Edit tour

Windows Analysis Report
OneDriveSetUp.exe

Overview

General Information

Sample name:OneDriveSetUp.exe
Analysis ID:1365145
MD5:b471e4c796f44facbb40eac898b67503
SHA1:83bb0594f58ecca19b42a86f35d70774f390d823
SHA256:3084f8d75b253fd978855959eeb38bbd68f39dad1012486c73d4a9a91dfe4ddd

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Binary contains a suspicious time stamp
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Program does not show much activity (idle)
Tries to load missing DLLs

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious

Analysis Advice

Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
  • System is w10x64
  • OneDriveSetUp.exe (PID: 8 cmdline: C:\Users\user\Desktop\OneDriveSetUp.exe MD5: B471E4C796F44FACBB40EAC898B67503)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: OneDriveSetUp.exeStatic PE information: certificate valid
Source: OneDriveSetUp.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Binary string: D:\dbs\sh\odct\1115_093205_1\client\onedrive\Setup\Standalone\exe\obj\amd64\OneDriveSetup.pdb source: OneDriveSetUp.exe
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2#OneDrive
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2#OneDrive-1
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2#OneDriveta
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2$Chan
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2$Det
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2%Nem
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2%OneDrive
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2%Storitve
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2&OneDrive
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2(OneDrive
Source: OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://aka.ms/AAbbac2)OneDrive
Source: OneDriveSetUp.exeString found in binary or memory: https://clients.config.office.net/collector/v1.0/inventoryodb0.010.03ar;bg;ca;cs;da;de;el;en;en-GB;e
Source: OneDriveSetUp.exeString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey25.016393=%I.%M
Source: OneDriveSetUp.exeString found in binary or memory: https://dc.services.visualstudio.com/v2/track
Source: OneDriveSetUp.exeString found in binary or memory: https://dc.services.visualstudio.com/v2/trackh
Source: OneDriveSetUp.exeString found in binary or memory: https://g.live.com/odclientsettings/EnterpriseV2https://g.live.com/odclientsettings/MsitFastV2https:
Source: OneDriveSetUp.exeStatic PE information: Resource name: PAYLOAD type: Microsoft Cabinet archive data, many, 59599736 bytes, 950 files, at 0x44 +A "adal.dll" +A "alertIcon.png", flags 0x4, number 1, extra bytes 20 in head, 7587 datablocks, 0x1503 compression
Source: C:\Users\user\Desktop\OneDriveSetUp.exeSection loaded: version_orig.dllJump to behavior
Source: classification engineClassification label: clean1.winEXE@1/0@0/0
Source: OneDriveSetUp.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\OneDriveSetUp.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: OneDriveSetUp.exe, 00000000.00000002.2921543066.00007FF6A01E0000.00000008.00000001.01000000.00000003.sdmp, OneDriveSetUp.exe, 00000000.00000000.1673063265.00007FF6A01E0000.00000008.00000001.01000000.00000003.sdmpBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: OneDriveSetUp.exe, 00000000.00000002.2921543066.00007FF6A01E0000.00000008.00000001.01000000.00000003.sdmp, OneDriveSetUp.exe, 00000000.00000000.1673063265.00007FF6A01E0000.00000008.00000001.01000000.00000003.sdmpBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: OneDriveSetUp.exe, 00000000.00000002.2921543066.00007FF6A01E0000.00000008.00000001.01000000.00000003.sdmp, OneDriveSetUp.exe, 00000000.00000000.1673063265.00007FF6A01E0000.00000008.00000001.01000000.00000003.sdmpBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: OneDriveSetUp.exe, 00000000.00000002.2921543066.00007FF6A01E0000.00000008.00000001.01000000.00000003.sdmp, OneDriveSetUp.exe, 00000000.00000000.1673063265.00007FF6A01E0000.00000008.00000001.01000000.00000003.sdmpBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: OneDriveSetUp.exeString found in binary or memory: Software\RegisteredApplicationsSoftware\Microsoft\SkyDriveSoftware\Microsoft\Windows\CurrentVersion\UninstallSoftware\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersLocal AppDataSYSTEM\CurrentControlSet\Control\Session Manager\EnvironmentTMPUserInitiatedUninstallrefcount.iniMigrationCompletedMicrosoft SkyDriveMicrosoft OneDrivesetupMicrosoft\OneDriveMicrosoft\SkyDriveMicrosoft\OneDrive\setup\logs\DeletedDirectoriesGlobal\SkyDriveSetup-E678D3F5-C063-4161-8F0D-CBB04C96A016Global\OneDriveSetup-A03BCD95-2F7C-40A1-8557-ECF26D67C053logsMicrosoft\OneDrive\logssettingsClientPolicy.iniUpdateSkyDriveSetup.exeOneDriveSetup.exeThis is the registry for Microsoft OneDrive19.9999.9999.9999manifest.xmlListSync /permachine /peruser /silent /uninstall /childprocess /cusid /update /selfrepair /onedriverepair /vermismatchrepair /restart /detectprivsneeded /oem /thfirstsetup /extractFilesWithLessThreadCount /extractFilesInBackgroundThreadMode /enableOMCTelemetry /enableAriaUtc /WOFCompressionKillSwitch /removeNonCurrentVersions /allusers /renameReplaceOneDriveExe /renameReplaceODSUExe /enableODSUReportingMode /installWebView2 /SetPerProcessSystemDPIForceOffKey /RemovePerProcessSystemDPIForceOffKeyKillSwitch /EnableNucleusAutoStartFixSOFTWARE\Microsoft\Windows\CurrentVersion\RunOneDriveSetupSOFTWARE\Microsoft\Windows\CurrentVersion\RunOncevector too long,;
Source: OneDriveSetUp.exeString found in binary or memory: -aDdB
Source: OneDriveSetUp.exeStatic PE information: certificate valid
Source: initial sampleStatic PE information: Valid certificate with Microsoft Issuer
Source: OneDriveSetUp.exeStatic PE information: More than 263 > 100 exports found
Source: OneDriveSetUp.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: OneDriveSetUp.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: OneDriveSetUp.exeStatic file information: File size 65185712 > 1048576
Source: OneDriveSetUp.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x33de00
Source: OneDriveSetUp.exeStatic PE information: Raw size of .rdata is bigger than: 0x100000 < 0x110400
Source: OneDriveSetUp.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x3995e00
Source: OneDriveSetUp.exeStatic PE information: More than 200 imports for KERNEL32.dll
Source: OneDriveSetUp.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: OneDriveSetUp.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: OneDriveSetUp.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: OneDriveSetUp.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: OneDriveSetUp.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: OneDriveSetUp.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: OneDriveSetUp.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: OneDriveSetUp.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: D:\dbs\sh\odct\1115_093205_1\client\onedrive\Setup\Standalone\exe\obj\amd64\OneDriveSetup.pdb source: OneDriveSetUp.exe
Source: OneDriveSetUp.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: OneDriveSetUp.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: OneDriveSetUp.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: OneDriveSetUp.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: OneDriveSetUp.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: OneDriveSetUp.exeStatic PE information: 0xAF3B1A71 [Wed Feb 28 11:03:13 2063 UTC]
Source: OneDriveSetUp.exeStatic PE information: section name: .didat
Source: OneDriveSetUp.exeStatic PE information: section name: _RDATA
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\OneDriveSetUp.exeCode function: 0_2_00007FF69FF79D64 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF69FF79D64
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
1
DLL Side-Loading
1
Timestomp
OS Credential Dumping1
System Time Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
DLL Side-Loading
LSASS Memory2
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataSIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1365145 Sample: OneDriveSetUp.exe Startdate: 20/12/2023 Architecture: WINDOWS Score: 1 4 OneDriveSetUp.exe 2->4         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
OneDriveSetUp.exe0%ReversingLabs
OneDriveSetUp.exe0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://dc.services.visualstudio.com/v2/trackhOneDriveSetUp.exefalse
    high
    https://aka.ms/AAbbac2#OneDriveOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
      high
      https://aka.ms/AAbbac2#OneDrive-1OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
        high
        https://aka.ms/AAbbac2(OneDriveOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
          high
          https://aka.ms/AAbbac2#OneDrivetaOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
            high
            https://aka.ms/AAbbac2%StoritveOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
              high
              https://clients.config.office.net/user/v1.0/tenantassociationkey25.016393=%I.%MOneDriveSetUp.exefalse
                high
                https://aka.ms/AAbbac2$DetOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
                  high
                  https://aka.ms/AAbbac2&OneDriveOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
                    high
                    https://clients.config.office.net/collector/v1.0/inventoryodb0.010.03ar;bg;ca;cs;da;de;el;en;en-GB;eOneDriveSetUp.exefalse
                      high
                      https://aka.ms/AAbbac2OneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
                        high
                        https://aka.ms/AAbbac2%NemOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
                          high
                          https://aka.ms/AAbbac2)OneDriveOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
                            high
                            https://aka.ms/AAbbac2%OneDriveOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
                              high
                              https://dc.services.visualstudio.com/v2/trackOneDriveSetUp.exefalse
                                high
                                https://g.live.com/odclientsettings/EnterpriseV2https://g.live.com/odclientsettings/MsitFastV2https:OneDriveSetUp.exefalse
                                  high
                                  https://aka.ms/AAbbac2$ChanOneDriveSetUp.exe, 00000000.00000000.1673104566.00007FF6A3B61000.00000002.00000001.01000000.00000003.sdmpfalse
                                    high
                                    No contacted IP infos
                                    Joe Sandbox version:38.0.0 Ammolite
                                    Analysis ID:1365145
                                    Start date and time:2023-12-20 16:56:04 +01:00
                                    Joe Sandbox product:CloudBasic
                                    Overall analysis duration:0h 5m 17s
                                    Hypervisor based Inspection enabled:false
                                    Report type:full
                                    Cookbook file name:default.jbs
                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                    Number of analysed new started processes analysed:5
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Sample name:OneDriveSetUp.exe
                                    Detection:CLEAN
                                    Classification:clean1.winEXE@1/0@0/0
                                    EGA Information:Failed
                                    HCA Information:
                                    • Successful, ratio: 100%
                                    • Number of executed functions: 0
                                    • Number of non-executed functions: 0
                                    Cookbook Comments:
                                    • Found application associated with file extension: .exe
                                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                    • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                    • Execution Graph export aborted for target OneDriveSetUp.exe, PID 8 because there are no executed function
                                    • Not all processes where analyzed, report is missing behavior information
                                    No simulations
                                    No context
                                    No context
                                    No context
                                    No context
                                    No context
                                    No created / dropped files found
                                    File type:PE32+ executable (GUI) x86-64, for MS Windows
                                    Entropy (8bit):7.955559956136643
                                    TrID:
                                    • Win64 Executable GUI (202006/5) 92.65%
                                    • Win64 Executable (generic) (12005/4) 5.51%
                                    • Generic Win/DOS Executable (2004/3) 0.92%
                                    • DOS Executable Generic (2002/1) 0.92%
                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                    File name:OneDriveSetUp.exe
                                    File size:65'185'712 bytes
                                    MD5:b471e4c796f44facbb40eac898b67503
                                    SHA1:83bb0594f58ecca19b42a86f35d70774f390d823
                                    SHA256:3084f8d75b253fd978855959eeb38bbd68f39dad1012486c73d4a9a91dfe4ddd
                                    SHA512:e27e6642b78ff5e86571fa5e9a7ce2eb34dcd3d59d81368c83620f78bd0e2ce1ba07a10a20226f0b892168eb99b5b9ac73d8e0b7212173d5ffb6f27f67645215
                                    SSDEEP:1572864:WByu0K/9W9rHXaRJ6UdTpyNTTtMSmnpAmdzPIx:WBMMeHkIiTpyNTFkp5VIx
                                    TLSH:96E72306A7F901F5E0FAE2388AB36617FA727C655B31DB9F4251160A0F37BA09D39311
                                    File Content Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......-...i|..i|..i|.......|......z|......a|.......|......`|......R|......g|......k|......H|......^|..i|...~.......|.......|......h|.
                                    Icon Hash:8e172d4461e84521
                                    Entrypoint:0x1401e9210
                                    Entrypoint Section:.text
                                    Digitally signed:true
                                    Imagebase:0x140000000
                                    Subsystem:windows gui
                                    Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                    DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                                    Time Stamp:0xAF3B1A71 [Wed Feb 28 11:03:13 2063 UTC]
                                    TLS Callbacks:0x401e9300, 0x1, 0x401e9380, 0x1
                                    CLR (.Net) Version:
                                    OS Version Major:6
                                    OS Version Minor:0
                                    File Version Major:6
                                    File Version Minor:0
                                    Subsystem Version Major:6
                                    Subsystem Version Minor:0
                                    Import Hash:830d771eb3cf1fc69dcd5afd0a4a2d9a
                                    Signature Valid:true
                                    Signature Issuer:CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
                                    Signature Validation Error:The operation completed successfully
                                    Error Number:0
                                    Not Before, Not After
                                    • 19/10/2023 20:50:57 16/10/2024 20:50:57
                                    Subject Chain
                                    • CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
                                    Version:3
                                    Thumbprint MD5:85BB306029288A5127B76A61414E46CF
                                    Thumbprint SHA-1:3DA3E1A591E67BAA377A31CC88CA4B3C4815478F
                                    Thumbprint SHA-256:BA06A2B3BA853A2F04C7099FDC3A20B8D5C46B9B57559FE87AB076E139C0456A
                                    Serial:330000054E12B90A007B12499900000000054E
                                    Instruction
                                    dec eax
                                    sub esp, 28h
                                    call 00007FB458D3D2E0h
                                    dec eax
                                    add esp, 28h
                                    jmp 00007FB458D3C60Fh
                                    int3
                                    int3
                                    jmp 00007FB458D3BDACh
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    nop word ptr [eax+eax+00000000h]
                                    dec eax
                                    sub esp, 10h
                                    dec esp
                                    mov dword ptr [esp], edx
                                    dec esp
                                    mov dword ptr [esp+08h], ebx
                                    dec ebp
                                    xor ebx, ebx
                                    dec esp
                                    lea edx, dword ptr [esp+18h]
                                    dec esp
                                    sub edx, eax
                                    dec ebp
                                    cmovb edx, ebx
                                    dec esp
                                    mov ebx, dword ptr [00000010h]
                                    dec ebp
                                    cmp edx, ebx
                                    jnc 00007FB458D3C7A8h
                                    inc cx
                                    and edx, 8D4DF000h
                                    wait
                                    add al, dh
                                    NameVirtual AddressVirtual Size Is in Section
                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x4439e00x76a4.rdata
                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x44b0840x230.rdata
                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x4980000x3995c70.rsrc
                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x4760000x1f6f8.pdata
                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x3e282000x25b0.rsrc
                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x3e2e0000x5908.reloc
                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x3e7a900x70.rdata
                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_TLS0x3e7b800x28.rdata
                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x3e53f00x140.rdata
                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IAT0x33f0000x1398.rdata
                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x4438500x60.rdata
                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                    NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                    .text0x10000x33ddbc0x33de00unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                    .rdata0x33f0000x1103d60x110400False0.3043565986570248data4.885497142158017IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .data0x4500000x2538c0x1e800False0.18097624231557377data4.957836810712879IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    .pdata0x4760000x1f6f80x1f800False0.5073707217261905data6.1853284173794165IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .didat0x4960000x480x200False0.076171875data0.5649677521832702IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    _RDATA0x4970000x15c0x200False0.41015625data3.3465500236752033IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .rsrc0x4980000x3995c700x3995e00unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .reloc0x3e2e0000x59080x5a00False0.24596354166666667data5.4520261661251945IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                    EDPENLIGHTENEDAPPINFOID0x49a1740x2dataEnglishUnited States5.0
                                    EDPPERMISSIVEAPPINFOID0x49a1780x2dataEnglishUnited States5.0
                                    PAYLOAD0x49a17c0x38d91c0Microsoft Cabinet archive data, many, 59599736 bytes, 950 files, at 0x44 +A "adal.dll" +A "alertIcon.png", flags 0x4, number 1, extra bytes 20 in head, 7587 datablocks, 0x1503 compressionEnglishUnited States0.9651641845703125
                                    PNG0x3d7333c0x2906PNG image data, 321 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9824795277090078
                                    WEVT_TEMPLATE0x3d75c440x21adataEnglishUnited States0.5464684014869888
                                    RT_ICON0x3d75e600x8c6PNG image data, 128 x 128, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9652715939447908
                                    RT_ICON0x3d767280x94a8Device independent bitmap graphic, 96 x 192 x 32, image size 0EnglishUnited States0.03626235022072735
                                    RT_ICON0x3d7fbd00x67e8Device independent bitmap graphic, 80 x 160 x 32, image size 0EnglishUnited States0.045526315789473686
                                    RT_ICON0x3d863b80x4228Device independent bitmap graphic, 64 x 128 x 32, image size 0EnglishUnited States0.0543221539914974
                                    RT_ICON0x3d8a5e00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishUnited States0.07385892116182573
                                    RT_ICON0x3d8cb880x1a68Device independent bitmap graphic, 40 x 80 x 32, image size 0EnglishUnited States0.08979289940828403
                                    RT_ICON0x3d8e5f00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.11280487804878049
                                    RT_ICON0x3d8f6980xcd8Device independent bitmap graphic, 28 x 56 x 32, image size 0EnglishUnited States0.13351581508515814
                                    RT_ICON0x3d903700x988Device independent bitmap graphic, 24 x 48 x 32, image size 0EnglishUnited States0.16967213114754098
                                    RT_ICON0x3d90cf80x6b8Device independent bitmap graphic, 20 x 40 x 32, image size 0EnglishUnited States0.20116279069767443
                                    RT_ICON0x3d913b00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.2624113475177305
                                    RT_ICON0x3d918180x42028Device independent bitmap graphic, 256 x 512 x 32, image size 270336EnglishUnited States0.045273988815575344
                                    RT_ICON0x3dd38400x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.1358644307982995
                                    RT_ICON0x3dd7a680x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.17240663900414938
                                    RT_ICON0x3dda0100x1a68Device independent bitmap graphic, 40 x 80 x 32, image size 6720EnglishUnited States0.20029585798816568
                                    RT_ICON0x3ddba780x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.24835834896810507
                                    RT_ICON0x3ddcb200x988Device independent bitmap graphic, 24 x 48 x 32, image size 2400EnglishUnited States0.3163934426229508
                                    RT_ICON0x3ddd4a80x6b8Device independent bitmap graphic, 20 x 40 x 32, image size 1680EnglishUnited States0.18953488372093022
                                    RT_ICON0x3dddb600x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.23847517730496454
                                    RT_DIALOG0x3dddfc80xc8dataEnglishUnited States0.68
                                    RT_STRING0x3dde0900x21cMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.43333333333333335
                                    RT_STRING0x3dde2ac0x266Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4185667752442997
                                    RT_STRING0x3dde5140x248Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4212328767123288
                                    RT_STRING0x3dde75c0x254Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.40939597315436244
                                    RT_STRING0x3dde9b00x23eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.44947735191637633
                                    RT_STRING0x3ddebf00x24aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4351535836177474
                                    RT_STRING0x3ddee3c0x256Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4197324414715719
                                    RT_STRING0x3ddf0940x242Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4083044982698962
                                    RT_STRING0x3ddf2d80x26eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4533762057877814
                                    RT_STRING0x3ddf5480x254Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.42953020134228187
                                    RT_STRING0x3ddf79c0x284Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4363354037267081
                                    RT_STRING0x3ddfa200x242Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4463667820069204
                                    RT_STRING0x3ddfc640x24aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.42662116040955633
                                    RT_STRING0x3ddfeb00x27eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4106583072100313
                                    RT_STRING0x3de01300x268Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4318181818181818
                                    RT_STRING0x3de03980x268Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.40584415584415584
                                    RT_STRING0x3de06000x218Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.47761194029850745
                                    RT_STRING0x3de08180x29aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4084084084084084
                                    RT_STRING0x3de0ab40x260Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4144736842105263
                                    RT_STRING0x3de0d140x24aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.41467576791808874
                                    RT_STRING0x3de0f600x250Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0CatalanSpain0.42567567567567566
                                    RT_STRING0x3de11b00x1dcMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0ChineseTaiwan0.4810924369747899
                                    RT_STRING0x3de138c0x23eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0CzechCzech Republic0.43902439024390244
                                    RT_STRING0x3de15cc0x232Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0DanishDenmark0.39679715302491103
                                    RT_STRING0x3de18000x248Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0GermanGermany0.4178082191780822
                                    RT_STRING0x3de1a480x27cMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0GreekGreece0.45754716981132076
                                    RT_STRING0x3de1cc40x238Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0EnglishUnited States0.40669014084507044
                                    RT_STRING0x3de1efc0x254Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0FinnishFinland0.41442953020134227
                                    RT_STRING0x3de21500x274Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0FrenchFrance0.41878980891719747
                                    RT_STRING0x3de23c40x212Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0HebrewIsrael0.44150943396226416
                                    RT_STRING0x3de25d80x22cMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0HungarianHungary0.4172661870503597
                                    RT_STRING0x3de28040x288Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0ItalianItaly0.4058641975308642
                                    RT_STRING0x3de2a8c0x1fcMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0JapaneseJapan0.484251968503937
                                    RT_STRING0x3de2c880x1f8Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0KoreanNorth Korea0.503968253968254
                                    RT_STRING0x3de2c880x1f8Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0KoreanSouth Korea0.503968253968254
                                    RT_STRING0x3de2e800x24eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0DutchNetherlands0.40508474576271186
                                    RT_STRING0x3de30d00x250Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0NorwegianNorway0.41047297297297297
                                    RT_STRING0x3de33200x272Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0PolishPoland0.4217252396166134
                                    RT_STRING0x3de35940x24eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0PortugueseBrazil0.4067796610169492
                                    RT_STRING0x3de37e40x252Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0RomanianRomania0.41414141414141414
                                    RT_STRING0x3de3a380x270Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0RussianRussia0.42788461538461536
                                    RT_STRING0x3de3ca80x288Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0CroatianCroatia0.41975308641975306
                                    RT_STRING0x3de3f300x23aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0SlovakSlovakia0.43157894736842106
                                    RT_STRING0x3de416c0x24cMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0SwedishSweden0.4064625850340136
                                    RT_STRING0x3de43b80x23eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0ThaiThailand0.4425087108013937
                                    RT_STRING0x3de45f80x224Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0TurkishTurkey0.4124087591240876
                                    RT_STRING0x3de481c0x23eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0IndonesianIndonesia0.40069686411149824
                                    RT_STRING0x3de4a5c0x272Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0UkrainianUkrain0.43450479233226835
                                    RT_STRING0x3de4cd00x264Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0SlovenianSlovenia0.4035947712418301
                                    RT_STRING0x3de4f340x284Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0EstonianEstonia0.40993788819875776
                                    RT_STRING0x3de51b80x248Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0LatvianLativa0.4263698630136986
                                    RT_STRING0x3de54000x278Matlab v4 mat-file (little endian) M, numeric, rows 0, columns 0LithuanianLithuania0.4161392405063291
                                    RT_STRING0x3de56780x27cMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0VietnameseVietnam0.42452830188679247
                                    RT_STRING0x3de58f40x248Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0AzeriItaly0.4332191780821918
                                    RT_STRING0x3de5b3c0x248Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0BasqueFrance0.4092465753424658
                                    RT_STRING0x3de5b3c0x248Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0BasqueSpain0.4092465753424658
                                    RT_STRING0x3de5d840x29eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0SetsuanaSouth Africa0.3940298507462687
                                    RT_STRING0x3de60240x266Matlab v4 mat-file (little endian) M, numeric, rows 0, columns 0XhosaSouth Africa0.41205211726384366
                                    RT_STRING0x3de628c0x246Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0HindiIndia0.4415807560137457
                                    RT_STRING0x3de64d40x274Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0MalteseMalta0.4124203821656051
                                    RT_STRING0x3de67480x28aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0MalayMalaysia0.38769230769230767
                                    RT_STRING0x3de69d40x256Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0BengaliIndia0.46321070234113715
                                    RT_STRING0x3de6c2c0x254Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0GujaratiIndia0.46476510067114096
                                    RT_STRING0x3de6e800x284Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0OriyaIndia0.4394409937888199
                                    RT_STRING0x3de71040x274Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0TamilIndia0.445859872611465
                                    RT_STRING0x3de71040x274Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0TamilSri Lanka0.445859872611465
                                    RT_STRING0x3de73780x240Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0TeluguIndia0.4375
                                    RT_STRING0x3de75b80x258Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0KannadaKanada0.47
                                    RT_STRING0x3de78100x286Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0MalayalamIndia0.42260061919504643
                                    RT_STRING0x3de7a980x262Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0AssameseIndia0.47704918032786886
                                    RT_STRING0x3de7cfc0x24eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0MarathiIndia0.4288135593220339
                                    RT_STRING0x3de7f4c0x25eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0WelshEngland0.41254125412541254
                                    RT_STRING0x3de81ac0x25aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0KhmerVietnam0.48172757475083056
                                    RT_STRING0x3de81ac0x25aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0KhmerThailand0.48172757475083056
                                    RT_STRING0x3de84080x230Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0AmharicEthiopia0.46785714285714286
                                    RT_STRING0x3de86380x252Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0NepaliNepal0.4377104377104377
                                    RT_STRING0x3de888c0x24eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0FilipinoPhilippines0.4016949152542373
                                    RT_STRING0x3de8adc0x250Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.44256756756756754
                                    RT_STRING0x3de8d2c0x250Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4172297297297297
                                    RT_STRING0x3de8f7c0x236Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0IgboNigeria0.4293286219081272
                                    RT_STRING0x3de91b40x240Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0MaoriNew Zealand0.3993055555555556
                                    RT_STRING0x3de93f40x258Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.42333333333333334
                                    RT_STRING0x3de964c0x1d8Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0ChineseChina0.4788135593220339
                                    RT_STRING0x3de98240x238Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0EnglishGreat Britain0.40669014084507044
                                    RT_STRING0x3de9a5c0x24eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0NorwegianNorway0.411864406779661
                                    RT_STRING0x3de9cac0x282Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0PortuguesePortugal0.40965732087227413
                                    RT_STRING0x3de9f300x26eMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 0GaelicIreland0.41639871382636656
                                    RT_STRING0x3dea1a00x284Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.40993788819875776
                                    RT_STRING0x3dea4240x244Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.40344827586206894
                                    RT_STRING0x3dea6680x266Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 0BosnianBosnian0.41368078175895767
                                    RT_STRING0x3dea8d00x268Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.42857142857142855
                                    RT_STRING0x3deab380x25aMatlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4152823920265781
                                    RT_STRING0x3dead940x258Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.4266666666666667
                                    RT_STRING0x3deafec0x238Matlab v4 mat-file (little endian) i, numeric, rows 0, columns 00.45422535211267606
                                    RT_STRING0x3deb2240x6f0data0.30743243243243246
                                    RT_STRING0x3deb9140x842data0.2861873226111637
                                    RT_STRING0x3dec1580x78edata0.297311271975181
                                    RT_STRING0x3dec8e80x7dedata0.27805362462760674
                                    RT_STRING0x3ded0c80x870data0.3013888888888889
                                    RT_STRING0x3ded9380x82adata0.3004784688995215
                                    RT_STRING0x3dee1640x8c8data0.26201067615658363
                                    RT_STRING0x3deea2c0x8a2data0.25927601809954753
                                    RT_STRING0x3def2d00x8ecdata0.28984238178633975
                                    RT_STRING0x3defbbc0x896data0.2857142857142857
                                    RT_STRING0x3df04540x7c2data0.30614300100704933
                                    RT_STRING0x3df0c180x784data0.3264033264033264
                                    RT_STRING0x3df139c0x818data0.2905405405405405
                                    RT_STRING0x3df1bb40x7b8data0.2768218623481781
                                    RT_STRING0x3df236c0x842data0.2899716177861873
                                    RT_STRING0x3df2bb00x8c4data0.24866310160427807
                                    RT_STRING0x3df34740x608data0.37823834196891193
                                    RT_STRING0x3df3a7c0x970data0.2582781456953642
                                    RT_STRING0x3df43ec0x81adata0.2772420443587271
                                    RT_STRING0x3df4c080x6baAmigaOS bitmap font "a", fc_YSize 25856, 21248 elements, 2nd "b", 3rd "g"0.3118466898954704
                                    RT_STRING0x3df52c40x84adataCatalanSpain0.28039585296889724
                                    RT_STRING0x3df5b100x380dataChineseTaiwan0.48214285714285715
                                    RT_STRING0x3df5e900x7d8dataCzechCzech Republic0.3057768924302789
                                    RT_STRING0x3df66680x796dataDanishDenmark0.27909371781668385
                                    RT_STRING0x3df6e000x992dataGermanGermany0.2624489795918367
                                    RT_STRING0x3df77940xa1adataGreekGreece0.2819025522041763
                                    RT_STRING0x3df81b00x7e2dataEnglishUnited States0.26858275520317143
                                    RT_STRING0x3df89940x81cdataFinnishFinland0.2866088631984586
                                    RT_STRING0x3df91b00x87edataFrenchFrance0.265869365225391
                                    RT_STRING0x3df9a300x656dataHebrewIsrael0.31442663378545005
                                    RT_STRING0x3dfa0880x834dataHungarianHungary0.29619047619047617
                                    RT_STRING0x3dfa8bc0x81cdataItalianItaly0.26734104046242774
                                    RT_STRING0x3dfb0d80x570dataJapaneseJapan0.39080459770114945
                                    RT_STRING0x3dfb6480x4b6dataKoreanNorth Korea0.4129353233830846
                                    RT_STRING0x3dfb6480x4b6dataKoreanSouth Korea0.4129353233830846
                                    RT_STRING0x3dfbb000x84edataDutchNetherlands0.2704609595484478
                                    RT_STRING0x3dfc3500x7b8dataNorwegianNorway0.27479757085020245
                                    RT_STRING0x3dfcb080x89adataPolishPoland0.2811080835603996
                                    RT_STRING0x3dfd3a40x862dataPortugueseBrazil0.26887232059645855
                                    RT_STRING0x3dfdc080x848dataRomanianRomania0.2759433962264151
                                    RT_STRING0x3dfe4500x7badataRussianRussia0.3068756319514661
                                    RT_STRING0x3dfec0c0x810dataCroatianCroatia0.2771317829457364
                                    RT_STRING0x3dff41c0x7f0dataSlovakSlovakia0.30118110236220474
                                    RT_STRING0x3dffc0c0x78cdataSwedishSweden0.2727743271221532
                                    RT_STRING0x3e003980x712dataThaiThailand0.30994475138121547
                                    RT_STRING0x3e00aac0x77cdataTurkishTurkey0.2954070981210856
                                    RT_STRING0x3e012280x73cdataIndonesianIndonesia0.2737580993520518
                                    RT_STRING0x3e019640x842dataUkrainianUkrain0.30416272469252603
                                    RT_STRING0x3e021a80x8dcdataSlovenianSlovenia0.2724867724867725
                                    RT_STRING0x3e02a840x7cedataEstonianEstonia0.2877877877877878
                                    RT_STRING0x3e032540x7d8dataLatvianLativa0.28336653386454186
                                    RT_STRING0x3e03a2c0x786dataLithuanianLithuania0.3011422637590862
                                    RT_STRING0x3e041b40x7c6dataVietnameseVietnam0.30954773869346736
                                    RT_STRING0x3e0497c0x8a0dataAzeriItaly0.28125
                                    RT_STRING0x3e0521c0x768dataBasqueFrance0.2732067510548523
                                    RT_STRING0x3e0521c0x768dataBasqueSpain0.2732067510548523
                                    RT_STRING0x3e059840x8a8dataSetsuanaSouth Africa0.25406137184115524
                                    RT_STRING0x3e0622c0x870dataXhosaSouth Africa0.2740740740740741
                                    RT_STRING0x3e06a9c0x864dataHindiIndia0.29702048417132215
                                    RT_STRING0x3e073000x830dataMalteseMalta0.27719465648854963
                                    RT_STRING0x3e07b300x902dataMalayMalaysia0.2588898525585429
                                    RT_STRING0x3e084340x836dataBengaliIndia0.31303520456707895
                                    RT_STRING0x3e08c6c0x84edataGujaratiIndia0.3019755409219191
                                    RT_STRING0x3e094bc0x882dataOriyaIndia0.29292929292929293
                                    RT_STRING0x3e09d400x962dataTamilIndia0.2656119900083264
                                    RT_STRING0x3e09d400x962dataTamilSri Lanka0.2656119900083264
                                    RT_STRING0x3e0a6a40x86cdataTeluguIndia0.29916512059369205
                                    RT_STRING0x3e0af100x87adataKannadaKanada0.2894009216589862
                                    RT_STRING0x3e0b78c0x94adataMalayalamIndia0.2767031118587048
                                    RT_STRING0x3e0c0d80x8acdataAssameseIndia0.29954954954954954
                                    RT_STRING0x3e0c9840x85adataMarathiIndia0.2970065481758653
                                    RT_STRING0x3e0d1e00x87cdataWelshEngland0.27992633517495397
                                    RT_STRING0x3e0da5c0x7a4dataKhmerVietnam0.3338445807770961
                                    RT_STRING0x3e0da5c0x7a4dataKhmerThailand0.3338445807770961
                                    RT_STRING0x3e0e2000x5badataAmharicEthiopia0.3813096862210095
                                    RT_STRING0x3e0e7bc0x852dataNepaliNepal0.28826291079812205
                                    RT_STRING0x3e0f0100x8a4dataFilipinoPhilippines0.26582278481012656
                                    RT_STRING0x3e0f8b40x7c6data0.31256281407035175
                                    RT_STRING0x3e1007c0x8eadata0.27256792287467135
                                    RT_STRING0x3e109680x732dataIgboNigeria0.2969598262757872
                                    RT_STRING0x3e1109c0x774dataMaoriNew Zealand0.259958071278826
                                    RT_STRING0x3e118100x854data0.28095684803001875
                                    RT_STRING0x3e120640x376dataChineseChina0.48419864559819414
                                    RT_STRING0x3e123dc0x7e2dataEnglishGreat Britain0.26858275520317143
                                    RT_STRING0x3e12bc00x804dataNorwegianNorway0.2699805068226121
                                    RT_STRING0x3e133c40x82adataPortuguesePortugal0.26220095693779905
                                    RT_STRING0x3e13bf00x936dataGaelicIreland0.2553011026293469
                                    RT_STRING0x3e145280x85cdata0.2672897196261682
                                    RT_STRING0x3e14d840x774data0.269916142557652
                                    RT_STRING0x3e154f80x896dataBosnianBosnian0.27388535031847133
                                    RT_STRING0x3e15d900x8a2data0.2828054298642534
                                    RT_STRING0x3e166340x7eedata0.2738916256157635
                                    RT_STRING0x3e16e240x7ecdata0.2859960552268245
                                    RT_STRING0x3e176100x7badata0.31648129423660265
                                    RT_STRING0x3e17dcc0x372data0.4308390022675737
                                    RT_STRING0x3e181400x442data0.39541284403669724
                                    RT_STRING0x3e185840x3fcdata0.3931372549019608
                                    RT_STRING0x3e189800x43edata0.3720073664825046
                                    RT_STRING0x3e18dc00x41cdata0.4268060836501901
                                    RT_STRING0x3e191dc0x40edata0.4046242774566474
                                    RT_STRING0x3e195ec0x426data0.3860640301318267
                                    RT_STRING0x3e19a140x434data0.36059479553903345
                                    RT_STRING0x3e19e480x44cdata0.4072727272727273
                                    RT_STRING0x3e1a2940x49edata0.4120135363790186
                                    RT_STRING0x3e1a7340x3d4data0.41836734693877553
                                    RT_STRING0x3e1ab080x472data0.4112478031634446
                                    RT_STRING0x3e1af7c0x360data0.44560185185185186
                                    RT_STRING0x3e1b2dc0x406data0.3699029126213592
                                    RT_STRING0x3e1b6e40x49adata0.3938879456706282
                                    RT_STRING0x3e1bb800xf2data0.5247933884297521
                                    RT_STRING0x3e1bc740xe2data0.5707964601769911
                                    RT_STRING0x3e1bd580xf2data0.5289256198347108
                                    RT_STRING0x3e1be4c0x106data0.5229007633587787
                                    RT_STRING0x3e1bf540xecdata0.5296610169491526
                                    RT_STRING0x3e1c0400x3fcdataCatalanSpain0.35784313725490197
                                    RT_STRING0x3e1c43c0x234dataChineseTaiwan0.5939716312056738
                                    RT_STRING0x3e1c6700x420dataCzechCzech Republic0.4053030303030303
                                    RT_STRING0x3e1ca900x444dataDanishDenmark0.36355311355311354
                                    RT_STRING0x3e1ced40x494dataGermanGermany0.34897610921501704
                                    RT_STRING0x3e1d3680x49adataGreekGreece0.39813242784380304
                                    RT_STRING0x3e1d8040x402dataEnglishUnited States0.37816764132553604
                                    RT_STRING0x3e1dc080x3c0dataFinnishFinland0.38645833333333335
                                    RT_STRING0x3e1dfc80x488dataFrenchFrance0.38448275862068965
                                    RT_STRING0x3e1e4500x38edataHebrewIsrael0.43626373626373627
                                    RT_STRING0x3e1e7e00x3f0dataHungarianHungary0.4117063492063492
                                    RT_STRING0x3e1ebd00x40cdataItalianItaly0.3590733590733591
                                    RT_STRING0x3e1efdc0x2f8dataJapaneseJapan0.48026315789473684
                                    RT_STRING0x3e1f2d40x2b6PCX ver. 2.5 image data bounding box [48708, 32] - [51473, 51077], 201-bit uncompressedKoreanNorth Korea0.5446685878962536
                                    RT_STRING0x3e1f2d40x2b6PCX ver. 2.5 image data bounding box [48708, 32] - [51473, 51077], 201-bit uncompressedKoreanSouth Korea0.5446685878962536
                                    RT_STRING0x3e1f58c0x3ecdataDutchNetherlands0.37350597609561753
                                    RT_STRING0x3e1f9780x414dataNorwegianNorway0.3544061302681992
                                    RT_STRING0x3e1fd8c0x472dataPolishPoland0.36994727592267135
                                    RT_STRING0x3e202000x44adataPortugueseBrazil0.36885245901639346
                                    RT_STRING0x3e2064c0x422dataRomanianRomania0.3629489603024575
                                    RT_STRING0x3e20a700x424dataRussianRussia0.4028301886792453
                                    RT_STRING0x3e20e940x41edataCroatianCroatia0.3766603415559772
                                    RT_STRING0x3e212b40x45cdataSlovakSlovakia0.3835125448028674
                                    RT_STRING0x3e217100x42adataSwedishSweden0.3630393996247655
                                    RT_STRING0x3e21b3c0x41adataThaiThailand0.42952380952380953
                                    RT_STRING0x3e21f580x3dedataTurkishTurkey0.4161616161616162
                                    RT_STRING0x3e223380x416dataIndonesianIndonesia0.3632887189292543
                                    RT_STRING0x3e227500x430dataUkrainianUkrain0.39738805970149255
                                    RT_STRING0x3e22b800x45edataSlovenianSlovenia0.37209302325581395
                                    RT_STRING0x3e22fe00x424dataEstonianEstonia0.36981132075471695
                                    RT_STRING0x3e234040x3dadataLatvianLativa0.3995943204868154
                                    RT_STRING0x3e237e00x3fedataLithuanianLithuania0.4021526418786693
                                    RT_STRING0x3e23be00x450dataVietnameseVietnam0.42028985507246375
                                    RT_STRING0x3e240300x45cdataAzeriItaly0.3906810035842294
                                    RT_STRING0x3e2448c0x424dataBasqueFrance0.3745283018867924
                                    RT_STRING0x3e2448c0x424dataBasqueSpain0.3745283018867924
                                    RT_STRING0x3e248b00xfedataSetsuanaSouth Africa0.5
                                    RT_STRING0x3e249b00x110dataXhosaSouth Africa0.5147058823529411
                                    RT_STRING0x3e24ac00x468dataHindiIndia0.4033687943262411
                                    RT_STRING0x3e24f280x44cdataMalteseMalta0.3936363636363636
                                    RT_STRING0x3e253740x420dataMalayMalaysia0.3740530303030303
                                    RT_STRING0x3e257940x45edataBengaliIndia0.43112701252236135
                                    RT_STRING0x3e25bf40x470dataGujaratiIndia0.4128521126760563
                                    RT_STRING0x3e260640x492dataOriyaIndia0.3769230769230769
                                    RT_STRING0x3e264f80x446dataTamilIndia0.4113345521023766
                                    RT_STRING0x3e264f80x446dataTamilSri Lanka0.4113345521023766
                                    RT_STRING0x3e269400x500dataTeluguIndia0.39375
                                    RT_STRING0x3e26e400x4aedataKannadaKanada0.3964941569282137
                                    RT_STRING0x3e272f00x540dataMalayalamIndia0.3757440476190476
                                    RT_STRING0x3e278300x43adataAssameseIndia0.4565619223659889
                                    RT_STRING0x3e27c6c0x46adataMarathiIndia0.3920353982300885
                                    RT_STRING0x3e280d80x42edataWelshEngland0.3897196261682243
                                    RT_STRING0x3e285080x406dataKhmerVietnam0.458252427184466
                                    RT_STRING0x3e285080x406dataKhmerThailand0.458252427184466
                                    RT_STRING0x3e289100x30cdataAmharicEthiopia0.5153846153846153
                                    RT_STRING0x3e28c1c0x462dataNepaliNepal0.39572192513368987
                                    RT_STRING0x3e290800x464dataFilipinoPhilippines0.3487544483985765
                                    RT_STRING0x3e294e40xe8data0.5431034482758621
                                    RT_STRING0x3e295cc0x4b4data0.36710963455149503
                                    RT_STRING0x3e29a800xecdataIgboNigeria0.5084745762711864
                                    RT_STRING0x3e29b6c0x426dataMaoriNew Zealand0.3578154425612053
                                    RT_STRING0x3e29f940x430data0.3591417910447761
                                    RT_STRING0x3e2a3c40x21cdataChineseChina0.587037037037037
                                    RT_STRING0x3e2a5e00x402dataEnglishGreat Britain0.37816764132553604
                                    RT_STRING0x3e2a9e40x436dataNorwegianNorway0.349721706864564
                                    RT_STRING0x3e2ae1c0x444dataPortuguesePortugal0.3782051282051282
                                    RT_STRING0x3e2b2600x49adataGaelicIreland0.3548387096774194
                                    RT_STRING0x3e2b6fc0x414data0.36302681992337166
                                    RT_STRING0x3e2bb100x3d4data0.38571428571428573
                                    RT_STRING0x3e2bee40x440dataBosnianBosnian0.3795955882352941
                                    RT_STRING0x3e2c3240x4a2data0.3802698145025295
                                    RT_STRING0x3e2c7c80x45adata0.3734290843806104
                                    RT_STRING0x3e2cc240x454data0.4007220216606498
                                    RT_STRING0x3e2d0780x102data0.5348837209302325
                                    RT_MESSAGETABLE0x3e2d17c0x64dataEnglishUnited States0.75
                                    RT_GROUP_ICON0x3e2d1e00xa0dataEnglishUnited States0.725
                                    RT_GROUP_ICON0x3e2d2800x76dataEnglishUnited States0.7288135593220338
                                    RT_VERSION0x3e2d2f80x3f4dataEnglishUnited States0.43379446640316205
                                    RT_MANIFEST0x3e2d6ec0x584XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4468838526912181
                                    DLLImport
                                    bcrypt.dllBCryptEncrypt, BCryptGenerateSymmetricKey, BCryptCloseAlgorithmProvider, BCryptSetProperty, BCryptGenRandom, BCryptDestroyKey, BCryptOpenAlgorithmProvider
                                    ntdll.dllRtlLookupFunctionEntry, RtlUnwind, RtlVirtualUnwind, RtlPcToFileHeader, RtlUnwindEx, VerSetConditionMask, RtlCaptureContext
                                    wer.dllWerReportCreate, WerReportCloseHandle, WerReportSubmit, WerReportSetParameter
                                    KERNEL32.dllWritePrivateProfileStringW, SetDllDirectoryW, MoveFileExW, ReplaceFileW, GetComputerNameW, RegisterApplicationRestart, GetFileInformationByHandleEx, OpenFileById, GetDllDirectoryW, GetTempFileNameW, CreateToolhelp32Snapshot, WriteConsoleW, SetEnvironmentVariableW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetOEMCP, GetACP, IsValidCodePage, ReadConsoleW, SetStdHandle, GetConsoleMode, GetConsoleOutputCP, GetFileSize, GetFileInformationByHandle, GetFileAttributesExW, GetFileAttributesW, GetDiskFreeSpaceExW, FindVolumeClose, FindNextVolumeW, FindFirstVolumeW, SetThreadInformation, GetSystemTimes, SetProcessShutdownParameters, CreateProcessW, GetExitCodeProcess, GetProcessTimes, WaitForMultipleObjects, Sleep, CreateEventW, ReleaseMutex, GetLongPathNameW, SetLastError, VerifyVersionInfoW, GetProductInfo, CopyFileW, ExpandEnvironmentStringsW, LCMapStringW, WideCharToMultiByte, MultiByteToWideChar, K32GetModuleFileNameExW, GetUserDefaultLocaleName, GetUserDefaultLCID, LCIDToLocaleName, MoveFileW, GetVersionExW, GetSystemTimeAsFileTime, OpenProcess, TerminateProcess, GetPrivateProfileStringW, CreateMutexW, WaitForSingleObject, GetModuleFileNameW, GetTempPathW, GetCommandLineW, CreateDirectoryW, WerUnregisterFile, WerRegisterFile, SystemTimeToFileTime, SetFileTime, LoadLibraryW, GetProcAddress, FreeLibrary, DeviceIoControl, FindNextFileW, FindFirstFileW, FindClose, GetSystemTime, GetCurrentThreadId, GetCurrentProcessId, CloseHandle, WriteFile, DeleteFileW, CreateFileW, CompareFileTime, DeleteCriticalSection, InitializeCriticalSectionEx, GetProcessHeap, GetUserGeoID, HeapFree, EnumSystemLocalesW, IsValidLocale, GetLocaleInfoW, CompareStringW, GetTimeFormatW, GetDateFormatW, GetCurrentThread, GetStdHandle, ExitProcess, VirtualProtect, VirtualAlloc, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, PeekNamedPipe, GetDriveTypeW, CompareStringOrdinal, CreateSymbolicLinkW, ReadDirectoryChangesW, LoadLibraryExW, IsWow64Process, PostQueuedCompletionStatus, FreeLibraryAndExitThread, ResumeThread, ExitThread, CreateThread, HeapReAlloc, HeapAlloc, HeapDestroy, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, GetUserDefaultUILanguage, Process32NextW, GetCurrentProcess, InterlockedPushEntrySList, GetCPInfo, CompareStringEx, LCMapStringEx, GetQueuedCompletionStatus, CreateIoCompletionPort, CreatePipe, SetHandleInformation, IsDebuggerPresent, FindFirstFileNameW, GetCompressedFileSizeW, SetFilePointer, EncodePointer, GetTickCount64, GetLastError, DecodePointer, CreateEventExW, FlsFree, FlsSetValue, FlsGetValue, FlsAlloc, CreateHardLinkW, SetFilePointerEx, FindFirstFileExW, GetCurrentDirectoryW, GetLocaleInfoEx, AcquireSRWLockShared, ReleaseSRWLockShared, QueryPerformanceFrequency, SleepConditionVariableSRW, SleepConditionVariableCS, WakeAllConditionVariable, WakeConditionVariable, InitializeConditionVariable, GetExitCodeThread, SwitchToThread, GetStringTypeW, LocalFree, LocalAlloc, LeaveCriticalSection, EnterCriticalSection, GetEnvironmentVariableW, SetFileInformationByHandle, SetFileAttributesW, CreateDirectoryA, GetShortPathNameW, RemoveDirectoryA, GetTempFileNameA, CompareStringA, FileTimeToLocalFileTime, FileTimeToDosDateTime, FindResourceExW, LoadResource, LockResource, SizeofResource, FindResourceW, Process32FirstW, RemoveDirectoryW, ReadFile, GetVolumePathNameW, GetFinalPathNameByHandleW, GetFileType, HeapSize, GetFileSizeEx, WaitForMultipleObjectsEx, GlobalLock, GetPriorityClass, SetPriorityClass, GetThreadPriority, SetThreadPriority, LoadLibraryExA, VirtualFree, GlobalAlloc, GetSystemDefaultLCID, GetSystemDefaultUILanguage, GetComputerNameExW, FlushInstructionCache, InterlockedPopEntrySList, GetLocalTime, GlobalMemoryStatusEx, QueueUserWorkItem, OutputDebugStringA, GetModuleFileNameA, GetModuleHandleW, GetModuleHandleExW, GetTimeZoneInformation, RaiseException, GetNativeSystemInfo, GetSystemPowerStatus, FlushFileBuffers, GetTickCount, QueryPerformanceCounter, MapViewOfFile, CreateFileMappingW, FormatMessageA, LockFileEx, UnlockFile, HeapCompact, GetSystemInfo, DeleteFileA, WaitForSingleObjectEx, LoadLibraryA, CreateFileA, FlushViewOfFile, OutputDebugStringW, GetFileAttributesA, GetDiskFreeSpaceA, FormatMessageW, GetTempPathA, HeapValidate, UnmapViewOfFile, UnlockFileEx, SetEndOfFile, GetFullPathNameA, LockFile, GetDiskFreeSpaceW, GetFullPathNameW, HeapCreate, AreFileApisANSI, InitializeCriticalSection, TryEnterCriticalSection, InitOnceExecuteOnce, InitializeCriticalSectionAndSpinCount, SetEvent, ResetEvent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, InitializeSListHead, GetStartupInfoW, VirtualQuery, InitializeSRWLock, ReleaseSRWLockExclusive, AcquireSRWLockExclusive
                                    USER32.dllUnregisterClassW, ShowWindow, DestroyWindow, CreateWindowExW, RegisterClassW, GetMessageW, PostThreadMessageW, PostQuitMessage, AllowSetForegroundWindow, GetShellWindow, GetSystemMetrics, SendMessageW, AttachThreadInput, IsWindow, SetWindowPos, IsWindowVisible, BringWindowToTop, CreateDialogParamW, DialogBoxParamW, GetDlgItem, SetActiveWindow, GetForegroundWindow, SetForegroundWindow, SetWindowTextW, GetClientRect, GetWindowRect, MapWindowPoints, GetWindowLongW, SetWindowLongW, SetWindowLongPtrW, GetParent, GetWindow, LoadIconW, MonitorFromWindow, GetMonitorInfoW, PeekMessageW, MsgWaitForMultipleObjectsEx, SetCursor, LoadCursorW, TranslateMessage, DispatchMessageW, IsDialogMessageW, PostMessageW, EnumWindows, GetClassNameW, GetWindowThreadProcessId, SystemParametersInfoW, UnregisterPowerSettingNotification, SendMessageTimeoutW, RegisterPowerSettingNotification
                                    ADVAPI32.dllLookupPrivilegeValueW, RegGetValueA, EventRegister, EventWriteTransfer, EventUnregister, EventWrite, CredWriteW, CredReadW, CredDeleteW, CredFree, RegOverridePredefKey, LookupAccountNameW, CryptDestroyKey, CryptSetHashParam, CryptImportKey, AddAce, DeleteAce, GetAce, InitializeAcl, ImpersonateLoggedOnUser, CreateProcessWithTokenW, GetUserNameW, SetFileSecurityW, ConvertSidToStringSidW, SetNamedSecurityInfoW, GetNamedSecurityInfoW, SetEntriesInAclW, StartServiceW, StartServiceCtrlDispatcherW, SetServiceStatus, RegisterServiceCtrlHandlerW, QueryServiceStatusEx, QueryServiceStatus, QueryServiceConfigW, OpenServiceW, OpenSCManagerW, DeleteService, CreateServiceW, ControlService, CloseServiceHandle, ChangeServiceConfig2W, ChangeServiceConfigW, RegDeleteTreeW, RegUnLoadKeyW, RegLoadKeyW, RegEnumKeyW, RegDeleteKeyExW, RegCreateKeyTransactedW, GetAclInformation, FreeSid, DuplicateTokenEx, CreateWellKnownSid, AllocateAndInitializeSid, CreateProcessAsUserW, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegGetValueW, RegSetKeyValueW, RegSetValueExW, RegQueryValueExW, RegQueryInfoKeyW, RegOpenKeyExW, RegEnumValueW, RegEnumKeyExW, RegDeleteValueW, RegCreateKeyExW, RegCloseKey, CredEnumerateW, IsValidSid, InitializeSid, GetTokenInformation, GetSidSubAuthorityCount, GetSidSubAuthority, GetSidLengthRequired, GetLengthSid, EqualSid, CopySid, AdjustTokenPrivileges, OpenProcessToken, CryptDestroyHash, CryptHashData, CryptCreateHash, CryptGetHashParam, CryptReleaseContext, CryptAcquireContextW, ConvertStringSidToSidW, RevertToSelf
                                    SHELL32.dllShellExecuteW, SHFileOperationW, SHLoadNonloadedIconOverlayIdentifiers, SHGetFolderPathW, CommandLineToArgvW, SHCreateDirectoryExW, SHGetKnownFolderPath, SHGetSpecialFolderPathW, SHChangeNotify, SHParseDisplayName, ShellExecuteExW, SHCreateItemFromParsingName, SHAssocEnumHandlers, SHGetFolderPathAndSubDirW, SHSetKnownFolderPath, SHGetFolderPathA
                                    ole32.dllCreateItemMoniker, CoGetObject, CoSetProxyBlanket, CLSIDFromString, StringFromCLSID, CoInitialize, StringFromGUID2, CoCreateInstance, CoCreateGuid, CoTaskMemFree, CoInitializeEx, CoUninitialize, CoCreateFreeThreadedMarshaler, CreateStreamOnHGlobal, CoTaskMemAlloc, PropVariantClear, CoWaitForMultipleHandles, CreateBindCtx, GetRunningObjectTable
                                    OLEAUT32.dllSysAllocStringLen, VarBstrCmp, VariantChangeType, VariantClear, VariantInit, SysAllocStringByteLen, SysStringByteLen, SysStringLen, SysFreeString, SysAllocString, GetRecordInfoFromTypeInfo, SetErrorInfo, GetErrorInfo, LoadTypeLib, LoadRegTypeLib
                                    IPHLPAPI.DLLGetAdaptersInfo
                                    RstrtMgr.DLLRmRegisterResources, RmEndSession, RmStartSession, RmGetList
                                    CRYPT32.dllCertFindExtension, CryptStringToBinaryW, CryptBinaryToStringW, CertFreeCertificateChain, CertVerifyCertificateChainPolicy
                                    RPCRT4.dllRpcExceptionFilter, RpcBindingFree, RpcBindingFromStringBindingW, RpcBindingVectorFree, RpcStringFreeW, UuidToStringW, RpcStringBindingComposeW, RpcServerInqCallAttributesW, RpcEpUnregister, RpcEpRegisterW, RpcBindingSetAuthInfoExW, RpcServerUseProtseqW, RpcServerUnregisterIf, RpcServerRegisterIfEx, RpcServerInqBindings
                                    Secur32.dllGetUserNameExW
                                    SHLWAPI.dllStrStrIW, PathIsPrefixW, PathStripToRootW, PathStripPathW, PathSkipRootW, PathIsRelativeW, SHRegGetUSValueW, SHGetValueW, PathFindFileNameW, PathIsDirectoryW, PathRemoveFileSpecW, SHDeleteKeyW, SHDeleteValueW, SHGetValueA, SHSetValueW, SHRegGetValueW, SHRegGetPathW, SHRegGetBoolUSValueW, AssocQueryStringW, SHCreateStreamOnFileW, SHCreateStreamOnFileEx, PathFindExtensionW, PathIsDirectoryEmptyW, PathFileExistsW, PathFileExistsA, PathFindFileNameA, PathGetDriveNumberA, PathIsDirectoryA, SHCreateStreamOnFileA
                                    VERSION.dllGetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
                                    WININET.dllInternetCheckConnectionW, InternetCrackUrlA, InternetOpenW, InternetCloseHandle, InternetConnectA, InternetReadFile, InternetQueryOptionW, InternetSetStatusCallbackW, HttpOpenRequestA, HttpAddRequestHeadersA, HttpSendRequestW, HttpQueryInfoA
                                    WS2_32.dllsetsockopt, htons, WSAStartup, WSAGetLastError, send, listen, htonl, socket, bind, accept, closesocket
                                    WTSAPI32.dllWTSQuerySessionInformationW, WTSEnumerateSessionsW, WTSFreeMemory, WTSQueryUserToken
                                    USERENV.dllCreateEnvironmentBlock, GetDefaultUserProfileDirectoryW, UnloadUserProfile
                                    GDI32.dllCreateDIBSection, SetDIBColorTable, GetObjectW, SelectObject, CreateCompatibleDC, DeleteDC, DeleteObject
                                    urlmon.dllURLOpenStreamW
                                    gdiplus.dllGdipDisposeImage, GdipCloneImage, GdiplusStartup, GdipFree, GdipAlloc, GdiplusShutdown, GdipGetImageWidth, GdipGetImageHeight, GdipGetImagePixelFormat, GdipGetImagePalette, GdipGetImagePaletteSize, GdipCreateBitmapFromStream, GdipGetImageGraphicsContext, GdipDeleteGraphics, GdipCreateBitmapFromScan0, GdipBitmapLockBits, GdipBitmapUnlockBits, GdipDrawImageI
                                    COMCTL32.dll
                                    WINTRUST.dllWinVerifyTrustEx, WTHelperProvDataFromStateData, WTHelperGetProvSignerFromChain
                                    WINHTTP.dllWinHttpCrackUrl, WinHttpOpenRequest, WinHttpOpen, WinHttpReceiveResponse, WinHttpSendRequest, WinHttpConnect, WinHttpReadData, WinHttpQueryDataAvailable, WinHttpQueryHeaders, WinHttpCloseHandle
                                    Cabinet.dll
                                    NameOrdinalAddress
                                    ?$TSS0@?1??stateLock@DebugEventSource@Events@Applications@Microsoft@@KAAEAVrecursive_mutex@std@@XZ@4HA10x140470950
                                    ??0DebugEventDispatcher@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z20x140096020
                                    ??0DebugEventDispatcher@Events@Applications@Microsoft@@QEAA@XZ30x140096020
                                    ??0DebugEventListener@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z40x140096030
                                    ??0DebugEventListener@Events@Applications@Microsoft@@QEAA@XZ50x140096030
                                    ??0DebugEventSource@Events@Applications@Microsoft@@QEAA@$$QEAV0123@@Z60x140096040
                                    ??0DebugEventSource@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z70x140096100
                                    ??0DebugEventSource@Events@Applications@Microsoft@@QEAA@XZ80x1400378d0
                                    ??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z90x14009db10
                                    ??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z100x14009db60
                                    ??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEBV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@2@@5@@Z110x14009db90
                                    ??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@E@Z120x14009dbe0
                                    ??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$initializer_list@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@5@@Z130x14009dce0
                                    ??0EventProperties@Events@Applications@Microsoft@@QEAA@XZ140x14009dd40
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@$$QEAU0123@@Z150x1400a30c0
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@AEAV?$vector@NV?$allocator@N@std@@@std@@W4PiiKind@123@W4DataCategory@123@@Z160x1400a3110
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@AEAV?$vector@UGUID_t@Events@Applications@Microsoft@@V?$allocator@UGUID_t@Events@Applications@Microsoft@@@std@@@std@@W4PiiKind@123@W4DataCategory@123@@Z170x1400a3180
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@AEAV?$vector@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$allocator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@std@@W4PiiKind@123@W4DataCategory@123@@Z180x1400a31f0
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@AEAV?$vector@_JV?$allocator@_J@std@@@std@@W4PiiKind@123@W4DataCategory@123@@Z190x1400a3260
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@AEBU0123@@Z200x1400a30c0
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4PiiKind@123@W4DataCategory@123@@Z210x1400a32d0
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@CW4PiiKind@123@W4DataCategory@123@@Z220x1400a3350
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@EW4PiiKind@123@W4DataCategory@123@@Z230x1400a3380
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@FW4PiiKind@123@W4DataCategory@123@@Z240x1400a33b0
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@GW4PiiKind@123@W4DataCategory@123@@Z250x1400a33e0
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@HW4PiiKind@123@W4DataCategory@123@@Z260x1400a3410
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@IW4PiiKind@123@W4DataCategory@123@@Z270x1400a3440
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@JW4PiiKind@123@W4DataCategory@123@@Z280x1400a3410
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@NW4PiiKind@123@W4DataCategory@123@@Z290x1400a3470
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@PEBDW4PiiKind@123@W4DataCategory@123@@Z300x1400a34a0
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@UGUID_t@123@W4PiiKind@123@W4DataCategory@123@@Z310x1400a3530
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@Utime_ticks_t@123@W4PiiKind@123@W4DataCategory@123@@Z320x1400a3570
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@XZ330x1400a35a0
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@_JW4PiiKind@123@W4DataCategory@123@@Z340x1400a3610
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@_KW4PiiKind@123@W4DataCategory@123@@Z350x1400a3610
                                    ??0EventProperty@Events@Applications@Microsoft@@QEAA@_NW4PiiKind@123@W4DataCategory@123@@Z360x1400a3640
                                    ??0GUID_t@Events@Applications@Microsoft@@QEAA@AEBU0123@@Z370x1400a3660
                                    ??0GUID_t@Events@Applications@Microsoft@@QEAA@HHHAEBV?$initializer_list@E@std@@@Z380x1400a36a0
                                    ??0GUID_t@Events@Applications@Microsoft@@QEAA@PEBD@Z390x1400a36e0
                                    ??0GUID_t@Events@Applications@Microsoft@@QEAA@QEBE_N@Z400x1400a37c0
                                    ??0GUID_t@Events@Applications@Microsoft@@QEAA@U_GUID@@@Z410x1400a38a0
                                    ??0GUID_t@Events@Applications@Microsoft@@QEAA@XZ420x1400a3910
                                    ??0IAuthTokensController@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z430x140096170
                                    ??0IAuthTokensController@Events@Applications@Microsoft@@QEAA@XZ440x140096170
                                    ??0ILogConfiguration@Events@Applications@Microsoft@@QEAA@$$QEAV0123@@Z450x140096180
                                    ??0ILogConfiguration@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z460x140096220
                                    ??0ILogConfiguration@Events@Applications@Microsoft@@QEAA@AEBV?$initializer_list@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VVariant@Events@Applications@Microsoft@@@std@@@std@@@Z470x1400a0980
                                    ??0ILogConfiguration@Events@Applications@Microsoft@@QEAA@XZ480x140037a60
                                    ??0ILogController@Events@Applications@Microsoft@@QEAA@$$QEAV0123@@Z490x140096270
                                    ??0ILogController@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z500x140096270
                                    ??0ILogController@Events@Applications@Microsoft@@QEAA@XZ510x140096270
                                    ??0ILogManager@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z520x140096280
                                    ??0ILogManager@Events@Applications@Microsoft@@QEAA@XZ530x140096280
                                    ??0ILogger@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z540x1400962b0
                                    ??0ILogger@Events@Applications@Microsoft@@QEAA@XZ550x1400962b0
                                    ??0IModule@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z560x1400962c0
                                    ??0IModule@Events@Applications@Microsoft@@QEAA@XZ570x1400962c0
                                    ??0ISemanticContext@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z580x1400962d0
                                    ??0ISemanticContext@Events@Applications@Microsoft@@QEAA@XZ590x1400962d0
                                    ??0LogConfiguration@Telemetry@Applications@Microsoft@@QEAA@$$QEAU0123@@Z600x1400962e0
                                    ??0LogConfiguration@Telemetry@Applications@Microsoft@@QEAA@AEBU0123@@Z610x1400963e0
                                    ??0LogConfiguration@Telemetry@Applications@Microsoft@@QEAA@XZ620x1400964a0
                                    ??0time_ticks_t@Events@Applications@Microsoft@@QEAA@AEBU0123@@Z630x140096f10
                                    ??0time_ticks_t@Events@Applications@Microsoft@@QEAA@PEB_J@Z640x1400a3920
                                    ??0time_ticks_t@Events@Applications@Microsoft@@QEAA@XZ650x1400a3940
                                    ??0time_ticks_t@Events@Applications@Microsoft@@QEAA@_K@Z660x1400a3950
                                    ??1DebugEventDispatcher@Events@Applications@Microsoft@@UEAA@XZ670x140009290
                                    ??1DebugEventListener@Events@Applications@Microsoft@@UEAA@XZ680x140009290
                                    ??1DebugEventSource@Events@Applications@Microsoft@@UEAA@XZ690x140038d70
                                    ??1EventProperties@Events@Applications@Microsoft@@UEAA@XZ700x14009e100
                                    ??1EventProperty@Events@Applications@Microsoft@@UEAA@XZ710x1400a3990
                                    ??1IAuthTokensController@Events@Applications@Microsoft@@UEAA@XZ720x140096890
                                    ??1ILogConfiguration@Events@Applications@Microsoft@@QEAA@XZ730x14004a200
                                    ??1ILogManager@Events@Applications@Microsoft@@UEAA@XZ740x1400968a0
                                    ??1ILogger@Events@Applications@Microsoft@@UEAA@XZ750x1400968d0
                                    ??1IModule@Events@Applications@Microsoft@@UEAA@XZ760x140009290
                                    ??1ISemanticContext@Events@Applications@Microsoft@@UEAA@XZ770x1400968e0
                                    ??1LogConfiguration@Telemetry@Applications@Microsoft@@QEAA@XZ780x1400968f0
                                    ??4DebugEventDispatcher@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z790x14000b8b0
                                    ??4DebugEventListener@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z800x14000b8b0
                                    ??4DebugEventSource@Events@Applications@Microsoft@@QEAAAEAV0123@$$QEAV0123@@Z810x140096ba0
                                    ??4DebugEventSource@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z820x140096c50
                                    ??4EventProperties@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z830x14009e230
                                    ??4EventProperties@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@2@@std@@@Z840x14009e250
                                    ??4EventProperties@Events@Applications@Microsoft@@QEAAAEAV0123@V?$initializer_list@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@std@@@Z850x14009e290
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBU0123@@Z860x1400a39a0
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z870x1400a39e0
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$vector@NV?$allocator@N@std@@@std@@@Z880x1400a3a60
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$vector@UGUID_t@Events@Applications@Microsoft@@V?$allocator@UGUID_t@Events@Applications@Microsoft@@@std@@@std@@@Z890x1400a3ac0
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$vector@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$allocator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@std@@@Z900x1400a3b20
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$vector@_JV?$allocator@_J@std@@@std@@@Z910x1400a3b80
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@C@Z920x1400a3be0
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@E@Z930x1400a3bf0
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@F@Z940x1400a3c00
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@G@Z950x1400a3c10
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@H@Z960x1400a3c20
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@I@Z970x1400a3c30
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@J@Z980x1400a3c20
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@N@Z990x1400a3c40
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@PEBD@Z1000x1400a3c70
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@UGUID_t@123@@Z1010x1400a3cd0
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@Utime_ticks_t@123@@Z1020x1400a3d10
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@_J@Z1030x1400a3d50
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@_K@Z1040x1400a3d80
                                    ??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@_N@Z1050x1400a3d90
                                    ??4GUID_t@Events@Applications@Microsoft@@QEAAAEAU0123@AEBU0123@@Z1060x140096ce0
                                    ??4IAuthTokensController@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z1070x14000b8b0
                                    ??4ILogConfiguration@Events@Applications@Microsoft@@QEAAAEAV0123@$$QEAV0123@@Z1080x140096cf0
                                    ??4ILogConfiguration@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z1090x140096d80
                                    ??4ILogController@Events@Applications@Microsoft@@QEAAAEAV0123@$$QEAV0123@@Z1100x14000b8b0
                                    ??4ILogController@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z1110x14000b8b0
                                    ??4ILogManager@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z1120x14000b8b0
                                    ??4ILogger@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z1130x14000b8b0
                                    ??4IModule@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z1140x14000b8b0
                                    ??4ISemanticContext@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z1150x14000b8b0
                                    ??4LogConfiguration@Telemetry@Applications@Microsoft@@QEAAAEAU0123@$$QEAU0123@@Z1160x140096df0
                                    ??4LogConfiguration@Telemetry@Applications@Microsoft@@QEAAAEAU0123@AEBU0123@@Z1170x140096e80
                                    ??4LogManagerProvider@Events@Applications@Microsoft@@QEAAAEAV0123@$$QEAV0123@@Z1180x14000b8b0
                                    ??4LogManagerProvider@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z1190x14000b8b0
                                    ??4time_ticks_t@Events@Applications@Microsoft@@QEAAAEAU0123@AEBU0123@@Z1200x140096f10
                                    ??8EventProperty@Events@Applications@Microsoft@@QEBA_NAEBU0123@@Z1210x1400a3dc0
                                    ??8GUID_t@Events@Applications@Microsoft@@QEBA_NAEBU0123@@Z1220x1400a42e0
                                    ??AILogConfiguration@Events@Applications@Microsoft@@QEAAAEAVVariant@123@PEBD@Z1230x1400a0a10
                                    ??DILogConfiguration@Events@Applications@Microsoft@@QEAAAEAV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VVariant@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VVariant@Events@Applications@Microsoft@@@std@@@2@@std@@XZ1240x14000b8b0
                                    ??MGUID_t@Events@Applications@Microsoft@@QEBA_NAEBU0123@@Z1250x1400a4330
                                    ??YEventProperties@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@2@@std@@@Z1260x14009e470
                                    ??_7DebugEventDispatcher@Events@Applications@Microsoft@@6B@1270x140349e68
                                    ??_7DebugEventListener@Events@Applications@Microsoft@@6B@1280x14034b048
                                    ??_7DebugEventSource@Events@Applications@Microsoft@@6B@1290x140349e80
                                    ??_7EventProperties@Events@Applications@Microsoft@@6B@1300x140359aa0
                                    ??_7EventProperty@Events@Applications@Microsoft@@6B@1310x14035a1c0
                                    ??_7IAuthTokensController@Events@Applications@Microsoft@@6B@1320x1403591f0
                                    ??_7ILogController@Events@Applications@Microsoft@@6B@1330x140359238
                                    ??_7ILogManager@Events@Applications@Microsoft@@6BDebugEventDispatcher@123@@1340x140359418
                                    ??_7ILogManager@Events@Applications@Microsoft@@6BIContextProvider@123@@1350x140359400
                                    ??_7ILogManager@Events@Applications@Microsoft@@6BILogController@123@@1360x1403592a0
                                    ??_7ILogger@Events@Applications@Microsoft@@6B@1370x140359098
                                    ??_7IModule@Events@Applications@Microsoft@@6B@1380x140358d48
                                    ??_7ISemanticContext@Events@Applications@Microsoft@@6B@1390x140358d78
                                    ?AddEventListener@DebugEventSource@Events@Applications@Microsoft@@UEAAXW4DebugEventType@234@AEAVDebugEventListener@234@@Z1400x14009c7f0
                                    ?AddModule@ILogConfiguration@Events@Applications@Microsoft@@QEAAXPEBDAEBV?$shared_ptr@VIModule@Events@Applications@Microsoft@@@std@@@Z1410x1400a0ac0
                                    ?AttachEventSource@DebugEventSource@Events@Applications@Microsoft@@UEAA_NAEAV1234@@Z1420x14009c8a0
                                    ?ClearExperimentIds@ISemanticContext@Events@Applications@Microsoft@@UEAAXXZ1430x140009290
                                    ?CreateLogManager@LogManagerProvider@Events@Applications@Microsoft@@SAPEAVILogManager@234@AEAVILogConfiguration@234@AEAW4status_t@234@@Z1440x140097560
                                    ?CreateLogManager@LogManagerProvider@Events@Applications@Microsoft@@SAPEAVILogManager@234@PEBDAEAW4status_t@234@_K@Z1450x140097570
                                    ?CreateLogManager@LogManagerProvider@Events@Applications@Microsoft@@SAPEAVILogManager@234@PEBD_NAEAVILogConfiguration@234@AEAW4status_t@234@_K@Z1460x140097580
                                    ?DecrementActiveHydrationsCount@QoS@@YAXXZ1470x1402c1380
                                    ?DestroyLogManager@LogManagerProvider@Events@Applications@Microsoft@@SA?AW4status_t@234@PEBD@Z1480x140097690
                                    ?DetachEventSource@DebugEventSource@Events@Applications@Microsoft@@UEAA_NAEAV1234@@Z1490x14009c940
                                    ?DispatchEvent@DebugEventSource@Events@Applications@Microsoft@@UEAA_NVDebugEvent@234@@Z1500x14009c9c0
                                    ?DispatchEventBroadcast@ILogManager@Events@Applications@Microsoft@@SA_NVDebugEvent@234@@Z1510x1400b90d0
                                    ?FromJSON@Events@Applications@Microsoft@@YA?AVILogConfiguration@123@PEBD@Z1520x1400b0280
                                    ?FromLogConfiguration@Events@Applications@Microsoft@@YA?AVILogConfiguration@123@AEAULogConfiguration@Telemetry@23@@Z1530x1400b0440
                                    ?Get@LogManagerProvider@Events@Applications@Microsoft@@CAPEAVILogManager@234@AEAVILogConfiguration@234@AEAW4status_t@234@@Z1540x1400a1160
                                    ?Get@LogManagerProvider@Events@Applications@Microsoft@@CAPEAVILogManager@234@PEBDAEAW4status_t@234@@Z1550x1400a11a0
                                    ?GetActiveHydrationsCount@QoS@@YAIXZ1560x1402c1390
                                    ?GetApplicationPropertyId@QoS@@YA?AW4Id@PropertyId@TelemetryConstants@@XZ1570x1402c13a0
                                    ?GetDefaultConfiguration@Events@Applications@Microsoft@@YAAEBVILogConfiguration@123@XZ1580x1400b0830
                                    ?GetErrorType@QoS@@YA?AW4Type@ErrorType@TelemetryConstants@@JI@Z1590x1402c13b0
                                    ?GetErrorType@QoS@@YA?AW4Type@ErrorType@TelemetryConstants@@JIAEBV?$set@IU?$less@I@std@@V?$allocator@I@2@@std@@@Z1600x1402c1420
                                    ?GetInstance@Telemetry@@CAPEAV1@XZ1610x1402c1800
                                    ?GetLatency@EventProperties@Events@Applications@Microsoft@@QEBA?AW4EventLatency@234@XZ1620x14009e650
                                    ?GetLogObfuscationKeyManger@@YAJPEAPEAVILogObfuscationKeyManager@@@Z1630x14004df90
                                    ?GetLogObfuscatorAes@@YAJPEAPEAVILogObfuscatorAes@@@Z1640x14004b770
                                    ?GetModule@ILogConfiguration@Events@Applications@Microsoft@@QEAA?AV?$shared_ptr@VIModule@Events@Applications@Microsoft@@@std@@PEBD@Z1650x1400a0b90
                                    ?GetModules@ILogConfiguration@Events@Applications@Microsoft@@QEAAAEAV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$shared_ptr@VIModule@Events@Applications@Microsoft@@@2@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$shared_ptr@VIModule@Events@Applications@Microsoft@@@2@@std@@@2@@std@@XZ1660x1400a0de0
                                    ?GetName@EventProperties@Events@Applications@Microsoft@@QEBAAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ1670x1400283c0
                                    ?GetPersistence@EventProperties@Events@Applications@Microsoft@@QEBA?AW4EventPersistence@234@XZ1680x14009e660
                                    ?GetPiiProperties@EventProperties@Events@Applications@Microsoft@@QEBA?BV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$pair@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4PiiKind@Events@Applications@Microsoft@@@2@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$pair@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4PiiKind@Events@Application1690x14009e670
                                    ?GetPolicyBitFlags@EventProperties@Events@Applications@Microsoft@@QEBA_KXZ1700x14009e8e0
                                    ?GetPopSample@EventProperties@Events@Applications@Microsoft@@QEBANXZ1710x14009e8f0
                                    ?GetPriority@EventProperties@Events@Applications@Microsoft@@QEBA?AW4EventPriority@234@XZ1720x14009e650
                                    ?GetProperties@EventProperties@Events@Applications@Microsoft@@QEBAAEBV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@2@@std@@W4DataCategory@234@@Z1730x14009e900
                                    ?GetResultType@QoS@@YAPEB_WJI@Z1740x1402c1540
                                    ?GetResultType@QoS@@YAPEB_WW4Type@ErrorType@TelemetryConstants@@@Z1750x1402c1560
                                    ?GetTimestamp@EventProperties@Events@Applications@Microsoft@@QEBA_JXZ1760x14009e920
                                    ?GetType@EventProperties@Events@Applications@Microsoft@@QEBAAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ1770x14009e930
                                    ?HasConfig@ILogConfiguration@Events@Applications@Microsoft@@QEAA_NPEBD@Z1780x1400a0df0
                                    ?Hash@GUID_t@Events@Applications@Microsoft@@QEBA_KXZ1790x1400a4510
                                    ?IncrementActiveHydrationsCount@QoS@@YAXXZ1800x1402c1590
                                    ?Initialize@IModule@Events@Applications@Microsoft@@UEAAXPEAVILogManager@234@@Z1810x140009290
                                    ?InsertIntoIrmEnabledLibrarySet@QoS@@YAXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z1820x1402c15a0
                                    ?IsAnyLibraryIrmEnabled@QoS@@YA_NXZ1830x1402c15b0
                                    ?Release@LogManagerProvider@Events@Applications@Microsoft@@SA?AW4status_t@234@AEAVILogConfiguration@234@@Z1840x1400a1260
                                    ?Release@LogManagerProvider@Events@Applications@Microsoft@@SA?AW4status_t@234@PEBD@Z1850x1400a1290
                                    ?RemoveEventListener@DebugEventSource@Events@Applications@Microsoft@@UEAAXW4DebugEventType@234@AEAVDebugEventListener@234@@Z1860x14009cb80
                                    ?RemoveFromIrmEnabledLibrarySet@QoS@@YAXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z1870x1402c15c0
                                    ?SetAppEnv@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1880x1400976a0
                                    ?SetAppExperimentETag@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1890x140097790
                                    ?SetAppExperimentIds@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1900x140097890
                                    ?SetAppExperimentImpressionId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1910x140097980
                                    ?SetAppId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1920x140097a70
                                    ?SetAppLanguage@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1930x140097b60
                                    ?SetAppName@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1940x140097c50
                                    ?SetAppVersion@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1950x140097d40
                                    ?SetApplicationId@QoS@@YAXI@Z1960x1402c15d0
                                    ?SetCommercialId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z1970x140097e30
                                    ?SetCommonField@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEBUEventProperty@234@@Z1980x140009290
                                    ?SetCustomField@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEBUEventProperty@234@@Z1990x140009290
                                    ?SetDeviceClass@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2000x140097f20
                                    ?SetDeviceId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2010x140098010
                                    ?SetDeviceMake@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2020x140098100
                                    ?SetDeviceModel@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2030x1400981f0
                                    ?SetDeviceOrgId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2040x1400982e0
                                    ?SetEventExperimentIds@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0@Z2050x140009290
                                    ?SetLatency@EventProperties@Events@Applications@Microsoft@@QEAAXW4EventLatency@234@@Z2060x14009e940
                                    ?SetLevel@EventProperties@Events@Applications@Microsoft@@QEAAXE@Z2070x1400983d0
                                    ?SetName@EventProperties@Events@Applications@Microsoft@@QEAA_NAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2080x14009e950
                                    ?SetNetworkCost@ISemanticContext@Events@Applications@Microsoft@@UEAAXW4NetworkCost@234@@Z2090x140098490
                                    ?SetNetworkProvider@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2100x1400985c0
                                    ?SetNetworkType@ISemanticContext@Events@Applications@Microsoft@@UEAAXW4NetworkType@234@@Z2110x1400986b0
                                    ?SetOsBuild@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2120x1400987e0
                                    ?SetOsName@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2130x1400988d0
                                    ?SetOsVersion@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2140x1400989c0
                                    ?SetPersistence@EventProperties@Events@Applications@Microsoft@@QEAAXW4EventPersistence@234@@Z2150x14009ea90
                                    ?SetPolicyBitFlags@EventProperties@Events@Applications@Microsoft@@QEAAX_K@Z2160x14009eaa0
                                    ?SetPopsample@EventProperties@Events@Applications@Microsoft@@QEAAXN@Z2170x14009eab0
                                    ?SetPriority@EventProperties@Events@Applications@Microsoft@@QEAAXW4EventPriority@234@@Z2180x14009eac0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0W4PiiKind@234@W4DataCategory@234@@Z2190x14009eb00
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEAV?$vector@NV?$allocator@N@std@@@6@W4PiiKind@234@W4DataCategory@234@@Z2200x14009eb50
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEAV?$vector@UGUID_t@Events@Applications@Microsoft@@V?$allocator@UGUID_t@Events@Applications@Microsoft@@@std@@@6@W4PiiKind@234@W4DataCategory@234@@Z2210x14009eba0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEAV?$vector@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$allocator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@6@W4PiiKind@234@W4DataCategory@234@@Z2220x14009ebf0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEAV?$vector@_JV?$allocator@_J@std@@@6@W4PiiKind@234@W4DataCategory@234@@Z2230x14009ec40
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@CW4PiiKind@234@W4DataCategory@234@@Z2240x140098ab0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@EW4PiiKind@234@W4DataCategory@234@@Z2250x140098ac0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@FW4PiiKind@234@W4DataCategory@234@@Z2260x140098ad0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@GW4PiiKind@234@W4DataCategory@234@@Z2270x140098ae0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@HW4PiiKind@234@W4DataCategory@234@@Z2280x140098af0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@IW4PiiKind@234@W4DataCategory@234@@Z2290x140098b00
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@NW4PiiKind@234@W4DataCategory@234@@Z2300x14009ec90
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@PEBDW4PiiKind@234@W4DataCategory@234@@Z2310x14009ece0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@234@@Z2320x14009ed30
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UGUID_t@234@W4PiiKind@234@W4DataCategory@234@@Z2330x14009ee30
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@Utime_ticks_t@234@W4PiiKind@234@W4DataCategory@234@@Z2340x14009ee80
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_JW4PiiKind@234@W4DataCategory@234@@Z2350x14009eee0
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_KW4PiiKind@234@W4DataCategory@234@@Z2360x140098b10
                                    ?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_NW4PiiKind@234@W4DataCategory@234@@Z2370x14009ef30
                                    ?SetTicket@ISemanticContext@Events@Applications@Microsoft@@UEAAXW4TicketType@234@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2380x140009290
                                    ?SetTimestamp@EventProperties@Events@Applications@Microsoft@@QEAAX_J@Z2390x14009ef80
                                    ?SetType@EventProperties@Events@Applications@Microsoft@@QEAA_NAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2400x14009ef90
                                    ?SetUserANID@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2410x140098b20
                                    ?SetUserAdvertisingId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2420x140098c10
                                    ?SetUserId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4PiiKind@234@@Z2430x140098d00
                                    ?SetUserLanguage@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2440x140098de0
                                    ?SetUserMsaId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2450x140098ed0
                                    ?SetUserTimeZone@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z2460x140098fc0
                                    ?SizeUnknown@QoS@@YAIXZ2470x14000a9c0
                                    ?Teardown@IModule@Events@Applications@Microsoft@@UEAAXXZ2480x140009290
                                    ?TryGetLevel@EventProperties@Events@Applications@Microsoft@@QEBA?AV?$tuple@_NE@std@@XZ2490x14009f130
                                    ?clear@EventProperty@Events@Applications@Microsoft@@QEAAXXZ2500x1400a4760
                                    ?convertUintVectorToGUID@GUID_t@Events@Applications@Microsoft@@SA?AU_GUID@@AEBV?$vector@EV?$allocator@E@std@@@std@@@Z2510x1400a4810
                                    ?copydata@EventProperty@Events@Applications@Microsoft@@AEAAXPEBU1234@@Z2520x1400a4870
                                    ?empty@EventProperty@Events@Applications@Microsoft@@QEAA_NXZ2530x1400a4a00
                                    ?erase@EventProperties@Events@Applications@Microsoft@@QEAA_KAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4DataCategory@234@@Z2540x14009f510
                                    ?lock@?1??stateLock@DebugEventSource@Events@Applications@Microsoft@@KAAEAVrecursive_mutex@std@@XZ@4V67@A2550x140470900
                                    ?pack@EventProperties@Events@Applications@Microsoft@@QEAAPEAUevt_prop@@XZ2560x14009f530
                                    ?stateLock@DebugEventSource@Events@Applications@Microsoft@@KAAEAVrecursive_mutex@std@@XZ2570x14009bb70
                                    ?to_bytes@GUID_t@Events@Applications@Microsoft@@QEBAXAEAY0BA@E@Z2580x1400a4b20
                                    ?to_string@EventProperty@Events@Applications@Microsoft@@UEBA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ2590x1400a4b70
                                    ?to_string@GUID_t@Events@Applications@Microsoft@@QEBA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ2600x1400a5420
                                    ?type_name@EventProperty@Events@Applications@Microsoft@@SAPEBDI@Z2610x1400a5440
                                    ?unpack@EventProperties@Events@Applications@Microsoft@@QEAA_NPEAUevt_prop@@_K@Z2620x14009f800
                                    OnLoadTelemetryExtensions2630x140009290
                                    evt_api_call_default2640x1400933b0
                                    Language of compilation systemCountry where language is spokenMap
                                    EnglishUnited States
                                    CatalanSpain
                                    ChineseTaiwan
                                    CzechCzech Republic
                                    DanishDenmark
                                    GermanGermany
                                    GreekGreece
                                    FinnishFinland
                                    FrenchFrance
                                    HebrewIsrael
                                    HungarianHungary
                                    ItalianItaly
                                    JapaneseJapan
                                    KoreanNorth Korea
                                    KoreanSouth Korea
                                    DutchNetherlands
                                    NorwegianNorway
                                    PolishPoland
                                    PortugueseBrazil
                                    RomanianRomania
                                    RussianRussia
                                    CroatianCroatia
                                    SlovakSlovakia
                                    SwedishSweden
                                    ThaiThailand
                                    TurkishTurkey
                                    IndonesianIndonesia
                                    UkrainianUkrain
                                    SlovenianSlovenia
                                    EstonianEstonia
                                    LatvianLativa
                                    LithuanianLithuania
                                    VietnameseVietnam
                                    SetsuanaSouth Africa
                                    HindiIndia
                                    MalteseMalta
                                    MalayMalaysia
                                    TamilSri Lanka
                                    KannadaKanada
                                    WelshEngland
                                    AmharicEthiopia
                                    NepaliNepal
                                    FilipinoPhilippines
                                    IgboNigeria
                                    MaoriNew Zealand
                                    ChineseChina
                                    EnglishGreat Britain
                                    PortuguesePortugal
                                    GaelicIreland
                                    BosnianBosnian
                                    No network behavior found
                                    050100s020406080100

                                    Click to jump to process

                                    050100s0.00204060MB

                                    Click to jump to process

                                    Target ID:0
                                    Start time:16:56:55
                                    Start date:20/12/2023
                                    Path:C:\Users\user\Desktop\OneDriveSetUp.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Users\user\Desktop\OneDriveSetUp.exe
                                    Imagebase:0x7ff69fd90000
                                    File size:65'185'712 bytes
                                    MD5 hash:B471E4C796F44FACBB40EAC898B67503
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:false

                                    No disassembly