (e.g. firearms firearm components fighting knives stun guns. 11. Sales of products that are replicas or imitations of designer or other goods 12. Sales or distribution of coursework or student essays 13. Content regarding programs which compensate users for clicking ads or offers performing searches surfing websites or reading emails 14. Any other content that is illegal promotes illegal activity or infringes on the legal rights of othersRedistribution in binary forms without modification are permitted provided that the following conditions are met: 1. Redistributions in binary form must reproduce the above copyright notice this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 2. Redistributions should have linkback to app.prntscr.com website. 3. All advertising materials mentioning features or use of this software must display the following acknowledgement: This product includes software developed by the Skillbrains. THIS SOFTWARE IS PROVIDED BY SKILLBRAINS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL SKILLBRAINS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE DATA OR PROFITS; OR BUSINESS INTERRUPTION. HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY WHETHER IN CONTRACT STRICT LIABILITY OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE. ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.I &accept the agreementI &do not accept the agreement&Next >Cancel
Source: setup-lightshot.exeStatic file information: File size 2786328 > 1048576
Source: setup-lightshot.exeStatic PE information: certificate valid
Source: setup-lightshot.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\is-83UO2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\net.dll (copy)
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpFile created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\is-A7PF5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe (copy)
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-94U68.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\DXGIODScreenshot.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\unins000.exe (copy)
Source: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exeFile created: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpFile created: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-JG8JA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\is-2F2BU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpFile created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-PQ4AC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-DA1S1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpFile created: C:\Program Files (x86)\Skillbrains\Updater\is-L7PTH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\_isetup\_setup64.tmp
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\uploader.dll (copy)
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-8UHCP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot\Uninstall Lightshot.lnk
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot\Lightshot.lnk
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot\Learn More.url
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot\Screenshot history.url
Source: C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exeFile created: C:\Windows\Tasks\update-sys.job
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\setup-lightshot.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpDropped PE file which has not been started: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\net.dll (copy)
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpDropped PE file which has not been started: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-94U68.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpDropped PE file which has not been started: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-JG8JA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpDropped PE file which has not been started: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-DA1S1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\_isetup\_setup64.tmp
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpDropped PE file which has not been started: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-8UHCP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess information queried: ProcessInformation
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000
Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: Debug
Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: Debug
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im lightshot.exe
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "taskkill.exe" /F /IM lightshot.exe
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\System32\taskkill.exe" /f /im lightshot.exe
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe "C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe" /verysilent
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe "C:\Program Files (x86)\Skillbrains\Updater\updater.exe" -runmode=addtask
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\lightshot\info.xml
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://app.prntscr.com/thankyou_desktop.html#install_source=default
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\Updater.exe" -runmode=addproduct -info="C:\Program Files (x86)\Skillbrains\Updater\info.xml
Source: C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmpProcess created: C:\Program Files (x86)\Skillbrains\Updater\Updater.exe C:\Program Files (x86)\Skillbrains\Updater\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true
Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 START SCHEDULE
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeQueries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeDirectory queried: C:\Users\user\Documents
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeDirectory queried: C:\Users\user\Documents\Lightshot
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeDirectory queried: C:\Users\user\Documents
Source: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exeDirectory queried: C:\Users\user\Documents
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts1
Windows Management Instrumentation
1
Scheduled Task/Job
11
Process Injection
12
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Data from Local System
Exfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default Accounts1
Scheduled Task/Job
1
Registry Run Keys / Startup Folder
1
Scheduled Task/Job
1
Disable or Modify Tools
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Ingress Tool Transfer
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)1
DLL Side-Loading
1
Registry Run Keys / Startup Folder
1
Virtualization/Sandbox Evasion
Security Account Manager2
System Owner/User Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Non-Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)1
DLL Side-Loading
11
Process Injection
NTDS1
Remote System Discovery
Distributed Component Object ModelInput CaptureScheduled Transfer3
Application Layer Protocol
SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
File and Directory Discovery
SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain Credentials23
System Information Discovery
VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

No bigger version
No bigger version
No bigger version
No bigger version
No bigger version
No bigger version

windows-stand
SourceDetectionScannerLabelLink
setup-lightshot.exe5%ReversingLabs
setup-lightshot.exe6%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-8UHCP.tmp0%ReversingLabs
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-8UHCP.tmp0%VirustotalBrowse
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-94U68.tmp0%ReversingLabs
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-94U68.tmp0%VirustotalBrowse
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-DA1S1.tmp0%ReversingLabs
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-DA1S1.tmp0%VirustotalBrowse
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-JG8JA.tmp0%ReversingLabs
C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-PQ4AC.tmp0%ReversingLabs
C:\Program Files (x86)\Skillbrains\lightshot\is-2F2BU.tmp2%ReversingLabs
C:\Program Files (x86)\Skillbrains\lightshot\is-83UO2.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\_isetup\_setup64.tmp0%ReversingLabs
C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe (copy)0%ReversingLabs
C:\Program Files (x86)\Skillbrains\Updater\Updater.exe (copy)5%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-5U1EQ.tmp\setupupdater.exe2%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp3%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
mc.yandex.ru
77.88.21.119
truefalse
    high
    static.cloudflareinsights.com
    104.16.57.101
    truefalse
      unknown
      accounts.google.com
      142.250.185.109
      truefalse
        high
        app.prntscr.com
        104.23.139.12
        truefalse
          high
          updater.prntscr.com
          104.23.140.12
          truefalse
            high
            st.prntscr.com
            104.23.139.12
            truefalse
              high
              api.prntscr.com
              104.23.139.12
              truefalse
                high
                upload.prntscr.com
                104.23.139.12
                truefalse
                  high
                  clients.l.google.com
                  142.250.186.78
                  truefalse
                    high
                    clients2.google.com
                    unknown
                    unknownfalse
                      high
                      NameMaliciousAntivirus DetectionReputation
                      http://updater.prntscr.com/getver/updater?ping=truefalse
                        high
                        http://app.prntscr.com/thankyou_desktop.htmlfalse
                          high
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          142.250.185.109
                          accounts.google.comUnited States
                          15169GOOGLEUSfalse
                          142.250.186.78
                          clients.l.google.comUnited States
                          15169GOOGLEUSfalse
                          34.104.35.123
                          unknownUnited States
                          15169GOOGLEUSfalse
                          1.1.1.1
                          unknownAustralia
                          13335CLOUDFLARENETUSfalse
                          104.23.140.12
                          updater.prntscr.comUnited States
                          13335CLOUDFLARENETUSfalse
                          104.23.139.12
                          app.prntscr.comUnited States
                          13335CLOUDFLARENETUSfalse
                          216.239.34.36
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.250.185.227
                          unknownUnited States
                          15169GOOGLEUSfalse
                          216.58.206.46
                          unknownUnited States
                          15169GOOGLEUSfalse
                          93.158.134.119
                          unknownRussian Federation
                          13238YANDEXRUfalse
                          239.255.255.250
                          unknownReserved
                          unknownunknownfalse
                          77.88.21.119
                          mc.yandex.ruRussian Federation
                          13238YANDEXRUfalse
                          104.16.57.101
                          static.cloudflareinsights.comUnited States
                          13335CLOUDFLARENETUSfalse
                          142.250.186.142
                          unknownUnited States
                          15169GOOGLEUSfalse
                          87.250.251.119
                          unknownRussian Federation
                          13238YANDEXRUfalse
                          142.250.184.238
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.250.184.206
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.250.186.168
                          unknownUnited States
                          15169GOOGLEUSfalse
                          IP
                          192.168.2.1
                          Joe Sandbox Version:38.0.0 Beryl
                          Analysis ID:1285697
                          Start date and time:2023-08-04 13:47:50 +02:00
                          Joe Sandbox Product:CloudBasic
                          Overall analysis duration:
                          Hypervisor based Inspection enabled:false
                          Report type:light
                          Cookbook file name:defaultwindowsinteractivecookbook.jbs
                          Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                          Number of analysed new started processes analysed:29
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:0
                          Technologies:
                          • EGA enabled
                          Analysis Mode:stream
                          Analysis stop reason:Timeout
                          Sample file name:setup-lightshot.exe
                          Detection:CLEAN
                          Classification:clean3.winEXE@43/166@14/140
                          Cookbook Comments:
                          • Found application associated with file extension: .exe
                          • Exclude process from analysis (whitelisted): svchost.exe
                          • Created / dropped Files have been reduced to 100
                          • Excluded IPs from analysis (whitelisted): 142.250.184.238, 142.250.186.142, 216.58.206.46, 142.250.185.227, 34.104.35.123, 142.250.186.168, 142.250.184.206, 216.239.34.36, 216.239.32.36
                          • Excluded domains from analysis (whitelisted): login.live.com
                          • Not all processes where analyzed, report is missing behavior information
                          • Report size getting too big, too many NtOpenKeyEx calls found.
                          • Report size getting too big, too many NtProtectVirtualMemory calls found.
                          • Report size getting too big, too many NtQueryValueKey calls found.
                          • Timeout during stream target processing, analysis might miss dynamic analysis data
                          • VT rate limit hit for: C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\is-JG8JA.tmp
                          Process:C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):875160
                          Entropy (8bit):6.524839226424313
                          Encrypted:false
                          SSDEEP:
                          MD5:FBE0664E1C333E36E3CE73D8BD5CC8A1
                          SHA1:D7F284E9A8D3A3B5A832C37B58382000B583FBC1
                          SHA-256:C4CE15B1BC8ADECBF20A655256AAB267C1D72E7A33947598AF48EA287CCA5670
                          SHA-512:7B7E34AA69E2E92590B79D2B9C9FD095D15FC5A2943335D0F59CDEE15083A8BB1A66B669615CE716BB714A59A1BE54E8FEA88A5889BFA8E0371E7EB8902FA555
                          Malicious:false
                          Antivirus:
                          • Antivirus: ReversingLabs, Detection: 0%
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6...WbQ.WbQ.WbQ...Q.WbQ...Q.WbQ...Q.WbQ...Q.WbQ./.Q.WbQ./.Q.WbQ.WcQvWbQ...Q.WbQ...Q.WbQ.W.Q.WbQ...Q.WbQRich.WbQ........PE..L......X.............................[....... ....@.......................................@..................................Q..,........)...........D.......0..`~...$..8............................\..@............ ..`............................text............................... ..`.rdata...E... ...F..................@..@.data........p...L...N..............@....rsrc....).......*..................@..@.reloc..`~...0......................@..B................................................................................................................................................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):875160
                          Entropy (8bit):6.524839226424313
                          Encrypted:false
                          SSDEEP:
                          MD5:FBE0664E1C333E36E3CE73D8BD5CC8A1
                          SHA1:D7F284E9A8D3A3B5A832C37B58382000B583FBC1
                          SHA-256:C4CE15B1BC8ADECBF20A655256AAB267C1D72E7A33947598AF48EA287CCA5670
                          SHA-512:7B7E34AA69E2E92590B79D2B9C9FD095D15FC5A2943335D0F59CDEE15083A8BB1A66B669615CE716BB714A59A1BE54E8FEA88A5889BFA8E0371E7EB8902FA555
                          Malicious:false
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6...WbQ.WbQ.WbQ...Q.WbQ...Q.WbQ...Q.WbQ...Q.WbQ./.Q.WbQ./.Q.WbQ.WcQvWbQ...Q.WbQ...Q.WbQ.W.Q.WbQ...Q.WbQRich.WbQ........PE..L......X.............................[....... ....@.......................................@..................................Q..,........)...........D.......0..`~...$..8............................\..@............ ..`............................text............................... ..`.rdata...E... ...F..................@..@.data........p...L...N..............@....rsrc....).......*..................@..@.reloc..`~...0......................@..B................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files (x86)\Skillbrains\Updater\1.8.0.0\Updater.exe
                          File Type:XML 1.0 document, ASCII text, with very long lines (373), with no line terminators
                          Category:dropped
                          Size (bytes):373
                          Entropy (8bit):4.867857443132644
                          Encrypted:false
                          SSDEEP:
                          MD5:C09CC520F19DF1BB59AC85EE57CD24EA
                          SHA1:FD5F46677BF1786A54F153201581728E96957609
                          SHA-256:27BF875E572455AAADE46C5BC19CA253BD651EFD7BCB4A48A0054D2EA6A55DEF
                          SHA-512:249380175CCAD2EC4E76CC7F3B11ACFAF48F170F40EA0CBA900D6EFC430D69DA4FB203B89E1BDDDCF58FB5EC4233915621054D63B6AF246541683DBB7EF69BD6
                          Malicious:false
                          Reputation:low
                          Preview:<?xml version='1.0' encoding='UTF-8'?><products><product friendlyname='Skillbrains Updater!' installurl='' intname='updater' needadmin='yes' productdir='C:\Program Files (x86)\Skillbrains\Updater' uninstall='' updateurl='http://updater.prntscr.com/getver/updater' version='1.8.0.0'><registryactions></registryactions><unistallactions></unistallactions></product></products>
                          Process:C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):414872
                          Entropy (8bit):5.674322626128572
                          Encrypted:false
                          SSDEEP:
                          MD5:3EC8F4BD54EF439A8FAB6467122DA0C4
                          SHA1:EE2E65CBBAA22DB70D89B85DB28EE955D4DB12F9
                          SHA-256:A5E3BDC3B0B0BD6455892E23008161B5478B24F4FE1801F43A8A01CFFF1BCBA7
                          SHA-512:0F50CE35241D5D55F0F3BAE6FB38DE39213A48D356478EFAC76C0292B286B58DDB855E130FD03BDF3CD63E141AA14FFD5318671E9885B2C17411F8BA3ABA6189
                          Malicious:false
                          Antivirus:
                          • Antivirus: ReversingLabs, Detection: 5%
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........8...k...k...k...k...k...k..k...k...k%..j...k%..j...k%..j...k..rk...k...k..k...j...k...k...k..vk...k...j...kRich...k........PE..L...=..X............................0@............@.................................eR....@..................................r..d....................>.......P...%...c..T....................d......(d..@............................................text............................... ..`.rdata..............................@..@.data................l..............@....tls.................v..............@....rsrc................x..............@..@.reloc...%...P...&..................@..B................................................................................................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp
                          File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                          Category:dropped
                          Size (bytes):276
                          Entropy (8bit):5.043696768304233
                          Encrypted:false
                          SSDEEP:
                          MD5:466B19BC0B21FE6667778A0C114A9D25
                          SHA1:3B930A9A836F39467B7BFCE4A35499FEF7803C36
                          SHA-256:EFCE940E2E2504326DCE91E1112DC19C31A9DE49F0FC34886389D36997594EF0
                          SHA-512:1D995818BED8C356AA691EF19A6CE3DF54C2FA08C086304F32B0F963934CA6402F1890BDD376D2CB411C58561E3740B73125A4CF0187FF49172D57B3B712028A
                          Malicious:false
                          Reputation:low
                          Preview:.<?xml version="1.0" encoding="UTF-8"?>..<product intname="updater" productdir="C:\Program Files (x86)\Skillbrains\Updater" uninstall="" friendlyname="Skillbrains Updater!" updateurl="http://updater.prntscr.com/getver/updater" version="1.8.0.0" needadmin="yes" ></product>..
                          Process:C:\Users\user\AppData\Local\Temp\is-K12B0.tmp\setupupdater.tmp
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):414872
                          Entropy (8bit):5.674322626128572
                          Encrypted:false
                          SSDEEP:
                          MD5:3EC8F4BD54EF439A8FAB6467122DA0C4
                          SHA1:EE2E65CBBAA22DB70D89B85DB28EE955D4DB12F9
                          SHA-256:A5E3BDC3B0B0BD6455892E23008161B5478B24F4FE1801F43A8A01CFFF1BCBA7
                          SHA-512:0F50CE35241D5D55F0F3BAE6FB38DE39213A48D356478EFAC76C0292B286B58DDB855E130FD03BDF3CD63E141AA14FFD5318671E9885B2C17411F8BA3ABA6189
                          Malicious:false
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........8...k...k...k...k...k...k..k...k...k%..j...k%..j...k%..j...k..rk...k...k..k...j...k...k...k..vk...k...j...kRich...k........PE..L...=..X............................0@............@.................................eR....@..................................r..d....................>.......P...%...c..T....................d......(d..@............................................text............................... ..`.rdata..............................@..@.data................l..............@....tls.................v..............@....rsrc................x..............@..@.reloc...%...P...&..................@..B................................................................................................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):95656
                          Entropy (8bit):6.415071063495964
                          Encrypted:false
                          SSDEEP:
                          MD5:25C632CD2F529BA142FA706205AC00C9
                          SHA1:495B777348D26E5FA75DFBF6B50498428FE7748B
                          SHA-256:6ACDCD817CC5DF637AA4CD101C25C9E0A69C778347A7A40CE7511EEEA26FD6F0
                          SHA-512:606E9856EB8153F9DAB7F4C23FF967B2D9CE9FCF1902823A424CA4B4EE0A4F1A95BFDD316356DD65831C494F7E74EC4562BF684AB6A20C3376ABEF8FF10F6C7A
                          Malicious:false
                          Reputation:low
                          Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......X}.............(......*......+.....d]....'B....'B....'B.8...dJ...........B.....B.....B&......N.....B....Rich...........................PE..L....M5]...........!.................-....................................................@..........................9..\....9..x....................\...............+..p....................,......0,..@...............d............................text............................... ..`.rdata...b.......d..................@..@.data........P.......8..............@....gfids.......p.......B..............@..@.tls.................D..............@....rsrc................F..............@..@.reloc...............L..............@..B........................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):502696
                          Entropy (8bit):7.389939877593927
                          Encrypted:false
                          SSDEEP:
                          MD5:F256A9C7E68A249FE760019D19C022CE
                          SHA1:5A6279EF4F82270B756053CD34BBA96D7FE0CE05
                          SHA-256:04A27F0D1E89341722461119E00A10E00EC2A52F5E305961161EC4378E610E93
                          SHA-512:A97F1CD4554D59EE0D69DF6EBFC234E025C5E6E64C057F28C62F3743C8CCF8B502CE3EAFC437A34A492B6B590FE62591293E551D0E7DB5B6036890A64E6D8DE9
                          Malicious:false
                          Reputation:low
                          Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$........R...<...<...<.;l....<.;l....<.;l....<...?...<...8...<...9...<.......<...=...<.......<.......<.%.5...<.%.<...<.%.....<......<.%.>...<.Rich..<.........................PE..L....M5]...........!................................................................F....@.........................._.......`..........x........................-...$..p....................%......P%..@............................................text...t........................... ..`.rdata..............................@..@.data....%...........n..............@....gfids..............................@..@.tls................................@....rsrc...x...........................@..@.reloc...-...........d..............@..B................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):499624
                          Entropy (8bit):6.110809334310596
                          Encrypted:false
                          SSDEEP:
                          MD5:1E1C83B9680029AD4A9F8D3B3AC93197
                          SHA1:FA7B69793454131A5B21B32867533305651E2DD4
                          SHA-256:0B899508777D7ED5159E2A99A5EFF60C54D0724493DF3D630525B837FA43AA51
                          SHA-512:FE6F8DF3DBBCC7535EAD60028EC3E45801A33CCC81C9137B2288BC0D18BE42379564C907EB406CE9491F46930690EFA9A86A9F6506414992B5DBA75ADB3D1136
                          Malicious:false
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........GkO.&...&...&..S....&..S...l&..S....&...x...&...x...&...x...&...^...&...^...&...&...'..Mx...&..Mx...&...&...&..Mx...&..Rich.&..........................PE..L....M5]..........................................@.................................i_....@.................................H...........x.......................|4..P/..p....................0......./..@............................................text.............................. ..`.rdata..@...........................@..@.data....&..........................@....gfids..4...........................@..@.tls................................@....rsrc...x...........................@..@.reloc..|4.......6...P..............@..B................................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):95656
                          Entropy (8bit):6.415071063495964
                          Encrypted:false
                          SSDEEP:
                          MD5:25C632CD2F529BA142FA706205AC00C9
                          SHA1:495B777348D26E5FA75DFBF6B50498428FE7748B
                          SHA-256:6ACDCD817CC5DF637AA4CD101C25C9E0A69C778347A7A40CE7511EEEA26FD6F0
                          SHA-512:606E9856EB8153F9DAB7F4C23FF967B2D9CE9FCF1902823A424CA4B4EE0A4F1A95BFDD316356DD65831C494F7E74EC4562BF684AB6A20C3376ABEF8FF10F6C7A
                          Malicious:false
                          Antivirus:
                          • Antivirus: ReversingLabs, Detection: 0%
                          • Antivirus: Virustotal, Detection: 0%, Browse
                          Reputation:low
                          Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......X}.............(......*......+.....d]....'B....'B....'B.8...dJ...........B.....B.....B&......N.....B....Rich...........................PE..L....M5]...........!.................-....................................................@..........................9..\....9..x....................\...............+..p....................,......0,..@...............d............................text............................... ..`.rdata...b.......d..................@..@.data........P.......8..............@....gfids.......p.......B..............@..@.tls.................D..............@....rsrc................F..............@..@.reloc...............L..............@..B........................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):220584
                          Entropy (8bit):6.536382959641074
                          Encrypted:false
                          SSDEEP:
                          MD5:08CF9E363D79C9379CABD75382131315
                          SHA1:22CE1F3506FC46976F2D5DCC5A5735CE8EDE63BF
                          SHA-256:037EE2F3243918FFFA71B9E3FE0541245F75F89ABCAC0CCF2EA6A57020DDAAD7
                          SHA-512:CAB0C8A5B8596054315C69F1FF858DA1FAD89EA1E3C28D4C90411C293B6B40438E2BE67E029A51279637F2704E30903D0D4751E31FA1D1B2AF0393AF90C8907B
                          Malicious:false
                          Antivirus:
                          • Antivirus: ReversingLabs, Detection: 0%
                          • Antivirus: Virustotal, Detection: 0%, Browse
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........{{....@...@...@W..@...@W..@k..@W..@...@.b.@...@.D.A...@.D.A...@.D.A...@.b.@...@...@9..@ID.A...@ID.A...@ID.@...@...@...@ID.A...@Rich...@................PE..L....M5]...........!.....L...................`............................................@.............................h...(........`..P............D.......p..."..0...p...............................@............`...............................text....J.......L.................. ..`.rdata.......`.......P..............@..@.data... .... ......................@....gfids.......@......................@..@.tls.........P......................@....rsrc...P....`......................@..@.reloc..."...p...$... ..............@..B................................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):502696
                          Entropy (8bit):7.389939877593927
                          Encrypted:false
                          SSDEEP:
                          MD5:F256A9C7E68A249FE760019D19C022CE
                          SHA1:5A6279EF4F82270B756053CD34BBA96D7FE0CE05
                          SHA-256:04A27F0D1E89341722461119E00A10E00EC2A52F5E305961161EC4378E610E93
                          SHA-512:A97F1CD4554D59EE0D69DF6EBFC234E025C5E6E64C057F28C62F3743C8CCF8B502CE3EAFC437A34A492B6B590FE62591293E551D0E7DB5B6036890A64E6D8DE9
                          Malicious:false
                          Antivirus:
                          • Antivirus: ReversingLabs, Detection: 0%
                          • Antivirus: Virustotal, Detection: 0%, Browse
                          Reputation:low
                          Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$........R...<...<...<.;l....<.;l....<.;l....<...?...<...8...<...9...<.......<...=...<.......<.......<.%.5...<.%.<...<.%.....<......<.%.>...<.Rich..<.........................PE..L....M5]...........!................................................................F....@.........................._.......`..........x........................-...$..p....................%......P%..@............................................text...t........................... ..`.rdata..............................@..@.data....%...........n..............@....gfids..............................@..@.tls................................@....rsrc...x...........................@..@.reloc...-...........d..............@..B................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):532904
                          Entropy (8bit):6.677919829499898
                          Encrypted:false
                          SSDEEP:
                          MD5:E68D7EAD1C2F5970541346AC8CB6F4FB
                          SHA1:F0E737DBF948141CF2499B0AA75C4774EF4CE2B7
                          SHA-256:45B2C27A4345D789287539DD82C9F85AC9324D01825F6E2E0C2CDD4C4172C038
                          SHA-512:11703B51D4DC40ED8EF0E502662055127D2A1C34E0FA09C204CEEFEE3DB6E7C567F519526E7794801AB7CB921BF29CC10E67C3C34426D2B1797080B52C748B4D
                          Malicious:false
                          Antivirus:
                          • Antivirus: ReversingLabs, Detection: 0%
                          Reputation:low
                          Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.......u^i.1?..1?..1?......=?.......?......+?......7?...a..)?...a..#?...a...?..8G..0?..1?...?..8G..*?...a..n?...a..8?...a..0?...a..0?..1?..0?...a..0?..Rich1?..................PE..L...wM5]...........!.....`..........W........p...............................`............@............................x...X....................................G..@...p...............................@............p..8............................text....^.......`.................. ..`.rdata...E...p...F...d..............@..@.data...0...........................@....gfids..............................@..@.tls................................@....rsrc...............................@..@.reloc...G.......H..................@..B................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:MS Windows 95 Internet shortcut text (URL=<http://app.prntscr.com/ru/learnmore.html>), ASCII text
                          Category:dropped
                          Size (bytes):63
                          Entropy (8bit):4.303852590718637
                          Encrypted:false
                          SSDEEP:
                          MD5:2965233936B91BD8BB3D9EEAF91FA6AE
                          SHA1:9CD3995294970CE009A4B9B4F91CCC86C955E1DC
                          SHA-256:78C231231AC2C07AE87A1E3BEC5869D6568A16C66E5922AF1310B811837F8925
                          SHA-512:82B42EA1D4A6AE0D0C9A056BF2E1F2E21F0F5689B4C9C32F1B1975C2BAEC3B2E8BB46C31A41E88E014196B6792D4286EC170271C5E260ABFC921E18E90D1EC23
                          Malicious:false
                          Reputation:low
                          Preview:[InternetShortcut].URL=http://app.prntscr.com/ru/learnmore.html
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:MS Windows 95 Internet shortcut text (URL=<http://app.prntscr.com/learnmore.html>), ASCII text
                          Category:dropped
                          Size (bytes):60
                          Entropy (8bit):4.306238928653388
                          Encrypted:false
                          SSDEEP:
                          MD5:61CBFB8CA48B0BE0BC4D2F3C286D5B2E
                          SHA1:4024015085B9058DE26A3A3739CB4C856F21A637
                          SHA-256:C8345F016B914C6502173CD41BF7CD23D6BE3FD6F7D8F274845FE02595538B37
                          SHA-512:83C2BEB29690E7BCBF4EDFD99D9576562B4D75272C5155A7E641853B29BE74420CCC098115BBD3709771CCABE6F76C5F0FF107ECBBCF2C30FA58A76480CC5393
                          Malicious:false
                          Reputation:low
                          Preview:[InternetShortcut].URL=http://app.prntscr.com/learnmore.html
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Category:dropped
                          Size (bytes):499624
                          Entropy (8bit):6.110809334310596
                          Encrypted:false
                          SSDEEP:
                          MD5:1E1C83B9680029AD4A9F8D3B3AC93197
                          SHA1:FA7B69793454131A5B21B32867533305651E2DD4
                          SHA-256:0B899508777D7ED5159E2A99A5EFF60C54D0724493DF3D630525B837FA43AA51
                          SHA-512:FE6F8DF3DBBCC7535EAD60028EC3E45801A33CCC81C9137B2288BC0D18BE42379564C907EB406CE9491F46930690EFA9A86A9F6506414992B5DBA75ADB3D1136
                          Malicious:false
                          Antivirus:
                          • Antivirus: ReversingLabs, Detection: 0%
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........GkO.&...&...&..S....&..S...l&..S....&...x...&...x...&...x...&...^...&...^...&...&...'..Mx...&..Mx...&...&...&..Mx...&..Rich.&..........................PE..L....M5]..........................................@.................................i_....@.................................H...........x.......................|4..P/..p....................0......./..@............................................text.............................. ..`.rdata..@...........................@..@.data....&..........................@....gfids..4...........................@..@.tls................................@....rsrc...x...........................@..@.reloc..|4.......6...P..............@..B................................................................................................................................................................................................
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:MS Windows 95 Internet shortcut text (URL=<http://app.prntscr.com/learnmore.html>), ASCII text
                          Category:dropped
                          Size (bytes):60
                          Entropy (8bit):4.306238928653388
                          Encrypted:false
                          SSDEEP:
                          MD5:61CBFB8CA48B0BE0BC4D2F3C286D5B2E
                          SHA1:4024015085B9058DE26A3A3739CB4C856F21A637
                          SHA-256:C8345F016B914C6502173CD41BF7CD23D6BE3FD6F7D8F274845FE02595538B37
                          SHA-512:83C2BEB29690E7BCBF4EDFD99D9576562B4D75272C5155A7E641853B29BE74420CCC098115BBD3709771CCABE6F76C5F0FF107ECBBCF2C30FA58A76480CC5393
                          Malicious:false
                          Reputation:low
                          Preview:[InternetShortcut].URL=http://app.prntscr.com/learnmore.html
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:MS Windows 95 Internet shortcut text (URL=<http://app.prntscr.com/ru/learnmore.html>), ASCII text
                          Category:dropped
                          Size (bytes):63
                          Entropy (8bit):4.303852590718637
                          Encrypted:false
                          SSDEEP:
                          MD5:2965233936B91BD8BB3D9EEAF91FA6AE
                          SHA1:9CD3995294970CE009A4B9B4F91CCC86C955E1DC
                          SHA-256:78C231231AC2C07AE87A1E3BEC5869D6568A16C66E5922AF1310B811837F8925
                          SHA-512:82B42EA1D4A6AE0D0C9A056BF2E1F2E21F0F5689B4C9C32F1B1975C2BAEC3B2E8BB46C31A41E88E014196B6792D4286EC170271C5E260ABFC921E18E90D1EC23
                          Malicious:false
                          Reputation:low
                          Preview:[InternetShortcut].URL=http://app.prntscr.com/ru/learnmore.html
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (610)
                          Category:dropped
                          Size (bytes):11008
                          Entropy (8bit):5.216434895376966
                          Encrypted:false
                          SSDEEP:
                          MD5:CD83A38536EF1AC82033C88B40C1C299
                          SHA1:39946888C6DBDD2327AEB9B3F323C85B80D01B15
                          SHA-256:1671AE6D38467FE894E2190AC4E03ECF443BCDB535348B4E3B861BC8BB030C58
                          SHA-512:FA71259F29AD9C7D5ADF37ADF971F9465551E23F2AA565AD8AE8700A9F093A290D182A36264206056538BF3DA5A47A962B86F6BF83D2F3942C800010B7FC41CF
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[...]].[[screenshot_plugin.copy]]=[[...]].[[screenshot_plugin.print]]=[[.....]].[[screenshot_plugin.fullscreen]]=[[..... ...... .....]].[[screenshot_plugin.clear]]=[[..... ........]].[[screenshot_plugin.cancel]]=[[.....]].[[screenshot_plugin.editonline]]=[[..... ...... .. ......]].[[screenshot_plugin.upload]]=[[... ...... ... Prntscr.com]].[[screenshot_plugin.close]]=[[.....]]..[[screenshot_plugin.share_googlesearch]]=[[..... .. .... ..... .. ....]].[[screenshot_plugin.share_tineyesearch]]=[[..... .. .... ...... .. Tineye]].[[screenshot_plugin.share_sendmail]]=[[..... ... .......]].[[screenshot_plugin.share_twitter]]=[[... ... .....]].[[screenshot_plugin.share_facebook]]=[[...... ... ........]].[[screenshot_plugin.share_vk]]=[[........ ... VK]].[[screenshot_plugin.share_pinterest]]=
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (960)
                          Category:dropped
                          Size (bytes):14817
                          Entropy (8bit):5.250728591248304
                          Encrypted:false
                          SSDEEP:
                          MD5:1E03EAEA8317F8957E3550C5CBE7B1C2
                          SHA1:AA99447995880271B770698C95949DAD750A148D
                          SHA-256:A8F0633F9AC6B0AA75477547D254E41A2B7571F1E832F8E22F2DA47C12ACA023
                          SHA-512:1695B65441B72CFA68020E4C11894645FB3ED13F74ED847C53E0CD4ED0D89FCBC6BE7FE37483F1E21348EC16F31FCF327505BA1E149F05215285B54FC49BE8E6
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[........]].[[screenshot_plugin.copy]]=[[.........]].[[screenshot_plugin.print]]=[[.........]].[[screenshot_plugin.fullscreen]]=[[........ ..... .....]].[[screenshot_plugin.clear]]=[[......... .........]].[[screenshot_plugin.cancel]]=[[.........]].[[screenshot_plugin.editonline]]=[[.......... ...... ...... ......]].[[screenshot_plugin.upload]]=[[........... .. prntscr.com]].[[screenshot_plugin.close]]=[[........]]..[[screenshot_plugin.share_googlesearch]]=[[...... ........ ........ . Google]].[[screenshot_plugin.share_tineyesearch]]=[[...... ........ ........ . Tineye]].[[screenshot_plugin.share_sendmail]]=[[....... .... email]].[[screenshot_plugin.share_twitter]]=[[.......... . Twitter]].[[screenshot_plugin.share_facebook]]=[[.......... . Facebook]].[[screens
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1008)
                          Category:dropped
                          Size (bytes):14747
                          Entropy (8bit):5.151861698418845
                          Encrypted:false
                          SSDEEP:
                          MD5:BB52B0A262414EB4D611072E7ADF8C58
                          SHA1:F7507947C3B45337409A2CC8133B1E685698A825
                          SHA-256:57EC7737EB0BCCC19F8674F1CC462C2A9A8554E2B0A167E3F01B8BC94129E054
                          SHA-512:FBB9B407892FEE54664FF63E700AC490D397A30A4EC64C433002ACA8D0806E1114C564DE05D0E5EB8574EC4CF1A2D8F42A78518F863E2D9DECEE9CC9B86E8467
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.........]].[[screenshot_plugin.copy]]=[[........]].[[screenshot_plugin.print]]=[[..........]].[[screenshot_plugin.fullscreen]]=[[........ .. ..... .....]].[[screenshot_plugin.clear]]=[[..........]].[[screenshot_plugin.cancel]]=[[......]].[[screenshot_plugin.editonline]]=[[...... ...........]].[[screenshot_plugin.upload]]=[[....... . prntscr.com]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_googlesearch]]=[[....... .. ....... ........... . Google]].[[screenshot_plugin.share_tineyesearch]]=[[....... .. ....... ........... . Tineye]].[[screenshot_plugin.share_sendmail]]=[[....... .... email]].[[screenshot_plugin.share_twitter]]=[[....... . Twitter]].[[screenshot_plugin.share_facebook]]=[[....... . Facebook]].[[screenshot_plugin.share_vk]]=[[....... .
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (964)
                          Category:dropped
                          Size (bytes):19027
                          Entropy (8bit):4.732656173496707
                          Encrypted:false
                          SSDEEP:
                          MD5:BCB08DB5044B9ECD6FDD972342919E64
                          SHA1:225C6464CA0FE7CF5BEF790ABD7DBFEF7232890B
                          SHA-256:6AB63FBA0DEDFEAD6B75105378015DDC38F4C72007A1D2D4DB8BAEE9FE3CD93D
                          SHA-512:0290B6584C3DA452A7CA5EA654CF1B9834BA3409EF093470881CF9AE2C833E6BADDC462FB59D0B534FFFA6ED08199C1A8FE73FA6B706CFCF892E7D9BDFDE5E35
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[... ....]].[[screenshot_plugin.copy]]=[[... ....]].[[screenshot_plugin.print]]=[[....... ....]].[[screenshot_plugin.fullscreen]]=[[........ ....... ....... ....]].[[screenshot_plugin.clear]]=[[....... ..... ....]].[[screenshot_plugin.cancel]]=[[..... ....]].[[screenshot_plugin.editonline]]=[[....... .... ......... .... ....]].[[screenshot_plugin.upload]]=[[Prntscr.com . ..... ....]].[[screenshot_plugin.close]]=[[.... ....]]..[[screenshot_plugin.share_googlesearch]]=[[..... ... ..... ... ......]].[[screenshot_plugin.share_tineyesearch]]=[[Tineye .. ...... ... ......]].[[screenshot_plugin.share_sendmail]]=[[...... .....
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (972)
                          Category:dropped
                          Size (bytes):10728
                          Entropy (8bit):5.002922909528201
                          Encrypted:false
                          SSDEEP:
                          MD5:E53D7FDAE82FE462BD51C0B1AE52CFD7
                          SHA1:A502CA692306A1B5F4A3105271DDAF759BF4CFBA
                          SHA-256:861AD3BA1045D7BCFDC455226F13C43DC07808F4286850ED3F2C1875CE202790
                          SHA-512:D5C9183C4E73F0C62E74E1F3425D962AB194EC570EB15F28564EEF193E3305CC94CAEB488682865753A07995F12FC8C8571D3E4EE16566F32526C8D83DCCFAB9
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Spremi]].[[screenshot_plugin.copy]]=[[Kopiraj]].[[screenshot_plugin.print]]=[[Printaj]].[[screenshot_plugin.fullscreen]]=[[Odaberi cijeli ekran]].[[screenshot_plugin.clear]]=[[Ukloni selekciju]].[[screenshot_plugin.cancel]]=[[Otkazati]].[[screenshot_plugin.editonline]]=[[Uredi screenshot online]].[[screenshot_plugin.upload]]=[[Uploaduj na prntscr.com]].[[screenshot_plugin.close]]=[[Zatvori]]..[[screenshot_plugin.share_googlesearch]]=[[Prona.i sli.ne slike na Google-u]].[[screenshot_plugin.share_tineyesearch]]=[[Prona.i sli.ne slike na Tineye-u]].[[screenshot_plugin.share_sendmail]]=[[Po.alji pute mail-a]].[[screenshot_plugin.share_twitter]]=[[Podijeli na Twitter]].[[screenshot_plugin.share_facebook]]=[[Podijeli na Facebook]].[[screenshot_plugin.share_vk]]=[[Podijeli na VK]].[[screenshot_plugin.share_pinterest]]=[[Podijeli na Pinterest]].[[screenshot_plugin.share]]=[[Podijeli na Socijalne Mre.e]]..[[screenshot_plugin.incorrect_size]]=[[Pogre.na vel
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):3761
                          Entropy (8bit):4.75111012331288
                          Encrypted:false
                          SSDEEP:
                          MD5:B85E43201C3D051F8D4F5E7210E6E0BC
                          SHA1:C7FC7CCD6F8AC76F674D3B42CFAF2AF74EB1B515
                          SHA-256:5DEEBC0DC369C6E2F85E549C6AD38AF0F385CC0163373C857508AF3A8E96E8DF
                          SHA-512:15D2744DCED11591C4AF340F1C95595C41BDADEBC5C6BD1DED962A1DFBAA9159555F1DDD21714DD0C13E53600BD92F036D33861FF21760B1BC7E9202A4756D3C
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Desa]].[[screenshot_plugin.print]]=[[Imprimeix]].[[screenshot_plugin.fullscreen]]=[[Selecciona pantalla completa]].[[screenshot_plugin.clear]]=[[Neteja la selecci.]].[[screenshot_plugin.editonline]]=[[Editeu una captura de pantalla en l.nia]].[[screenshot_plugin.upload]]=[[Puja a prntscr.com]].[[screenshot_plugin.close]]=[[Tanca]]..[[screenshot_plugin.share_tineyesearch]]=[[Cerca imatges similars a Tineye]].[[screenshot_plugin.share_sendmail]]=[[Envia a trav.s de correu electr.nic]].[[screenshot_plugin.share_twitter]]=[[Comparteix al Twitter]].[[screenshot_plugin.share_facebook]]=[[Comparteix al Facebook]].[[screenshot_plugin.share_pinterest]]=[[Comparteix a Pinterest]].[[screenshot_plugin.share]]=[[Comparteix a les xarxes socials]]..[[screenshot_plugin.incorrect_size]]=[[Mida incorrecta]].[[screenshot_plugin.error_capt]]=[[Error]]..[[screenshot_plugin.open]]=[[Obre]]..[[screenshot_app.take_screenshot]]=[[Feu una captura de pantalla]].[[screenshot_ap
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1017)
                          Category:dropped
                          Size (bytes):11222
                          Entropy (8bit):5.219145596006698
                          Encrypted:false
                          SSDEEP:
                          MD5:B69442C812103E4D0679A07D0EEC0AF8
                          SHA1:9EA6A3F20A49EF7B10895622B71E8F346216A370
                          SHA-256:EDA81D8D1BF445FEAC5AF9A7B2F6FF10F39C57449FB5FE202D2662B596DD2AA6
                          SHA-512:BC15A2A46FA508E99951C66CA66911727441F5FD98478B6630B3BDB6A3DAF42E6F7B9030B2B5FBC161391F9D28F748A210E6C5E4992F18E5914258EE1F5865A0
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Ulo.it]].[[screenshot_plugin.copy]]=[[Kop.rovat]].[[screenshot_plugin.print]]=[[Vytisknout]].[[screenshot_plugin.fullscreen]]=[[Vybrat celou obrazovku]].[[screenshot_plugin.clear]]=[[Odstranit v.b.r]].[[screenshot_plugin.cancel]]=[[Zru.it]].[[screenshot_plugin.editonline]]=[[Editovat sn.mek online]].[[screenshot_plugin.upload]]=[[Nahr.t na prntscr.com]].[[screenshot_plugin.close]]=[[Zav..t]]..[[screenshot_plugin.share_googlesearch]]=[[Vyhledat podobn. obr.zky na Googlu]].[[screenshot_plugin.share_tineyesearch]]=[[Vyhledat podobn. obr.zky na Tineye]].[[screenshot_plugin.share_sendmail]]=[[Poslat p.es email]].[[screenshot_plugin.share_twitter]]=[[Sd.let na Twitteru]].[[screenshot_plugin.share_facebook]]=[[Sd.let na Facebooku]].[[screenshot_plugin.share_vk]]=[[Sd.let na VK]].[[screenshot_plugin.share_pinterest]]=[[Sd.let na Pinterestu]].[[screenshot_plugin.share]]=[[Sd.let na soci.ln.ch s.t.ch]]..[[screenshot_plugin.incorrect_size]]=[
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1050)
                          Category:dropped
                          Size (bytes):10777
                          Entropy (8bit):4.96781859221012
                          Encrypted:false
                          SSDEEP:
                          MD5:EC2BCE92371B3A0B2DC4C4FC5CEB52D0
                          SHA1:5330E9AFBF34E1392624D320FBF2D96115460118
                          SHA-256:998C50A30EFCA47F3EBEBEF43AAE172B66274B1BB4FE9D956D1AA3521DFE072D
                          SHA-512:8C10A9D9BD856A7B101E089847680D6B3B2C85168F53287865F3B5D153BB0CCD75ED11BEFF4C8E9B1F8276195B5E95C5A2446E6EC4C969EF561593B340674BA0
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Gem]].[[screenshot_plugin.copy]]=[[Kopier]].[[screenshot_plugin.print]]=[[Print]].[[screenshot_plugin.fullscreen]]=[[V.lg fuld sk.rm]].[[screenshot_plugin.clear]]=[[Nulstil det valgte]].[[screenshot_plugin.cancel]]=[[Annuller]].[[screenshot_plugin.editonline]]=[[Rediger et sk.rmbillede online]].[[screenshot_plugin.upload]]=[[Upload til prntscr.com]].[[screenshot_plugin.close]]=[[Luk]]..[[screenshot_plugin.share_googlesearch]]=[[S.g lignende billeder p. Google]].[[screenshot_plugin.share_tineyesearch]]=[[S.g lignende billeder p. Tineye]].[[screenshot_plugin.share_sendmail]]=[[Send via email]].[[screenshot_plugin.share_twitter]]=[[Del p. Twitter]].[[screenshot_plugin.share_facebook]]=[[Del p. Facebook]].[[screenshot_plugin.share_vk]]=[[Del p. VK]].[[screenshot_plugin.share_pinterest]]=[[Del p. Pinterest]].[[screenshot_plugin.share]]=[[Del p. dine sociale netv.rk]]..[[screenshot_plugin.incorrect_size]]=[[Forkert st.rrelse]].[[screenshot_plugin
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1109)
                          Category:dropped
                          Size (bytes):11376
                          Entropy (8bit):4.9286221743577405
                          Encrypted:false
                          SSDEEP:
                          MD5:D115749DC09721FA6C20257AFC71A64D
                          SHA1:CC741E1AB1BE8A6BC7C42AB265E86857F74894FB
                          SHA-256:5742F1EBCE39FBBAB90A6A3581E57B7B6C35D0CD9A2DD23BBA61712533F0C468
                          SHA-512:61CEB72D39504FA33780F74C077FDF7CD58128FB75AAFE48262FA4D15FC8E62D5EEA9DAE9C9B9F3A53040F5890DBCB263BB463F4C72712BB288EB5E919A4CA91
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Speichern]].[[screenshot_plugin.copy]]=[[Kopieren]].[[screenshot_plugin.print]]=[[Drucken]].[[screenshot_plugin.fullscreen]]=[[Kompletten Bildschirm ausw.hlen]].[[screenshot_plugin.clear]]=[[Auswahl aufheben]].[[screenshot_plugin.cancel]]=[[Abbrechen]].[[screenshot_plugin.editonline]]=[[Screenshot online bearbeiten]].[[screenshot_plugin.upload]]=[[Hochladen auf prntscr.com]].[[screenshot_plugin.close]]=[[Schlie.en]]..[[screenshot_plugin.share_googlesearch]]=[[Nach .hnlichen Bildern auf Google suchen]].[[screenshot_plugin.share_tineyesearch]]=[[Nach .hnlichen Bildern auf Tineye suchen]].[[screenshot_plugin.share_sendmail]]=[[Per Email verschicken]].[[screenshot_plugin.share_twitter]]=[[Auf Twitter teilen]].[[screenshot_plugin.share_facebook]]=[[Auf Facebook teilen]].[[screenshot_plugin.share_vk]]=[[Auf VK teilen]].[[screenshot_plugin.share_pinterest]]=[[Auf Pinterest teilen]].[[screenshot_plugin.share]]=[[Auf sozialen Netzwerken teilen]]..[[screenshot
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1126)
                          Category:dropped
                          Size (bytes):16679
                          Entropy (8bit):5.169336661683813
                          Encrypted:false
                          SSDEEP:
                          MD5:25CC5EB2A8E15D7903A31C83B0DB5096
                          SHA1:2ED5CFCBD5A2D96B308A75CEF705218E842A04F0
                          SHA-256:F4E2936E6CC32D0E41BF4A4FDA14623FB7665B5A8BCFC14D8595F0119359B05E
                          SHA-512:F5A0C91972F9C5650927A4DF82EA88D370206E55E0C57D54753781C012C714C19A87CDF1049BE017E68A7D4B07205E3065FE4AC27E04931E05BEE50397EC5A46
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..........]].[[screenshot_plugin.copy]]=[[.........]].[[screenshot_plugin.print]]=[[........]].[[screenshot_plugin.fullscreen]]=[[....... ....... ......]].[[screenshot_plugin.clear]]=[[........ ........]].[[screenshot_plugin.cancel]]=[[.....]].[[screenshot_plugin.editonline]]=[[........... .... ............ online]].[[screenshot_plugin.upload]]=[[........... ... prntscr.com]].[[screenshot_plugin.close]]=[[........]]..[[screenshot_plugin.share_googlesearch]]=[[......... ......... ....... ... Google]].[[screenshot_plugin.share_tineyesearch]]=[[......... ......... ....... ... Tineye]].[[screenshot_plugin.share_sendmail]]=[[........ .... email]].[[screenshot_plugin.share_twitter]]=[[........... .. ... Twitter]].[[screenshot_plugin.share_facebook]]=[[......
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1009)
                          Category:dropped
                          Size (bytes):10420
                          Entropy (8bit):4.837706672185901
                          Encrypted:false
                          SSDEEP:
                          MD5:4D195562C84403DD347BD2C45403EFC5
                          SHA1:4203BD1C9F0C0A2133BA7DC5FF1F9C86C942D131
                          SHA-256:4A57246BD4CE9D387EC10F0AB2084C3D91E8463D03C1412F3665AEE3885A85A5
                          SHA-512:3DE1BA358834C7D238E35F533A192C6E6E41FDF276A29B6714CF02636CAD123EFF571614A1185025757BEC3E9F9F351D612598496600684E4AC676E576E8C601
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Save]].[[screenshot_plugin.copy]]=[[Copy]].[[screenshot_plugin.print]]=[[Print]].[[screenshot_plugin.fullscreen]]=[[Select full screen]].[[screenshot_plugin.clear]]=[[Clear selection]].[[screenshot_plugin.cancel]]=[[Cancel]].[[screenshot_plugin.editonline]]=[[Edit a screenshot online]].[[screenshot_plugin.upload]]=[[Upload to prntscr.com]].[[screenshot_plugin.close]]=[[Close]]..[[screenshot_plugin.share_googlesearch]]=[[Search similar images on Google]].[[screenshot_plugin.share_tineyesearch]]=[[Search similar images on Tineye]].[[screenshot_plugin.share_sendmail]]=[[Send via email]].[[screenshot_plugin.share_twitter]]=[[Share on Twitter]].[[screenshot_plugin.share_facebook]]=[[Share on Facebook]].[[screenshot_plugin.share_vk]]=[[Share on VK]].[[screenshot_plugin.share_pinterest]]=[[Share on Pinterest]].[[screenshot_plugin.share]]=[[Share on social networks]]..[[screenshot_plugin.incorrect_size]]=[[Wrong size]].[[screenshot_plugin.error_capt]]=[[Error]].
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1059)
                          Category:dropped
                          Size (bytes):11416
                          Entropy (8bit):4.851928229994875
                          Encrypted:false
                          SSDEEP:
                          MD5:C7532FCF181919333E0A247E447CF56E
                          SHA1:CF1ADF1C620BA5AEF0F26066964E9D2447EA9211
                          SHA-256:037F23F925BA25D30D221D0FB36FE9925DBEA3079A4AAFEDC13ECC9A8D306F40
                          SHA-512:A95FF21659E6F68A49B011AB47BF4C24990F1318CD0CD9661AC6A55C7B0A178EAD9D533C81D5B916C12C4A5ED7AF9013DA739FA33F463807634A6D43497A3F49
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Guardar]].[[screenshot_plugin.copy]]=[[Copiar]].[[screenshot_plugin.print]]=[[Imprimir]].[[screenshot_plugin.fullscreen]]=[[Seleccionar pantalla completa]].[[screenshot_plugin.clear]]=[[Borrar selecci.n]].[[screenshot_plugin.cancel]]=[[Cancelar]].[[screenshot_plugin.editonline]]=[[Editar una captura de pantalla en l.nea]].[[screenshot_plugin.upload]]=[[Subir a prntscr.com]].[[screenshot_plugin.close]]=[[Cerrar]]..[[screenshot_plugin.share_googlesearch]]=[[Buscar im.genes similares en Google]].[[screenshot_plugin.share_tineyesearch]]=[[Buscar im.genes similares en Tineye]].[[screenshot_plugin.share_sendmail]]=[[Send via email]].[[screenshot_plugin.share_twitter]]=[[Compartir en Twitter]].[[screenshot_plugin.share_facebook]]=[[Compartir en Facebook]].[[screenshot_plugin.share_vk]]=[[Compartir en VK]].[[screenshot_plugin.share_pinterest]]=[[Compartir en Pinterest]].[[screenshot_plugin.share]]=[[Compartir en redes sociales]]..[[screenshot_plugin.incorrec
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (972)
                          Category:dropped
                          Size (bytes):10478
                          Entropy (8bit):4.9285769816878435
                          Encrypted:false
                          SSDEEP:
                          MD5:2B75C4A44B3D45B7F412638B34FC3D0E
                          SHA1:966765B328774BF3093EC293579C3D40DB215F27
                          SHA-256:269653CAA6B7C42F8E927CE48B273313302C8BF68E8DC67381F066F2F96C8D61
                          SHA-512:43CB33704A08158B6CBDBEFA71DD901F4383ACB2601C14DD4C75EA9A4F709D06F342B3B00D2AF7A9E9BBF785644FC93B8F0250E1BF643BAB823D6951BA83A92E
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Salvesta]].[[screenshot_plugin.copy]]=[[Kopeeri]].[[screenshot_plugin.print]]=[[Prindi]].[[screenshot_plugin.fullscreen]]=[[Vali t.isekraan]].[[screenshot_plugin.clear]]=[[Puhasta valitud]].[[screenshot_plugin.cancel]]=[[Loobu]].[[screenshot_plugin.editonline]]=[[Redigeeri kuvat.mmist v.rgus]].[[screenshot_plugin.upload]]=[[Lae .lesse prntscr.com lehele]].[[screenshot_plugin.close]]=[[Sule]]..[[screenshot_plugin.share_googlesearch]]=[[Otsi sarnaseid pilte Google-st]].[[screenshot_plugin.share_tineyesearch]]=[[Otsi sarnaseid pilte Tineye-st]].[[screenshot_plugin.share_sendmail]]=[[Saada E-mailga]].[[screenshot_plugin.share_twitter]]=[[Jaga Twitteris]].[[screenshot_plugin.share_facebook]]=[[Jaga Facebookis]].[[screenshot_plugin.share_vk]]=[[Jaga VKs]].[[screenshot_plugin.share_pinterest]]=[[Jaga Pinterest-is]].[[screenshot_plugin.share]]=[[Jaga sotsiaalv.rgustikes]]..[[screenshot_plugin.incorrect_size]]=[[Vale suurus]].[[screenshot_plugin.error_capt]]
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):10491
                          Entropy (8bit):5.221991886945581
                          Encrypted:false
                          SSDEEP:
                          MD5:A91D80CB2770EA0BD50DB9690FC5D6DF
                          SHA1:762226BD50FB39C7AFA9AC6B55688D48376D1E25
                          SHA-256:D8EDEC9A317E7722D304486657AE047B1627CD3FE80F2EEBC6BDA88D8323673E
                          SHA-512:3950B544A83FBB12003D622B60D96ABE104CE5B2A60E33C3C7474F256AD35902C26B79C10346F69C5F0E01209F2DB01C3B9CB842768243B9C00D83591B41D076
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.....]].[[screenshot_plugin.copy]]=[[...]].[[screenshot_plugin.print]]=[[.....]].[[screenshot_plugin.fullscreen]]=[[..... .... ....]].[[screenshot_plugin.clear]]=[[... .... ......]].[[screenshot_plugin.cancel]]=[[... ....]].[[screenshot_plugin.editonline]]=[[...... ...... ....... ...]].[[screenshot_plugin.upload]]=[[........ .. prntscr.com]].[[screenshot_plugin.close]]=[[....]]..[[screenshot_plugin.share_googlesearch]]=[[...... ...... ..... .. ....]].[[screenshot_plugin.share_tineyesearch]]=[[...... ...... ..... .. Tineye]].[[screenshot_plugin.share_sendmail]]=[[..... .. .....]].[[screenshot_plugin.share_twitter]]=[[...... ..... .. ......]].[[screenshot_plugin.share_facebook]]=[[...... ..... .. ......]].[[screenshot_plugin.share_vk]]=[[...... ..... .. VK]].[[screenshot_p
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1037)
                          Category:dropped
                          Size (bytes):11019
                          Entropy (8bit):4.926299005060986
                          Encrypted:false
                          SSDEEP:
                          MD5:1FECEA4E623EC7B0DFF4457589D2A901
                          SHA1:00DCA986CBF21798F42E57B76E9C234E010441D9
                          SHA-256:537C962EEC10C69CCA2CA6A11A5BA0FBFDCC15FE6896FA623D4DFB00CBDCE5E5
                          SHA-512:0726992375548CC358FCA8DAEB21A8E1F2FBB180AC7F2AEFEA90C32EF67910F5B1436FD9231D6F710FA43803E1CFC6DCF9101605225B26070ED07FC77A37995D
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Tallenna]].[[screenshot_plugin.copy]]=[[Kopioi]].[[screenshot_plugin.print]]=[[Tulosta]].[[screenshot_plugin.fullscreen]]=[[Valitse koko n.ytt.]].[[screenshot_plugin.clear]]=[[Tyhjenn. valinta]].[[screenshot_plugin.cancel]]=[[Peruuta]].[[screenshot_plugin.editonline]]=[[Muokkaa kuvankaappausta verkossa]].[[screenshot_plugin.upload]]=[[Lataa sivustolle prntscr.com]].[[screenshot_plugin.close]]=[[Sulje]]..[[screenshot_plugin.share_googlesearch]]=[[Etsi samanlaisia kuvia Googlesta]].[[screenshot_plugin.share_tineyesearch]]=[[Etsi samankaltaisia kuvia sivustolta Tineye]].[[screenshot_plugin.share_sendmail]]=[[L.het. s.hk.postilla]].[[screenshot_plugin.share_twitter]]=[[Jaa Twitteriss.]].[[screenshot_plugin.share_facebook]]=[[Jaa Facebookissa]].[[screenshot_plugin.share_vk]]=[[Jaa VK:ssa]].[[screenshot_plugin.share_pinterest]]=[[Jaa Pinterestiss.]].[[screenshot_plugin.share]]=[[Jaa sosiaalisessa mediassa]]..[[screenshot_plugin.incorrect_size]]=[[V..
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1243)
                          Category:dropped
                          Size (bytes):11981
                          Entropy (8bit):4.93189390113932
                          Encrypted:false
                          SSDEEP:
                          MD5:61C9C831A6C90D4C7E34DE114CF01AD2
                          SHA1:FE1456F52D3731F844F890ABCD42F03011AB27CC
                          SHA-256:86FAFD94CF0E4D7AC3C7C510E60364690286F43E8A6E051A72DC5CD845FBA47F
                          SHA-512:007DADBDBB22375EA2287DEDFFF5B66D51BAAE570113089821BA9A78CEC740BB1813336BB3B2D6611E4B0F7BE5CEA4ACDFF6F463205FBA241148B06CBD0A3BDD
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Sauvegarder]].[[screenshot_plugin.copy]]=[[Copier]].[[screenshot_plugin.print]]=[[Imprimer]].[[screenshot_plugin.fullscreen]]=[[S.lectionner tout l..cran]].[[screenshot_plugin.clear]]=[[Effacer la s.lection]].[[screenshot_plugin.cancel]]=[[Annuler]].[[screenshot_plugin.editonline]]=[[Modifier la capture d..cran en ligne]].[[screenshot_plugin.upload]]=[[Publier sur prntscr.com]].[[screenshot_plugin.close]]=[[Fermer]]..[[screenshot_plugin.share_googlesearch]]=[[Rechercher des images similaires sur Google]].[[screenshot_plugin.share_tineyesearch]]=[[Rechercher des images similaires sur Tineye]].[[screenshot_plugin.share_sendmail]]=[[Envoyer par courriel]].[[screenshot_plugin.share_twitter]]=[[Partager sur Twitter]].[[screenshot_plugin.share_facebook]]=[[Partager sur Facebook]].[[screenshot_plugin.share_vk]]=[[Partager sur VK]].[[screenshot_plugin.share_pinterest]]=[[Partager sur Pinterest]].[[screenshot_plugin.share]]=[[Partager sur les r.seaux soc
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):2571
                          Entropy (8bit):4.694878240736071
                          Encrypted:false
                          SSDEEP:
                          MD5:6AF8D75A375BF14CE817227FA848B8C4
                          SHA1:54A880E4AB5F10E895D016012B4AD73BB4B7E24E
                          SHA-256:6D6897C134235CEB66BE8B9DE9E0C93C1906681B7BD7153169F423CAF66501CE
                          SHA-512:EE2A1DF21F530114D0B65A68EC6738B5776BDA3D04447CE3B021F1C374E27B6F389B368C4C9202BCB8E5492B421FE63E4257F20B36670685C8E5B5ED3C5B863C
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Gardar]].[[screenshot_plugin.copy]]=[[Copiar]].[[screenshot_plugin.print]]=[[Imprimir]].[[screenshot_plugin.fullscreen]]=[[Seleccionar pantalla completa]].[[screenshot_plugin.cancel]]=[[Cancelar]].[[screenshot_plugin.close]]=[[Pechar]]..[[screenshot_plugin.share_googlesearch]]=[[Procurar imaxes semellantes no Google]].[[screenshot_plugin.share_sendmail]]=[[Enviar v.a correo electr.nico]].[[screenshot_plugin.share_twitter]]=[[Compartir no Twitter]].[[screenshot_plugin.share_facebook]]=[[Compartir no Facebook]].[[screenshot_plugin.share_pinterest]]=[[Compartir no Pinterest]].[[screenshot_plugin.share]]=[[Compartir nas redes sociais]]..[[screenshot_plugin.error_capt]]=[[Erro]]..[[screenshot_plugin.tooltip]]=[[Seleccionar .rea]].[[screenshot_plugin.open]]=[[Abrir]].[[screenshot_plugin.upload_failed_retry]]=[[Erro ao cargar. Volver tentar?]]..[[screenshot_app.take_screenshot]]=[[Facer unha captura de pantalla]].[[screenshot_app.about]]=[[Acerca de]].[[scre
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1009)
                          Category:dropped
                          Size (bytes):12149
                          Entropy (8bit):5.088872199833535
                          Encrypted:false
                          SSDEEP:
                          MD5:3CA46C43929B540F39DAFF85DD06BFEB
                          SHA1:8ABED3FCB1C273C4173DEC8FB6CC2768F777ECA3
                          SHA-256:ECDA5230381AD49094439BF6E98637FFBFBA9408C5930F76708E2592A5D2DEF7
                          SHA-512:AE1295708A8DD79C1ABF1AA3A6D3F0C8E08ABF5C61A901A966A02200C5FC442D5DB88FFFBD4AD72240524115F2028902377C99DCC68154B1109141B52AD40127
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[....]].[[screenshot_plugin.copy]]=[[....]].[[screenshot_plugin.print]]=[[....]].[[screenshot_plugin.fullscreen]]=[[... ... ...]].[[screenshot_plugin.clear]]=[[... .....]].[[screenshot_plugin.cancel]]=[[...]].[[screenshot_plugin.editonline]]=[[.... ..... ... .......]].[[screenshot_plugin.upload]]=[[.... ....... . prntscr.com]].[[screenshot_plugin.close]]=[[....]]..[[screenshot_plugin.share_googlesearch]]=[[... ...... ..... .....]].[[screenshot_plugin.share_tineyesearch]]=[[... ...... ..... .......]].[[screenshot_plugin.share_sendmail]]=[[... ... .... ........]].[[screenshot_plugin.share_twitter]]=[[... .......]].[[screenshot_plugin.share_facebook]]=[[... ........]].[[screenshot_plugin.share_vk]]=[[... .: VK]].[[screenshot_plugin.share_pinterest]]=[[... .: Pinterest]].[[screenshot_plugin.share]]=[[...
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1021)
                          Category:dropped
                          Size (bytes):10863
                          Entropy (8bit):5.0046250426445
                          Encrypted:false
                          SSDEEP:
                          MD5:8B7C86791CB7A6CC264BB6D6F086CCEA
                          SHA1:45D14F8943F7DBFB338ADAC2E76D7D719D8512EC
                          SHA-256:28CBFD25496EBB77EDECA119F0F8FF78D4952F5A8D71E10AD345382D7DF27C74
                          SHA-512:539973FAD93D460263397E12DB229EB37DF16DBFB5F7561421961B74EBBC420E254A3609A25C650EEBA956A22069BE6FE598BF7883AEE9D34D0C8A6B1CD7C535
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Spremi]].[[screenshot_plugin.copy]]=[[Kopiraj]].[[screenshot_plugin.print]]=[[Ispis]].[[screenshot_plugin.fullscreen]]=[[Odaberi puni zaslon]].[[screenshot_plugin.clear]]=[[Izbri.i odabrano]].[[screenshot_plugin.cancel]]=[[Poni.ti]].[[screenshot_plugin.editonline]]=[[Uredi snimku zaslona na mre.i]].[[screenshot_plugin.upload]]=[[Prenesi na prntscr.com]].[[screenshot_plugin.close]]=[[Zatvori]]..[[screenshot_plugin.share_googlesearch]]=[[Tra.i sli.ne slike na Google]].[[screenshot_plugin.share_tineyesearch]]=[[Tra.i sli.ne slike na Tineye]].[[screenshot_plugin.share_sendmail]]=[[Po.alji e-po.tom]].[[screenshot_plugin.share_twitter]]=[[Podijeli na Twitter]].[[screenshot_plugin.share_facebook]]=[[Podijeli na Facebook]].[[screenshot_plugin.share_vk]]=[[Podijeli na VK]].[[screenshot_plugin.share_pinterest]]=[[Dijeli na Pinterest]].[[screenshot_plugin.share]]=[[Podijeli na dru.tvenim mre.ama]]..[[screenshot_plugin.incorrect_size]]=[[Pogre.na veli.i
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1014)
                          Category:dropped
                          Size (bytes):11574
                          Entropy (8bit):5.153798849120497
                          Encrypted:false
                          SSDEEP:
                          MD5:5765DD5FCA07300F79AD162F5BDEE1BF
                          SHA1:187C25B4D4307F43B7FF741A513D101D9D1010E2
                          SHA-256:37FB2455B89697F3F3442E355B8C3FC372D1C61FAF43C1567EC7894C6DEF0D5C
                          SHA-512:EC3B7741735A34921DD84A1FE454C5FB444E337F28D3CF36A6D8B7BEEFED39911E8856A9663798F27A10F23901AEF51AA83CA7DB78ED1F745C93A9EE10383E52
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Ment.s]].[[screenshot_plugin.copy]]=[[M.sol.s]].[[screenshot_plugin.print]]=[[Nyomtat.s]].[[screenshot_plugin.fullscreen]]=[[Teljes k.perny.]].[[screenshot_plugin.clear]]=[[Kijel.l.s t.rl.se]].[[screenshot_plugin.cancel]]=[[M.gsem]].[[screenshot_plugin.editonline]]=[[K.perny.ment.s szerkeszt.se online]].[[screenshot_plugin.upload]]=[[Felt.lt.s a prntscr.com-ra]].[[screenshot_plugin.close]]=[[Bez.r.s]]..[[screenshot_plugin.share_googlesearch]]=[[Hasonl. k.pek keres.se itt: Google]].[[screenshot_plugin.share_tineyesearch]]=[[Hasonl. k.pek keres.se itt: Tineye]].[[screenshot_plugin.share_sendmail]]=[[Elk.ld.se email .ltal]].[[screenshot_plugin.share_twitter]]=[[Megoszt.s a Twitteren]].[[screenshot_plugin.share_facebook]]=[[Megoszt.s a Facebookon]].[[screenshot_plugin.share_vk]]=[[Megoszt.s a VK-n]].[[screenshot_plugin.share_pinterest]]=[[Megoszt.s a Pinteresten]].[[screenshot_plugin.share]]=[[Megoszt.s a k.z.ss.gi port.l
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (887)
                          Category:dropped
                          Size (bytes):13487
                          Entropy (8bit):5.262276183422655
                          Encrypted:false
                          SSDEEP:
                          MD5:2AAE7AF8598C3BC89B17CB8F36A0BD59
                          SHA1:F211568F746150D413D15AA72688345D0142F925
                          SHA-256:C3BE9BA8219F9BECD5AE9279BA5620270131880D276F3799CC2D1C0C3B224CA3
                          SHA-512:823E749BF3172E94766F8CC337E4D3D86CE195F1F9E06F6255E731F8197815263F38BDA65D0171A5DB2C3BABDF1E67A5707B347370A9AB48024CF62089F9FAA5
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[........]].[[screenshot_plugin.copy]]=[[........]].[[screenshot_plugin.print]]=[[....]].[[screenshot_plugin.fullscreen]]=[[.... ...... ......]].[[screenshot_plugin.clear]]=[[......]].[[screenshot_plugin.cancel]]=[[........]].[[screenshot_plugin.editonline]]=[[........ ......]].[[screenshot_plugin.upload]]=[[......... prntscr.com]].[[screenshot_plugin.close]]=[[.....]]..[[screenshot_plugin.share_googlesearch]]=[[...... .... ......... Google-...]].[[screenshot_plugin.share_tineyesearch]]=[[...... .... ......... Tineye-...]].[[screenshot_plugin.share_sendmail]]=[[........ ...... .........]].[[screenshot_plugin.share_twitter]]=[[....... Twitter-...]].[[screenshot_plugin.share_facebook]]=[[....... Facebook-...]].[[screenshot_plugin.share_vk]]=[[....... VK-...]].[[screenshot_plugin.share_p
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1077)
                          Category:dropped
                          Size (bytes):10796
                          Entropy (8bit):4.8500073537614945
                          Encrypted:false
                          SSDEEP:
                          MD5:0FCA4BD83616AFBB1979A4E191F0D8B4
                          SHA1:B7F14F5B8F9243842F75173E7B6B26A7B7423A5E
                          SHA-256:82DEC9FF06F22776DCA34A8846B3D78CD543FA90B3A6A7250B4E44428ADEDC64
                          SHA-512:5343F3CB21711B0E73AECA482FDB515596E35CBC4F7F53DBA6792ED829FB0876FD5BA485495B526493EC964C6081DF9FCE7111FBE4C3805DF185451C0466667E
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Simpan]].[[screenshot_plugin.copy]]=[[Salin]].[[screenshot_plugin.print]]=[[Cetak]].[[screenshot_plugin.fullscreen]]=[[Pilih Layar Penuh]].[[screenshot_plugin.clear]]=[[Bersihkan Area]].[[screenshot_plugin.cancel]]=[[Batalkan]].[[screenshot_plugin.editonline]]=[[Menyunting screenshot secara online]].[[screenshot_plugin.upload]]=[[Unggah ke prntscr.com]].[[screenshot_plugin.close]]=[[Tutup]]..[[screenshot_plugin.share_googlesearch]]=[[Cari gambar yang mirip di Google]].[[screenshot_plugin.share_tineyesearch]]=[[Cari Gambar Serupa di Tineye]].[[screenshot_plugin.share_sendmail]]=[[Kirim lewat email]].[[screenshot_plugin.share_twitter]]=[[Bagikan di Twitter]].[[screenshot_plugin.share_facebook]]=[[Bagikan di Facebook]].[[screenshot_plugin.share_vk]]=[[Bagikan di VK]].[[screenshot_plugin.share_pinterest]]=[[Bagikan ke Pinterest]].[[screenshot_plugin.share]]=[[Bagikan di jejaring sosial]]..[[screenshot_plugin.incorrect_size]]=[[Ukuran Salah]].[[screenshot_pl
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (628)
                          Category:dropped
                          Size (bytes):9937
                          Entropy (8bit):6.105361124203797
                          Encrypted:false
                          SSDEEP:
                          MD5:FACF10F05E9598E2F8254CEAE56E3E0C
                          SHA1:0D7198F03B9837D98F63F937DD8A16421861DB8A
                          SHA-256:8BBEA3318E2843DBFAB7A2BE7E0BC378E5A196720514A45F2EB535FA8FF5CE46
                          SHA-512:6DC937ED6209A68CF0039674B0A20975A7CB87035BCCA5301238F99EEF3CE20F965F0B5F78F2BD7538E5BDA6D0C7FBDB2F2B38C23B6E64DAE32D075A3DC49682
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..]].[[screenshot_plugin.copy]]=[[..]].[[screenshot_plugin.print]]=[[..]].[[screenshot_plugin.fullscreen]]=[[.....]].[[screenshot_plugin.clear]]=[[..]].[[screenshot_plugin.cancel]]=[[..]].[[screenshot_plugin.editonline]]=[[......]].[[screenshot_plugin.upload]]=[[... prntscr.com]].[[screenshot_plugin.close]]=[[..]]..[[screenshot_plugin.share_googlesearch]]=[[. Google ......]].[[screenshot_plugin.share_tineyesearch]]=[[. Tineye ......]].[[screenshot_plugin.share_sendmail]]=[[.. email ..]].[[screenshot_plugin.share_twitter]]=[[.. Twitter ..]].[[screenshot_plugin.share_facebook]]=[[.. Facebook ..]].[[screenshot_plugin.share_vk]]=[[.. VK ..]].[[screenshot_plugin.share_pinterest]]=[[. Pinterest ..]].[[screenshot_plugin.share]]=[[..]]..[[screenshot_plugin.incorrect_size]]=[[....]].[[screenshot_plugin.error_capt]]=[[..]]..[[screen
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):5927
                          Entropy (8bit):5.877550510084327
                          Encrypted:false
                          SSDEEP:
                          MD5:E57F6619FF7B09B3D7038553A3D24E0F
                          SHA1:79B1EAA08F83B9C9145791CE61CA2AFED470F2E0
                          SHA-256:05D69F78C57FE818645EAB63DD3CB51C0C51EBAF30B5C0556701D0B72547F4F0
                          SHA-512:14F1E21331A95C1663F43BB7FC80CE2AE4F13FC1D0A15F1DA5AF1B1831DD96A753AF56EB3FFD61D0EC73CABBB85ED72DB103587A3CC45A99ED0458D30CC7DC07
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..]].[[screenshot_plugin.copy]]=[[..]].[[screenshot_plugin.print]]=[[..]].[[screenshot_plugin.fullscreen]]=[[.....]].[[screenshot_plugin.clear]]=[[..]].[[screenshot_plugin.cancel]]=[[..]].[[screenshot_plugin.editonline]]=[[......]].[[screenshot_plugin.upload]]=[[... prntscr.com]].[[screenshot_plugin.close]]=[[..]]..[[screenshot_plugin.share_googlesearch]]=[[.Google......]].[[screenshot_plugin.share_tineyesearch]]=[[.Tineye......]].[[screenshot_plugin.share_sendmail]]=[[........]].[[screenshot_plugin.share_twitter]]=[[..Twitter..]].[[screenshot_plugin.share_facebook]]=[[..Facebook..]].[[screenshot_plugin.share]]=[[........]]..[[screenshot_plugin.incorrect_size]]=[[.....]].[[screenshot_plugin.error_capt]]=[[..]]..[[screenshot_plugin.tooltip]]=[[....]].[[screenshot_plugin.open]]=[[..]].[[screenshot_plugin.
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1050)
                          Category:dropped
                          Size (bytes):10777
                          Entropy (8bit):4.96781859221012
                          Encrypted:false
                          SSDEEP:
                          MD5:EC2BCE92371B3A0B2DC4C4FC5CEB52D0
                          SHA1:5330E9AFBF34E1392624D320FBF2D96115460118
                          SHA-256:998C50A30EFCA47F3EBEBEF43AAE172B66274B1BB4FE9D956D1AA3521DFE072D
                          SHA-512:8C10A9D9BD856A7B101E089847680D6B3B2C85168F53287865F3B5D153BB0CCD75ED11BEFF4C8E9B1F8276195B5E95C5A2446E6EC4C969EF561593B340674BA0
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Gem]].[[screenshot_plugin.copy]]=[[Kopier]].[[screenshot_plugin.print]]=[[Print]].[[screenshot_plugin.fullscreen]]=[[V.lg fuld sk.rm]].[[screenshot_plugin.clear]]=[[Nulstil det valgte]].[[screenshot_plugin.cancel]]=[[Annuller]].[[screenshot_plugin.editonline]]=[[Rediger et sk.rmbillede online]].[[screenshot_plugin.upload]]=[[Upload til prntscr.com]].[[screenshot_plugin.close]]=[[Luk]]..[[screenshot_plugin.share_googlesearch]]=[[S.g lignende billeder p. Google]].[[screenshot_plugin.share_tineyesearch]]=[[S.g lignende billeder p. Tineye]].[[screenshot_plugin.share_sendmail]]=[[Send via email]].[[screenshot_plugin.share_twitter]]=[[Del p. Twitter]].[[screenshot_plugin.share_facebook]]=[[Del p. Facebook]].[[screenshot_plugin.share_vk]]=[[Del p. VK]].[[screenshot_plugin.share_pinterest]]=[[Del p. Pinterest]].[[screenshot_plugin.share]]=[[Del p. dine sociale netv.rk]]..[[screenshot_plugin.incorrect_size]]=[[Forkert st.rrelse]].[[screenshot_plugin
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):6048
                          Entropy (8bit):5.114480664907674
                          Encrypted:false
                          SSDEEP:
                          MD5:70BA5C9C3E83584713663332BCF0ED60
                          SHA1:2093C3D4A269D6D80714E2DEB0F86B727B43B82E
                          SHA-256:4B04AC2BF41F9A71FD626297956759B0F3321851BFCDBB4D788EAFD3BC662EE8
                          SHA-512:F379313B91FD4EB976736C4D65624215FEFD381323F2F469E6AE7BDE2BE79B5DE6F5B34B28B90DCA1D3BE7BD5496DBC85DF5A0E22E88A1F4C38E2F30824AB132
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.......]].[[screenshot_plugin.fullscreen]]=[[...... ....... .....]].[[screenshot_plugin.editonline]]=[[..... ........ ......]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_googlesearch]]=[[.......... ...... ..... .. ......]].[[screenshot_plugin.share_twitter]]=[[....... .. Twitter]].[[screenshot_plugin.share_facebook]]=[[....... .. Facebook]].[[screenshot_plugin.share_pinterest]]=[[....... .. Pinterest]].[[screenshot_plugin.share]]=[[......... .. ........... .....]]..[[screenshot_plugin.error_capt]]=[[......]]..[[screenshot_plugin.tooltip]]=[[.......... ........]].[[screenshot_plugin.open]]=[[......]].[[screenshot_plugin.upload_failed_retry]]=[[............. .. .... ........ ....... .. ........?]]..[[screenshot_app.take_screensho
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):7426
                          Entropy (8bit):4.869278439819597
                          Encrypted:false
                          SSDEEP:
                          MD5:8990E3DC38D9E65460480F257204E37D
                          SHA1:566FB8314D0385A66071D8BCC4DE5307699E88C4
                          SHA-256:46330DDC3BCA222A6BEEC79291C5CC09FF59FE7AF2613059D935ED88C92861FC
                          SHA-512:005EF52768441CAD3AC3C7FFAA0227E16C3FD602109EA9A4D1C74284625D9DD86C4BF88179E3E1FE73D3830BD59D58D8378C13D99D49D17E4196EBAA4ABB8129
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Shrani]].[[screenshot_plugin.copy]]=[[Kopiraj]].[[screenshot_plugin.print]]=[[Tiskaj]].[[screenshot_plugin.fullscreen]]=[[Izberi celoten zaslon]].[[screenshot_plugin.clear]]=[[Po.isti selekcijo]].[[screenshot_plugin.cancel]]=[[Prekli.i]].[[screenshot_plugin.editonline]]=[[Uredite posnetek zaslona na spletu]].[[screenshot_plugin.upload]]=[[Nalo.i na prntscr.com]].[[screenshot_plugin.close]]=[[Zapri]]..[[screenshot_plugin.share_googlesearch]]=[[I..i podobne slike na Google-u]].[[screenshot_plugin.share_tineyesearch]]=[[I..i podobne slike na Tineye]].[[screenshot_plugin.share_sendmail]]=[[Po.lji preko elektronske po.te]].[[screenshot_plugin.share_twitter]]=[[Deli na Twitter-ju]].[[screenshot_plugin.share_facebook]]=[[Deli na Facebook-u]].[[screenshot_plugin.share_vk]]=[[Deli na VK]].[[screenshot_plugin.share_pinterest]]=[[Deli na Pinterest]].[[screenshot_plugin.share]]=[[Deli na dru.benih omre.jih]]..[[screenshot_plugin.incorrect_size]]=[[Napa.n
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1017)
                          Category:dropped
                          Size (bytes):11222
                          Entropy (8bit):5.219145596006698
                          Encrypted:false
                          SSDEEP:
                          MD5:B69442C812103E4D0679A07D0EEC0AF8
                          SHA1:9EA6A3F20A49EF7B10895622B71E8F346216A370
                          SHA-256:EDA81D8D1BF445FEAC5AF9A7B2F6FF10F39C57449FB5FE202D2662B596DD2AA6
                          SHA-512:BC15A2A46FA508E99951C66CA66911727441F5FD98478B6630B3BDB6A3DAF42E6F7B9030B2B5FBC161391F9D28F748A210E6C5E4992F18E5914258EE1F5865A0
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Ulo.it]].[[screenshot_plugin.copy]]=[[Kop.rovat]].[[screenshot_plugin.print]]=[[Vytisknout]].[[screenshot_plugin.fullscreen]]=[[Vybrat celou obrazovku]].[[screenshot_plugin.clear]]=[[Odstranit v.b.r]].[[screenshot_plugin.cancel]]=[[Zru.it]].[[screenshot_plugin.editonline]]=[[Editovat sn.mek online]].[[screenshot_plugin.upload]]=[[Nahr.t na prntscr.com]].[[screenshot_plugin.close]]=[[Zav..t]]..[[screenshot_plugin.share_googlesearch]]=[[Vyhledat podobn. obr.zky na Googlu]].[[screenshot_plugin.share_tineyesearch]]=[[Vyhledat podobn. obr.zky na Tineye]].[[screenshot_plugin.share_sendmail]]=[[Poslat p.es email]].[[screenshot_plugin.share_twitter]]=[[Sd.let na Twitteru]].[[screenshot_plugin.share_facebook]]=[[Sd.let na Facebooku]].[[screenshot_plugin.share_vk]]=[[Sd.let na VK]].[[screenshot_plugin.share_pinterest]]=[[Sd.let na Pinterestu]].[[screenshot_plugin.share]]=[[Sd.let na soci.ln.ch s.t.ch]]..[[screenshot_plugin.incorrect_size]]=[
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1093)
                          Category:dropped
                          Size (bytes):11311
                          Entropy (8bit):4.823856219956849
                          Encrypted:false
                          SSDEEP:
                          MD5:A3C763A6AB5795AA432071DFF7262D22
                          SHA1:2297CE94424FE24144246CB4EEBEAFEC7C6972BA
                          SHA-256:E48BBA86D86DD2A2C0D8B789168BF7FA33CCCA80EB90BA2CA1CD1AFEEC70FB36
                          SHA-512:26DD8BBAAD6CAECE6AB0A406DF2B608012DD0CD40F24F47D78054C3CD85F75960158D68CE2E1C9AA52C2D0524DDE35A5D2B3AAD24B3ABCBBEC4A20EC8FCECC21
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Salva]].[[screenshot_plugin.copy]]=[[Copia]].[[screenshot_plugin.print]]=[[Stampa]].[[screenshot_plugin.fullscreen]]=[[Seleziona schermo intero]].[[screenshot_plugin.clear]]=[[Annulla selezione]].[[screenshot_plugin.cancel]]=[[Annulla]].[[screenshot_plugin.editonline]]=[[Modifica online uno screenshot]].[[screenshot_plugin.upload]]=[[Carica su prntscr.com]].[[screenshot_plugin.close]]=[[Chiuso]]..[[screenshot_plugin.share_googlesearch]]=[[Cerca immagini simili su Google]].[[screenshot_plugin.share_tineyesearch]]=[[Cerca immagini simili su Tineye]].[[screenshot_plugin.share_sendmail]]=[[Invia via email]].[[screenshot_plugin.share_twitter]]=[[Condividi su Twitter]].[[screenshot_plugin.share_facebook]]=[[Condividi su Facebook]].[[screenshot_plugin.share_vk]]=[[Condividi su VK]].[[screenshot_plugin.share_pinterest]]=[[Condividi su Pinterest]].[[screenshot_plugin.share]]=[[Condividi sui social network]]..[[screenshot_plugin.incorrect_size]]=[[Dimensione sbagl
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1009)
                          Category:dropped
                          Size (bytes):10420
                          Entropy (8bit):4.837706672185901
                          Encrypted:false
                          SSDEEP:
                          MD5:4D195562C84403DD347BD2C45403EFC5
                          SHA1:4203BD1C9F0C0A2133BA7DC5FF1F9C86C942D131
                          SHA-256:4A57246BD4CE9D387EC10F0AB2084C3D91E8463D03C1412F3665AEE3885A85A5
                          SHA-512:3DE1BA358834C7D238E35F533A192C6E6E41FDF276A29B6714CF02636CAD123EFF571614A1185025757BEC3E9F9F351D612598496600684E4AC676E576E8C601
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Save]].[[screenshot_plugin.copy]]=[[Copy]].[[screenshot_plugin.print]]=[[Print]].[[screenshot_plugin.fullscreen]]=[[Select full screen]].[[screenshot_plugin.clear]]=[[Clear selection]].[[screenshot_plugin.cancel]]=[[Cancel]].[[screenshot_plugin.editonline]]=[[Edit a screenshot online]].[[screenshot_plugin.upload]]=[[Upload to prntscr.com]].[[screenshot_plugin.close]]=[[Close]]..[[screenshot_plugin.share_googlesearch]]=[[Search similar images on Google]].[[screenshot_plugin.share_tineyesearch]]=[[Search similar images on Tineye]].[[screenshot_plugin.share_sendmail]]=[[Send via email]].[[screenshot_plugin.share_twitter]]=[[Share on Twitter]].[[screenshot_plugin.share_facebook]]=[[Share on Facebook]].[[screenshot_plugin.share_vk]]=[[Share on VK]].[[screenshot_plugin.share_pinterest]]=[[Share on Pinterest]].[[screenshot_plugin.share]]=[[Share on social networks]]..[[screenshot_plugin.incorrect_size]]=[[Wrong size]].[[screenshot_plugin.error_capt]]=[[Error]].
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1086)
                          Category:dropped
                          Size (bytes):11509
                          Entropy (8bit):5.18057505039434
                          Encrypted:false
                          SSDEEP:
                          MD5:1CCB1D13BEF7FE4BCBDE7E8ADF3C7F51
                          SHA1:F1CBF6569C36AAF6226C18AFF56EA19720F2D513
                          SHA-256:E272C3467A7CAFF058318DD4774D627F9A66B6AFFAB1681388DEB828352A7B7B
                          SHA-512:909936FB6FE2E20A95A016CED8B0A6576A6DE1BCA208E8AE8E000B41322FC9D4713687E0128A4A1008BC838D13E7DE71E8EB2D1CD3B59475060FDA6043946FE9
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Ulo.i.]].[[screenshot_plugin.copy]]=[[Kop.rova.]].[[screenshot_plugin.print]]=[[Vytla.i.]].[[screenshot_plugin.fullscreen]]=[[Ozna.i. cel. obrazovku]].[[screenshot_plugin.clear]]=[[Zru.i. ozna.enie]].[[screenshot_plugin.cancel]]=[[Zru.i.]].[[screenshot_plugin.editonline]]=[[Upravi. screenshot online]].[[screenshot_plugin.upload]]=[[Nahra. do prntscr.com]].[[screenshot_plugin.close]]=[[Zatvori.]]..[[screenshot_plugin.share_googlesearch]]=[[H.ada. podobn. obr.zky na Googli]].[[screenshot_plugin.share_tineyesearch]]=[[H.ada. podobn. obr.zky na Tineye]].[[screenshot_plugin.share_sendmail]]=[[Posla. pomocou emailu]].[[screenshot_plugin.share_twitter]]=[[Zdie.a. na Twittri]].[[screenshot_plugin.share_facebook]]=[[Zdie.a. na Facebooku]].[[screenshot_plugin.share_vk]]=[[Zdie.a. na VK]].[[screenshot_plugin.share_pinterest]]=[[Zdie.a. na Pinterest]].[[screenshot_plugin.share]]=[[Zdie.a. na soci.lnych sie.ach]]..[[screenshot_pl
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1243)
                          Category:dropped
                          Size (bytes):11981
                          Entropy (8bit):4.93189390113932
                          Encrypted:false
                          SSDEEP:
                          MD5:61C9C831A6C90D4C7E34DE114CF01AD2
                          SHA1:FE1456F52D3731F844F890ABCD42F03011AB27CC
                          SHA-256:86FAFD94CF0E4D7AC3C7C510E60364690286F43E8A6E051A72DC5CD845FBA47F
                          SHA-512:007DADBDBB22375EA2287DEDFFF5B66D51BAAE570113089821BA9A78CEC740BB1813336BB3B2D6611E4B0F7BE5CEA4ACDFF6F463205FBA241148B06CBD0A3BDD
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Sauvegarder]].[[screenshot_plugin.copy]]=[[Copier]].[[screenshot_plugin.print]]=[[Imprimer]].[[screenshot_plugin.fullscreen]]=[[S.lectionner tout l..cran]].[[screenshot_plugin.clear]]=[[Effacer la s.lection]].[[screenshot_plugin.cancel]]=[[Annuler]].[[screenshot_plugin.editonline]]=[[Modifier la capture d..cran en ligne]].[[screenshot_plugin.upload]]=[[Publier sur prntscr.com]].[[screenshot_plugin.close]]=[[Fermer]]..[[screenshot_plugin.share_googlesearch]]=[[Rechercher des images similaires sur Google]].[[screenshot_plugin.share_tineyesearch]]=[[Rechercher des images similaires sur Tineye]].[[screenshot_plugin.share_sendmail]]=[[Envoyer par courriel]].[[screenshot_plugin.share_twitter]]=[[Partager sur Twitter]].[[screenshot_plugin.share_facebook]]=[[Partager sur Facebook]].[[screenshot_plugin.share_vk]]=[[Partager sur VK]].[[screenshot_plugin.share_pinterest]]=[[Partager sur Pinterest]].[[screenshot_plugin.share]]=[[Partager sur les r.seaux soc
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1021)
                          Category:dropped
                          Size (bytes):10863
                          Entropy (8bit):5.0046250426445
                          Encrypted:false
                          SSDEEP:
                          MD5:8B7C86791CB7A6CC264BB6D6F086CCEA
                          SHA1:45D14F8943F7DBFB338ADAC2E76D7D719D8512EC
                          SHA-256:28CBFD25496EBB77EDECA119F0F8FF78D4952F5A8D71E10AD345382D7DF27C74
                          SHA-512:539973FAD93D460263397E12DB229EB37DF16DBFB5F7561421961B74EBBC420E254A3609A25C650EEBA956A22069BE6FE598BF7883AEE9D34D0C8A6B1CD7C535
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Spremi]].[[screenshot_plugin.copy]]=[[Kopiraj]].[[screenshot_plugin.print]]=[[Ispis]].[[screenshot_plugin.fullscreen]]=[[Odaberi puni zaslon]].[[screenshot_plugin.clear]]=[[Izbri.i odabrano]].[[screenshot_plugin.cancel]]=[[Poni.ti]].[[screenshot_plugin.editonline]]=[[Uredi snimku zaslona na mre.i]].[[screenshot_plugin.upload]]=[[Prenesi na prntscr.com]].[[screenshot_plugin.close]]=[[Zatvori]]..[[screenshot_plugin.share_googlesearch]]=[[Tra.i sli.ne slike na Google]].[[screenshot_plugin.share_tineyesearch]]=[[Tra.i sli.ne slike na Tineye]].[[screenshot_plugin.share_sendmail]]=[[Po.alji e-po.tom]].[[screenshot_plugin.share_twitter]]=[[Podijeli na Twitter]].[[screenshot_plugin.share_facebook]]=[[Podijeli na Facebook]].[[screenshot_plugin.share_vk]]=[[Podijeli na VK]].[[screenshot_plugin.share_pinterest]]=[[Dijeli na Pinterest]].[[screenshot_plugin.share]]=[[Podijeli na dru.tvenim mre.ama]]..[[screenshot_plugin.incorrect_size]]=[[Pogre.na veli.i
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):2571
                          Entropy (8bit):4.694878240736071
                          Encrypted:false
                          SSDEEP:
                          MD5:6AF8D75A375BF14CE817227FA848B8C4
                          SHA1:54A880E4AB5F10E895D016012B4AD73BB4B7E24E
                          SHA-256:6D6897C134235CEB66BE8B9DE9E0C93C1906681B7BD7153169F423CAF66501CE
                          SHA-512:EE2A1DF21F530114D0B65A68EC6738B5776BDA3D04447CE3B021F1C374E27B6F389B368C4C9202BCB8E5492B421FE63E4257F20B36670685C8E5B5ED3C5B863C
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Gardar]].[[screenshot_plugin.copy]]=[[Copiar]].[[screenshot_plugin.print]]=[[Imprimir]].[[screenshot_plugin.fullscreen]]=[[Seleccionar pantalla completa]].[[screenshot_plugin.cancel]]=[[Cancelar]].[[screenshot_plugin.close]]=[[Pechar]]..[[screenshot_plugin.share_googlesearch]]=[[Procurar imaxes semellantes no Google]].[[screenshot_plugin.share_sendmail]]=[[Enviar v.a correo electr.nico]].[[screenshot_plugin.share_twitter]]=[[Compartir no Twitter]].[[screenshot_plugin.share_facebook]]=[[Compartir no Facebook]].[[screenshot_plugin.share_pinterest]]=[[Compartir no Pinterest]].[[screenshot_plugin.share]]=[[Compartir nas redes sociais]]..[[screenshot_plugin.error_capt]]=[[Erro]]..[[screenshot_plugin.tooltip]]=[[Seleccionar .rea]].[[screenshot_plugin.open]]=[[Abrir]].[[screenshot_plugin.upload_failed_retry]]=[[Erro ao cargar. Volver tentar?]]..[[screenshot_app.take_screenshot]]=[[Facer unha captura de pantalla]].[[screenshot_app.about]]=[[Acerca de]].[[scre
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1201)
                          Category:dropped
                          Size (bytes):15600
                          Entropy (8bit):5.1688353887279685
                          Encrypted:false
                          SSDEEP:
                          MD5:45BF9B5D594B33A064AE4C04C4C3C96A
                          SHA1:5FFB92F13CA6B7F61CAD36839EBBA97A4BE67925
                          SHA-256:71FBFCC0E199ED012DECF96CE7671CF9A5D4B72F765281A1A66545DDBF025209
                          SHA-512:9C2E89B26AE36DFF4A182AF0C826DE08A46AD0F36FB59C665F247E0EAE5642882018FB946C11D5CEB2B6EFBB75FB7E6914A2AEF387B1DC8ED9AAC26E56A574F5
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.........]].[[screenshot_plugin.copy]]=[[..........]].[[screenshot_plugin.print]]=[[......]].[[screenshot_plugin.fullscreen]]=[[........ .... .....]].[[screenshot_plugin.clear]]=[[........]].[[screenshot_plugin.cancel]]=[[........]].[[screenshot_plugin.editonline]]=[[.............]].[[screenshot_plugin.upload]]=[[......... .. prntscr.com]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_googlesearch]]=[[...... ....... ........... .. Google]].[[screenshot_plugin.share_tineyesearch]]=[[...... ....... ........... .. Tineye]].[[screenshot_plugin.share_sendmail]]=[[......... .. email]].[[screenshot_plugin.share_twitter]]=[[.......... . Twitter]].[[screenshot_plugin.share_facebook]]=[[.......... .. Facebook]].[[screenshot_plugin.share_vk]]=[[.......... ....
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1062)
                          Category:dropped
                          Size (bytes):11480
                          Entropy (8bit):5.419848029758379
                          Encrypted:false
                          SSDEEP:
                          MD5:1519DB2C13A378136674B71398DFAA6D
                          SHA1:B601FD64338E54DCEE5A2365BBE520ECFACE43F0
                          SHA-256:C9730104D6D2F66DA4419D9D7C8CC64A3A839DFA06AC88E42DDEE58AE3B170D2
                          SHA-512:8CE125AC27B86C95F7EADECBADA1652C897794EC9CAFFFFED451F36B87BDE85077C65FBA99085FADFB0AFD5BDC08D60077F71C253545D86143055CDA0FF41BD3
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[L.u]].[[screenshot_plugin.copy]]=[[Sao ch.p]].[[screenshot_plugin.print]]=[[In]].[[screenshot_plugin.fullscreen]]=[[Ch.n to.n m.n h.nh]].[[screenshot_plugin.clear]]=[[X.a v.ng ch.n]].[[screenshot_plugin.cancel]]=[[H.y b.]].[[screenshot_plugin.editonline]]=[[Ch.nh s.a .nh ch.p m.n h.nh tr.c tuy.n]].[[screenshot_plugin.upload]]=[[T.i l.n prntscr.com]].[[screenshot_plugin.close]]=[[..ng]]..[[screenshot_plugin.share_googlesearch]]=[[T.m ki.m .nh t..ng t. tr.n Google]].[[screenshot_plugin.share_tineyesearch]]=[[T.m ki.m .nh t..ng t. tr.n Tineye]].[[screenshot_plugin.share_sendmail]]=[[G.i qua email]].[[screenshot_plugin.share_twitter]]=[[Chia s. l.n Twitter]].[[screenshot_plugin.share_facebook]]=[[Chia s. l.n Facebook]].[[screenshot_plugin.share_vk]]=[[Chia s. l.n VK]].[[screenshot_plugin.share_pinterest]]=[[Chia s. l.n m.ng x. h.i Pinterest]].[[screenshot_plugin.share]]=[[Chia s. l.
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1008)
                          Category:dropped
                          Size (bytes):14747
                          Entropy (8bit):5.151861698418845
                          Encrypted:false
                          SSDEEP:
                          MD5:BB52B0A262414EB4D611072E7ADF8C58
                          SHA1:F7507947C3B45337409A2CC8133B1E685698A825
                          SHA-256:57EC7737EB0BCCC19F8674F1CC462C2A9A8554E2B0A167E3F01B8BC94129E054
                          SHA-512:FBB9B407892FEE54664FF63E700AC490D397A30A4EC64C433002ACA8D0806E1114C564DE05D0E5EB8574EC4CF1A2D8F42A78518F863E2D9DECEE9CC9B86E8467
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.........]].[[screenshot_plugin.copy]]=[[........]].[[screenshot_plugin.print]]=[[..........]].[[screenshot_plugin.fullscreen]]=[[........ .. ..... .....]].[[screenshot_plugin.clear]]=[[..........]].[[screenshot_plugin.cancel]]=[[......]].[[screenshot_plugin.editonline]]=[[...... ...........]].[[screenshot_plugin.upload]]=[[....... . prntscr.com]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_googlesearch]]=[[....... .. ....... ........... . Google]].[[screenshot_plugin.share_tineyesearch]]=[[....... .. ....... ........... . Tineye]].[[screenshot_plugin.share_sendmail]]=[[....... .... email]].[[screenshot_plugin.share_twitter]]=[[....... . Twitter]].[[screenshot_plugin.share_facebook]]=[[....... . Facebook]].[[screenshot_plugin.share_vk]]=[[....... .
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1037)
                          Category:dropped
                          Size (bytes):11019
                          Entropy (8bit):4.926299005060986
                          Encrypted:false
                          SSDEEP:
                          MD5:1FECEA4E623EC7B0DFF4457589D2A901
                          SHA1:00DCA986CBF21798F42E57B76E9C234E010441D9
                          SHA-256:537C962EEC10C69CCA2CA6A11A5BA0FBFDCC15FE6896FA623D4DFB00CBDCE5E5
                          SHA-512:0726992375548CC358FCA8DAEB21A8E1F2FBB180AC7F2AEFEA90C32EF67910F5B1436FD9231D6F710FA43803E1CFC6DCF9101605225B26070ED07FC77A37995D
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Tallenna]].[[screenshot_plugin.copy]]=[[Kopioi]].[[screenshot_plugin.print]]=[[Tulosta]].[[screenshot_plugin.fullscreen]]=[[Valitse koko n.ytt.]].[[screenshot_plugin.clear]]=[[Tyhjenn. valinta]].[[screenshot_plugin.cancel]]=[[Peruuta]].[[screenshot_plugin.editonline]]=[[Muokkaa kuvankaappausta verkossa]].[[screenshot_plugin.upload]]=[[Lataa sivustolle prntscr.com]].[[screenshot_plugin.close]]=[[Sulje]]..[[screenshot_plugin.share_googlesearch]]=[[Etsi samanlaisia kuvia Googlesta]].[[screenshot_plugin.share_tineyesearch]]=[[Etsi samankaltaisia kuvia sivustolta Tineye]].[[screenshot_plugin.share_sendmail]]=[[L.het. s.hk.postilla]].[[screenshot_plugin.share_twitter]]=[[Jaa Twitteriss.]].[[screenshot_plugin.share_facebook]]=[[Jaa Facebookissa]].[[screenshot_plugin.share_vk]]=[[Jaa VK:ssa]].[[screenshot_plugin.share_pinterest]]=[[Jaa Pinterestiss.]].[[screenshot_plugin.share]]=[[Jaa sosiaalisessa mediassa]]..[[screenshot_plugin.incorrect_size]]=[[V..
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (610)
                          Category:dropped
                          Size (bytes):11008
                          Entropy (8bit):5.216434895376966
                          Encrypted:false
                          SSDEEP:
                          MD5:CD83A38536EF1AC82033C88B40C1C299
                          SHA1:39946888C6DBDD2327AEB9B3F323C85B80D01B15
                          SHA-256:1671AE6D38467FE894E2190AC4E03ECF443BCDB535348B4E3B861BC8BB030C58
                          SHA-512:FA71259F29AD9C7D5ADF37ADF971F9465551E23F2AA565AD8AE8700A9F093A290D182A36264206056538BF3DA5A47A962B86F6BF83D2F3942C800010B7FC41CF
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[...]].[[screenshot_plugin.copy]]=[[...]].[[screenshot_plugin.print]]=[[.....]].[[screenshot_plugin.fullscreen]]=[[..... ...... .....]].[[screenshot_plugin.clear]]=[[..... ........]].[[screenshot_plugin.cancel]]=[[.....]].[[screenshot_plugin.editonline]]=[[..... ...... .. ......]].[[screenshot_plugin.upload]]=[[... ...... ... Prntscr.com]].[[screenshot_plugin.close]]=[[.....]]..[[screenshot_plugin.share_googlesearch]]=[[..... .. .... ..... .. ....]].[[screenshot_plugin.share_tineyesearch]]=[[..... .. .... ...... .. Tineye]].[[screenshot_plugin.share_sendmail]]=[[..... ... .......]].[[screenshot_plugin.share_twitter]]=[[... ... .....]].[[screenshot_plugin.share_facebook]]=[[...... ... ........]].[[screenshot_plugin.share_vk]]=[[........ ... VK]].[[screenshot_plugin.share_pinterest]]=
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):7252
                          Entropy (8bit):5.0367350116439455
                          Encrypted:false
                          SSDEEP:
                          MD5:282E5B1C57E18FA97A4D54AFEFDF2485
                          SHA1:D64C78923257FBDF9F136C2F1BC0D817305FB211
                          SHA-256:DDD5A868F9E0C9F988225B1E99223AA45C75122D9E5A399BED508D3C96EA6CD2
                          SHA-512:4581DD61F28A691F6AB00EC8C8F4E8B87DA15822D426167A623B1818ED1ED37CD5F07EB7328BE2977AADA422B544B049F112AD5AC5C94E5214A32C54556652DF
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Saglab.t]].[[screenshot_plugin.copy]]=[[Kop.t]].[[screenshot_plugin.print]]=[[Druk.t]].[[screenshot_plugin.fullscreen]]=[[Iez.m.t pilnu ekr.nu]].[[screenshot_plugin.clear]]=[[Not.r.t iez.m.to]].[[screenshot_plugin.cancel]]=[[Atcelt]].[[screenshot_plugin.editonline]]=[[Redi..t ekr.nuz..mumu internet. onlain.]].[[screenshot_plugin.upload]]=[[Aug.upiel.d.t uz prntscr.com]].[[screenshot_plugin.close]]=[[Aizv.rt]]..[[screenshot_plugin.share_googlesearch]]=[[Mekl.t l.dz.gus att.lus Google]].[[screenshot_plugin.share_tineyesearch]]=[[Mekl.t l.dz.gus att.lus Tineye]].[[screenshot_plugin.share_sendmail]]=[[Nos.t.t pa e-pastu]].[[screenshot_plugin.share_twitter]]=[[Kop.got Twitter vietn.]].[[screenshot_plugin.share_facebook]]=[[Kop.got Facebook vietn.]].[[screenshot_plugin.share_vk]]=[[Kop.got VK vietn.]].[[screenshot_plugin.share_pinterest]]=[[Dal.ties Pinterest vietn.]].[[screenshot_plugin.share]]=[[Kop.got soci.lajos t.
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1126)
                          Category:dropped
                          Size (bytes):16679
                          Entropy (8bit):5.169336661683813
                          Encrypted:false
                          SSDEEP:
                          MD5:25CC5EB2A8E15D7903A31C83B0DB5096
                          SHA1:2ED5CFCBD5A2D96B308A75CEF705218E842A04F0
                          SHA-256:F4E2936E6CC32D0E41BF4A4FDA14623FB7665B5A8BCFC14D8595F0119359B05E
                          SHA-512:F5A0C91972F9C5650927A4DF82EA88D370206E55E0C57D54753781C012C714C19A87CDF1049BE017E68A7D4B07205E3065FE4AC27E04931E05BEE50397EC5A46
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..........]].[[screenshot_plugin.copy]]=[[.........]].[[screenshot_plugin.print]]=[[........]].[[screenshot_plugin.fullscreen]]=[[....... ....... ......]].[[screenshot_plugin.clear]]=[[........ ........]].[[screenshot_plugin.cancel]]=[[.....]].[[screenshot_plugin.editonline]]=[[........... .... ............ online]].[[screenshot_plugin.upload]]=[[........... ... prntscr.com]].[[screenshot_plugin.close]]=[[........]]..[[screenshot_plugin.share_googlesearch]]=[[......... ......... ....... ... Google]].[[screenshot_plugin.share_tineyesearch]]=[[......... ......... ....... ... Tineye]].[[screenshot_plugin.share_sendmail]]=[[........ .... email]].[[screenshot_plugin.share_twitter]]=[[........... .. ... Twitter]].[[screenshot_plugin.share_facebook]]=[[......
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1014)
                          Category:dropped
                          Size (bytes):11202
                          Entropy (8bit):4.9289519644156865
                          Encrypted:false
                          SSDEEP:
                          MD5:62946D959F30092FE18CD081D90A1135
                          SHA1:ABA3A2CD65D5BF80AE08433994E006B3557BE3AE
                          SHA-256:6A20F444F3087CAEB940B2D21CCF437BCC93673308F4898577DFA82677369068
                          SHA-512:757333E7DC4173E7D793C71AFE3517D09D1B4B02731A02F7CBAD835C2160506900BA2A5CD80550E68E07C08A3EF1CEF33A0A85FB11EA8D53186CCEE0C086D111
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Salveaz.]].[[screenshot_plugin.copy]]=[[Copiaz.]].[[screenshot_plugin.print]]=[[Printeaz.]].[[screenshot_plugin.fullscreen]]=[[Pe tot ecranul]].[[screenshot_plugin.clear]]=[[Cur... sectiunea]].[[screenshot_plugin.cancel]]=[[Anuleaz.]].[[screenshot_plugin.editonline]]=[[Editeaz. captura de ecran online]].[[screenshot_plugin.upload]]=[[.ncarc. pe prntscr.com]].[[screenshot_plugin.close]]=[[.nchide]]..[[screenshot_plugin.share_googlesearch]]=[[Caut. imagini similare pe Google]].[[screenshot_plugin.share_tineyesearch]]=[[Caut. imagini similare pe Google Tineye]].[[screenshot_plugin.share_sendmail]]=[[Trimite prin email]].[[screenshot_plugin.share_twitter]]=[[Distribui.i pe Twitter]].[[screenshot_plugin.share_facebook]]=[[Distribui.i pe Facebook]].[[screenshot_plugin.share_vk]]=[[Distribuie pe VK]].[[screenshot_plugin.share_pinterest]]=[[Distribuie pe Pinterest]].[[screenshot_plugin.share]]=[[Distribuiti pe retelele sociale.]]..[[screenshot_plu
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (972)
                          Category:dropped
                          Size (bytes):10728
                          Entropy (8bit):5.002922909528201
                          Encrypted:false
                          SSDEEP:
                          MD5:E53D7FDAE82FE462BD51C0B1AE52CFD7
                          SHA1:A502CA692306A1B5F4A3105271DDAF759BF4CFBA
                          SHA-256:861AD3BA1045D7BCFDC455226F13C43DC07808F4286850ED3F2C1875CE202790
                          SHA-512:D5C9183C4E73F0C62E74E1F3425D962AB194EC570EB15F28564EEF193E3305CC94CAEB488682865753A07995F12FC8C8571D3E4EE16566F32526C8D83DCCFAB9
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Spremi]].[[screenshot_plugin.copy]]=[[Kopiraj]].[[screenshot_plugin.print]]=[[Printaj]].[[screenshot_plugin.fullscreen]]=[[Odaberi cijeli ekran]].[[screenshot_plugin.clear]]=[[Ukloni selekciju]].[[screenshot_plugin.cancel]]=[[Otkazati]].[[screenshot_plugin.editonline]]=[[Uredi screenshot online]].[[screenshot_plugin.upload]]=[[Uploaduj na prntscr.com]].[[screenshot_plugin.close]]=[[Zatvori]]..[[screenshot_plugin.share_googlesearch]]=[[Prona.i sli.ne slike na Google-u]].[[screenshot_plugin.share_tineyesearch]]=[[Prona.i sli.ne slike na Tineye-u]].[[screenshot_plugin.share_sendmail]]=[[Po.alji pute mail-a]].[[screenshot_plugin.share_twitter]]=[[Podijeli na Twitter]].[[screenshot_plugin.share_facebook]]=[[Podijeli na Facebook]].[[screenshot_plugin.share_vk]]=[[Podijeli na VK]].[[screenshot_plugin.share_pinterest]]=[[Podijeli na Pinterest]].[[screenshot_plugin.share]]=[[Podijeli na Socijalne Mre.e]]..[[screenshot_plugin.incorrect_size]]=[[Pogre.na vel
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (960)
                          Category:dropped
                          Size (bytes):14817
                          Entropy (8bit):5.250728591248304
                          Encrypted:false
                          SSDEEP:
                          MD5:1E03EAEA8317F8957E3550C5CBE7B1C2
                          SHA1:AA99447995880271B770698C95949DAD750A148D
                          SHA-256:A8F0633F9AC6B0AA75477547D254E41A2B7571F1E832F8E22F2DA47C12ACA023
                          SHA-512:1695B65441B72CFA68020E4C11894645FB3ED13F74ED847C53E0CD4ED0D89FCBC6BE7FE37483F1E21348EC16F31FCF327505BA1E149F05215285B54FC49BE8E6
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[........]].[[screenshot_plugin.copy]]=[[.........]].[[screenshot_plugin.print]]=[[.........]].[[screenshot_plugin.fullscreen]]=[[........ ..... .....]].[[screenshot_plugin.clear]]=[[......... .........]].[[screenshot_plugin.cancel]]=[[.........]].[[screenshot_plugin.editonline]]=[[.......... ...... ...... ......]].[[screenshot_plugin.upload]]=[[........... .. prntscr.com]].[[screenshot_plugin.close]]=[[........]]..[[screenshot_plugin.share_googlesearch]]=[[...... ........ ........ . Google]].[[screenshot_plugin.share_tineyesearch]]=[[...... ........ ........ . Tineye]].[[screenshot_plugin.share_sendmail]]=[[....... .... email]].[[screenshot_plugin.share_twitter]]=[[.......... . Twitter]].[[screenshot_plugin.share_facebook]]=[[.......... . Facebook]].[[screens
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):2100
                          Entropy (8bit):5.4607972532477875
                          Encrypted:false
                          SSDEEP:
                          MD5:4582B37D89F133893F2095D7B57A3AD1
                          SHA1:3242904BEDF29E6AFC5BB6AEB1DCB7A994C84ECC
                          SHA-256:EE6DFB2E7262954FA5365FAD842B24CD53AFB5E23AF523751D8211B4CC5A8891
                          SHA-512:8FC673A7405499DE5DE184A695ECEDBFA230C0A0CA6A1D74AC7B6A08E3629A64537CEE016AFB85FFE64E7B6460DF4BCC183B7DA1AD1418D48A6482FB59B50E42
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..]].[[screenshot_plugin.copy]]=[[...]].[[screenshot_plugin.print]]=[[..]].[[screenshot_plugin.fullscreen]]=[[.......]].[[screenshot_plugin.clear]]=[[....]].[[screenshot_plugin.cancel]]=[[.....]].[[screenshot_plugin.editonline]]=[[............]].[[screenshot_plugin.upload]]=[["prntscr.com" .......]].[[screenshot_plugin.close]]=[[...]]..[[screenshot_plugin.share_googlesearch]]=[["Google" ........]].[[screenshot_plugin.share_tineyesearch]]=[["Tineye" ........]].[[screenshot_plugin.share_sendmail]]=[[......]].[[screenshot_plugin.share_twitter]]=[["Twitter" ...]].[[screenshot_plugin.share_facebook]]=[["Facebook" ...]]..[[screenshot_plugin.incorrect_size]]=[[.......]].[[screenshot_plugin.error_capt]]=[[...]]..[[screenshot_plugin.tooltip]]=[[.....]].[[screenshot_plugin.open]]=[[..]].
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1009)
                          Category:dropped
                          Size (bytes):12149
                          Entropy (8bit):5.088872199833535
                          Encrypted:false
                          SSDEEP:
                          MD5:3CA46C43929B540F39DAFF85DD06BFEB
                          SHA1:8ABED3FCB1C273C4173DEC8FB6CC2768F777ECA3
                          SHA-256:ECDA5230381AD49094439BF6E98637FFBFBA9408C5930F76708E2592A5D2DEF7
                          SHA-512:AE1295708A8DD79C1ABF1AA3A6D3F0C8E08ABF5C61A901A966A02200C5FC442D5DB88FFFBD4AD72240524115F2028902377C99DCC68154B1109141B52AD40127
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[....]].[[screenshot_plugin.copy]]=[[....]].[[screenshot_plugin.print]]=[[....]].[[screenshot_plugin.fullscreen]]=[[... ... ...]].[[screenshot_plugin.clear]]=[[... .....]].[[screenshot_plugin.cancel]]=[[...]].[[screenshot_plugin.editonline]]=[[.... ..... ... .......]].[[screenshot_plugin.upload]]=[[.... ....... . prntscr.com]].[[screenshot_plugin.close]]=[[....]]..[[screenshot_plugin.share_googlesearch]]=[[... ...... ..... .....]].[[screenshot_plugin.share_tineyesearch]]=[[... ...... ..... .......]].[[screenshot_plugin.share_sendmail]]=[[... ... .... ........]].[[screenshot_plugin.share_twitter]]=[[... .......]].[[screenshot_plugin.share_facebook]]=[[... ........]].[[screenshot_plugin.share_vk]]=[[... .: VK]].[[screenshot_plugin.share_pinterest]]=[[... .: Pinterest]].[[screenshot_plugin.share]]=[[...
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1077)
                          Category:dropped
                          Size (bytes):10796
                          Entropy (8bit):4.8500073537614945
                          Encrypted:false
                          SSDEEP:
                          MD5:0FCA4BD83616AFBB1979A4E191F0D8B4
                          SHA1:B7F14F5B8F9243842F75173E7B6B26A7B7423A5E
                          SHA-256:82DEC9FF06F22776DCA34A8846B3D78CD543FA90B3A6A7250B4E44428ADEDC64
                          SHA-512:5343F3CB21711B0E73AECA482FDB515596E35CBC4F7F53DBA6792ED829FB0876FD5BA485495B526493EC964C6081DF9FCE7111FBE4C3805DF185451C0466667E
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Simpan]].[[screenshot_plugin.copy]]=[[Salin]].[[screenshot_plugin.print]]=[[Cetak]].[[screenshot_plugin.fullscreen]]=[[Pilih Layar Penuh]].[[screenshot_plugin.clear]]=[[Bersihkan Area]].[[screenshot_plugin.cancel]]=[[Batalkan]].[[screenshot_plugin.editonline]]=[[Menyunting screenshot secara online]].[[screenshot_plugin.upload]]=[[Unggah ke prntscr.com]].[[screenshot_plugin.close]]=[[Tutup]]..[[screenshot_plugin.share_googlesearch]]=[[Cari gambar yang mirip di Google]].[[screenshot_plugin.share_tineyesearch]]=[[Cari Gambar Serupa di Tineye]].[[screenshot_plugin.share_sendmail]]=[[Kirim lewat email]].[[screenshot_plugin.share_twitter]]=[[Bagikan di Twitter]].[[screenshot_plugin.share_facebook]]=[[Bagikan di Facebook]].[[screenshot_plugin.share_vk]]=[[Bagikan di VK]].[[screenshot_plugin.share_pinterest]]=[[Bagikan ke Pinterest]].[[screenshot_plugin.share]]=[[Bagikan di jejaring sosial]]..[[screenshot_plugin.incorrect_size]]=[[Ukuran Salah]].[[screenshot_pl
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):4901
                          Entropy (8bit):5.025306265427669
                          Encrypted:false
                          SSDEEP:
                          MD5:B120214A70252EA6E6676EF8ABC25F5C
                          SHA1:70D9579B75E377B2A28198BF107846EE936560FA
                          SHA-256:40946D5C72FDAEC7106FCB6E7F2114365988C76070A4D1E2C110721625E9406B
                          SHA-512:290E823F929A2E80AD4FF4F4648A4244468547A6DD128E117FD0300B21496E0E1B5FCFA3D1DB1D2B8E271DE45EB42A325954E2EBB5A4544EA4456CF97D6B22FF
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[......]].[[screenshot_plugin.copy]]=[[......]].[[screenshot_plugin.print]]=[[.....]].[[screenshot_plugin.fullscreen]]=[[..........]].[[screenshot_plugin.clear]]=[[....]].[[screenshot_plugin.cancel]]=[[......]].[[screenshot_plugin.editonline]]=[[...........]].[[screenshot_plugin.upload]]=[[............ prntscr.com]].[[screenshot_plugin.close]]=[[...]]..[[screenshot_plugin.share_googlesearch]]=[[...................... Google]].[[screenshot_plugin.share_tineyesearch]]=[[...................... Tineye]].[[screenshot_plugin.share_sendmail]]=[[....... Email]].[[screenshot_plugin.share_twitter]]=[[......... Twitter]].[[screenshot_plugin.share_facebook]]=[[......... Facebook]].[[screenshot_plugin.share_p
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1094)
                          Category:dropped
                          Size (bytes):11567
                          Entropy (8bit):4.848204007772776
                          Encrypted:false
                          SSDEEP:
                          MD5:1DBF0C68099CDAA5F8800DC14AA2F5B0
                          SHA1:F43D913B1FA098F89B28756CEC754022AFE62C3C
                          SHA-256:B82B3A16C09AB2E1340C1D42F22146B30B7445CE1652D2114412F7A1AF6AECEF
                          SHA-512:89AD7CDC635D128A22081100E1DA0A2ED89B90582B856172DE2E2901DDDFA09A21E1E27A4139C68096160B836FFC37E1C7AF0DE81232A624B683DF4FCD49F9F3
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Opslaan]].[[screenshot_plugin.copy]]=[[Kopi.ren]].[[screenshot_plugin.print]]=[[Afdrukken]].[[screenshot_plugin.fullscreen]]=[[Het volledige scherm kiezen]].[[screenshot_plugin.clear]]=[[Keuze wissen]].[[screenshot_plugin.cancel]]=[[Afbreken]].[[screenshot_plugin.editonline]]=[[Een afbeelding op het web bewerken]].[[screenshot_plugin.upload]]=[[Naar prntscr.com versturen]].[[screenshot_plugin.close]]=[[Afsluiten]]..[[screenshot_plugin.share_googlesearch]]=[[Soortgelijke afbeeldingen op Google zoeken]].[[screenshot_plugin.share_tineyesearch]]=[[Soortgelijke afbeeldingen op Tineye zoeken]].[[screenshot_plugin.share_sendmail]]=[[Via de e-post versturen]].[[screenshot_plugin.share_twitter]]=[[Via Twitter delen]].[[screenshot_plugin.share_facebook]]=[[Via Facebook delen]].[[screenshot_plugin.share_vk]]=[[Via VK delen]].[[screenshot_plugin.share_pinterest]]=[[Via Pinterest delen]].[[screenshot_plugin.share]]=[[Op maatschappelijke netwerken delen]]..[[screensh
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1028)
                          Category:dropped
                          Size (bytes):10799
                          Entropy (8bit):4.980991806531341
                          Encrypted:false
                          SSDEEP:
                          MD5:9F1DC3AECD16265A7C7A6D6267FB5F98
                          SHA1:4EE8C5160CD707004482EFC73BD152B5A0D0C284
                          SHA-256:F6C24CF6BAE9777E1694B92C88AFBE77C99791AED35EB0FDA44F33287455C047
                          SHA-512:FA473916834B79E56BBA1548707383ABD4B1C82BEDD8187C167B59679AF8529D5A6D4C585C6FB18706DF2B76827E95E7BF9C37535BC36BACB6128B037A37C724
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Spara]].[[screenshot_plugin.copy]]=[[Kopiera]].[[screenshot_plugin.print]]=[[Skriv ut]].[[screenshot_plugin.fullscreen]]=[[V.lj fullsk.rm]].[[screenshot_plugin.clear]]=[[Rensa val]].[[screenshot_plugin.cancel]]=[[Avbryt]].[[screenshot_plugin.editonline]]=[[Redigera en shreenshot online]].[[screenshot_plugin.upload]]=[[Ladda ner till prntscr.com]].[[screenshot_plugin.close]]=[[St.ng]]..[[screenshot_plugin.share_googlesearch]]=[[S.k liknande bilder p. Google]].[[screenshot_plugin.share_tineyesearch]]=[[S.k liknande bilder p. Tineye]].[[screenshot_plugin.share_sendmail]]=[[Skicka via e-mejl]].[[screenshot_plugin.share_twitter]]=[[Dela p. Twitter]].[[screenshot_plugin.share_facebook]]=[[Dela p. Facebook]].[[screenshot_plugin.share_vk]]=[[Dela p. VK]].[[screenshot_plugin.share_pinterest]]=[[Dela p. Pinterest]].[[screenshot_plugin.share]]=[[Dela p. sociala n.tverk]]..[[screenshot_plugin.incorrect_size]]=[[Fel storlek]].[[screenshot_plugin.error_ca
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (910)
                          Category:dropped
                          Size (bytes):14023
                          Entropy (8bit):5.2569029518286685
                          Encrypted:false
                          SSDEEP:
                          MD5:27C710C7C361A9B94703BD1C4C717522
                          SHA1:231EE42EFC2BC4055DE6AADD275CA83CB2562839
                          SHA-256:627D3F4BB34F3F5AC2BAAAED82FBE80B3739C58D2F710BCBBD11DDBA85BB14BF
                          SHA-512:1CAA0C3FFBDB42577D27C0090E98B39E925BF711A0814E52E943003D06E8BD00493318A7B1D27B11C66847091EF64BB102BEB669C3D999535F258700ADC268DB
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[........]].[[screenshot_plugin.copy]]=[[.........]].[[screenshot_plugin.print]]=[[.........]].[[screenshot_plugin.fullscreen]]=[[........ .... .....]].[[screenshot_plugin.clear]]=[[........]].[[screenshot_plugin.cancel]]=[[.........]].[[screenshot_plugin.editonline]]=[[..........]].[[screenshot_plugin.upload]]=[[........... .. ...... prntscr.com]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_googlesearch]]=[[...... ..... .......... . Google]].[[screenshot_plugin.share_tineyesearch]]=[[...... ..... .......... . Tineye]].[[screenshot_plugin.share_sendmail]]=[[......... .. email]].[[screenshot_plugin.share_twitter]]=[[.......... . Twitter]].[[screenshot_plugin.share_facebook]]=[[.......... .. Facebook]].[[screenshot_plugin.share_vk]]=[[.......... . VK]].
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):1853
                          Entropy (8bit):4.858703658195675
                          Encrypted:false
                          SSDEEP:
                          MD5:6EA5AF7F09D1CDD8929B1D6C2F8B9DFD
                          SHA1:7A185908954EFADDA847870CA30E344EDA0B72D1
                          SHA-256:6BC8AD750CB4142C2C628C3C3F3006C853A48566FC988CD7179EA6CAE0FF7A79
                          SHA-512:149456B744531945A7ABCD294F7B45EAE3959D8B672DE10431A26D9458E683B1A48D03136C672DAB00C804AC8F6738A6C35D0F18D48818F28038864499DCDB78
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Vista]].[[screenshot_plugin.copy]]=[[Afrita]].[[screenshot_plugin.print]]=[[Prenta]].[[screenshot_plugin.fullscreen]]=[[Velja fullan skj.]].[[screenshot_plugin.clear]]=[[Hreinsa]].[[screenshot_plugin.cancel]]=[[H.tta Vi.]].[[screenshot_plugin.editonline]]=[[Breyta Mynd]].[[screenshot_plugin.upload]]=[[Senda . prntscr.com]].[[screenshot_plugin.close]]=[[Loka]]..[[screenshot_plugin.share_googlesearch]]=[[Leita a. svipu.um myndum . Google]].[[screenshot_plugin.share_tineyesearch]]=[[Leita a. svipu.um myndum . Tineye]].[[screenshot_plugin.share_sendmail]]=[[Senda . email]].[[screenshot_plugin.share_twitter]]=[[Deila . Twitter]].[[screenshot_plugin.share_facebook]]=[[Deila in Facebook]]..[[screenshot_plugin.incorrect_size]]=[[Vitlaus St.r.]].[[screenshot_plugin.error_capt]]=[[Villa]]..[[screenshot_plugin.tooltip]]=[[Velja sv..i]].[[screenshot_plugin.open]]=[[Opna]].[[screenshot_plugin.uploading_window_capt]]=[[Sendi mynd]].[[screenshot_plugin.
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (321)
                          Category:dropped
                          Size (bytes):14334
                          Entropy (8bit):4.609688160373262
                          Encrypted:false
                          SSDEEP:
                          MD5:4D839F6C4DB8B58158BA136BBE209E50
                          SHA1:BA84439054819925F1FCC8118536B12F67A4262B
                          SHA-256:8844248F8E3446BB01581C801275E060C0E8171B150C84A2552D26ECCC1349D5
                          SHA-512:7EC12E55AAD2EF65F57B08F53FD392E5D2278402FDFB1F6BB6E22A4212D40F7300FBACD269F57D29BC24443CD7643969DA85013375613CB0407C597726AFEF5F
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.......]].[[screenshot_plugin.copy]]=[[........]].[[screenshot_plugin.print]]=[[........]].[[screenshot_plugin.fullscreen]]=[[..... ....... ......]].[[screenshot_plugin.clear]]=[[...........]].[[screenshot_plugin.cancel]]=[[........]].[[screenshot_plugin.editonline]]=[[......... ...... ........]].[[screenshot_plugin.upload]]=[[........ prntscr.com-..]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_googlesearch]]=[[....... ....... ....... Google-..]].[[screenshot_plugin.share_tineyesearch]]=[[....... ....... ....... Tineye-..]].[[screenshot_plugin.share_sendmail]]=[[...... ........ ..-.......]].[[screen
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1120)
                          Category:dropped
                          Size (bytes):11186
                          Entropy (8bit):4.953572434226719
                          Encrypted:false
                          SSDEEP:
                          MD5:70F2CB3F106AB633BD97214FFC1ED887
                          SHA1:2FC524704C19FB2F299CCE09573A3D7E2EF093F9
                          SHA-256:66ED6820B982F5055EAE9893338EA992A97F84A0280D1E8A54142ADA09D31821
                          SHA-512:71D56A062EC41A11294EFAD9018E80AEA039537A6077D25E140D766624DA1F467CB84067718AF80488A64ECED84D71FBFEF438CDF9434459C62B9BEC64BE7B90
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Lagre]].[[screenshot_plugin.copy]]=[[Kopi.r]].[[screenshot_plugin.print]]=[[Skriv ut]].[[screenshot_plugin.fullscreen]]=[[Velg fullskjermsvisning]].[[screenshot_plugin.clear]]=[[Fjern utsnitt]].[[screenshot_plugin.cancel]]=[[Avbryt]].[[screenshot_plugin.editonline]]=[[Redig.r skjermbildet i nettleseren]].[[screenshot_plugin.upload]]=[[Last opp til prntscr.com]].[[screenshot_plugin.close]]=[[Lukk]]..[[screenshot_plugin.share_googlesearch]]=[[S.k etter lignende bilder p. Google]].[[screenshot_plugin.share_tineyesearch]]=[[S.k etter lignende bilder p. Tineye]].[[screenshot_plugin.share_sendmail]]=[[Send via e-post]].[[screenshot_plugin.share_twitter]]=[[Del p. Twitter]].[[screenshot_plugin.share_facebook]]=[[Del p. Facebook]].[[screenshot_plugin.share_vk]]=[[Del p. VK]].[[screenshot_plugin.share_pinterest]]=[[Del p. Pinterest]].[[screenshot_plugin.share]]=[[Del p. sosiale nettverk]]..[[screenshot_plugin.incorrect_size]]=[[Feil st.rrelse]].[[scre
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (651)
                          Category:dropped
                          Size (bytes):6945
                          Entropy (8bit):4.814228636128868
                          Encrypted:false
                          SSDEEP:
                          MD5:C5D8FB04C0A7BE0D53FD031090BC36F8
                          SHA1:7738786D699380CFD5A13940C65EA86DBB1979EF
                          SHA-256:4357C2DD05BB87E381E07681B9E8D17FE5953997CCEF1045DC004A93B791F159
                          SHA-512:2D58FAA2C557B631AF7FF1022B1E8E77B6972D7405F748A706BE823C45B95165FE9B00087F49A7AEAB73420AE25AB96608869F23F7C8049BE5E0D07F9D7FBDA5
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Guardar]].[[screenshot_plugin.copy]]=[[Copiar]].[[screenshot_plugin.print]]=[[Imprimir]].[[screenshot_plugin.fullscreen]]=[[Selecionar tela inteira]].[[screenshot_plugin.clear]]=[[Limpar sele..o]].[[screenshot_plugin.cancel]]=[[Cancelar]].[[screenshot_plugin.editonline]]=[[Editar captura de ecr. online]].[[screenshot_plugin.upload]]=[[Enviar para prntscr.com]].[[screenshot_plugin.close]]=[[Fechar]]..[[screenshot_plugin.share_googlesearch]]=[[Pesquisar imagens semelhantes no Google]].[[screenshot_plugin.share_tineyesearch]]=[[Pesquisar imagens semelhantes no Tineye]].[[screenshot_plugin.share_sendmail]]=[[Enviar por email]].[[screenshot_plugin.share_twitter]]=[[Partilhar no Twitter]].[[screenshot_plugin.share_facebook]]=[[Partilhar no Facebook]].[[screenshot_plugin.share_vk]]=[[Partilhar no VK]].[[screenshot_plugin.share_pinterest]]=[[Partilhar no Pinterest]].[[screenshot_plugin.share]]=[[Partilhar nas redes sociais]]..[[screenshot_plugin.incorrect_siz
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (984)
                          Category:dropped
                          Size (bytes):10821
                          Entropy (8bit):4.994608224609736
                          Encrypted:false
                          SSDEEP:
                          MD5:6F6D725EF25A08411050A1B8B64971ED
                          SHA1:8931A4ADCC03DA6E792B27AE75D5A6B7F800628B
                          SHA-256:2C54125C6083783887B438DC2B503DE6C3396819EDF0A553446117E2D61E7316
                          SHA-512:20463FF7432B510BA1383342690E321607559F7D5C564E32FC4BD3F902BC6A4BE299F8FE21673FA99BA7F6C7B6FB9F31EA3355B7643EA8E4E5F0449448C801BE
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Snimi]].[[screenshot_plugin.copy]]=[[Kopiraj]].[[screenshot_plugin.print]]=[[Od.tampaj]].[[screenshot_plugin.fullscreen]]=[[Izaberi ceo ekran]].[[screenshot_plugin.clear]]=[[Obri.i selektovano]].[[screenshot_plugin.cancel]]=[[Otka.i]].[[screenshot_plugin.editonline]]=[[Izmeni sliku onlajn]].[[screenshot_plugin.upload]]=[[Otpremi na prntscr.com]].[[screenshot_plugin.close]]=[[Zatvori]]..[[screenshot_plugin.share_googlesearch]]=[[Pretra.i sli.ne fotografije na Google]].[[screenshot_plugin.share_tineyesearch]]=[[Pretra.i sli.ne fotografije na Tineye]].[[screenshot_plugin.share_sendmail]]=[[Po.alji elektronskom po.tom]].[[screenshot_plugin.share_twitter]]=[[Podeli na Twitter]].[[screenshot_plugin.share_facebook]]=[[Podeli na Facebook]].[[screenshot_plugin.share_vk]]=[[Deli na VK]].[[screenshot_plugin.share_pinterest]]=[[Deli na Pinterestu]].[[screenshot_plugin.share]]=[[Deli na socijalnim mre.ama]]..[[screenshot_plugin.incorrect_size]]=[[Pogre.na
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):5991
                          Entropy (8bit):5.132534694916237
                          Encrypted:false
                          SSDEEP:
                          MD5:B59655503491EDE3F4E384D1CD1D4B92
                          SHA1:B7C97861BE859DD9B5CD4B5B6417E74072EB6389
                          SHA-256:5668F40DE78CFAC84078449DE88F628C49C126C43E14EB9E4F10A2CA689BDF85
                          SHA-512:423A6F639AE3071F436EB31C684196C620C88FCFFAEB2C1326E6974545BE2DEDB040167828E1527D1EEB268013EDFFED867E8655A25783CAFE4254031D7375D4
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.......]].[[screenshot_plugin.fullscreen]]=[[....... ..... ..... ......]].[[screenshot_plugin.editonline]]=[[...... ..... ......]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_twitter]]=[[...... .. .......]].[[screenshot_plugin.share_facebook]]=[[...... .. ........]].[[screenshot_plugin.share_pinterest]]=[[...... .. ..........]].[[screenshot_plugin.share]]=[[...... .. .......... .......]]..[[screenshot_plugin.error_capt]]=[[......]]..[[screenshot_plugin.tooltip]]=[[...... ........]].[[screenshot_plugin.upload_failed_retry]]=[[..... .......... ...... ......?]]..[[screenshot_app.help]]=[[.....]].[[screenshot_app.exit]]=[[.....]].[[screenshot_app.copyright]]=[[%company% ... ..... .........]]..[[screenshotplugin_name]]=[[Lightshot (....
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):11282
                          Entropy (8bit):5.22650088499113
                          Encrypted:false
                          SSDEEP:
                          MD5:ADDA7B38ACB9923473E8E5F8FE9555F0
                          SHA1:73C3BEF88E8ED893A98A19F702EA9F7C159D30F8
                          SHA-256:88F1EC35A57672CB75E96662819901899F8BC7CE546B3DA3AAD636229D4695D1
                          SHA-512:B214D0AFDB5546EFBD8C95C758EF0B8EAC4C19462B44645220BB8FBB4BBABAB5CD066E7C56850C67E11BEFD173B49C4C1010023338FA66F1F5B9D6EC4083CAC7
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[............]].[[screenshot_plugin.copy]]=[[............]].[[screenshot_plugin.print]]=[[.......]].[[screenshot_plugin.fullscreen]]=[[.......... ..... ......]].[[screenshot_plugin.clear]]=[[....... ............]].[[screenshot_plugin.cancel]]=[[.....]].[[screenshot_plugin.editonline]]=[[.......... ..... ..... ....]].[[screenshot_plugin.upload]]=[[Prntscr.com ............ .... ..]].[[screenshot_plugin.close]]=[[......]]..[[screenshot_plugin.share_googlesearch]]=[[..... .. ..... ....... .. .... ]].[[screenshot_plugin.share_tineyesearch]]=[[Tineye ..... .. ..... ....... .. ]].[[screenshot_plugin.share_sendmail]]=[[..... ....... ........]].[[screenshot_plugin.share_twitter]]=[[........... .. ......]].[[screenshot_plugin.share_facebook]]=[[........
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (887)
                          Category:dropped
                          Size (bytes):13487
                          Entropy (8bit):5.262276183422655
                          Encrypted:false
                          SSDEEP:
                          MD5:2AAE7AF8598C3BC89B17CB8F36A0BD59
                          SHA1:F211568F746150D413D15AA72688345D0142F925
                          SHA-256:C3BE9BA8219F9BECD5AE9279BA5620270131880D276F3799CC2D1C0C3B224CA3
                          SHA-512:823E749BF3172E94766F8CC337E4D3D86CE195F1F9E06F6255E731F8197815263F38BDA65D0171A5DB2C3BABDF1E67A5707B347370A9AB48024CF62089F9FAA5
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[........]].[[screenshot_plugin.copy]]=[[........]].[[screenshot_plugin.print]]=[[....]].[[screenshot_plugin.fullscreen]]=[[.... ...... ......]].[[screenshot_plugin.clear]]=[[......]].[[screenshot_plugin.cancel]]=[[........]].[[screenshot_plugin.editonline]]=[[........ ......]].[[screenshot_plugin.upload]]=[[......... prntscr.com]].[[screenshot_plugin.close]]=[[.....]]..[[screenshot_plugin.share_googlesearch]]=[[...... .... ......... Google-...]].[[screenshot_plugin.share_tineyesearch]]=[[...... .... ......... Tineye-...]].[[screenshot_plugin.share_sendmail]]=[[........ ...... .........]].[[screenshot_plugin.share_twitter]]=[[....... Twitter-...]].[[screenshot_plugin.share_facebook]]=[[....... Facebook-...]].[[screenshot_plugin.share_vk]]=[[....... VK-...]].[[screenshot_plugin.share_p
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (758)
                          Category:dropped
                          Size (bytes):11110
                          Entropy (8bit):5.888845253303549
                          Encrypted:false
                          SSDEEP:
                          MD5:99F15556368A9025A678AE20E3E5EDB4
                          SHA1:1DAE062FE596367350FA7EAE68BBF1645C11A143
                          SHA-256:F07C0EE08ED2895729E734B349B1AF3CA8A0646126FD4E3A01D37A8DE299B7B8
                          SHA-512:BC69A8371EAE0AADDDB6B507E1B5E49F9BD18AB0595C0C8FCA02F9648E2736CCD6406907D3DD38121912D2FAC00639F563FBDFEE458876604692ECF05CC08906
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..]].[[screenshot_plugin.copy]]=[[..]].[[screenshot_plugin.print]]=[[..]].[[screenshot_plugin.fullscreen]]=[[.. .. ..]].[[screenshot_plugin.clear]]=[[.. ..]].[[screenshot_plugin.cancel]]=[[..]].[[screenshot_plugin.editonline]]=[[..... .... ..]].[[screenshot_plugin.upload]]=[[Prntscr.com. ...]].[[screenshot_plugin.close]]=[[..]]..[[screenshot_plugin.share_googlesearch]]=[[Google.. ... ... ..]].[[screenshot_plugin.share_tineyesearch]]=[[Tineye.. ... ... ..]].[[screenshot_plugin.share_sendmail]]=[[.... ...]].[[screenshot_plugin.share_twitter]]=[[Twitter. ..]].[[screenshot_plugin.share_facebook]]=[[Facebook.. ..]].[[screenshot_plugin.share_vk]]=[[VK. ..]].[[screenshot_plugin.share_pinterest]]=[[Pinterest. ..]].[[screenshot_plugin.share]]=[[.. ..... ..]]..[[screenshot_plugin.incorrect_size]]=[[
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (606)
                          Category:dropped
                          Size (bytes):9229
                          Entropy (8bit):4.988338896224836
                          Encrypted:false
                          SSDEEP:
                          MD5:BDD17AB1EDA8488B8CFE02327DF05F90
                          SHA1:031F1B7B21FB7C8BAA2FCD6FAD0589D8C5437629
                          SHA-256:0E251986CD97BDE529CC2726EFC18F821661301DF1B8F44FB17898F851393D82
                          SHA-512:4853412D4FC5A0293EC5F4C92F468B06924C00DEBDAA8A2B6372CD0C339D1C5B2B7360CF1BE353E2459ACEBA7C82AF33B04F552733E221C2A5CBE9246BE3277E
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[I.saugoti]].[[screenshot_plugin.copy]]=[[Kopijuoti]].[[screenshot_plugin.print]]=[[Spausdinti]].[[screenshot_plugin.fullscreen]]=[[Pasirinkti vis. ekrano vaizd.]].[[screenshot_plugin.clear]]=[[I.trinti pasirinkim.]].[[screenshot_plugin.cancel]]=[[At.aukti]].[[screenshot_plugin.editonline]]=[[Koreguoti paveiksl.l. internete]].[[screenshot_plugin.upload]]=[[.kelti . prntscr.com]].[[screenshot_plugin.close]]=[[U.daryti]]..[[screenshot_plugin.share_googlesearch]]=[[Ie.koti pana.i. paveiksl.li. per Google]].[[screenshot_plugin.share_tineyesearch]]=[[Ie.koti pana.i. paveiksl.li. per Tineye]].[[screenshot_plugin.share_sendmail]]=[[I.si.sti elektroniniu pa.tu]].[[screenshot_plugin.share_twitter]]=[[Pasidalinti per Twitter]].[[screenshot_plugin.share_facebook]]=[[Pasidalinti per Facebook]].[[screenshot_plugin.share_vk]]=[[Pasidalinti per VK]].[[screenshot_plugin.share_pinterest]]=[[Pasidalinti per Pinterest]].[[screenshot_plugin.share]]=[[
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1059)
                          Category:dropped
                          Size (bytes):11416
                          Entropy (8bit):4.851928229994875
                          Encrypted:false
                          SSDEEP:
                          MD5:C7532FCF181919333E0A247E447CF56E
                          SHA1:CF1ADF1C620BA5AEF0F26066964E9D2447EA9211
                          SHA-256:037F23F925BA25D30D221D0FB36FE9925DBEA3079A4AAFEDC13ECC9A8D306F40
                          SHA-512:A95FF21659E6F68A49B011AB47BF4C24990F1318CD0CD9661AC6A55C7B0A178EAD9D533C81D5B916C12C4A5ED7AF9013DA739FA33F463807634A6D43497A3F49
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Guardar]].[[screenshot_plugin.copy]]=[[Copiar]].[[screenshot_plugin.print]]=[[Imprimir]].[[screenshot_plugin.fullscreen]]=[[Seleccionar pantalla completa]].[[screenshot_plugin.clear]]=[[Borrar selecci.n]].[[screenshot_plugin.cancel]]=[[Cancelar]].[[screenshot_plugin.editonline]]=[[Editar una captura de pantalla en l.nea]].[[screenshot_plugin.upload]]=[[Subir a prntscr.com]].[[screenshot_plugin.close]]=[[Cerrar]]..[[screenshot_plugin.share_googlesearch]]=[[Buscar im.genes similares en Google]].[[screenshot_plugin.share_tineyesearch]]=[[Buscar im.genes similares en Tineye]].[[screenshot_plugin.share_sendmail]]=[[Send via email]].[[screenshot_plugin.share_twitter]]=[[Compartir en Twitter]].[[screenshot_plugin.share_facebook]]=[[Compartir en Facebook]].[[screenshot_plugin.share_vk]]=[[Compartir en VK]].[[screenshot_plugin.share_pinterest]]=[[Compartir en Pinterest]].[[screenshot_plugin.share]]=[[Compartir en redes sociales]]..[[screenshot_plugin.incorrec
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (958)
                          Category:dropped
                          Size (bytes):11265
                          Entropy (8bit):5.379695241539821
                          Encrypted:false
                          SSDEEP:
                          MD5:9EF4A08C21E1448BED2D3DCF8AE3B922
                          SHA1:F2209C45F7DCA7BC1FA60E454E9C8C52AB570DFA
                          SHA-256:9C1DEFA92587EC92A09B098745ECCAA5B8F7197FA154A41A74C663F62C532C21
                          SHA-512:45F03E9A8CCB794D0EA8264EAAA3237E1FA37A086EB23BD2214EE6EB22E948A3A4706031CE3F9E6A1508F45C05C327A9A610D1748901899FB44FCC62B1EA0980
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..... ....]].[[screenshot_plugin.copy]]=[[... ....]].[[screenshot_plugin.print]]=[[.... ....]].[[screenshot_plugin.fullscreen]]=[[.... .... .... .. ...... ....]].[[screenshot_plugin.clear]]=[[...... ..... ....]].[[screenshot_plugin.cancel]]=[[..... ....]].[[screenshot_plugin.editonline]]=[[.... .... ... ... ..... ....]].[[screenshot_plugin.upload]]=[[.. ..... .... prntscr.com]].[[screenshot_plugin.close]]=[[... ....]]..[[screenshot_plugin.share_googlesearch]]=[[.... .. .... .... ...... .. .... ....]].[[screenshot_plugin.share_tineyesearch]]=[[.. .... .... ...... .. .... .... Tineye]].[[screenshot_plugin.share_sendmail]]=[[...... .. ... ..... ....]].[[screenshot_plugin.share_twitter]]=[[..... .. ..... ....]].[[screenshot_plugin.share_facebook]]=[[...
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):10491
                          Entropy (8bit):5.221991886945581
                          Encrypted:false
                          SSDEEP:
                          MD5:A91D80CB2770EA0BD50DB9690FC5D6DF
                          SHA1:762226BD50FB39C7AFA9AC6B55688D48376D1E25
                          SHA-256:D8EDEC9A317E7722D304486657AE047B1627CD3FE80F2EEBC6BDA88D8323673E
                          SHA-512:3950B544A83FBB12003D622B60D96ABE104CE5B2A60E33C3C7474F256AD35902C26B79C10346F69C5F0E01209F2DB01C3B9CB842768243B9C00D83591B41D076
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.....]].[[screenshot_plugin.copy]]=[[...]].[[screenshot_plugin.print]]=[[.....]].[[screenshot_plugin.fullscreen]]=[[..... .... ....]].[[screenshot_plugin.clear]]=[[... .... ......]].[[screenshot_plugin.cancel]]=[[... ....]].[[screenshot_plugin.editonline]]=[[...... ...... ....... ...]].[[screenshot_plugin.upload]]=[[........ .. prntscr.com]].[[screenshot_plugin.close]]=[[....]]..[[screenshot_plugin.share_googlesearch]]=[[...... ...... ..... .. ....]].[[screenshot_plugin.share_tineyesearch]]=[[...... ...... ..... .. Tineye]].[[screenshot_plugin.share_sendmail]]=[[..... .. .....]].[[screenshot_plugin.share_twitter]]=[[...... ..... .. ......]].[[screenshot_plugin.share_facebook]]=[[...... ..... .. ......]].[[screenshot_plugin.share_vk]]=[[...... ..... .. VK]].[[screenshot_p
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1055)
                          Category:dropped
                          Size (bytes):11043
                          Entropy (8bit):4.899724610981938
                          Encrypted:false
                          SSDEEP:
                          MD5:09540A630D97751B5B922D9A54D72FE4
                          SHA1:FABB626059A1A504888C23795470A4DE14C52445
                          SHA-256:6F931F38924CF8C233A1B46E5D80BAD2182F8DD0D670E7F54824D8CAA5AE0C11
                          SHA-512:C992B7545B70A77C0C4ACB7B4445F50BD35285DDB4B580C4573F99FCAC0EBF666431FD8B43715D1CF116F5379F8B0E375884C8C390697D4C2C0667AF99321A9D
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Salvar]].[[screenshot_plugin.copy]]=[[Copiar]].[[screenshot_plugin.print]]=[[Imprimir]].[[screenshot_plugin.fullscreen]]=[[Selecionar tela inteira]].[[screenshot_plugin.clear]]=[[Limpar sele..o]].[[screenshot_plugin.cancel]]=[[Cancelar]].[[screenshot_plugin.editonline]]=[[Editar captura de tela online]].[[screenshot_plugin.upload]]=[[Enviar para prntscr.com]].[[screenshot_plugin.close]]=[[Fechar]]..[[screenshot_plugin.share_googlesearch]]=[[Pesquisar imagens semelhantes no Google]].[[screenshot_plugin.share_tineyesearch]]=[[Pesquisar imagens semelhantes no Tineye]].[[screenshot_plugin.share_sendmail]]=[[Enviar por email]].[[screenshot_plugin.share_twitter]]=[[Compartilhar no Twitter]].[[screenshot_plugin.share_facebook]]=[[Compartilhar no Facebook]].[[screenshot_plugin.share_vk]]=[[Compartilhar no VK]].[[screenshot_plugin.share_pinterest]]=[[Compartilhar no Pinterest]].[[screenshot_plugin.share]]=[[Compartilhar nas redes sociais]]..[[screenshot_plugin.
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1121)
                          Category:dropped
                          Size (bytes):11553
                          Entropy (8bit):4.986278108970552
                          Encrypted:false
                          SSDEEP:
                          MD5:C472AAE2B0373E15A29D72B3CF5E0E3D
                          SHA1:D8D0F01FBD6C0EBD69E68951E846915268B199E9
                          SHA-256:DCBE37332E05768D3A3F9E46686F4BEF18A4B9F4622BA9BC9F2BF0451092419B
                          SHA-512:A4EF6FC6D6A67A52E45EA7172E8CF0292B9EB803B2205231ACE4E2850E7E1CDF83659216D4750DD9DDB6FB0AA63FC6A5F9D55A6192E1D8E0176729A840DADA32
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Ruaj]].[[screenshot_plugin.copy]]=[[Kopjo]].[[screenshot_plugin.print]]=[[Printoje]].[[screenshot_plugin.fullscreen]]=[[Selektoni ekran t. plot.]].[[screenshot_plugin.clear]]=[[Pastro selektimin]].[[screenshot_plugin.cancel]]=[[Anulo]].[[screenshot_plugin.editonline]]=[[Redaktoni nj. prerje n. Internet]].[[screenshot_plugin.upload]]=[[Ngarko te prntscr.com]].[[screenshot_plugin.close]]=[[Mbylle]]..[[screenshot_plugin.share_googlesearch]]=[[K.rko imazhe t. ngjash.m n. Google]].[[screenshot_plugin.share_tineyesearch]]=[[K.rko Imazhe t. ngjashme n. Tineye]].[[screenshot_plugin.share_sendmail]]=[[D.rgo me Email]].[[screenshot_plugin.share_twitter]]=[[Shp.rndaje n. Twitter]].[[screenshot_plugin.share_facebook]]=[[Shp.rndaje n. Facebook]].[[screenshot_plugin.share_vk]]=[[Shp.rndaje n. VK]].[[screenshot_plugin.share_pinterest]]=[[Shp.rndaje n. Pinterest]].[[screenshot_plugin.share]]=[[Shp.rndaje n. Rrjetet Sociale]]..[[screenshot_plugin.in
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (964)
                          Category:dropped
                          Size (bytes):19027
                          Entropy (8bit):4.732656173496707
                          Encrypted:false
                          SSDEEP:
                          MD5:BCB08DB5044B9ECD6FDD972342919E64
                          SHA1:225C6464CA0FE7CF5BEF790ABD7DBFEF7232890B
                          SHA-256:6AB63FBA0DEDFEAD6B75105378015DDC38F4C72007A1D2D4DB8BAEE9FE3CD93D
                          SHA-512:0290B6584C3DA452A7CA5EA654CF1B9834BA3409EF093470881CF9AE2C833E6BADDC462FB59D0B534FFFA6ED08199C1A8FE73FA6B706CFCF892E7D9BDFDE5E35
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[... ....]].[[screenshot_plugin.copy]]=[[... ....]].[[screenshot_plugin.print]]=[[....... ....]].[[screenshot_plugin.fullscreen]]=[[........ ....... ....... ....]].[[screenshot_plugin.clear]]=[[....... ..... ....]].[[screenshot_plugin.cancel]]=[[..... ....]].[[screenshot_plugin.editonline]]=[[....... .... ......... .... ....]].[[screenshot_plugin.upload]]=[[Prntscr.com . ..... ....]].[[screenshot_plugin.close]]=[[.... ....]]..[[screenshot_plugin.share_googlesearch]]=[[..... ... ..... ... ......]].[[screenshot_plugin.share_tineyesearch]]=[[Tineye .. ...... ... ......]].[[screenshot_plugin.share_sendmail]]=[[...... .....
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1014)
                          Category:dropped
                          Size (bytes):11574
                          Entropy (8bit):5.153798849120497
                          Encrypted:false
                          SSDEEP:
                          MD5:5765DD5FCA07300F79AD162F5BDEE1BF
                          SHA1:187C25B4D4307F43B7FF741A513D101D9D1010E2
                          SHA-256:37FB2455B89697F3F3442E355B8C3FC372D1C61FAF43C1567EC7894C6DEF0D5C
                          SHA-512:EC3B7741735A34921DD84A1FE454C5FB444E337F28D3CF36A6D8B7BEEFED39911E8856A9663798F27A10F23901AEF51AA83CA7DB78ED1F745C93A9EE10383E52
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Ment.s]].[[screenshot_plugin.copy]]=[[M.sol.s]].[[screenshot_plugin.print]]=[[Nyomtat.s]].[[screenshot_plugin.fullscreen]]=[[Teljes k.perny.]].[[screenshot_plugin.clear]]=[[Kijel.l.s t.rl.se]].[[screenshot_plugin.cancel]]=[[M.gsem]].[[screenshot_plugin.editonline]]=[[K.perny.ment.s szerkeszt.se online]].[[screenshot_plugin.upload]]=[[Felt.lt.s a prntscr.com-ra]].[[screenshot_plugin.close]]=[[Bez.r.s]]..[[screenshot_plugin.share_googlesearch]]=[[Hasonl. k.pek keres.se itt: Google]].[[screenshot_plugin.share_tineyesearch]]=[[Hasonl. k.pek keres.se itt: Tineye]].[[screenshot_plugin.share_sendmail]]=[[Elk.ld.se email .ltal]].[[screenshot_plugin.share_twitter]]=[[Megoszt.s a Twitteren]].[[screenshot_plugin.share_facebook]]=[[Megoszt.s a Facebookon]].[[screenshot_plugin.share_vk]]=[[Megoszt.s a VK-n]].[[screenshot_plugin.share_pinterest]]=[[Megoszt.s a Pinteresten]].[[screenshot_plugin.share]]=[[Megoszt.s a k.z.ss.gi port.l
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1109)
                          Category:dropped
                          Size (bytes):11376
                          Entropy (8bit):4.9286221743577405
                          Encrypted:false
                          SSDEEP:
                          MD5:D115749DC09721FA6C20257AFC71A64D
                          SHA1:CC741E1AB1BE8A6BC7C42AB265E86857F74894FB
                          SHA-256:5742F1EBCE39FBBAB90A6A3581E57B7B6C35D0CD9A2DD23BBA61712533F0C468
                          SHA-512:61CEB72D39504FA33780F74C077FDF7CD58128FB75AAFE48262FA4D15FC8E62D5EEA9DAE9C9B9F3A53040F5890DBCB263BB463F4C72712BB288EB5E919A4CA91
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Speichern]].[[screenshot_plugin.copy]]=[[Kopieren]].[[screenshot_plugin.print]]=[[Drucken]].[[screenshot_plugin.fullscreen]]=[[Kompletten Bildschirm ausw.hlen]].[[screenshot_plugin.clear]]=[[Auswahl aufheben]].[[screenshot_plugin.cancel]]=[[Abbrechen]].[[screenshot_plugin.editonline]]=[[Screenshot online bearbeiten]].[[screenshot_plugin.upload]]=[[Hochladen auf prntscr.com]].[[screenshot_plugin.close]]=[[Schlie.en]]..[[screenshot_plugin.share_googlesearch]]=[[Nach .hnlichen Bildern auf Google suchen]].[[screenshot_plugin.share_tineyesearch]]=[[Nach .hnlichen Bildern auf Tineye suchen]].[[screenshot_plugin.share_sendmail]]=[[Per Email verschicken]].[[screenshot_plugin.share_twitter]]=[[Auf Twitter teilen]].[[screenshot_plugin.share_facebook]]=[[Auf Facebook teilen]].[[screenshot_plugin.share_vk]]=[[Auf VK teilen]].[[screenshot_plugin.share_pinterest]]=[[Auf Pinterest teilen]].[[screenshot_plugin.share]]=[[Auf sozialen Netzwerken teilen]]..[[screenshot
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):3761
                          Entropy (8bit):4.75111012331288
                          Encrypted:false
                          SSDEEP:
                          MD5:B85E43201C3D051F8D4F5E7210E6E0BC
                          SHA1:C7FC7CCD6F8AC76F674D3B42CFAF2AF74EB1B515
                          SHA-256:5DEEBC0DC369C6E2F85E549C6AD38AF0F385CC0163373C857508AF3A8E96E8DF
                          SHA-512:15D2744DCED11591C4AF340F1C95595C41BDADEBC5C6BD1DED962A1DFBAA9159555F1DDD21714DD0C13E53600BD92F036D33861FF21760B1BC7E9202A4756D3C
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Desa]].[[screenshot_plugin.print]]=[[Imprimeix]].[[screenshot_plugin.fullscreen]]=[[Selecciona pantalla completa]].[[screenshot_plugin.clear]]=[[Neteja la selecci.]].[[screenshot_plugin.editonline]]=[[Editeu una captura de pantalla en l.nia]].[[screenshot_plugin.upload]]=[[Puja a prntscr.com]].[[screenshot_plugin.close]]=[[Tanca]]..[[screenshot_plugin.share_tineyesearch]]=[[Cerca imatges similars a Tineye]].[[screenshot_plugin.share_sendmail]]=[[Envia a trav.s de correu electr.nic]].[[screenshot_plugin.share_twitter]]=[[Comparteix al Twitter]].[[screenshot_plugin.share_facebook]]=[[Comparteix al Facebook]].[[screenshot_plugin.share_pinterest]]=[[Comparteix a Pinterest]].[[screenshot_plugin.share]]=[[Comparteix a les xarxes socials]]..[[screenshot_plugin.incorrect_size]]=[[Mida incorrecta]].[[screenshot_plugin.error_capt]]=[[Error]]..[[screenshot_plugin.open]]=[[Obre]]..[[screenshot_app.take_screenshot]]=[[Feu una captura de pantalla]].[[screenshot_ap
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (972)
                          Category:dropped
                          Size (bytes):10478
                          Entropy (8bit):4.9285769816878435
                          Encrypted:false
                          SSDEEP:
                          MD5:2B75C4A44B3D45B7F412638B34FC3D0E
                          SHA1:966765B328774BF3093EC293579C3D40DB215F27
                          SHA-256:269653CAA6B7C42F8E927CE48B273313302C8BF68E8DC67381F066F2F96C8D61
                          SHA-512:43CB33704A08158B6CBDBEFA71DD901F4383ACB2601C14DD4C75EA9A4F709D06F342B3B00D2AF7A9E9BBF785644FC93B8F0250E1BF643BAB823D6951BA83A92E
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Salvesta]].[[screenshot_plugin.copy]]=[[Kopeeri]].[[screenshot_plugin.print]]=[[Prindi]].[[screenshot_plugin.fullscreen]]=[[Vali t.isekraan]].[[screenshot_plugin.clear]]=[[Puhasta valitud]].[[screenshot_plugin.cancel]]=[[Loobu]].[[screenshot_plugin.editonline]]=[[Redigeeri kuvat.mmist v.rgus]].[[screenshot_plugin.upload]]=[[Lae .lesse prntscr.com lehele]].[[screenshot_plugin.close]]=[[Sule]]..[[screenshot_plugin.share_googlesearch]]=[[Otsi sarnaseid pilte Google-st]].[[screenshot_plugin.share_tineyesearch]]=[[Otsi sarnaseid pilte Tineye-st]].[[screenshot_plugin.share_sendmail]]=[[Saada E-mailga]].[[screenshot_plugin.share_twitter]]=[[Jaga Twitteris]].[[screenshot_plugin.share_facebook]]=[[Jaga Facebookis]].[[screenshot_plugin.share_vk]]=[[Jaga VKs]].[[screenshot_plugin.share_pinterest]]=[[Jaga Pinterest-is]].[[screenshot_plugin.share]]=[[Jaga sotsiaalv.rgustikes]]..[[screenshot_plugin.incorrect_size]]=[[Vale suurus]].[[screenshot_plugin.error_capt]]
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1029)
                          Category:dropped
                          Size (bytes):11134
                          Entropy (8bit):5.158411756543586
                          Encrypted:false
                          SSDEEP:
                          MD5:B42697871A6AD6A19E4825A1949AAB85
                          SHA1:8D24E98FD532E511E1C147180D50A950FD72BA05
                          SHA-256:306603A966B7ACB1B4FEEA9ECC94E08E0C5C686C520083206005B0929A812F41
                          SHA-512:577E554F69D401CBFA0FF71A8A0814B616AF5B38476FEBD750062F9704251D45546ADC70244CD8402A5FD2D944640D7E43D790E064E95313ADEB4BF2FC0B0CCB
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Zapisz]].[[screenshot_plugin.copy]]=[[Kopiuj]].[[screenshot_plugin.print]]=[[Drukuj]].[[screenshot_plugin.fullscreen]]=[[Zaznacz ca.y ekran]].[[screenshot_plugin.clear]]=[[Wyczy.. zaznaczenie]].[[screenshot_plugin.cancel]]=[[Anuluj]].[[screenshot_plugin.editonline]]=[[Edytuj zrzut ekranu online ]].[[screenshot_plugin.upload]]=[[Prze.lij do prntscr.com]].[[screenshot_plugin.close]]=[[Zamknij]]..[[screenshot_plugin.share_googlesearch]]=[[Szukaj podobnych obraz.w w Google]].[[screenshot_plugin.share_tineyesearch]]=[[Szukaj podobnych obrazk.w w Tineye]].[[screenshot_plugin.share_sendmail]]=[[Wy.lij e-mailem]].[[screenshot_plugin.share_twitter]]=[[Udost.pnij na Twitterze]].[[screenshot_plugin.share_facebook]]=[[Udost.pnij na Facebooku]].[[screenshot_plugin.share_vk]]=[[Udost.pnij na VK]].[[screenshot_plugin.share_pinterest]]=[[Udost.pnij na Pinterest]].[[screenshot_plugin.share]]=[[Udost.pnij w serwisach spo.eczno.ciowych]]..[[screenshot_plugin.
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (922)
                          Category:dropped
                          Size (bytes):11379
                          Entropy (8bit):5.149530343017641
                          Encrypted:false
                          SSDEEP:
                          MD5:A6A1B66FA9E552BF131CF58D1EC6D5E9
                          SHA1:F2971C40374259A63FDD0BECEF50AF7A2A4F738D
                          SHA-256:BDDA3AF25EE6A69886A3F6C83BBED160928A762EA3E4185F31EFC46FCF64D8F7
                          SHA-512:66D646C405EC4CF49753B0A6953B069565405A594BF0B21D00B85CE97081C7DE107F85760CC7F187BA90416978F7746C2BA75F63E6AD9B992B6764D2A862CA1E
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Kaydet]].[[screenshot_plugin.copy]]=[[Kopyala]].[[screenshot_plugin.print]]=[[Yazd.r]].[[screenshot_plugin.fullscreen]]=[[T.m ekran. se.]].[[screenshot_plugin.clear]]=[[Se.imi Temizle]].[[screenshot_plugin.cancel]]=[[.ptal]].[[screenshot_plugin.editonline]]=[[Ekran G.r.nt.s.n. .evrimi.i d.zenle]].[[screenshot_plugin.upload]]=[[Prntscr.com'a y.kle]].[[screenshot_plugin.close]]=[[Kapat]]..[[screenshot_plugin.share_googlesearch]]=[[Google'da benzer g.rselleri ara]].[[screenshot_plugin.share_tineyesearch]]=[[Tineye'de benzer g.rselleri ara]].[[screenshot_plugin.share_sendmail]]=[[E-posta ile g.nder]].[[screenshot_plugin.share_twitter]]=[[Twitter'da payla.]].[[screenshot_plugin.share_facebook]]=[[Facebook'da payla.]].[[screenshot_plugin.share_vk]]=[[VK'da payla.]].[[screenshot_plugin.share_pinterest]]=[[Pinterest'de payla.]].[[screenshot_plugin.share]]=[[Sosyal a.larda payla.]]..[[screenshot_plugin.incorrect_size]]=[[Hatal. Boyut]].[[
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):1853
                          Entropy (8bit):4.858703658195675
                          Encrypted:false
                          SSDEEP:
                          MD5:6EA5AF7F09D1CDD8929B1D6C2F8B9DFD
                          SHA1:7A185908954EFADDA847870CA30E344EDA0B72D1
                          SHA-256:6BC8AD750CB4142C2C628C3C3F3006C853A48566FC988CD7179EA6CAE0FF7A79
                          SHA-512:149456B744531945A7ABCD294F7B45EAE3959D8B672DE10431A26D9458E683B1A48D03136C672DAB00C804AC8F6738A6C35D0F18D48818F28038864499DCDB78
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Vista]].[[screenshot_plugin.copy]]=[[Afrita]].[[screenshot_plugin.print]]=[[Prenta]].[[screenshot_plugin.fullscreen]]=[[Velja fullan skj.]].[[screenshot_plugin.clear]]=[[Hreinsa]].[[screenshot_plugin.cancel]]=[[H.tta Vi.]].[[screenshot_plugin.editonline]]=[[Breyta Mynd]].[[screenshot_plugin.upload]]=[[Senda . prntscr.com]].[[screenshot_plugin.close]]=[[Loka]]..[[screenshot_plugin.share_googlesearch]]=[[Leita a. svipu.um myndum . Google]].[[screenshot_plugin.share_tineyesearch]]=[[Leita a. svipu.um myndum . Tineye]].[[screenshot_plugin.share_sendmail]]=[[Senda . email]].[[screenshot_plugin.share_twitter]]=[[Deila . Twitter]].[[screenshot_plugin.share_facebook]]=[[Deila in Facebook]]..[[screenshot_plugin.incorrect_size]]=[[Vitlaus St.r.]].[[screenshot_plugin.error_capt]]=[[Villa]]..[[screenshot_plugin.tooltip]]=[[Velja sv..i]].[[screenshot_plugin.open]]=[[Opna]].[[screenshot_plugin.uploading_window_capt]]=[[Sendi mynd]].[[screenshot_plugin.
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (1093)
                          Category:dropped
                          Size (bytes):11311
                          Entropy (8bit):4.823856219956849
                          Encrypted:false
                          SSDEEP:
                          MD5:A3C763A6AB5795AA432071DFF7262D22
                          SHA1:2297CE94424FE24144246CB4EEBEAFEC7C6972BA
                          SHA-256:E48BBA86D86DD2A2C0D8B789168BF7FA33CCCA80EB90BA2CA1CD1AFEEC70FB36
                          SHA-512:26DD8BBAAD6CAECE6AB0A406DF2B608012DD0CD40F24F47D78054C3CD85F75960158D68CE2E1C9AA52C2D0524DDE35A5D2B3AAD24B3ABCBBEC4A20EC8FCECC21
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Salva]].[[screenshot_plugin.copy]]=[[Copia]].[[screenshot_plugin.print]]=[[Stampa]].[[screenshot_plugin.fullscreen]]=[[Seleziona schermo intero]].[[screenshot_plugin.clear]]=[[Annulla selezione]].[[screenshot_plugin.cancel]]=[[Annulla]].[[screenshot_plugin.editonline]]=[[Modifica online uno screenshot]].[[screenshot_plugin.upload]]=[[Carica su prntscr.com]].[[screenshot_plugin.close]]=[[Chiuso]]..[[screenshot_plugin.share_googlesearch]]=[[Cerca immagini simili su Google]].[[screenshot_plugin.share_tineyesearch]]=[[Cerca immagini simili su Tineye]].[[screenshot_plugin.share_sendmail]]=[[Invia via email]].[[screenshot_plugin.share_twitter]]=[[Condividi su Twitter]].[[screenshot_plugin.share_facebook]]=[[Condividi su Facebook]].[[screenshot_plugin.share_vk]]=[[Condividi su VK]].[[screenshot_plugin.share_pinterest]]=[[Condividi su Pinterest]].[[screenshot_plugin.share]]=[[Condividi sui social network]]..[[screenshot_plugin.incorrect_size]]=[[Dimensione sbagl
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):2100
                          Entropy (8bit):5.4607972532477875
                          Encrypted:false
                          SSDEEP:
                          MD5:4582B37D89F133893F2095D7B57A3AD1
                          SHA1:3242904BEDF29E6AFC5BB6AEB1DCB7A994C84ECC
                          SHA-256:EE6DFB2E7262954FA5365FAD842B24CD53AFB5E23AF523751D8211B4CC5A8891
                          SHA-512:8FC673A7405499DE5DE184A695ECEDBFA230C0A0CA6A1D74AC7B6A08E3629A64537CEE016AFB85FFE64E7B6460DF4BCC183B7DA1AD1418D48A6482FB59B50E42
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..]].[[screenshot_plugin.copy]]=[[...]].[[screenshot_plugin.print]]=[[..]].[[screenshot_plugin.fullscreen]]=[[.......]].[[screenshot_plugin.clear]]=[[....]].[[screenshot_plugin.cancel]]=[[.....]].[[screenshot_plugin.editonline]]=[[............]].[[screenshot_plugin.upload]]=[["prntscr.com" .......]].[[screenshot_plugin.close]]=[[...]]..[[screenshot_plugin.share_googlesearch]]=[["Google" ........]].[[screenshot_plugin.share_tineyesearch]]=[["Tineye" ........]].[[screenshot_plugin.share_sendmail]]=[[......]].[[screenshot_plugin.share_twitter]]=[["Twitter" ...]].[[screenshot_plugin.share_facebook]]=[["Facebook" ...]]..[[screenshot_plugin.incorrect_size]]=[[.......]].[[screenshot_plugin.error_capt]]=[[...]]..[[screenshot_plugin.tooltip]]=[[.....]].[[screenshot_plugin.open]]=[[..]].
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (321)
                          Category:dropped
                          Size (bytes):14334
                          Entropy (8bit):4.609688160373262
                          Encrypted:false
                          SSDEEP:
                          MD5:4D839F6C4DB8B58158BA136BBE209E50
                          SHA1:BA84439054819925F1FCC8118536B12F67A4262B
                          SHA-256:8844248F8E3446BB01581C801275E060C0E8171B150C84A2552D26ECCC1349D5
                          SHA-512:7EC12E55AAD2EF65F57B08F53FD392E5D2278402FDFB1F6BB6E22A4212D40F7300FBACD269F57D29BC24443CD7643969DA85013375613CB0407C597726AFEF5F
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.......]].[[screenshot_plugin.copy]]=[[........]].[[screenshot_plugin.print]]=[[........]].[[screenshot_plugin.fullscreen]]=[[..... ....... ......]].[[screenshot_plugin.clear]]=[[...........]].[[screenshot_plugin.cancel]]=[[........]].[[screenshot_plugin.editonline]]=[[......... ...... ........]].[[screenshot_plugin.upload]]=[[........ prntscr.com-..]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_googlesearch]]=[[....... ....... ....... Google-..]].[[screenshot_plugin.share_tineyesearch]]=[[....... ....... ....... Tineye-..]].[[screenshot_plugin.share_sendmail]]=[[...... ........ ..-.......]].[[screen
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (758)
                          Category:dropped
                          Size (bytes):11110
                          Entropy (8bit):5.888845253303549
                          Encrypted:false
                          SSDEEP:
                          MD5:99F15556368A9025A678AE20E3E5EDB4
                          SHA1:1DAE062FE596367350FA7EAE68BBF1645C11A143
                          SHA-256:F07C0EE08ED2895729E734B349B1AF3CA8A0646126FD4E3A01D37A8DE299B7B8
                          SHA-512:BC69A8371EAE0AADDDB6B507E1B5E49F9BD18AB0595C0C8FCA02F9648E2736CCD6406907D3DD38121912D2FAC00639F563FBDFEE458876604692ECF05CC08906
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[..]].[[screenshot_plugin.copy]]=[[..]].[[screenshot_plugin.print]]=[[..]].[[screenshot_plugin.fullscreen]]=[[.. .. ..]].[[screenshot_plugin.clear]]=[[.. ..]].[[screenshot_plugin.cancel]]=[[..]].[[screenshot_plugin.editonline]]=[[..... .... ..]].[[screenshot_plugin.upload]]=[[Prntscr.com. ...]].[[screenshot_plugin.close]]=[[..]]..[[screenshot_plugin.share_googlesearch]]=[[Google.. ... ... ..]].[[screenshot_plugin.share_tineyesearch]]=[[Tineye.. ... ... ..]].[[screenshot_plugin.share_sendmail]]=[[.... ...]].[[screenshot_plugin.share_twitter]]=[[Twitter. ..]].[[screenshot_plugin.share_facebook]]=[[Facebook.. ..]].[[screenshot_plugin.share_vk]]=[[VK. ..]].[[screenshot_plugin.share_pinterest]]=[[Pinterest. ..]].[[screenshot_plugin.share]]=[[.. ..... ..]]..[[screenshot_plugin.incorrect_size]]=[[
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):11282
                          Entropy (8bit):5.22650088499113
                          Encrypted:false
                          SSDEEP:
                          MD5:ADDA7B38ACB9923473E8E5F8FE9555F0
                          SHA1:73C3BEF88E8ED893A98A19F702EA9F7C159D30F8
                          SHA-256:88F1EC35A57672CB75E96662819901899F8BC7CE546B3DA3AAD636229D4695D1
                          SHA-512:B214D0AFDB5546EFBD8C95C758EF0B8EAC4C19462B44645220BB8FBB4BBABAB5CD066E7C56850C67E11BEFD173B49C4C1010023338FA66F1F5B9D6EC4083CAC7
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[............]].[[screenshot_plugin.copy]]=[[............]].[[screenshot_plugin.print]]=[[.......]].[[screenshot_plugin.fullscreen]]=[[.......... ..... ......]].[[screenshot_plugin.clear]]=[[....... ............]].[[screenshot_plugin.cancel]]=[[.....]].[[screenshot_plugin.editonline]]=[[.......... ..... ..... ....]].[[screenshot_plugin.upload]]=[[Prntscr.com ............ .... ..]].[[screenshot_plugin.close]]=[[......]]..[[screenshot_plugin.share_googlesearch]]=[[..... .. ..... ....... .. .... ]].[[screenshot_plugin.share_tineyesearch]]=[[Tineye ..... .. ..... ....... .. ]].[[screenshot_plugin.share_sendmail]]=[[..... ....... ........]].[[screenshot_plugin.share_twitter]]=[[........... .. ......]].[[screenshot_plugin.share_facebook]]=[[........
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (606)
                          Category:dropped
                          Size (bytes):9229
                          Entropy (8bit):4.988338896224836
                          Encrypted:false
                          SSDEEP:
                          MD5:BDD17AB1EDA8488B8CFE02327DF05F90
                          SHA1:031F1B7B21FB7C8BAA2FCD6FAD0589D8C5437629
                          SHA-256:0E251986CD97BDE529CC2726EFC18F821661301DF1B8F44FB17898F851393D82
                          SHA-512:4853412D4FC5A0293EC5F4C92F468B06924C00DEBDAA8A2B6372CD0C339D1C5B2B7360CF1BE353E2459ACEBA7C82AF33B04F552733E221C2A5CBE9246BE3277E
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[I.saugoti]].[[screenshot_plugin.copy]]=[[Kopijuoti]].[[screenshot_plugin.print]]=[[Spausdinti]].[[screenshot_plugin.fullscreen]]=[[Pasirinkti vis. ekrano vaizd.]].[[screenshot_plugin.clear]]=[[I.trinti pasirinkim.]].[[screenshot_plugin.cancel]]=[[At.aukti]].[[screenshot_plugin.editonline]]=[[Koreguoti paveiksl.l. internete]].[[screenshot_plugin.upload]]=[[.kelti . prntscr.com]].[[screenshot_plugin.close]]=[[U.daryti]]..[[screenshot_plugin.share_googlesearch]]=[[Ie.koti pana.i. paveiksl.li. per Google]].[[screenshot_plugin.share_tineyesearch]]=[[Ie.koti pana.i. paveiksl.li. per Tineye]].[[screenshot_plugin.share_sendmail]]=[[I.si.sti elektroniniu pa.tu]].[[screenshot_plugin.share_twitter]]=[[Pasidalinti per Twitter]].[[screenshot_plugin.share_facebook]]=[[Pasidalinti per Facebook]].[[screenshot_plugin.share_vk]]=[[Pasidalinti per VK]].[[screenshot_plugin.share_pinterest]]=[[Pasidalinti per Pinterest]].[[screenshot_plugin.share]]=[[
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):7252
                          Entropy (8bit):5.0367350116439455
                          Encrypted:false
                          SSDEEP:
                          MD5:282E5B1C57E18FA97A4D54AFEFDF2485
                          SHA1:D64C78923257FBDF9F136C2F1BC0D817305FB211
                          SHA-256:DDD5A868F9E0C9F988225B1E99223AA45C75122D9E5A399BED508D3C96EA6CD2
                          SHA-512:4581DD61F28A691F6AB00EC8C8F4E8B87DA15822D426167A623B1818ED1ED37CD5F07EB7328BE2977AADA422B544B049F112AD5AC5C94E5214A32C54556652DF
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[Saglab.t]].[[screenshot_plugin.copy]]=[[Kop.t]].[[screenshot_plugin.print]]=[[Druk.t]].[[screenshot_plugin.fullscreen]]=[[Iez.m.t pilnu ekr.nu]].[[screenshot_plugin.clear]]=[[Not.r.t iez.m.to]].[[screenshot_plugin.cancel]]=[[Atcelt]].[[screenshot_plugin.editonline]]=[[Redi..t ekr.nuz..mumu internet. onlain.]].[[screenshot_plugin.upload]]=[[Aug.upiel.d.t uz prntscr.com]].[[screenshot_plugin.close]]=[[Aizv.rt]]..[[screenshot_plugin.share_googlesearch]]=[[Mekl.t l.dz.gus att.lus Google]].[[screenshot_plugin.share_tineyesearch]]=[[Mekl.t l.dz.gus att.lus Tineye]].[[screenshot_plugin.share_sendmail]]=[[Nos.t.t pa e-pastu]].[[screenshot_plugin.share_twitter]]=[[Kop.got Twitter vietn.]].[[screenshot_plugin.share_facebook]]=[[Kop.got Facebook vietn.]].[[screenshot_plugin.share_vk]]=[[Kop.got VK vietn.]].[[screenshot_plugin.share_pinterest]]=[[Dal.ties Pinterest vietn.]].[[screenshot_plugin.share]]=[[Kop.got soci.lajos t.
                          Process:C:\Users\user\AppData\Local\Temp\is-0KHQ7.tmp\setup-lightshot.tmp
                          File Type:Unicode text, UTF-8 (with BOM) text
                          Category:dropped
                          Size (bytes):6048
                          Entropy (8bit):5.114480664907674
                          Encrypted:false
                          SSDEEP:
                          MD5:70BA5C9C3E83584713663332BCF0ED60
                          SHA1:2093C3D4A269D6D80714E2DEB0F86B727B43B82E
                          SHA-256:4B04AC2BF41F9A71FD626297956759B0F3321851BFCDBB4D788EAFD3BC662EE8
                          SHA-512:F379313B91FD4EB976736C4D65624215FEFD381323F2F469E6AE7BDE2BE79B5DE6F5B34B28B90DCA1D3BE7BD5496DBC85DF5A0E22E88A1F4C38E2F30824AB132
                          Malicious:false
                          Reputation:low
                          Preview:.[[screenshot_plugin.save]]=[[.......]].[[screenshot_plugin.fullscreen]]=[[...... ....... .....]].[[screenshot_plugin.editonline]]=[[..... ........ ......]].[[screenshot_plugin.close]]=[[.......]]..[[screenshot_plugin.share_googlesearch]]=[[.......... ...... ..... .. ......]].[[screenshot_plugin.share_twitter]]=[[....... .. Twitter]].[[screenshot_plugin.share_facebook]]=[[....... .. Facebook]].[[screenshot_plugin.share_pinterest]]=[[....... .. Pinterest]].[[screenshot_plugin.share]]=[[......... .. ........... .....]]..[[screenshot_plugin.error_capt]]=[[......]]..[[screenshot_plugin.tooltip]]=[[.......... ........]].[[screenshot_plugin.open]]=[[......]].[[screenshot_plugin.upload_failed_retry]]=[[............. .. .... ........ ....... .. ........?]]..[[screenshot_app.take_screensho
                          File type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Entropy (8bit):7.774912772810246
                          TrID:
                          • Win32 Executable (generic) a (10002005/4) 99.94%
                          • Win16/32 Executable Delphi generic (2074/23) 0.02%
                          • Generic Win/DOS Executable (2004/3) 0.02%
                          • DOS Executable Generic (2002/1) 0.02%
                          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                          File name:setup-lightshot.exe
                          File size:2'786'328 bytes
                          MD5:a1f6923e771b4ff0df9fec9555f97c65
                          SHA1:545359cd68d0ee37f4b15e1a22c2c9a5fda69e22
                          SHA256:928c2808421dfd487ffa697379548cbe682c0e13aeb595eb89973ba9c515b8a1
                          SHA512:c9e54f48208151dcf60bf049d09a5c69f6ef7e4f046359fdfd50c61d49a6f9a37c3d3a2016d4beb70ae47270e9e9689e03064c02bee1e1d3d95998000e47f153
                          SSDEEP:49152:/i85nVhfVnQiGmEwZbyVKf3tOOr/o2rm0mMXgT11rNjiG0C+0LRzasw:a85nVZarmEwZecPzJWDLN+GwOnw
                          TLSH:A2D512C1A1A550B1E9A8B8F1B966D4112CF63CA84DC3544D3EF9F23E0472A87DD3A91F
                          File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                          Icon Hash:0c06920363ed6d19
                          Entrypoint:0x41181c
                          Entrypoint Section:.itext
                          Digitally signed:true
                          Imagebase:0x400000
                          Subsystem:windows gui
                          Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                          DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                          Time Stamp:0x5B226D52 [Thu Jun 14 13:27:46 2018 UTC]
                          TLS Callbacks:
                          CLR (.Net) Version:
                          OS Version Major:5
                          OS Version Minor:0
                          File Version Major:5
                          File Version Minor:0
                          Subsystem Version Major:5
                          Subsystem Version Minor:0
                          Import Hash:20dd26497880c05caed9305b3c8b9109
                          Signature Valid:true
                          Signature Issuer:CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US
                          Signature Validation Error:The operation completed successfully
                          Error Number:0
                          Not Before, Not After
                          • 5/30/2019 2:39:46 AM 5/30/2022 2:39:46 AM
                          Subject Chain
                          • CN=Kilonova LLC, O=Kilonova LLC, L=Seattle, S=Washington, C=US
                          Version:3
                          Thumbprint MD5:01CF5F0DB47B2689D338B977568A2CED
                          Thumbprint SHA-1:65F3B3CC35EFDEC600A6E68FF7A5C1DEF5054EC9
                          Thumbprint SHA-256:450898F0278E753151C321FF1A5C4CF37B7AE36B03A8214447A486D4D41A27E1
                          Serial:00C93423CE0C606667
                          Instruction
                          push ebp
                          mov ebp, esp
                          add esp, FFFFFFA4h
                          push ebx
                          push esi
                          push edi
                          xor eax, eax
                          mov dword ptr [ebp-3Ch], eax
                          mov dword ptr [ebp-40h], eax
                          mov dword ptr [ebp-5Ch], eax
                          mov dword ptr [ebp-30h], eax
                          mov dword ptr [ebp-38h], eax
                          mov dword ptr [ebp-34h], eax
                          mov dword ptr [ebp-2Ch], eax
                          mov dword ptr [ebp-28h], eax
                          mov dword ptr [ebp-14h], eax
                          mov eax, 0041015Ch
                          call 00007F58B47550BDh
                          xor eax, eax
                          push ebp
                          push 00411EFEh
                          push dword ptr fs:[eax]
                          mov dword ptr fs:[eax], esp
                          xor edx, edx
                          push ebp
                          push 00411EBAh
                          push dword ptr fs:[edx]
                          mov dword ptr fs:[edx], esp
                          mov eax, dword ptr [00415B48h]
                          call 00007F58B475D81Bh
                          call 00007F58B475D36Ah
                          cmp byte ptr [00412AE0h], 00000000h
                          je 00007F58B476033Eh
                          call 00007F58B475D930h
                          xor eax, eax
                          call 00007F58B4753155h
                          lea edx, dword ptr [ebp-14h]
                          xor eax, eax
                          call 00007F58B475A39Bh
                          mov edx, dword ptr [ebp-14h]
                          mov eax, 00418658h
                          call 00007F58B475372Ah
                          push 00000002h
                          push 00000000h
                          push 00000001h
                          mov ecx, dword ptr [00418658h]
                          mov dl, 01h
                          mov eax, dword ptr [0040C04Ch]
                          call 00007F58B475ACB2h
                          mov dword ptr [0041865Ch], eax
                          xor edx, edx
                          push ebp
                          push 00411E66h
                          push dword ptr fs:[edx]
                          mov dword ptr fs:[edx], esp
                          call 00007F58B475D88Eh
                          mov dword ptr [00418664h], eax
                          mov eax, dword ptr [00418664h]
                          cmp dword ptr [eax+0Ch], 01h
                          jne 00007F58B476037Ah
                          NameVirtual AddressVirtual Size Is in Section
                          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                          IMAGE_DIRECTORY_ENTRY_IMPORT0x190000xe04.idata
                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x1c0000x64408.rsrc
                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                          IMAGE_DIRECTORY_ENTRY_SECURITY0x2a6a700x19a8
                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                          IMAGE_DIRECTORY_ENTRY_TLS0x1b0000x18.rdata
                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                          IMAGE_DIRECTORY_ENTRY_IAT0x193040x214.idata
                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                          NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                          .text0x10000xf25c0xf400False0.5482197745901639data6.375879013420213IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                          .itext0x110000xfa40x1000False0.563720703125data5.778765357049134IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                          .data0x120000xc8c0xe00False0.25362723214285715data2.3028287433175367IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                          .bss0x130000x56bc0x0False0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                          .idata0x190000xe040x1000False0.321533203125data4.597812557707959IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                          .tls0x1a0000x80x0False0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                          .rdata0x1b0000x180x200False0.05078125data0.2044881574398449IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                          .rsrc0x1c0000x644080x64600False0.21693551525529264data4.905507363696471IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                          NameRVASizeTypeLanguageCountryZLIB Complexity
                          RT_ICON0x1c47c0x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.6675531914893617
                          RT_ICON0x1c8e40x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.5098499061913696
                          RT_ICON0x1d98c0x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.41773858921161827
                          RT_ICON0x1ff340x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.3512045347189419
                          RT_ICON0x2415c0x10828Device independent bitmap graphic, 128 x 256 x 32, image size 67584EnglishUnited States0.25592984739145863
                          RT_ICON0x349840x42028Device independent bitmap graphic, 256 x 512 x 32, image size 270336EnglishUnited States0.19482498446607688
                          RT_STRING0x769ac0x68data0.6538461538461539
                          RT_STRING0x76a140xd4data0.5283018867924528
                          RT_STRING0x76ae80xa4data0.6524390243902439
                          RT_STRING0x76b8c0x2acdata0.45614035087719296
                          RT_STRING0x76e380x34cdata0.4218009478672986
                          RT_STRING0x771840x294data0.4106060606060606
                          RT_RCDATA0x774180x82e8dataEnglishUnited States0.11261637622344235
                          RT_RCDATA0x7f7000x10data1.5
                          RT_RCDATA0x7f7100x150data0.8392857142857143
                          RT_RCDATA0x7f8600x2cdata1.2045454545454546
                          RT_GROUP_ICON0x7f88c0x5adataEnglishUnited States0.7555555555555555
                          RT_VERSION0x7f8e80x4f4dataEnglishUnited States0.27602523659305994
                          RT_MANIFEST0x7fddc0x62cXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4240506329113924
                          DLLImport
                          oleaut32.dllSysFreeString, SysReAllocStringLen, SysAllocStringLen
                          advapi32.dllRegQueryValueExW, RegOpenKeyExW, RegCloseKey
                          user32.dllGetKeyboardType, LoadStringW, MessageBoxA, CharNextW
                          kernel32.dllGetACP, Sleep, VirtualFree, VirtualAlloc, GetSystemInfo, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenW, lstrcpynW, LoadLibraryExW, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetLocaleInfoW, GetCommandLineW, FreeLibrary, FindFirstFileW, FindClose, ExitProcess, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle, CloseHandle
                          kernel32.dllTlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleW
                          user32.dllCreateWindowExW, TranslateMessage, SetWindowLongW, PeekMessageW, MsgWaitForMultipleObjects, MessageBoxW, LoadStringW, GetSystemMetrics, ExitWindowsEx, DispatchMessageW, DestroyWindow, CharUpperBuffW, CallWindowProcW
                          kernel32.dllWriteFile, WideCharToMultiByte, WaitForSingleObject, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, SizeofResource, SignalObjectAndWait, SetLastError, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResetEvent, RemoveDirectoryW, ReadFile, MultiByteToWideChar, LockResource, LoadResource, LoadLibraryW, GetWindowsDirectoryW, GetVersionExW, GetVersion, GetUserDefaultLangID, GetThreadLocale, GetSystemInfo, GetSystemDirectoryW, GetStdHandle, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetLocaleInfoW, GetLastError, GetFullPathNameW, GetFileSize, GetFileAttributesW, GetExitCodeProcess, GetEnvironmentVariableW, GetDiskFreeSpaceW, GetCurrentProcess, GetCommandLineW, GetCPInfo, InterlockedExchange, InterlockedCompareExchange, FreeLibrary, FormatMessageW, FindResourceW, EnumCalendarInfoW, DeleteFileW, CreateProcessW, CreateFileW, CreateEventW, CreateDirectoryW, CloseHandle
                          advapi32.dllRegQueryValueExW, RegOpenKeyExW, RegCloseKey, OpenProcessToken, LookupPrivilegeValueW
                          comctl32.dllInitCommonControls
                          kernel32.dllSleep
                          advapi32.dllAdjustTokenPrivileges
                          Language of compilation systemCountry where language is spokenMap
                          EnglishUnited States