Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SyncBackPro64_Setup.exe

Overview

General Information

Sample name:SyncBackPro64_Setup.exe
Analysis ID:1557311
MD5:2b6068d3087ac283c4cc8822927bd711
SHA1:d05c97e93755b892bf36534b48e4dda9839f8707
SHA256:481c69d452ca4699994ef6b80fd26a85427edfc723dbc9a0b0476ef89179946b
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Compliance

Score:49
Range:0 - 100

Signatures

Allocates memory in foreign processes
Changes security center settings (notifications, updates, antivirus, firewall)
Found direct / indirect Syscall (likely to bypass EDR)
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Writes to foreign memory regions
Adds / modifies Windows certificates
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains capabilities to detect virtual machines
Creates files inside the system directory
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the windows directory (C:\Windows)
Enables security privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Queries information about the installed CPU (vendor, model number etc)
Queries the volume information (name, serial number etc) of a device
Registers a DLL
Stores files to the Windows start menu directory
Stores large binary data to the registry
Tries to disable installed Antivirus / HIPS / PFW
Uses 32bit PE files

Classification

  • System is w10x64_ra
  • SyncBackPro64_Setup.exe (PID: 1824 cmdline: "C:\Users\user\Desktop\SyncBackPro64_Setup.exe" MD5: 2B6068D3087AC283C4CC8822927BD711)
    • SyncBackPro64_Setup.tmp (PID: 6784 cmdline: "C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp" /SL5="$4038C,54789953,845312,C:\Users\user\Desktop\SyncBackPro64_Setup.exe" MD5: E47E7C49D587E0FA9BFAE76474B1D09F)
      • regsvr32.exe (PID: 3936 cmdline: "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
        • regsvr32.exe (PID: 2084 cmdline: /s "C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll" MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
      • regsvr32.exe (PID: 1596 cmdline: "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\EAGetMailObj.dll" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
        • regsvr32.exe (PID: 6584 cmdline: /s "C:\Program Files\2BrightSparks\SyncBackPro\EAGetMailObj.dll" MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
      • regsvr32.exe (PID: 4184 cmdline: "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\sfFTPLib.dll" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
        • regsvr32.exe (PID: 6328 cmdline: /s "C:\Program Files\2BrightSparks\SyncBackPro\sfFTPLib.dll" MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
      • regsvr32.exe (PID: 5748 cmdline: "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\wodFtpDLX.dll" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
        • regsvr32.exe (PID: 6340 cmdline: /s "C:\Program Files\2BrightSparks\SyncBackPro\wodFtpDLX.dll" MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
      • regsvr32.exe (PID: 6360 cmdline: "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\wodCertificate.dll" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
        • regsvr32.exe (PID: 6928 cmdline: /s "C:\Program Files\2BrightSparks\SyncBackPro\wodCertificate.dll" MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
      • regsvr32.exe (PID: 6280 cmdline: "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\ChilkatAx-x64.dll" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
        • regsvr32.exe (PID: 6312 cmdline: /s "C:\Program Files\2BrightSparks\SyncBackPro\ChilkatAx-x64.dll" MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
      • cmd.exe (PID: 1828 cmdline: "C:\Windows\system32\cmd.exe" /C mklink /H "C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.NE.exe" "C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 6380 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • SchedulesMonitor.exe (PID: 6016 cmdline: "C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor" /install /silent MD5: FC9A4B0D1A62B9349C3639B315B9643A)
      • SyncBackPro.exe (PID: 2548 cmdline: "C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe " MD5: 1157F60ACE930CEB10FCA5BE9025452A)
      • regsvr32.exe (PID: 3068 cmdline: "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\AOSMTP.DLL" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
      • regsvr32.exe (PID: 3492 cmdline: "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\AOSMTPEX.DLL" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
      • regsvr32.exe (PID: 4404 cmdline: "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\eSellerateControl350.dll" MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
  • svchost.exe (PID: 3860 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • svchost.exe (PID: 2920 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -p MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • SgrmBroker.exe (PID: 6952 cmdline: C:\Windows\system32\SgrmBroker.exe MD5: 3BA1A18A0DC30A0545E7765CB97D8E63)
  • svchost.exe (PID: 6968 cmdline: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • svchost.exe (PID: 7112 cmdline: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
    • MpCmdRun.exe (PID: 2536 cmdline: "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable MD5: B3676839B2EE96983F9ED735CD044159)
      • conhost.exe (PID: 3552 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • svchost.exe (PID: 7156 cmdline: C:\Windows\system32\svchost.exe -k UnistackSvcGroup MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • SchedulesMonitor.exe (PID: 6920 cmdline: "C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe" MD5: FC9A4B0D1A62B9349C3639B315B9643A)
  • Acrobat.exe (PID: 4112 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\GIGIYTFFYT.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
    • AcroCEF.exe (PID: 2228 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
      • AcroCEF.exe (PID: 3752 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2272 --field-trial-handle=1592,i,8943398227450087019,6429900512248474683,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
  • cleanup
No yara matches
Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 656, ProcessCommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, ProcessId: 3860, ProcessName: svchost.exe
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Compliance

barindex
Source: SyncBackPro64_Setup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\unins000.dat
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-71UJ7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-CG8P2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-6AV2I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-K47F8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-2AM10.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-IDTKU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-UG60S.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-J635Q.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-4PTCP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-AIIMS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-P90DJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-7CSKB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-6080B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-3J0FL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-L60SD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-BN8TH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-GHN9D.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-TP640.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-UU2O7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-RP8PO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-P5FCL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-LB23H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-UI0F3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8D473.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-IKQMD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-HR5N9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-SMA0T.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\en-US
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\en-US\is-3K9B7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-1RV20.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-J6H46.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-68F0E.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-SCU3R.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-H7I45.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-3P8I0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-N4SKD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-U3SIO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-HHE5L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-6L7CE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-1OJNJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-CD0TL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-IQO37.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-PKU38.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-NFUON.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-3CNEB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-JR5DJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8NGA7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-7I7QI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-82AIH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-1L29J.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-I5IP3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-HQEJS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-S3GS0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8UNFS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-2V9BJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-ISUFB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-GOR0F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-2GGD8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-R351F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-NA4BQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-SB1PN.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-C812F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-GU1UG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-AU4RV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-THK5F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8GC48.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-JK5AE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-2DI6I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-0I55G.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-4V8RC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-JIRH0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-3V26C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-10PVH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-IN94I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-0RM1U.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-T24A4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-CHNTA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-0UVGI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\is-MO9H1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\is-QINKJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\en-US
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\en-US\is-HBICL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\en-US\is-JT545.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-K7BM0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-0Q0SG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-CAOV7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-P9VO3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8IHCK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CA
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CA\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CA\LC_MESSAGES\is-8S0CK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CA\LC_MESSAGES\is-I65AR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE\LC_MESSAGES\is-457P3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE\LC_MESSAGES\is-3TCKL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE\LC_MESSAGES\is-H283M.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES\LC_MESSAGES\is-N4996.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES\LC_MESSAGES\is-11E7U.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES\LC_MESSAGES\is-2TAHQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR\LC_MESSAGES\is-LJHKF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR\LC_MESSAGES\is-0HSO3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR\LC_MESSAGES\is-SK2PB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT\LC_MESSAGES\is-LAHBR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT\LC_MESSAGES\is-F8K5N.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT\LC_MESSAGES\is-K9BP7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL\LC_MESSAGES\is-TQPM2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL\LC_MESSAGES\is-6PUEH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL\LC_MESSAGES\is-TDQI4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PL
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PL\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PL\LC_MESSAGES\is-0R4IC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PL\LC_MESSAGES\is-T5HQS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR\LC_MESSAGES\is-PG49K.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR\LC_MESSAGES\is-91P8H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR\LC_MESSAGES\is-275DA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH\LC_MESSAGES\is-ALQOH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH\LC_MESSAGES\is-9T8GR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH_HK
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH_HK\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH_HK\LC_MESSAGES\is-M14BK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HU
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HU\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HU\LC_MESSAGES\is-ENANO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HU\LC_MESSAGES\is-S2QJO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CS
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CS\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CS\LC_MESSAGES\is-RI1RU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CS\LC_MESSAGES\is-0F5I5.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NB
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NB\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NB\LC_MESSAGES\is-VAT3F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NB\LC_MESSAGES\is-4IK5A.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV\LC_MESSAGES\is-LTM6M.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV\LC_MESSAGES\is-BBI6T.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV\LC_MESSAGES\is-F2V66.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA\LC_MESSAGES\is-VOCPU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA\LC_MESSAGES\is-14OGR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA\LC_MESSAGES\is-E518J.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI\LC_MESSAGES\is-KVRPM.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI\LC_MESSAGES\is-17IIC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI\LC_MESSAGES\is-Q16U4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HY
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HY\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HY\LC_MESSAGES\is-MP1A0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HY\LC_MESSAGES\is-3VJRM.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA\LC_MESSAGES\is-2C23D.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA\LC_MESSAGES\is-SR8M9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA\LC_MESSAGES\is-TGEHR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU\LC_MESSAGES\is-4DCDV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU\LC_MESSAGES\is-FNCLP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU\LC_MESSAGES\is-EBC53.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\UK
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\UK\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\UK\LC_MESSAGES\is-G98QT.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\UK\LC_MESSAGES\is-2HSM8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RO
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RO\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RO\LC_MESSAGES\is-VIU67.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RO\LC_MESSAGES\is-IL4QA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\KO
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\KO\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\KO\LC_MESSAGES\is-2T9JU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\KO\LC_MESSAGES\is-LKRUA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL\LC_MESSAGES\is-3735G.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL\LC_MESSAGES\is-9B99K.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL\LC_MESSAGES\is-PLPVK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-AVFJS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\unins000.msg
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\~SB4BAA.tmp
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\LICENSE.txt
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\readme.txt
Source: SyncBackPro64_Setup.exeStatic PE information: certificate valid
Source: unknownHTTPS traffic detected: 104.26.3.34:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.26.3.34:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: SyncBackPro64_Setup.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData\Roaming
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.2brightsparks.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownHTTPS traffic detected: 104.26.3.34:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.26.3.34:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: C:\Windows\System32\svchost.exeFile created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Windows\SysWOW64\is-3LR55.tmp
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess token adjusted: Security
Source: SyncBackPro64_Setup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engineClassification label: mal60.evad.winEXE@60/186@1/11
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Users\user\AppData\Local\Programs
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: NULL
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:3552:120:WilError_03
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: \Sessions\1\BaseNamedObjects\SyncBackExpMtx
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: \Sessions\1\BaseNamedObjects\NarratorRunning
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: \Sessions\1\BaseNamedObjects\Mutex_SyncBackProSettingsSharedMem
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: \Sessions\1\BaseNamedObjects\Global\Mutex_SyncBackProVistaReloadRefreshPro
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: \Sessions\1\BaseNamedObjects\HookTThread$9f4
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: \Sessions\1\BaseNamedObjects\madExceptSettingsMtx$9f4
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpMutant created: \Sessions\1\BaseNamedObjects\SyncBackPro64_Setup
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: \Sessions\1\BaseNamedObjects\{8BD3A136-6962-412B-9D80-CD387EFFAC38}
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpMutant created: \Sessions\1\BaseNamedObjects\Global\SyncBackPro64_Setup
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMutant created: \Sessions\1\BaseNamedObjects\SyncBackPro
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeFile created: C:\Users\user\AppData\Local\Temp\is-TC366.tmp
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeKey opened: HKEY_USERS.DEFAULT\Software\Borland\Delphi\Locales
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeKey opened: HKEY_USERS.DEFAULT\Software\Borland\Delphi\Locales
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile read: C:\Windows\win.ini
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeFile read: C:\Users\user\Desktop\SyncBackPro64_Setup.exe
Source: unknownProcess created: C:\Users\user\Desktop\SyncBackPro64_Setup.exe "C:\Users\user\Desktop\SyncBackPro64_Setup.exe"
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeProcess created: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp "C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp" /SL5="$4038C,54789953,845312,C:\Users\user\Desktop\SyncBackPro64_Setup.exe"
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeProcess created: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp "C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp" /SL5="$4038C,54789953,845312,C:\Users\user\Desktop\SyncBackPro64_Setup.exe"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll"
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\EAGetMailObj.dll"
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files\2BrightSparks\SyncBackPro\EAGetMailObj.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\sfFTPLib.dll"
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files\2BrightSparks\SyncBackPro\sfFTPLib.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\wodFtpDLX.dll"
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files\2BrightSparks\SyncBackPro\wodFtpDLX.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\wodCertificate.dll"
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files\2BrightSparks\SyncBackPro\wodCertificate.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\ChilkatAx-x64.dll"
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files\2BrightSparks\SyncBackPro\ChilkatAx-x64.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /C mklink /H "C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.NE.exe" "C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe "C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor" /install /silent
Source: unknownProcess created: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe "C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe "C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe "
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p
Source: unknownProcess created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k UnistackSvcGroup
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\EAGetMailObj.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\sfFTPLib.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\wodFtpDLX.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\wodCertificate.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\ChilkatAx-x64.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /C mklink /H "C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.NE.exe" "C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe "C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor" /install /silent
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll"
Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\System32\regsvr32.exe /s "C:\Program Files\2BrightSparks\SyncBackPro\EAGetMailObj.dll"
Source: unknownProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\GIGIYTFFYT.pdf"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\AOSMTP.DLL"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\AOSMTPEX.DLL"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\eSellerateControl350.dll"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2272 --field-trial-handle=1592,i,8943398227450087019,6429900512248474683,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\AOSMTP.DLL"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\AOSMTPEX.DLL"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /u /s "C:\Program Files\2BrightSparks\SyncBackPro\eSellerateControl350.dll"
Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2272 --field-trial-handle=1592,i,8943398227450087019,6429900512248474683,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeSection loaded: netapi32.dll
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeSection loaded: netutils.dll
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: netapi32.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: winsta.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: shfolder.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: rstrtmgr.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: msftedit.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: windows.globalization.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: bcp47mrm.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: globinputhost.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: windows.ui.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: windowmanagementapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: inputhost.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: explorerframe.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: sfc_os.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: qmgr.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bitsperf.dll
Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dll
Source: C:\Windows\System32\svchost.exeSection loaded: firewallapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: esent.dll
Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dnsapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: iphlpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fwbase.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dll
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
Source: C:\Windows\System32\svchost.exeSection loaded: netprofm.dll
Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bitsigd.dll
Source: C:\Windows\System32\svchost.exeSection loaded: upnp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ssdpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: urlmon.dll
Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: srvcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wsmauto.dll
Source: C:\Windows\System32\svchost.exeSection loaded: miutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wsmsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dsrole.dll
Source: C:\Windows\System32\svchost.exeSection loaded: pcwum.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dll
Source: C:\Windows\System32\svchost.exeSection loaded: gpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wkscli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dll
Source: C:\Windows\System32\svchost.exeSection loaded: webio.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mswsock.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winnsi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rasadhlp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fwpuclnt.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: usermgrcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: execmodelclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dll
Source: C:\Windows\System32\svchost.exeSection loaded: coremessaging.dll
Source: C:\Windows\System32\svchost.exeSection loaded: twinapi.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: resourcepolicyclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\svchost.exeSection loaded: samcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: samlib.dll
Source: C:\Windows\System32\svchost.exeSection loaded: es.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bitsproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc6.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: schannel.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mskeyprotect.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntasn1.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ncrypt.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ncryptsslp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rsaenh.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: linkinfo.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: ntshrui.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: cscapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpSection loaded: apphelp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: moshost.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mapsbtsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mosstorage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ztrace_maps.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ztrace_maps.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bcp47langs.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mapconfiguration.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: storsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: devobj.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fltlib.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bcd.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wer.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: storageusage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: aphostservice.dll
Source: C:\Windows\System32\svchost.exeSection loaded: networkhelper.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdataplatformhelperutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mccspal.dll
Source: C:\Windows\System32\svchost.exeSection loaded: syncutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: syncutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vaultcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wintypes.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmcfgutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmcmnutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmxmlhelputils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dll
Source: C:\Windows\System32\svchost.exeSection loaded: inproclogger.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dll
Source: C:\Windows\System32\svchost.exeSection loaded: windows.networking.connectivity.dll
Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dll
Source: C:\Windows\System32\svchost.exeSection loaded: synccontroller.dll
Source: C:\Windows\System32\svchost.exeSection loaded: pimstore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: aphostclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: accountaccessor.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dsclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exeSection loaded: systemeventsbrokerclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdatalanguageutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mccsengineshared.dll
Source: C:\Windows\System32\svchost.exeSection loaded: pimstore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cemapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdatatypehelperutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: phoneutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: dnsapi.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: secur32.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: wininet.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: iphlpapi.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: iertutil.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: secur32.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: wldp.dll
Source: C:\Windows\System32\regsvr32.exeSection loaded: msasn1.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: version.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: winhttp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: winsta.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: uxtheme.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: userenv.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: profapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: sspicli.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: windows.storage.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: wldp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeSection loaded: propsys.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: version.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: netapi32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: winhttp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: shfolder.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wsock32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: mpr.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: winmm.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: oleacc.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wininet.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: faultrep.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: dbghelp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: dbgcore.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: ntmarta.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: uxtheme.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: winsta.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: security.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: secur32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: sspicli.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: libeay32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: ssleay32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: windows.storage.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wldp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wkscli.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: cscapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: dwmapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: compstui.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: msimg32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: dpapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: cryptbase.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: dwrite.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: cryptsp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: rsaenh.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: vssapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: vsstrace.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: resutils.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: clusapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: dnsapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: powrprof.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: umpdc.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: profapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: msasn1.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: gpapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: cryptnet.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: winnsi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: mswsock.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: dhcpcsvc6.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: dhcpcsvc.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: webio.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: rasadhlp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: fwpuclnt.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: cabinet.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wship6.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: userenv.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: explorerframe.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: propsys.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: textshaping.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: idndl.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: portabledeviceapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: devobj.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: taskschd.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: napinsp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: pnrpnsp.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wshbth.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: nlaapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: winrnr.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: firewallapi.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: fwbase.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: fwpolicyiomgr.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: textinputframework.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: coreuicomponents.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: coremessaging.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wintypes.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wintypes.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wintypes.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: windowscodecs.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: samcli.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: samlib.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: netutils.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: logoncli.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: wpnapps.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: rmclient.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: xmllite.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: twinapi.appcore.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: usermgrcli.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: msimg32.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: schannel.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: mskeyprotect.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: ntasn1.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: ncrypt.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeSection loaded: ncryptsslp.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: mpclient.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: secur32.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sspicli.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: version.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: msasn1.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: userenv.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: gpapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wbemcomn.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: amsi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: profapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wscapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: urlmon.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: iertutil.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: srvcli.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: netutils.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: slc.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sppc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile written: C:\Users\user\AppData\Local\2BrightSparks\SyncBackProSchedules.ini
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpWindow found: window name: TMainForm
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLL
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\unins000.dat
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-71UJ7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-CG8P2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-6AV2I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-K47F8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-2AM10.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-IDTKU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-UG60S.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-J635Q.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-4PTCP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-AIIMS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-P90DJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-7CSKB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-6080B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-3J0FL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-L60SD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-BN8TH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-GHN9D.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-TP640.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-UU2O7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-RP8PO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-P5FCL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-LB23H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-UI0F3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8D473.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-IKQMD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-HR5N9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-SMA0T.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\en-US
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\en-US\is-3K9B7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-1RV20.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-J6H46.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-68F0E.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-SCU3R.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-H7I45.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-3P8I0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-N4SKD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-U3SIO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-HHE5L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-6L7CE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-1OJNJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-CD0TL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-IQO37.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-PKU38.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-NFUON.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-3CNEB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-JR5DJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8NGA7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-7I7QI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-82AIH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-1L29J.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-I5IP3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-HQEJS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-S3GS0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8UNFS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-2V9BJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-ISUFB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-GOR0F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-2GGD8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-R351F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-NA4BQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-SB1PN.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-C812F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-GU1UG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-AU4RV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-THK5F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8GC48.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-JK5AE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-2DI6I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-0I55G.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-4V8RC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-JIRH0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-3V26C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-10PVH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-IN94I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-0RM1U.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-T24A4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-CHNTA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-0UVGI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\is-MO9H1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\is-QINKJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\en-US
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\en-US\is-HBICL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\ADMX\en-US\is-JT545.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-K7BM0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-0Q0SG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-CAOV7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-P9VO3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-8IHCK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CA
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CA\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CA\LC_MESSAGES\is-8S0CK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CA\LC_MESSAGES\is-I65AR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE\LC_MESSAGES\is-457P3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE\LC_MESSAGES\is-3TCKL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DE\LC_MESSAGES\is-H283M.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES\LC_MESSAGES\is-N4996.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES\LC_MESSAGES\is-11E7U.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ES\LC_MESSAGES\is-2TAHQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR\LC_MESSAGES\is-LJHKF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR\LC_MESSAGES\is-0HSO3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FR\LC_MESSAGES\is-SK2PB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT\LC_MESSAGES\is-LAHBR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT\LC_MESSAGES\is-F8K5N.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\IT\LC_MESSAGES\is-K9BP7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL\LC_MESSAGES\is-TQPM2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL\LC_MESSAGES\is-6PUEH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NL\LC_MESSAGES\is-TDQI4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PL
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PL\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PL\LC_MESSAGES\is-0R4IC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PL\LC_MESSAGES\is-T5HQS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR\LC_MESSAGES\is-PG49K.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR\LC_MESSAGES\is-91P8H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\PT_BR\LC_MESSAGES\is-275DA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH\LC_MESSAGES\is-ALQOH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH\LC_MESSAGES\is-9T8GR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH_HK
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH_HK\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\ZH_HK\LC_MESSAGES\is-M14BK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HU
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HU\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HU\LC_MESSAGES\is-ENANO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HU\LC_MESSAGES\is-S2QJO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CS
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CS\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CS\LC_MESSAGES\is-RI1RU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\CS\LC_MESSAGES\is-0F5I5.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NB
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NB\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NB\LC_MESSAGES\is-VAT3F.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\NB\LC_MESSAGES\is-4IK5A.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV\LC_MESSAGES\is-LTM6M.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV\LC_MESSAGES\is-BBI6T.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\SV\LC_MESSAGES\is-F2V66.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA\LC_MESSAGES\is-VOCPU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA\LC_MESSAGES\is-14OGR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\JA\LC_MESSAGES\is-E518J.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI\LC_MESSAGES\is-KVRPM.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI\LC_MESSAGES\is-17IIC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\FI\LC_MESSAGES\is-Q16U4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HY
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HY\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HY\LC_MESSAGES\is-MP1A0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\HY\LC_MESSAGES\is-3VJRM.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA\LC_MESSAGES\is-2C23D.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA\LC_MESSAGES\is-SR8M9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\DA\LC_MESSAGES\is-TGEHR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU\LC_MESSAGES\is-4DCDV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU\LC_MESSAGES\is-FNCLP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RU\LC_MESSAGES\is-EBC53.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\UK
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\UK\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\UK\LC_MESSAGES\is-G98QT.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\UK\LC_MESSAGES\is-2HSM8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RO
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RO\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RO\LC_MESSAGES\is-VIU67.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\RO\LC_MESSAGES\is-IL4QA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\KO
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\KO\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\KO\LC_MESSAGES\is-2T9JU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\KO\LC_MESSAGES\is-LKRUA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL\LC_MESSAGES
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL\LC_MESSAGES\is-3735G.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL\LC_MESSAGES\is-9B99K.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\locale\EL\LC_MESSAGES\is-PLPVK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\is-AVFJS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\unins000.msg
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeDirectory created: C:\Program Files\2BrightSparks\SyncBackPro\~SB4BAA.tmp
Source: SyncBackPro64_Setup.exeStatic PE information: certificate valid
Source: SyncBackPro64_Setup.exeStatic file information: File size 56285520 > 1048576
Source: SyncBackPro64_Setup.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: SyncBackPro64_Setup.exeStatic PE information: section name: .didata
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll"
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-IKQMD.tmpJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\legacy-x64.dllJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\libcrypto-3-x64.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-HR5N9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-AIIMS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-4PTCP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-71UJ7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-68F0E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-J6H46.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Windows\SysWOW64\is-3LR55.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\en-US\is-3K9B7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-7CSKB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-3J0FL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-UI0F3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-2AM10.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-SCU3R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-1RV20.tmpJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\libssl-3-x64.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Users\user\AppData\Local\Temp\is-5I41T.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-L60SD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-SMA0T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-CG8P2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-P90DJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-6AV2I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Program Files\2BrightSparks\SyncBackPro\is-K47F8.tmpJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\legacy-x64.dllJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\libcrypto-3-x64.dllJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\libssl-3-x64.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\Windows\SysWOW64\is-3LR55.tmpJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\LICENSE.txt
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile created: C:\ProgramData\ICS-OpenSSL\3302\readme.txt
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SyncBackPro (Not Elevated).lnk
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SyncBackPro.lnk

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeMemory written: PID: 2548 base: 6EC760 value: E9 5B F0 C0 02
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E Blob
Source: C:\Users\user\Desktop\SyncBackPro64_Setup.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeFile opened / queried: SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeWindow / User API: threadDelayed 1299
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exeWindow / User API: threadDelayed 6706
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-UI0F3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-IKQMD.tmpJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeDropped PE file which has not been started: C:\ProgramData\ICS-OpenSSL\3302\legacy-x64.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-2AM10.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-SCU3R.tmpJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeDropped PE file which has not been started: C:\ProgramData\ICS-OpenSSL\3302\libcrypto-3-x64.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-AIIMS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-1RV20.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-HR5N9.tmpJump to dropped file
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeDropped PE file which has not been started: C:\ProgramData\ICS-OpenSSL\3302\libssl-3-x64.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-5I41T.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-4PTCP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-SMA0T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-L60SD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-68F0E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-J6H46.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-P90DJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Windows\SysWOW64\is-3LR55.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-K47F8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\en-US\is-3K9B7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-7CSKB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpDropped PE file which has not been started: C:\Program Files\2BrightSparks\SyncBackPro\is-3J0FL.tmpJump to dropped file
Source: C:\Windows\System32\svchost.exe TID: 6716Thread sleep time: -30000s >= -30000s
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe TID: 1444Thread sleep count: 1299 > 30
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe TID: 1444Thread sleep time: -64950s >= -30000s
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe TID: 4636Thread sleep time: -30000s >= -30000s
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe TID: 3668Thread sleep count: 39 > 30
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe TID: 1444Thread sleep count: 6706 > 30
Source: C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe TID: 1444Thread sleep time: -335300s >= -30000s
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe TID: 3668Thread sleep count: 49 > 30
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe TID: 4372Thread sleep time: -30000s >= -30000s
Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\Windows\System32 FullSizeInformation
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData\Roaming
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: C:\Users\user\AppData
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpProcess information queried: ProcessInformation

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpMemory allocated: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe base: 28EAEE80000 protect: page read and write
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeNtQuerySystemInformation: Indirect: 0x4BB3F7
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeNtQuerySystemInformation: Indirect: 0x4BB4C1
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpMemory written: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe base: 28EAEE10008
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpMemory written: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe base: 28EAEE80000
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpMemory written: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe base: B437F982D8
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeFile opened: Windows Firewall: C:\Windows\System32\FirewallAPI.dll
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\2
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\2
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\3
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\3
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Windows\System32\svchost.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center cval
Source: C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E Blob
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Windows Management Instrumentation
1
Registry Run Keys / Startup Folder
21
Process Injection
23
Masquerading
1
Credential API Hooking
1
Query Registry
Remote Services1
Credential API Hooking
2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Abuse Elevation Control Mechanism
1
Modify Registry
LSASS Memory3
Security Software Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Registry Run Keys / Startup Folder
3
Virtualization/Sandbox Evasion
Security Account Manager3
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
DLL Side-Loading
12
Disable or Modify Tools
NTDS1
Process Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script21
Process Injection
LSA Secrets1
Application Window Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Abuse Elevation Control Mechanism
Cached Domain Credentials2
System Owner/User Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
Regsvr32
DCSync3
File and Directory Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
DLL Side-Loading
Proc Filesystem33
System Information Discovery
Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SyncBackPro64_Setup.exe0%ReversingLabs
SyncBackPro64_Setup.exe0%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Program Files\2BrightSparks\SyncBackPro\is-71UJ7.tmp0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\is-5I41T.tmp\_isetup\_setup64.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-5I41T.tmp\_isetup\_setup64.tmp0%VirustotalBrowse
C:\Program Files\2BrightSparks\SyncBackPro\ChilkatAx-x64.dll (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\ChilkatAx-x64.dll (copy)0%VirustotalBrowse
C:\Program Files\2BrightSparks\SyncBackPro\EAGetMailObj.dll (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\EAGetMailObj.dll (copy)0%VirustotalBrowse
C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\EASendMailObj.dll (copy)0%VirustotalBrowse
C:\Program Files\2BrightSparks\SyncBackPro\RemBlankPwd.exe (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\RemBlankPwd.exe (copy)0%VirustotalBrowse
C:\Program Files\2BrightSparks\SyncBackPro\SBShellExt32.dll (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\SBShellExt64.dll (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\SchedulesMonitor.exe (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\XcdSfxZ64.bin (copy)2%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\XcdSfxZ64AES.bin (copy)4%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\XcdSfxZ64BzAES.bin (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\XceedZip.dll (copy)0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\en-US\is-3K9B7.tmp0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\is-1RV20.tmp0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\is-68F0E.tmp0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\is-HR5N9.tmp0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\is-IKQMD.tmp0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\is-J6H46.tmp0%ReversingLabs
C:\Program Files\2BrightSparks\SyncBackPro\is-SMA0T.tmp0%ReversingLabs
C:\Windows\SysWOW64\SyncBackPro.dll (copy)3%ReversingLabs
C:\ProgramData\ICS-OpenSSL\3302\legacy-x64.dll0%ReversingLabs
C:\ProgramData\ICS-OpenSSL\3302\libcrypto-3-x64.dll0%ReversingLabs
C:\ProgramData\ICS-OpenSSL\3302\libssl-3-x64.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    high
    www.2brightsparks.com
    104.26.3.34
    truefalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      184.28.88.176
      unknownUnited States
      16625AKAMAI-ASUSfalse
      104.26.3.34
      www.2brightsparks.comUnited States
      13335CLOUDFLARENETUSfalse
      184.28.90.27
      unknownUnited States
      16625AKAMAI-ASUSfalse
      199.232.210.172
      bg.microsoft.map.fastly.netUnited States
      54113FASTLYUSfalse
      172.64.41.3
      unknownUnited States
      13335CLOUDFLARENETUSfalse
      IP
      127.0.0.1
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1557311
      Start date and time:2024-11-18 02:31:08 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsinteractivecookbook.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:39
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      Analysis Mode:stream
      Analysis stop reason:Timeout
      Sample name:SyncBackPro64_Setup.exe
      Detection:MAL
      Classification:mal60.evad.winEXE@60/186@1/11
      Cookbook Comments:
      • Found application associated with file extension: .exe
      • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, SgrmBroker.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 199.232.210.172, 184.28.88.176, 172.64.41.3, 162.159.61.3
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtEnumerateKey calls found.
      • Report size getting too big, too many NtOpenKeyEx calls found.
      • Report size getting too big, too many NtProtectVirtualMemory calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • Timeout during stream target processing, analysis might miss dynamic analysis data
      • VT rate limit hit for: C:\Program Files\2BrightSparks\SyncBackPro\SBShellExt32.dll (copy)
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:874D692EA3D520BC923C1B5EB2A48EEE
      SHA1:C37AA1C54B54894ACEBAC125DEC98C29BEF98376
      SHA-256:592125F7F0B51BB3B7E1C452A345A79A32887251EA57484E6B424656D85C36DD
      SHA-512:433310634CF90A18698628BDC2F157BC48AED828E47F62E552051BFFF9AAD1987809C53D23EADF57A8E98DFE9ACB4A61B39E0D5C922D5FBE11B84EEFE9CA91DE
      Malicious:false
      Reputation:unknown
      Preview:..=== DO NOT MOVE OR DELETE ANY FILES IN THIS FOLDER ===....If you want to move the SyncBack installation:.... 1. Export all your profiles (https://help.2brightsparks.com/support/solutions/articles/43000335681).. .. 2. Uninstall SyncBack. During the uninstall process, when prompted with "Would you like to keep your profiles and settings?" click Yes..... 3. Install SyncBack, and when asked which folder to install it into, choose your folder.......If you want to uninstall SyncBack then uninstall it just like any other Windows program:.... https://help.2brightsparks.com/support/solutions/articles/43000335665....
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:49C3231517F47E8C57B480BAF491A2F6
      SHA1:EEDEE4F501D7B1BE9BC2274DEF8FD55317D878E0
      SHA-256:DD616BC695B652139C323FFE313325C211C58A111B9D524AD0E741F5A1503852
      SHA-512:0953BF79073D7C67113946BADA517DF9B9587A32CFEAD76E55834E7C73680517310AD2054890D9E308919AAED7F0475A2087FC18404C07DB130FBFD9AA8937AC
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright 2023 2BrightSparks Pte Ltd -->..<policyDefinitions revision="1.0" schemaVersion="1.0" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">...<policyNamespaces>....<target prefix="2BrightSparks" namespace="MSC.Policies.2BrightSparks"/>....<using prefix="windows" namespace="Microsoft.Policies.Windows"/>...</policyNamespaces>...<supersededAdm fileName=""/>...<resources minRequiredRevision="1.0" fallbackCulture="en-US"/>...<categories>....<category name="2BrightSparks_ADMXL" displayName="$(string.2BrightSparks_ADMXL)" explainText="$(string.2BrightSparks_ADMXL_HELP)"/>....<category name="2BrightSparks_SyncBackPro_ADMXL" displayName="$(string.2BrightSparks_SyncBackPro_ADMXL)".......explainText="$(string.2BrightSparks_SyncBackPro_ADMXL_HELP)">.....<parentCategory ref="2BrightSparks_ADMXL"/>....</category>...</categories>...<policies>....<policy name="2BrightSparks_SyncBackPro_ADMXL_CanCreateP
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:7B6D262956F1547A97B9AA5B63EB35C7
      SHA1:811F606E33AAB61FBC539AAA246E38F08CA07918
      SHA-256:AA5229FAAC62FE8A5420B096EBE092D5A0A92672B2B3F6360AB8D87F7351DF93
      SHA-512:15C7F02CAE453563D41A9FAA293A2F61DE6DBB6380674FE9DB6F1764AD0BC766414FD67C93049144F3754752AB26DE94A1AB9A12792EC33E97064D1445162869
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright 2023 2BrightSparks Pte Ltd -->..<policyDefinitions revision="1.0" schemaVersion="1.0" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">...<policyNamespaces>....<target prefix="2BrightSparks" namespace="MSC.Policies.2BrightSparks"/>....<using prefix="windows" namespace="Microsoft.Policies.Windows"/>...</policyNamespaces>...<supersededAdm fileName=""/>...<resources minRequiredRevision="1.0" fallbackCulture="en-US"/>...<categories>....<category name="2BrightSparks_ADMXL" displayName="$(string.2BrightSparks_ADMXL)" explainText="$(string.2BrightSparks_ADMXL_HELP)"/>....<category name="2BrightSparks_SyncBackPro_ADMXL" displayName="$(string.2BrightSparks_SyncBackPro_ADMXL)".......explainText="$(string.2BrightSparks_SyncBackPro_ADMXL_HELP)">.....<parentCategory ref="2BrightSparks_ADMXL"/>....</category>...</categories>...<policies>....<policy name="2BrightSparks_SyncBackPro_ADMXL_CanCreateP
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:0EDE37767B3851C67F13DF39677D72C1
      SHA1:2E1199BAE45A164DED499112F49C59ECE037711C
      SHA-256:47B55DA39528CD6A68BE7851F7486F0258FF9AF68DE1104B3965BA3A692A07EF
      SHA-512:642CFC869DFD6AD9B2ACACDBAA3B52E28A1DB54705DA88C222AFB4978F3E9E7AB03623377D27FDE24B352944870AFA89D27B2D663AE06B0E7DD0BC409609C661
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0"?>.. Copyright 2023 2BrightSparks Pte Ltd -->..<policyDefinitionResources revision="1.0" schemaVersion="1.0" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">...<displayName>2BrightSparks_ADMXL</displayName>...<description>This policy file was generated for the 2BrightSparks applications.</description>...<resources>....<stringTable>.....<string id="2BrightSparks_ADMXL">2BrightSparks Policy</string>.....<string id="2BrightSparks_ADMXL_HELP">This Category configures the permissions located under the 2BrightSparks Policy Key.</string>.....<string id="2BrightSparks_SyncBackPro_ADMXL">SyncBackPro</string>.....<string id="2BrightSparks_SyncBackPro_ADMXL_HELP">This Category configures user permissions when using SyncBackPro.</string>.......<string id="2BrightSparks_SyncBackPro_ADMXL_CanCreateProfiles">CanCreateProfiles</string>.....<string id="2BrightSparks_SyncBackPro_ADMXL_CanCreateProfiles_HELP">With this policy you c
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):3767
      Entropy (8bit):5.180328291085916
      Encrypted:false
      SSDEEP:
      MD5:0EDE37767B3851C67F13DF39677D72C1
      SHA1:2E1199BAE45A164DED499112F49C59ECE037711C
      SHA-256:47B55DA39528CD6A68BE7851F7486F0258FF9AF68DE1104B3965BA3A692A07EF
      SHA-512:642CFC869DFD6AD9B2ACACDBAA3B52E28A1DB54705DA88C222AFB4978F3E9E7AB03623377D27FDE24B352944870AFA89D27B2D663AE06B0E7DD0BC409609C661
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0"?>.. Copyright 2023 2BrightSparks Pte Ltd -->..<policyDefinitionResources revision="1.0" schemaVersion="1.0" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">...<displayName>2BrightSparks_ADMXL</displayName>...<description>This policy file was generated for the 2BrightSparks applications.</description>...<resources>....<stringTable>.....<string id="2BrightSparks_ADMXL">2BrightSparks Policy</string>.....<string id="2BrightSparks_ADMXL_HELP">This Category configures the permissions located under the 2BrightSparks Policy Key.</string>.....<string id="2BrightSparks_SyncBackPro_ADMXL">SyncBackPro</string>.....<string id="2BrightSparks_SyncBackPro_ADMXL_HELP">This Category configures user permissions when using SyncBackPro.</string>.......<string id="2BrightSparks_SyncBackPro_ADMXL_CanCreateProfiles">CanCreateProfiles</string>.....<string id="2BrightSparks_SyncBackPro_ADMXL_CanCreateProfiles_HELP">With this policy you c
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):7054
      Entropy (8bit):5.42515487523141
      Encrypted:false
      SSDEEP:
      MD5:49C3231517F47E8C57B480BAF491A2F6
      SHA1:EEDEE4F501D7B1BE9BC2274DEF8FD55317D878E0
      SHA-256:DD616BC695B652139C323FFE313325C211C58A111B9D524AD0E741F5A1503852
      SHA-512:0953BF79073D7C67113946BADA517DF9B9587A32CFEAD76E55834E7C73680517310AD2054890D9E308919AAED7F0475A2087FC18404C07DB130FBFD9AA8937AC
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright 2023 2BrightSparks Pte Ltd -->..<policyDefinitions revision="1.0" schemaVersion="1.0" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">...<policyNamespaces>....<target prefix="2BrightSparks" namespace="MSC.Policies.2BrightSparks"/>....<using prefix="windows" namespace="Microsoft.Policies.Windows"/>...</policyNamespaces>...<supersededAdm fileName=""/>...<resources minRequiredRevision="1.0" fallbackCulture="en-US"/>...<categories>....<category name="2BrightSparks_ADMXL" displayName="$(string.2BrightSparks_ADMXL)" explainText="$(string.2BrightSparks_ADMXL_HELP)"/>....<category name="2BrightSparks_SyncBackPro_ADMXL" displayName="$(string.2BrightSparks_SyncBackPro_ADMXL)".......explainText="$(string.2BrightSparks_SyncBackPro_ADMXL_HELP)">.....<parentCategory ref="2BrightSparks_ADMXL"/>....</category>...</categories>...<policies>....<policy name="2BrightSparks_SyncBackPro_ADMXL_CanCreateP
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):7024
      Entropy (8bit):5.428784808875496
      Encrypted:false
      SSDEEP:
      MD5:7B6D262956F1547A97B9AA5B63EB35C7
      SHA1:811F606E33AAB61FBC539AAA246E38F08CA07918
      SHA-256:AA5229FAAC62FE8A5420B096EBE092D5A0A92672B2B3F6360AB8D87F7351DF93
      SHA-512:15C7F02CAE453563D41A9FAA293A2F61DE6DBB6380674FE9DB6F1764AD0BC766414FD67C93049144F3754752AB26DE94A1AB9A12792EC33E97064D1445162869
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright 2023 2BrightSparks Pte Ltd -->..<policyDefinitions revision="1.0" schemaVersion="1.0" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">...<policyNamespaces>....<target prefix="2BrightSparks" namespace="MSC.Policies.2BrightSparks"/>....<using prefix="windows" namespace="Microsoft.Policies.Windows"/>...</policyNamespaces>...<supersededAdm fileName=""/>...<resources minRequiredRevision="1.0" fallbackCulture="en-US"/>...<categories>....<category name="2BrightSparks_ADMXL" displayName="$(string.2BrightSparks_ADMXL)" explainText="$(string.2BrightSparks_ADMXL_HELP)"/>....<category name="2BrightSparks_SyncBackPro_ADMXL" displayName="$(string.2BrightSparks_SyncBackPro_ADMXL)".......explainText="$(string.2BrightSparks_SyncBackPro_ADMXL_HELP)">.....<parentCategory ref="2BrightSparks_ADMXL"/>....</category>...</categories>...<policies>....<policy name="2BrightSparks_SyncBackPro_ADMXL_CanCreateP
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:8571CBC9CB03FC24056C7F210F49FDA2
      SHA1:F364D98AD1B653A89D8456CA7ECDFE6CA9F9585C
      SHA-256:B1F50411747F1E44A0EEC950700017517BBE382DA80EA3B7C5C2C2932F3625AC
      SHA-512:54601CD7083D3648644F7602109272891F70C046E6A7AF102703B115C506D3DC0690BA4B04E8AAEBF0C4F6CB2E6F2C89065FAA17318453891F0B2129C425A4F3
      Malicious:false
      Reputation:unknown
      Preview://..// Example script for 2BrightSparks SyncBackPro V8 that lets you treat..// all drives as a single drive...//..// SBLang=Pascal..//..// http://www.2BrightSparks.com/..// February 2016..//..var gFSO, IsMainThread, DebugLog, IsDebugging;....//..// This is a location script..//..Function Description(var ScriptType);..begin.. Result:='All Drives Location';.. ScriptType:=SCRIPTTYPE_LOCATION;..End;....//..// This is called when the user adds the script to SyncBack..//..Function Install(Interactive);..begin.. Result:='';..// If Interactive Then..// SBSystem.Say 'Installed'..// end;..End;....//..// This is called when the user removes the script to SyncBack..//..procedure Uninstall;..begin..// SBSystem.Say 'Uninstalled'..End;....//..// The script is being exported..//..Function FilesToExport(Interactive, Cnt);..begin.. Result:='';..// If Cnt = 0 Then..// FilesToExport = 'D:\temp\junction.exe'..// ELseIf Cnt = 1 Then..// FilesToExport = 'C:\temp\test.txt'..// Else..// F
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:51195A005A1CF9C3B7F88B46C21959EF
      SHA1:104E625406284C11693CD062ED97E2E479DFE455
      SHA-256:7D66BCC19F082FFE769E31A1505D74695DC52C1979F7E5FBFE8D989E3ABDA6DE
      SHA-512:E4DFE0403963DF9D617C0812F01F0E77D330627A30B207FD6CC54C8E39591F8260C9F2A26682AE9164C40DF42B0CFE85E963692E7C2B6C4C0B0F60E7C5BFF1C3
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sets a file to..' be only on the source if its identical to the destination file...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "When files are identical change it to say its only on the source".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' Called when a file is compared and found to be identical..' See the Technical Reference->Scripting->Constants page for Diff values..'..Sub RunFileCompareSame(Filename, ByRef Diff).. ' Lets say its only in the source.. Diff = CDIFF_SRCONLY..End Sub..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:765BBB546E5D7F45AF8347202C208787
      SHA1:B45A13FBFA8CA110593923C65F2A039855AF30C9
      SHA-256:221BAD9CA5A2AD3E34FF442ADE86D2AB83C30A9E4A043C7F304AE630F5DC0BA1
      SHA-512:B337767D3474A95CE68FB53362504D4DC3FE8E83A9855FE22D0470BECC9B16486F03AB6D67BF2AEA15CF016AB28508C53B23C4468646A8019FC4455C0E3A980F
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................n......~.......~................x..............i.......o.......j.....Rich............................PE..d......g.........." .....&...pg..........................................................@..........................................:...............p.......`.......<...,......l....................................................@.. ............................text...2%.......&.................. ..`.rdata..H.G..@....G..*..............@..@.data........@.......&..............@....pdata.......`......................@..@.rsrc........p......................@..@.reloc..:...........................@..B........................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:97A285CA46DBF5670280C8E68876A903
      SHA1:0141A712888274B1F7CB372B8A40F2D8E8106B65
      SHA-256:A36542CACC14E75CFE1F1B8DC764D956BFDF1B22806650C663CE57CF38DE453B
      SHA-512:E635853691188E9EAACF4B3EBB73E65C9CBFFBDFF616CACF1C71F69F6B3730867D6572E462E3B209E315BFADE6BFF0EDFB5529A552DD97A6571883CE6EAE0BA1
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that uses NTFS..' compression on the copy of a file...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "NTFS compresses copies of a file".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' This function compresses the copy of a file...'..' Note this function is not called if it is a simulation...'..Sub RunAfterCopyFile(ToLeft, Filename, Failed).. ' If the copy failed then dont even try.. If Failed then.. SBRunning.DebugOut(Filename, "Failed", 1).. Exit Sub.. End If.... ' Only compress the copy if the original was compressed.. Attrs = SBRunning.GetFileAttrs(Filename, not ToLeft).. if Attrs >= 0 then.. if (Attrs and 2048) = 0 then.. Exit Sub.. End If.. End If.... ' Get the full filename.. If ToLeft then.. FullName = SBRunning.LeftFolder & Filename.. Else.. FullName = SBRunning.RightFolder & Filename..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:EBDECFE41DB73DFAA2FBF9CD37BD8FA2
      SHA1:28ED28FD17445D66C7BB744A961C65EA91FB43C8
      SHA-256:890D86AF76F6825CC461340A6663B8F857FE56EA170B4420A4ABE8AB57169939
      SHA-512:8228CF78D9A872990002B39A98775EDE20E2ACAD5C9AFB73DA38487965D380F0159F21C5DCDC09507C0A63972D70BC30E9898F75CE59367EB1D0D42DD454DDA0
      Malicious:false
      Reputation:unknown
      Preview://..// Example script for 2BrightSparks SyncBackPro that stops a profile..// from running if a specific file is detected as being corrupt...//..// This can be useful to guard against Ransomware corrupting your..// backups...//..// SBLang=Pascal..//..// http://www.2BrightSparks.com/..//....//..// This is a configuration script and runtime script..//..function Description(var ScriptType);..begin.. Result:='Check if a file is corrupt before running profile';.. ScriptType:=SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG;..end;....function RunDisabledCheck(NoLog);..var.. md5expected, md5actual, md5filename;..begin.. NoLog:=FALSE;.. Result:='';.... md5filename:=SBVariables.GetProperty('CorruptFilename', '', FALSE);.. md5expected:=SBVariables.GetProperty('CorruptMD5Hash', '', FALSE);.... if (md5filename <> '') and (md5expected <> '') then begin.. md5actual:=SBSystem.MD5(md5filename);.. if (md5actual <> md5expected) then.. Result:='File is corrupt: ' + md5filename;.. end;..end;....//../
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9DC3FC8E151470ABC758AD684268C9C9
      SHA1:AD9A14AC03F1186CE67C72B67C4CD65C66834F33
      SHA-256:1CC0472C286A792E1A16095D1C2E9CA2C78C7AD6C188B9F241784164F0CB4567
      SHA-512:ED2D9925D79D3FED3BE6FF3723C955CD7EA6723D172CA1E4B983A797076C563105DC6A2158EA02374BBDF38F0B99F2D3242B6F5037F1ADD49FCF808179FA9A3E
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that creates a..' Restore Point in Windows. If its a simulated run, or a restore,..' no restore point is created...'..' In Windows you must have Administrator privileges to create..' restore points...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Create a Restore Point in Windows when the profile run".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' We create the restore point before files are copied, deleted, etc...' If it fails then we record a warning in the log...'..Sub RunAfterConfig.. ' Restore or simulation? .. If SBRunning.Restore or SBRunning.Simulated then.. Exit Sub.. End If.... ' Create restore point.. if not SBSystem.UpdateFileStatus("Creating restore point...") then.. Set obj = GetObject("winmgmts:{impersonationLevel=impersonate}!root/default:SystemRestore").. ErrCode = obj.CreateRestorePoint("Rest
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:4CEC781684F1F35B2879C4D919360940
      SHA1:ACC428EA36D814130FB4CDB48A61A785D5FBF9E0
      SHA-256:4D5FB4E7BCE9B983E6C56DAC4A10D34A28A9D8C1EDBC3A08E51C9C91728C4386
      SHA-512:3FCA229232EDBCD4247109571EF7D7304A18ED9D0DCA58B947E8A17EB74AC4743EE6C793A6C9D9A166C324B4D138D89BC2836CAB6C452B27A486ABCDCBDB7D3B
      Malicious:false
      Reputation:unknown
      Preview://..// Example script for 2BrightSparks SyncBackPro that filters out..// files and folders. This is different from using filters in ..// SyncBack itself as these are applied to the scan results and ..// file and folder selectios and filters have been applied...//..// This can be useful if you want to only include certain..// sub-folders, for example. Because these custom filters are ..// applied to the final list of filenames (after any file and ..// folder selections and filters) it does not act like normal..// filters which are applied top-down...//..// For example, you have the following folders:..//..// \abc\..// \abc\xyz\..// \abc\123\..// \def\..// \def\456\xyz\..//..// In this exmaple, you only want to include files and sub-folders..// within folders named 'xyz'. With normal SyncBack filters you..// would need to have the filter *\ and *\xyz\*. That would include..// all folders (but not their files or sub-folders) because of the..// need to have *\ (because filters are applied
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:202696329681E65ECD926BE8155043AF
      SHA1:70BC363C01AE0F0D4407E5342D8A475BBBF2E86E
      SHA-256:551E6BAB279E347800AD4188927415421446082D7E72EF4BE48C733723E1911E
      SHA-512:FC62B05A4BC19B300E3147397B4C5ACB0192BFF39F6795D0568EFB9B40BA818F534FE00C2BB19BCFF66AF52DFC05E9938C5CAF7206480244F6EC81FFC89C12DD
      Malicious:false
      Reputation:unknown
      Preview:' DeSpace.VBS written by Dave Wilkins 2007....' used to exchange spaces for underscores in file & folder names..' in a path starting from (but not including) the folder shown.....' Typically this would be used in Programs -Before to prepare a file..' set For backup to an FTP server (or similar) which did not support..' filesnames containing spaces. A complementary script (ReSpace.VBS)..' is supplied to revert files back to their old filenames if req'd. ..' This complementary script would be placed in Programs - After....' Note that any pre-existing underscores in filenames will be turned..' into spaces by ReSpace.VBS, if used, ie....' original: My File_Name.ext..' DeSpaced: My_File_Name.ext..' ReSpaced: My File Name.ext....RootFolder = "X:\ROOT_FOLDER"....'OR....' Set objArgs = WScript.Arguments..' RootFolder = objArgs.Item(0) ..' note that any path argument with spaces must be wrapped in " "....RootFolder = RTB(RootFolder) ' remove trailing backslash (if any)....Set FSO = CreateObject
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:0EF0D4FD29777824444C212327752CED
      SHA1:F63D6F538382D8AB5CD2325835B53A20BB48F25B
      SHA-256:D428F07320CDA2763AF0CC3E2B66BE9A1BE7AF70545EEF11976D3EA85E8A8963
      SHA-512:4F1E122214659CCFF5ED0ED980D151E65166C99C411A050F7399A895265CC65C5F48F89F8A7A833989058620080761B4E3200231797C9820E8E36979B001E99F
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that removes the..' NTFS encryption from the copy of a file...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Removes the NTFS encryption from the copy of a file".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' This function unencrypts the copy of a file...'..' Note this function is not called if it is a simulation...'..Sub RunAfterCopyFile(ToLeft, Filename, Failed).. ' If the copy failed then dont even try.. If Failed then.. SBRunning.DebugOut(Filename, "Failed", 1).. Exit Sub.. End If.... ' Get the full filename.. If ToLeft then.. FullName = SBRunning.LeftFolder & Filename.. Else.. FullName = SBRunning.RightFolder & Filename.. End If.... ' Decrypt it.. ErrorMsg = SBSystem.DecryptFile(FullName).. if ErrorMsg <> "" then.. SBRunning.NotCriticalError(Filename, "Could not decrypt: " & ErrorMsg).. End If.
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:0C3FEF9E885E33745E840157D261A943
      SHA1:6BD91A5658D8EFD3E7448EB47C4AAEDF36325F16
      SHA-256:41047DF5EF044AC67503E34DE03D94E5C2AA4FABBBC0D86CFDF661169FD107E1
      SHA-512:A926022A33E970D73B16D4D703276C5764C502D0500FBDD92CD06D1D3AA80FB6A033DD0172D5E1A5DFE7C036AF3C5A95E823BA6535F0160C1EABDF14BD8CEC1D
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that exports..' the differences in files and folders when the Differences ..' window is displayed...'..' Note that the Differences window has an Export ability already..' via the main menu...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script and a configuration script..'..Function Description(ByRef ScriptType).. Description = "Differences export".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....Sub DoTheExport.. ' Export files.. ExportFilename = CStr(SBVariables.GetProperty("DEFiles", "", FALSE)).. If ExportFilename <> "" then.. Set objFileToWrite = CreateObject("Scripting.FileSystemObject").OpenTextFile(ExportFilename, 2, true, -1).. For I = 0 to SBRunning.FileCount - 1 step 1.. ExportName = SBRunning.GetFilename(i).. .. ' Filename,Difference,Action.. objFileToWrite.WriteLine(ExportName + "," + CStr(SBRunning.GetFileDiff(ExportName)) + "," + CStr
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9D6262FEF844370DB4B140800569EDEC
      SHA1:C6E40F38E99BBA102B0F7274F0FAE13E1A0D4F30
      SHA-256:2C1B5EEFD6697355B6A3D74E9CD1885E3FA70AF7F42C88F95BD1C1EC89D52B9D
      SHA-512:71769410EE853027F0925C0CB9B6616FDD08B6BD9B869B670E2F896EFAA25D5D9AFFA78A22744068E619321BC5FA8593FBD5CC1CCFFA9FB4BC183A72A6B14A1C
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds voice alert..' to the Differences window...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'..'..' This is a runtime script..'..Function Description(ByRef ScriptType).. Description = "Adds voice prompt if/when Differences window appears".. ScriptType = SCRIPTTYPE_RUN..End Function....Sub RunDiffOpened.. SBSystem.Say("Scan completed - review required" )' edit to phrase of choice..End Sub....' SBSystem.Say can also handle WAV files (not MP3 or similar)..' Simply replace spoken phrase with "X:\path\name.WAV" etc...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:EDB75BC30A3759C0E48282964FA3EC19
      SHA1:10EA34A730FF4620395CBD315B49703B6E15C23F
      SHA-256:095C39517E76F8378AF50C36645C99FAA3E26C6A1E444E26A11CDC3376BE85CF
      SHA-512:462C1D16BA4404D6E42DCFA204541002BA5AAADB21EAF7874C49BC98532E5F34449C2AEF84ABEF72AF99A1F2E1CEFEEDAAF590DFDD48DF22DBF410705CF65A88
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds..' extra columns to the Differences window...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script..'..Function Description(ByRef ScriptType).. Description = "Adds creation date and time, attributes and NTFS security columns".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' Tell SyncBack how many columns we are adding to the Differences window..'..Function RunDiffColumnsCount.. RunDiffColumnsCount=6..End Function....'..' The column captions..'..Function RunDiffColumnTitle(Col, Width).. If Col = 0 Then.. RunDiffColumnTitle = "Created (" + SBRunning.LeftName + ")".. Width = 150.. ElseIf Col = 1 then.. RunDiffColumnTitle = "Created (" + SBRunning.RightName + ")".. Width = 150.. ElseIf Col = 2 then.. RunDiffColumnTitle = "Attrs (" + SBRunning.LeftName + ")".. Width = 150.. ElseIf Col = 3 then.. RunDiffColumnTitle = "Attrs (" + SBRunning.RightName + ")".. Widt
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:7AE8414521FEB5ED4AAE66776D0FCAC1
      SHA1:CC53A95470A02411BBB763CAE7A2E92B2CBF56D9
      SHA-256:D2E7E2871B7C6E39E7D50F5800CA82906AB2583D41A5FAA621669B890E43373D
      SHA-512:630F8046C887ADCCF9AE5EEC2A79C409C9AE9997D35B3E76B7048D0B8F49BD1FF08212B40487195F4768938C26D91A9E42F34CAA540D407E08B8C11AFA4F0FE4
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........e.x...+...+...+..!+...+.U.+...+.U9+...+.U.+...+.|e+...+.|u+...+...+...+-..+...+-..+...+-.:+...+.V=+...+..q+...+-.8+...+Rich...+........PE..d....}.e.........." .........$......t.....................................................`..........................................w.......x.......... &...@...y......................8...........................P...p............................................text...^........................... ..`.rdata..............................@..@.data...........v...x..............@....pdata...y...@...z..................@..@.rsrc... &.......(...h..............@..@.reloc........... ..................@..B........................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:CFB6429F28A8DAF4BA6548BE3D76CE13
      SHA1:FCA8A394CBECC0B92472417BBD8CA02C8538D563
      SHA-256:0A51F665B625AFE94F761BB962D62AA75EDBB4491631F687F4590AF75282AD57
      SHA-512:9551A70BB329606D09BA28E32436F817C385EFCFE641C5041E15381FC8AD733819CCDE9ADCEF216B4A5C8494AD5C0F7E744E91DC3396EC098CE355033FA71553
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........]...<.K.<.K.<.K\..K.<.K.mXK_<.K.mgK.<.K.mYK.<.K.D;K.<.K.D+K.<.K.<.K.=.Kw.XK.<.Kw.YK.<.Kw.dK.<.K.ncK.<.K.</K.<.Kw.fK.<.KRich.<.K........................PE..d...s..c.........." ......................................................................`......................................... ...................h....p..P^..................@...8........................... z..p...............x............................text...^........................... ..`.rdata..t...........................@..@.data...h{.......T..................@....pdata..P^...p...`...&..............@..@.rsrc...h...........................@..@.reloc...............D..............@..B........................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:119576C7480B7E1DA14279671C17504B
      SHA1:3907EDD066FB93498356389678D9B727C180D6B9
      SHA-256:45926083A2856A8D779A8D703077CD6FC0FE6CE6101AE0CB173A8B87DF44DF87
      SHA-512:4BA76E6B9AE4FCC564B3C4EDCA1079A3737A85FC74859B1448E45A10DD6EC4EF7ACCF993DEB592449AF89DFBAF7E6688E7F86D07F71C30C91193450802617245
      Malicious:false
      Reputation:unknown
      Preview:'..' EMail services used by SyncBack (2BrightSparks Pte. Ltd.)..'..' Do not modify this file unless you know what you are doing...'..' IMPORTANT: THIS FILE IS REPLACED WHEN UPDATING OR UPGRADING SYNCBACK..'..' The section names are the names of the email service and are used by the user to make their selection...'..' [Unique name of email service]..' RType=P for POP3, I for IMAP4, W for Exchange Web Service (Exchange Server 2007 or newer), D for Exchange Web DAV (Exchange Server 2000/2003), O for Microsoft Outlook Personal, G for GMail OAUTH. Default is POP3...' RHostname=pop3/imap4/exchange hostname..' RPort=pop3/imap4 port. Ignored if Exchange. Usually port 993 if direct encryption or 143 for STLS encrpytion...' RLogin=0 if do not need to login, 1 if must login to pop3/imap4/exchange server, 2 for OAUTH2. Default is 0...' REncrypt=D for direct SSL/TLS, S for STLS (which is POP3 only), otherwise no encryption. Default is no encryption...' RUsername=default login username for POP3/IMAP
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:BF53CF6237204DB7C061AB7C3FB6795A
      SHA1:A7B46ED2DB74104EAD97361E7F94072B73854809
      SHA-256:FA3240B3636EB0B68C3500F5E4292A0CB6351F4D57D74DE8D231F7F042CC34FE
      SHA-512:417000BE87A0366C8C1EDD46D133472BCA2DD4F3F9166BDC542A1AC1F1516C5985B4093A620F2C360EA1FC32F90B8EEEE286A4FB298B3A3FF0C82CA4D7D3FEC0
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that uses NTFS..' encryption on the copy of a file...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "NTFS encrypts copies of a file".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' This function encrypts the copy of a file...'..' Note this function is not called if it is a simulation...'..Sub RunAfterCopyFile(ToLeft, Filename, Failed).. ' If the copy failed then dont even try.. If Failed then.. SBRunning.DebugOut(Filename, "Failed", 1).. Exit Sub.. End If.... ' Get the full filename.. If ToLeft then.. FullName = SBRunning.LeftFolder & Filename.. Else.. FullName = SBRunning.RightFolder & Filename.. End If.... ' Encrypt it.. ErrorMsg = SBSystem.EncryptFile(FullName).. if ErrorMsg <> "" then.. SBRunning.NotCriticalError(Filename, "Could not encrypt: " & ErrorMsg).. End If..End Sub..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:437C5783743CD0425E0BD493FB19D3CB
      SHA1:DE818450C771CA045124CCFE51536BC1767D0640
      SHA-256:F9D10B28D68D67D1CE6E1A8070700E50F41438A2B7E554C559D3B84DC5E47422
      SHA-512:EBD4116681684950AC4DDA9ADFD6497411C9E81406041E4FE337D92B57D6E8048D41D1664F7C34822C4EA88743468AFBF66F9DC47AC3767360D15E767AA6F1B7
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds an extra..' column in the main window that shows the number of files that..' were copied, deleted, etc. in the last profile run...'..' You need to install this script and enable it on the Main Interface..' tab. You also need to enable for each profile that you want the column..' to be used with (modify the profile and go to the Scripts tab)...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is both a runtime script and a main interface script..'..Function Description(ByRef ScriptType).. Description = "Show number of files copied, deleted, etc.".. ScriptType = SCRIPTTYPE_MAIN + SCRIPTTYPE_RUN..End Function....'..' Called when the profile has finished running. We get the..' variables and create a description, which we save as a..' property of the profile. This description is then used in..' the main interface...'..Sub RunProfileResult(ProfileResult, ErrMsg).. SBVariables.SetProperty("XInfo", .. SBVa
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, ASCII text, with very long lines (717), with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:FAD614A14ECEF7689DAF5B9379A83627
      SHA1:08CDE000D8ADCEB46AFB9E4D682CAD55268D3BD9
      SHA-256:65D4D3D2624BA01B2D9777005CC4A2A95BF9C0D7BA896365681F1523D0B4CB64
      SHA-512:CE70C0CEA1EEE22E175698500B1CA99448A7CDB790228CAEFA3ACBCF4DCD8C9E115CF36068C6234210AF95A6D2CD759957B8DEFF2C4DAC7EAEDF0F2152E81729
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0"?>..<License><Version>2.0</Version><Id>400016053</Id><Name>Michael Leaver</Name><Email>MJLeaver@2BrightSparks.com</Email><Company>2BrightSparks Pte Ltd</Company><Product>SmartFTP FTP Library</Product><Features><Feature>FTP</Feature><Feature>SFTP</Feature></Features><Users>1</Users><Maintenance>2010-02-22</Maintenance><Issue>2007-02-14</Issue><Signature>HzpkVdG5JmjuwuzsisEMfqxgMpN9nElGNux82pmePV3MCMNycZ3i6MBt9TXSuTq8K6aQTLumQolOXdNjfwA2vWomEKNocIrlGqJRb893bzAqb5JolZsKJgsvGPk3F8s8O2qsnSzRJMG80TSWL3g3R9efB2NKQ60Q5pDI/xPZ1a/Ff53lsYQkAmx10yfnFllYyV2SSHFEYZRi5h5O56HhdgFB3O64TZswrb0lBRQwxX2GSh6e5YmDXUsTdBB6CRzjjWMVx2K3aOkRlJRki933D/AoQQMGV2YeTlHhADK+R8OcTMPwrV3vjWQUqTlk392inwFVKbCfbtZzmIC3qmaNbw==</Signature></License>..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:F1E87BD2012A8B50B64D804887E25601
      SHA1:013BFE5594BEC342A2956397AA2737F50DDE2259
      SHA-256:885B80E4F0467794129E517F682D8D4D325A3DFA31689B3B99C1786769B86DE8
      SHA-512:9DBB299004D423800347B86658973618095AFF031CCC9015AE5B87F600281C3EED6A68C0A4A4C584EA8129EB3683997D44A1645BA4FF58596F5B337FAE5F3520
      Malicious:false
      Reputation:unknown
      Preview://..// Example script for 2BrightSparks SyncBackPro that stops a profile..// from running if a specific file does NOT exist. The file can then..// be optionally deleted automatically if it does exist (to stop the..// profile being run again until the file is re-created)...//..// This can be useful when files are being copied to a folder and..// you do not want to copy them until they have all been copied...// This assume you are using a special "marker" file that will..// always be the last file to be copied/created...//..// SBLang=Pascal..//..// http://www.2BrightSparks.com/..//....//..// This is a configuration script and runtime script..//..function Description(var ScriptType);..begin.. Result:='The profile will not run unless a specific file exists';.. ScriptType:=SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG;..end;....function RunDisabledCheck(NoLog);..var.. markerfilename, deletemarker, FSO;..begin.. NoLog:=TRUE;.. Result:='';.... markerfilename:=SBVariables.GetProperty('MarkerFilenam
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:E268BE202646CF0FF53F1044DF858862
      SHA1:3C145C4A65F11DACBB6516D7B15820E889CE5862
      SHA-256:CC7DEE104665A143047624F73FBB712034EACD91E9BE042E0748D73C92D69BDB
      SHA-512:5AABD2721A84A4AD9E1DDF54E28D900F65D204742A05DFA202D57BBF2296FA7C643B2E58740DBBB072A70BE9B2FF05B69A19F05B42553D68AC3A2B36851FF35C
      Malicious:false
      Reputation:unknown
      Preview:'..' Google Storage bucket locations used by SyncBackPro (2BrightSparks Pte. Ltd.)..'..' Do not modify this file unless you know what you are doing...'..' IMPORTANT: THIS FILE IS REPLACED WHEN UPDATING OR UPGRADING SYNCBACK..'..' The section names are the location constraint strings as defined by Google:..'..' https://cloud.google.com/storage/docs/bucket-locations..' https://cloud.google.com/storage/docs/regional-buckets..'..[ASIA]..Desc=Asia....[EU]..Desc=European Union....[US]..Desc=United States....[ASIA-EAST1]..Desc=Eastern Asia-Pacific..Regional=Y....[US-CENTRAL1]..Desc=Central United States..Regional=Y....[US-CENTRAL2]..Desc=Central United States (2)..Regional=Y....[US-EAST1]..Desc=Eastern United States..Regional=Y....[US-EAST2]..Desc=Eastern United States (2)..Regional=Y....[US-EAST3]..Desc=Eastern United States (3)..Regional=Y....[US-WEST1]..Desc=Western United States..Regional=Y..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:5DF38755279541C7471997D75271766F
      SHA1:F785B71F390F90527A34ED086B828A4E7144FA23
      SHA-256:D3FBAE36502F241C030C90B8520C452A4C6ED26878E1A4CC15A49AE5EC288A94
      SHA-512:9239C162E70D6CA9F76DAF28BAAEAD3FE27AA23191BA7E6E7C5BFF67EA2E49D73A164585371DDC576E826EB87FD12D8FE0435E433C6A1C936C844626DD36FDA3
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds an extra..' column in the main window that shows history information for..' the profile...'..' This script is an example of how to use caching to avoid..' performance problems in the main user interface. It also shows..' how to use the new PollingRefresh and RefreshDisplayEx..' functions...'..' You need to install this script and enable it on the Main Interface..' tab...'..' SBLang=VBScript..'..' http://www.2BrightSparks.com/..'....Dim gCache....'..' This is a main interface script..'..Function Description(ByRef ScriptType).. Description = "Show history count information".. ScriptType = SCRIPTTYPE_MAIN..End Function....'..' One column only showing history count...'..Function MainColumnsCount.. MainColumnsCount = 1..End Function....'..' Column title...'..Function MainColumnTitle(Col, ByRef Width).. MainColumnTitle = "History Count"..End Function....'..' Column text...'..Function MainColumnText(Col, IsGroup, ProfileName).
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:220667A9E826C3FEFA62BAF0B0F42D92
      SHA1:30992C5314DE296A632F1D2DA9292FAB90305A94
      SHA-256:F3687BD18BBC58B1DAB76FDF5A72E9052DA883598587EFCE68DCA60F73BAA109
      SHA-512:E64B9F977F509D4957884DEAD0B0B8D279006E076FD4A23534C46E081D0BB38129DC5AD399E9564AC7AF7825F8837910A0E4C1C4E728E58A8BB44758893DB68D
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that lets you create your own..' incrementing variable. You can also configure if it should be a full backup..' once it goes over a certain number...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The name of the variable you want. It should be unique...const MyVarName = "CustomIncVar"....' Set MinVarValue to what the variables minimum value should be..const MinVarValue = 1....' Set MaxVarValue to what the maximum variables value should be..const MaxVarValue = 12....' Should it be a full backup when it goes over the maximum value?..const FullBackupWhenOver = TRUE....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....' This is set to TRUE if it should be a full backup because the variables..' value went over MaxVarValue and FullBacku
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:578189387B30134D605EC3C0D6E83943
      SHA1:02626F42F329811292A78E4070EB5E8EAE5D7384
      SHA-256:CA6D6E5284BCE595560EE281F28AD4ADF5A222492EDB5A9BB542A0953D420ADF
      SHA-512:A05D6CC4848134A96534933837D086D79444183E2008620327904A5FC9055C485C4E45FD3CAF5107602D17515064174022F48D7299EEF5088C743BD3850B110C
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that lets you create your own..' incrementing variable. You can also configure if it should be a full backup..' once it goes over a certain number...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'..'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....' This is set to TRUE if it should be a full backup because the variables..' value went over MaxVarValue and FullBackupWhenOver is TRUE ..Dim DidReset....'..' This is a runtime script and a configuration script..'..' It must be a configuration script otherwise the variable will not be used..' when you modify the script..'..Function Description(ByRef ScriptType).. Description = "Custom incrementing variable".. .. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' Remind us
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:367D4FE2769349BA93BD9A9FC685FF5D
      SHA1:A00CB168B129FF0A9CEAE180CB248B1B69C2A2F7
      SHA-256:927303D72DD6A15B77B1C53AA3B12B9E24AF55FC2C1A3428AC08C5711091163C
      SHA-512:AF6B36F7C71B26E3263378F55DEE556972860250DD27855074CD99FF1FEBAC2392CFC45CC57BA5ECA7BCD4BF3405A67BD15B4ED089BDA3DBE2621C25E3D8E0E9
      Malicious:false
      Reputation:unknown
      Preview:' IsDriveReady by Dave Wilkins 2007....' either preload the drive letter in question (in which..' case suggest rename the script IsDriveXReady.vbs...)....DLetter = "X"....' OR ....' Set objArgs = WScript.Arguments..' DLetter = objArgs.Item(0)..' Cater for anyone who has "helpfully" included : or \..' DLetter = Left(DLetter,1)....Set fso = CreateObject("Scripting.FileSystemObject") ..Set dc = fso.Drives ' drive collection....Do.....For Each d In dc ' scan the drives looking for DLetter......If d.DriveLetter = DLetter Then.....retval = 0 ' "OK" value for SBSE to proceed.....Exit Do....End If...Next .....' we have a non-ready drive.....retval = MsgBox ("Please insert (or turn on) external drive " & DLetter, vbRetrycancel+Vbdefaultbutton1,"Backup Drive Not Ready").....If retval = VBCancel Then '....retval = 1 ' not OK (in SBSE-speak - diff val to VBCancel)....Exit Do...End If....Loop ' scan again; if still not ready, keep alerting till cancelled....Wscript.quit(retval)..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:484D934F7CEBB1A41C16FCB6B6A961B2
      SHA1:5C05BDE2875A0E63E846648F02C6817352EBA9AB
      SHA-256:8ACADAB63B9BD36020287467A04EB7862294385332A8CC38FE2C8180815582D7
      SHA-512:3DCDED6D3B5BF15F732F01F1B1881D18A9ED28DBF4A097F55910FDFE58AFEB0FDE9F67916760995823F30E9FE3F4E440D7326F137BB88A9EB1A80765412D463F
      Malicious:false
      Reputation:unknown
      Preview:' IsDriveReady by Dave Wilkins 2007....' either preload the drive letter in question (in which..' case suggest rename the script IsDriveXReady.vbs...)....DLetter = "X"....' OR ....' Set objArgs = WScript.Arguments..' DLetter = objArgs.Item(0)..' Cater for anyone who has "helpfully" included : or \..' DLetter = Left(DLetter,1)....Set fso = CreateObject("Scripting.FileSystemObject") ..Set dc = fso.Drives ' drive collection....Do.....For Each d In dc ' scan the drives looking for DLetter......If d.DriveLetter = DLetter Then.....retval = 0 ' "OK" value for SBSE to proceed.....Exit Do....End If...Next .....' we have a non-ready drive...retval = 1 ' not OK (in SBSE-speak - diff val to VBCancel)...Exit Do....Loop ' scan again....Wscript.quit(retval)..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:6B040A9EEDFE2BFF6CC3F21915CD0435
      SHA1:767F4CB437EF6367D930F945F37DB1FD727ACD3E
      SHA-256:0526037B9FBB960959C0130E424FA063F76D00A4076C5922BA024A3418EFC781
      SHA-512:9E11482AFB1EFC815758C81B276566405F38CF89389AD784DC062F3D03C8E5A68F636558E900B65E3D374B02A48569CF125515B8DD21AC731D613965500E7377
      Malicious:false
      Reputation:unknown
      Preview:' used in Programs - Before to check if PC is in 'home' office..' in current form, uses a config file on disk with DHCP addresses..' this should be in the form..' 10.0.0.1..' 123.124.125.126..' etcetera..' The file can contain other strings also - any that do not match..' the DHCP address supplied to the PC on arrival will be rejected ....' The config file name can be hard-coded, or supplied as a parameter, thus....ConfigName = "C:\DHCP.TXT"....'OR....'Set objArgs = WScript.Arguments..'ConfigName = objArgs.Item(0)....' actually the DHCP address itself could be hard coded if you prefer..' in which case the "Get contents of config" section can be discarded....' Get current DHCP....strComputer = "." ..strCurrentDHCP = "" ....Set objWMI = GetObject("winmgmts:\\" & strComputer & "\root\cimv2") ..Set colItems = objWMI.ExecQuery("SELECT * FROM Win32_NetworkAdapterConfiguration", , 48)....For Each objItem In colItems ...If Not IsNull(objItem.DHCPServer) Then ....strCurrentDHCP = objItem.DHCPSe
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:D3BF54E7BD17EC71A1C0B88ADEDF7850
      SHA1:5EE8D926812930FB5C565148E87A90DFEC29EB87
      SHA-256:80C8A216147938CD29A92AFF889628BE8B3627922DFB35F05C1344FD1B81EC51
      SHA-512:9772D3D4F5395D50AFD9A117C398951EEB484FAE81D380D5F7365ECBE6BB1A2D79ABABD8683F15F493A9B3E0B0DBFA62378AD8DBC6766ED6F865C364DA83D842
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that shows how..' to have a "Message Of The Day" which is retrieved from a..' web server and displayed (if it is new)...'..' How this works:..'..' - Put a message of the day file on your web server. It would..' be a good idea to make it a small file otherwise there..' will be a delay when starting SyncBackPro...'..' - Put the full URL of that file into the MOTD setting below..'..' - Change the MOTDEXT setting below to the extension of that..' Message Of The Day file...'..' - Install the script into SyncBackPro, enable it, and then..' restart SyncBackPro..'..' How to improve this script:..'..' Instead of downloading the entire message of the day file..' each time, you could instead have two files on your web..' server: a counter file, and the message of the day file. The..' counter file would be a small file that you change each time..' the message of the day file is changed. So instead of this..' script downloading the messag
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:D6A4D806933EE0E9D96ACCBFD3AD1820
      SHA1:6E31449E3411EB6CA162183C2102EFF111297C65
      SHA-256:20DAE620C1F84E553F99B967D3970941EC5D946C25CC562997BC48A2C9032819
      SHA-512:6188032C6A636E3B241AF7CFA7C29E5062BA3D334F8D03CAA97067B4203F8B834A7E8C1ADF2A79BF6DD6A85742ADB480079717B3686D41B405C8906E1A8315BF
      Malicious:false
      Reputation:unknown
      Preview:..' Subroutines to map next available drive letter to UNC path (create network drive)..' and UnMap it again after temporary use....' testing code below can be removed except recommend keep the Dim statement ..' as a "reminder" it is being used as a Public variable (sort of), not only..' to keep track of the drive letter between Subs but also for use in main logic (!)....' the Wscript.Echo commands used purely for monitoring progress can be removed, but suggest..' keep the "can't find a letter" in error-trap at end of MapNextAvailableDriveLetter sub....' Written 13 Nov 2007 by Dave Wilkins....Dim MappedDriveLetter ....MapNextAvailableDriveLetter "\\DWHOME\C$" ' substitute your own UNC path for testing....UnMapTempNetDrive......'= = = = = = = = = = END OF MAIN LOGIC / START OF SUBS & FUNCTIONS = = = = = = =......Sub MapNextAvailableDriveLetter (UNCpath) ' OR (UNCpath, Uname, Upwd).....Set objDict = CreateObject("Scripting.Dictionary")...Set objWMI = GetObject("winmgmts:\\.\root\cimv2").
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:ABA2966C1AEC583F30F96CB9AE69E69E
      SHA1:14BE61140C86AB14E062782A6CDB6377E06A8EE3
      SHA-256:6E50C9C4FF3320CC8624ED38155B826A6845955D97C7058AF4C74A32DF3DBAD3
      SHA-512:6D0775DBD9A20929DB9B6BB4665D3354D9CF53145CB456FE123E7F7A24B6D571B3685E587F0701E6E7F5D6844830A834ACE375BF4FFA24B5D86110DFE57213A3
      Malicious:false
      Reputation:unknown
      Preview:' MoveExpiredFiles by Dave Wilkins 2007....' a utility to strip out files over (as shown) 1 month old from a file-set...' This is to cater for the fact that SyncBackSE does not (at time of writing)..' have a facility For filtering by Months, only by secs, mins, hrs & days...' Because there are a varying number of days in a month, using (say) 30 days..' in the filter is inaccurate for more than half the year....' The script can be easily modified to handle 2 or 3 months (etc) by simply..' editing (or supplying) a different value of MonthBar....' The idea is to run this script in Programs - Before of a profile..' which uses the script's Destination as its (the profile's) Source...' The profile will then Zip the Moved files and transfer them to the..' "real" Destination, as set in profile...' Thus, requires the use of an interim staging-area with sufficient space....' Hard-code the Source and Dest (actually, staging-area)....SourcePath = "C:\TOPMOST FOLDER OF TARGET"..DestPath = "X:\TEMPL
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:3524681BA8AC88CCDE6519D52009A88C
      SHA1:B0936AB174E2E1964834E87E76DE53829539D909
      SHA-256:1BDB5E996EE77C577199B3564BBDD6DC66E091A148F157A5D5508CFCC320845E
      SHA-512:682F3DBF62322B941C5F239595E3CA0CDB47BC387C6ACC6D543E9A81F4EEB7B18B30000CEFE0A6C6D56B0BC01D8892879DE607E1583E3E0A7483143F17D76C19
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro that stops a profile..' from being run more than once per day. If its a simulated run,..' or a restore, then it can be run regardless...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Run at most once per day".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' We use the LastRunDT value from the profiles settings. It contains..' the last run date and time of the profile. If it has already been..' run today then we stop the profile running, and no log is created...'..Function RunDisabledCheck(NoLog).. ' Get the current date now just in case it changes while.. ' the string is being built.. RightNow = Date.... ' Create a string that has the current date in the.. ' format of YYYYMMDD.. NowDate = CStr(Year(RightNow)).... If Month(RightNow) < 10 Then.. NowDate = NowDate & "0" & CStr(Month(RightNow)).. Else.. NowDate = NowDat
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:DBA90A58279E2D3705234D53877767BB
      SHA1:BE2D8F5C02E3B7C8CE7A87C3BCAC8DADE9D45784
      SHA-256:0F9CE94B04DE7C7793D4C12F73DD1139CF4CAC538EB781CCE731C48BD839D4D9
      SHA-512:B663B65493D4BB1B2F91EEF4BBD19344399D7662ED9017FB7BDC64CCB90885EA6097700BD5442DAFD20F1D4A2082EC734778EBC3FF37C67349D718C2F525D27B
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro that stops a profile..' from being run more than once per day. If its a simulated run,..' or a restore, then it can be run regardless...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a configuration script and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Run at most once per day".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' We use the LastRunDT value from the profiles settings. It contains..' the last run date and time of the profile. If it has already been..' run today then we stop the profile running, and no log is created...'..Function RunDisabledCheck(NoLog).. ' Get the current date now just in case it changes while.. ' the string is being built.. RightNow = Date.... ' Create a string that has the current date in the.. ' format of YYYYMMDD.. NowDate = CStr(Year(RightNow)).... If Month(RightNow) < 10 Then.. NowDate = NowDate & "0" & CStr(M
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:20B87BD98ACE81AB5E6041A5D0BB4BF7
      SHA1:D524A062EED20859F7F32D56C12A717E1C31AF1B
      SHA-256:93B541694DAC93B8DC756D77B885E1710DD8BE10A7645AFAD910474A971348AB
      SHA-512:522C194BF5D73D1CB4B9D26AF5E930517D94944D46323EDA07E11416B47F1AC9FED83AF608DD312F7B0BEA5405321C6AB98214A3EC00E72A8FAECA48826C60B7
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro that ignores..' any source file not modified yesterday...'..' SBLang=VBScript..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Ignores any source files not modified yesterday. Not used on Restore.".. ScriptType = 2..End Function....Sub RunBeforeFileCompare(Filename, ByRef Skip).. ' Ignore if this is a Restore.. If SBRunning.Restore then.. Exit Sub.. End If.... YesterdayDate = Date - 1.. YesterdatStr = CStr(Year(YesterdayDate)) & CStr(Month(YesterdayDate)) & CStr(Day(YesterdayDate)).. .. FileDate = SBRunning.GetFileDateTime(Filename, TRUE).. FileStr = CStr(Year(FileDate)) & CStr(Month(FileDate)) & CStr(Day(FileDate)).... If FileStr = YesterdatStr then.. Skip = FALSE.. Else.. Skip = TRUE.. End If..End Sub..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:53BCCC0D004DC0C4818D1976953C7182
      SHA1:9DC3D22642A55D939BEA7349E17E8D3D2DB6AA4E
      SHA-256:7D849B53125D4B8249EB9431E6351DFF467BB9050D412DD56B17D05CF85D1292
      SHA-512:505B5CCC306CC315E27FBBA683B5E406FE2CF4860A9422E769AC37067B5FBBA3236EE95B4AF7A2549CC254FDEF899F27E494408DC6988831F07FE24BB6C751D8
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that stops a profile from..' running if too many files will be copied or moved. Does nothing if it..' is a restore...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a profile configuration and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Stops a profile from running if too many files will be copied or moved".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' Do nothing..'..Function Install(Interactive).. Install = ""..End Function....'..' Called before any copying etc. is done..'..Function RunPreCopyCheck.. ' Restoring?.. If SBRunning.Restore then.. RunPreCopyCheck = "".. Exit Function.. End If.... ' Too man
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:D5274BBEB2F05AE1A63C9F9AE7852AA6
      SHA1:4B7A981A4F82537F7342E82999219151A6F8A4DA
      SHA-256:C1B9CE0332C53808CDF964EDB23CCFFE3F3381B660DFE4480F6E3175A0ECE42A
      SHA-512:C750C6BBD291AF524054CE1E4DB2AE198896CA8AB1644654EA6978185A76A9A21CEC214D1300F70ED76FA7977C9C5B32DD72A3104CCB9E4BAFC66AA45CEF5A91
      Malicious:false
      Reputation:unknown
      Preview:' ReSpace.VBS written by Dave Wilkins 2007....' complementary script to DeSpace.VBS..' (see comments in DeSpace.vbs for further details)....' Note that any pre-existing underscores in filenames will be turned..' into spaces by ReSpace.VBS, if used, ie....' original: My File_Name.ext..' DeSpaced: My_File_Name.ext..' ReSpaced: My File Name.ext....RootFolder = "X:\ROOT_FOLDER"....'OR....' Set objArgs = WScript.Arguments..' RootFolder = objArgs.Item(0) ..' note that any path argument with spaces must be wrapped in " "....RootFolder = RTB(RootFolder) ' remove trailing backslash (if any)....Set FSO = CreateObject("Scripting.FileSystemObject")..Set Folders = FSO.GetFolder(RootFolder)....Recurse Folders....' < = < =< = < = end of main logioc / start of subs & functions = > = > = > = >....Sub Recurse (ByRef Folders).... Set SubFolders = Folders.SubFolders.. Set Files = Folders.Files.. .. For Each File In Files.. Temp = Replace(File.Name, "_", " ").. If File.Name <> Temp Then
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:C2B501F5E7E1C0088E4D114A3C99C472
      SHA1:DFAA26AE92398A7A46B55CC23C1075D9380407DA
      SHA-256:CC5342DC199EE143612A9EFE6AE79CC236E64A2AA9F7DE611CC63CD6DE60AC36
      SHA-512:0A110B33BDD8665366FE774F1BBD5F20A3DD2A563185D1B41094F8B9C9C3F74CB2233926497AC6A60B1478D4342258DF7E4B84EECB0331DB8156697A4454A536
      Malicious:false
      Reputation:unknown
      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch0\stshfhich0\stshfbi0\deflang18441\deflangfe18441\themelang18441\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f43\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Segoe UI;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\f
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (console) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:1E5540941342933F836EA6F69DF5D9D7
      SHA1:7E41CA42523DAE2326ACDC4346A19CBF5CB86EA1
      SHA-256:CA4A636E3981AA99C223A3E487FD208D44A45C01819B862DC00CAB840E78EC2D
      SHA-512:EB024693FECA57DE9BFC05537B39C7771CF1F105025A2DB7BDF22BC49F742B7F387B5E28BAF92EFBE30CCAECD2FAA40C626C7D51A3DE95967E610D4302B772E4
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....O8g.................v........................@..........................06.......5...@......@................... 0.t...../..<....4..............>5..R...P0..!...........................@0.....................T./.(.....0......................text....D.......F.................. ..`.itext.......`...0...J.............. ..`.data................z..............@....bss.....r...@/..........................idata...<..../..>..../.............@....didata.......0......Z/.............@....edata..t.... 0......p/.............@..@.tls....`....00..........................rdata..]....@0......r/.............@..@.reloc...!...P0.."...t/.............@..B.rsrc.........4.......3.............@..@.............06......>5.............@..@................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:88DA258BC093874EF4AA7D2D6A23EF2C
      SHA1:0EB8860F47B103B81C1D09E4A14C8CA22ABF95EF
      SHA-256:C54F02A872B629F2A1F875C577E1A1AA78A0D949588A4508466AC65241C4FEBC
      SHA-512:3203A7831649E0DE7E7582750E13B4E830AD66DFF5F30784ADBAF1CA94FEB59BADADB5A32EC1140AA75B43F7AF6E1F8B0D953AE9B11EF5A67D1E24670FAC1AA9
      Malicious:false
      Reputation:unknown
      Preview:'------------------------------------------------------..' Script to remove file or folder. File or folder is..' argument 1 when calling the script...'..' Created by Alex, based on code from timestamp.vbs as..' provided by Michael J. Leaver (www.2BrightSparks.com)..'..' Free for non-commercial use...'..' Run by calling "cscript removeSource.vbs <arg>"..' where <arg> is full path of the to-be-removed file or..' folder...' Files should be full filenames (path included)..' and without any wildcards...' Folders can either end with a "\" or not...'------------------------------------------------------......'------------------------------------------------------..'Main code..'------------------------------------------------------....Set objArgs = WScript.Arguments..Set fso = CreateObject("Scripting.FileSystemObject")....If (objArgs.Count < 1) then..WScript.Echo "No filename or dirname to remove was supplied."..Else..' Concatenate all the arguments to create on file/dirname..' This is to avoi
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:3DA62630DF43A6F0760251F6CAF5FCF1
      SHA1:A39B7DEE988981F4C7C9B6B3E21BD432A6A0BA93
      SHA-256:859B66EF39215E03AD64C6B19E9F4CEE58E7CCE5217AAEF3561E4B1CE91D76E8
      SHA-512:5490A4819848D0A4D7805D3A273DE04DBCD13021F8315788C59BAD5B429AE40FC3F45B64478E90E832625B07D0B9DDD2507367913705060A52714A987A1CC0C6
      Malicious:false
      Reputation:unknown
      Preview:'------------------------------------------------------..' Save historic versions of the backup, so that you can..' backtrack to previous versions. This script will, if..' ran BEFORE the SyncBack-backup, copy the last backup..' (either directory or zip-file) to a historic version..' in the same destination directory...'..' The historic set consists of folders/files in the..' backup-directory that have a "1_", "2_" etc prefixed..' to the original backupfilename or -foldername. After..' the (in this script configured) maximum number of..' historic versions is reached, the script starts over..' at "1_" and repeats the cyclus...'..' That way, by looking at the modifation-date of the..' historic files or folders, you can always find the..' previous backups. Because of this, you can not..' automatically assume that the "1_" version is the..' oldest or newest version, it all depends on the..' modification-date of the files or folders...'..' Created by Alex, based on code from timestamp.vbs as
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:0EC529A3E56F54B00FE1A66985545076
      SHA1:9214E810CEBD401B2EB71CBA4BDB0E0CAE489356
      SHA-256:E1C9CCE1026588B3640876A1D7CE2070488AC40BAC07AA8DC8019B40D7D7661E
      SHA-512:B7AC4B753AFCE6785567A198360AEEACB11389978D84A2560DF8D692FC945703AF07141AD77A84F57FB31C68D240F698F94C7E4B9EBDC27AA9DC8FCD3BDDE920
      Malicious:false
      Reputation:unknown
      Preview:'..' Amazon S3 bucket locations used by SyncBackPro (2BrightSparks Pte. Ltd.)..'..' Do not modify this file unless you know what you are doing or have been instructed to do so. ..'..' IMPORTANT: THIS FILE IS REPLACED WHEN UPDATING OR UPGRADING SYNCBACK..'..' The section names are the location constraint strings as defined by Amazon:..'..' http://docs.aws.amazon.com/general/latest/gr/rande.html#s3_region..'..' default is used (instead of an empty string, which is not a valid section name) for the..' default S3 location (US Standard)...'..' Last modified 17 September 2024..' See https://docs.aws.amazon.com/general/latest/gr/s3.html for official list of regions..' ..[default]..Desc=US Standard..URL=s3.amazonaws.com....[us-west-1]..Desc=US-West (Northern userfornia)..URL=s3-us-west-1.amazonaws.com....[us-west-2]..Desc=US-West (Oregon)..URL=s3-us-west-2.amazonaws.com....; Uses AWS4-HMAC-SHA256 security..[us-east-2]..Desc=US-East (Ohio)..URL=s3-us-east-2.amazonaws.com....[eu-west-1]..Desc=Eu
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:8258961B87B427B924B0A3C3B6CE58E1
      SHA1:9B58C2AA1D0A6545348088763FB7132382F031A5
      SHA-256:FEC2FEDFD59325F82E1CFAB67B0DDEB986980C47969C4454469BB1E3CA5DB6CD
      SHA-512:59CC308F5434B8C6306E90B543DEF58A813146FF2B56DCE5D232AEAF749C12B4F8F471D676441DC7A860819E94EB25AF2761A739B0762334AD43E60ED77F25F0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....O8g...........!......1..H......$A1......P1...@..........................P8......n8...@...........................2.......2..=...`7..............z7..R....3..Y....................................................2.h.....2......................text...<.0.......0................. ..`.itext..<1....1..2....1............. ..`.data...8....P1......21.............@....bss.....v....2..........................idata...=....2..>....1.............@....didata.......2...... 2.............@....edata........2......62.............@..@.rdata..E.....2......82.............@..@.reloc...Y....3..Z...:2.............@..B.rsrc........`7.......6.............@..@.............P8......z7.............@..@........................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:AB9259B7A918BCE2B3D37FA1079F49B7
      SHA1:05019B4F58CBA23964AEAA76FE101E08DB480A2E
      SHA-256:E23A1AE85E36744DCA0D6E2622690917CAB3DF820C23DE087873DB3740D6931D
      SHA-512:85C287DFBB562C35AFED16B40214CD13215D7A1D6164EF2F0EEDE69A1DC52481DE439B3DE34B9FED048B335E3D2DF5C7186CA025BBFCB8711F5B53DCDD251379
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7........................................................................................................................................PE..d....O8g.........." .....~I..........4G.......@...............................Z.....W.Y...`.......................... ................Q......0Q..Q....Y.......U......@Y..R....Q.@...................................................0DQ.......Q......................text....}I......~I................. ..`.data... .....I.......I.............@....bss.........PP..........................idata...Q...0Q..R...4P.............@....didata.......Q.......P.............@....edata........Q.......P.............@..@.rdata..E.....Q.......P.............@..@.reloc..@.....Q.......P.............@..B.pdata........U......JT.............@..@.rsrc.........Y......ZX.............@..@..............Z......@Y.............@..@........................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:FC9A4B0D1A62B9349C3639B315B9643A
      SHA1:40D2AB8DB57BB9107F222FA6315DF3E7AB8EBAF4
      SHA-256:F5629BD88FC39AA9FD6E822941AF09157582E4399FE3677CD7A7AFD540A95E14
      SHA-512:274C0CCF9265115FE64E4F9B1F714618FA2BF3D3B3F5FF1170B8AEA90AF73AFD95E1E8F974D752A1EA110FE84E49F3E3E1E42C1A7A00204EFE00292B1A0CAF7D
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7........................................................................................................................................PE..d...WQ8g..........".......D.........P.B.......@...............................V.....?.U...`..........@............... ...............@M.y.....L..L....T.......P.......T..R...pM..y...........................`M.(.....................L...... M.J....................text.....D.......D................. ..`.data...@?....D..@....D.............@....bss.........0K..........................idata...L....L..N...$K.............@....didata.J.... M......rK.............@....edata..y....@M.......K.............@..@.tls.........PM..........................rdata..m....`M.......K.............@..@.reloc...y...pM..z....K.............@..B.pdata........P.......O.............@..@.rsrc.........T.......R.............@..@..............V.......T.............@..@
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:B545FD4FF8BCD6BC074ADF8AC6CFBDC1
      SHA1:9FFAC8A915B21D782DCA3E555E312843DCC57695
      SHA-256:52F689C2A84955879055C694230F5F09BC1362365C5478502DD18EA5F55D91DB
      SHA-512:740791CBFBC0E7CA5B77F2A1AD3FB205A0B6507A3B9899A421F67E85B292636DE53981CCF0589C25637BD219D90A9A9D0000E5E77BBF6756847299A2AE0A7E48
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sends an SMS..' if a profile fails (if the run is simulated then it does not)...'..' IMPORTANT, READ THE FOLLOWING:..'..' - You must first create an account at http://www.clickatell.com/..' - You will receive an API ID. You must set SMSAppID below to that ID...' - Set the connection details below..'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The connection details for Clickatell to send an SMS..const SMSUsername = "xxx"..const SMSPassword = "xxx"..const SMSMobileNum = "xxx" ' Recommended you include the country code..const SMSAppID = "xxx" ' See the comments above on how to get this....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Des
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:BD77F8B2E77DC9108FAE77C256BFA3D1
      SHA1:298912D85941B6602C0A04EF2AF01732D714D7B4
      SHA-256:F19D42C27487B4003479DADAC1C6BE3F3A73D98C84884D5AADEB8D8BAD8359CD
      SHA-512:1D5101C1A45331896AAA5C3988A0EA39FCBB5A0C3447710DC52C5D8264EF4EB9819594B37A35246A01AF31D382AD3767F67A0F0F6FBDBB24A10AC20A3F390AF6
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sends an SMS..' if a profile fails (if the run is simulated then it does not)...'..' IMPORTANT, READ THE FOLLOWING:..'..' - You must first create an account at http://www.clickatell.com/..' - You will receive an API ID. You must set the profile to use that App ID...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a profile config and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Send SMS on profile failure".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' This routined is called after the profile has finished...'..Sub RunProfileResult(ProfileResult, ErrMsg).. Dim sUrl.. Dim sText.. Dim oXMLHTTP, sPostData, sRes
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:5021C120C98F304699CC0A62628ECD3D
      SHA1:B0F481939B2E9F3CE8138AECC842CF7A90556D39
      SHA-256:01B74E7E7E5F41F0E4EDE8CE15CF6EF583468593D4DB12A60F0DCD635F8718E1
      SHA-512:A3256FFF4F2E66A42C5C2ACE0BAEDE0CCC313CD3D1CBD12E9C687DC25BC44FCBB34B7007252923C2A4997F5520BABA7E4B8A88E4288B23CA657EF1DF6F9E8E0D
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sends a Twitter message ..' after a profile runs (if the run is simulated then it does not)...'..' IMPORTANT, READ THE FOLLOWING:..'..' - THIS SCRIPT IS FOR REFERENCE ONLY. THIS SCRIPT NO LONGER WORKS...' - You must first create an account at http://www.twitter.com/..' - Set the connection details below..'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The connection details for Twitter to send a message..const TwitterUsername = "YOUR TWITTER USERNAME"..const TwitterPassword = "YOUR TWITTER PASSWORD"....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Send Twitter message after a profile run".. ScriptType = SCRIPTTYPE_RUN..End Function
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9A14BBFE294FB1589465D9366C41CE28
      SHA1:AD0AB01C89672173A6B81275917C8E07F9AFF8EA
      SHA-256:B44ABDB9AE2163875BC3D5E6D021B391E1598134E79C87CF9CD78251E75A90D4
      SHA-512:2937DC6019045B6941707EB802F9FF98ABD64C3BD37C294202625A9B136902B1DE7D69BAF5EFAD767A07C11011806425F096F234084566CFB2B5F9617B63A0AB
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sends a Twitter message ..' after a profile runs (if the run is simulated then it does not)...'..' IMPORTANT, READ THE FOLLOWING:..'..' - THIS SCRIPT IS FOR REFERENCE ONLY. THIS SCRIPT NO LONGER WORKS...' - You must first create an account at http://www.twitter.com/..'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a profile configuration and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Send Twitter message after a profile run".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' This routine is called after the profile has finished...'..Sub RunProfileResult(ProfileResult, ErrMsg).. Dim sUrl.. Dim sText.. Dim oXML
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:4AD069515B3EDB085D56D4764043399D
      SHA1:59D57FB3E394962745A77B041F8C64A4CD62A998
      SHA-256:AA5C4D612BBD649C529DFB31619480E8B6289030DBCBA19A4697ADFF08646F46
      SHA-512:C2E525C869A626EF32397C0906CCF5671A5B8FE61CEFBB88A3CA644175CFC708BB2060DA6CD2B4047B2B00231F4F86DEF9E19377F12E2456C4F04C23847C2027
      Malicious:false
      Reputation:unknown
      Preview:'..' Scans an SBSE backup destination for Versions (contents of $SBV$ folders) and exports..' them to [elsewhere]; file/folder deletion of original $SBV$ folders is included..'..' Why are $SBV$ folders not deleted immediately after copy of all contents?..' Because the recursion logic tries (on next iteration) to check if there are..' any subfolders OF the $SBV$, which is kinda hard to do if you've just deleted it.....'..' Thus, the storage of $SBV$ deletion-candidates in array for later attack.....'..' Note that this routine will not handle UNC paths...' It will be necessary to map a network drive to the resource, using something like....' If Not fso.DriveExists("X:") Then..' Set TempNet = WScript.CreateObject("WScript.Network")..' TempNet.MapNetworkDrive "X:", "\\server\path", False, "username", "password"..' End If....' False refers to make-permanent, i.e don't (I assume if you wanted a permanent..' mapped drive, it would be in place already :->..' False is the default, so If UN
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:16A80D522383C49C6265F54E9A242829
      SHA1:F6AF8E32699E7A286310AE84D30E474E264C040C
      SHA-256:967D4E579167E410F0DCDA8D7F2F1A3B7406479F7F4C74A1434EC48EBAD012EF
      SHA-512:8FCA97BD8679FB3A727B90A3F6678ECEE5F2EE7BE674BFABC7B2614D1F78317F7F2A39914A508B6B871D57894DC0B1636FE8C48FA3A1E032F9FC0C0698F15BBA
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that removes the leading zeros..' from the day and month variables...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The name of the variables..const MyDayName = "NoZeroDay"..const MyMonthName = "NoZeroMonth"....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a runtime script and a configuration script..'..' It must be a configuration script otherwise the variable will not be used..' when you modify the script..'..Function Description(ByRef ScriptType).. Description = "Adds new variables " & MyDayName & " and " & MyMonthName .. .. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' This subroutine is called when the variables are initialised. This is either..' when the profile is run, or when the
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:28948E2B2AE93F91C25A6C4843C30119
      SHA1:66CB3D1C66AA1FBB3532744EEAC7C428ED316C55
      SHA-256:4F244E4B7E37A92E20A8FBC2AA087E64D399D539A1306B540993B9322B51C386
      SHA-512:D3637A108CF017EEC695FF6ABFBCCD76793FF0C0EBD34ACF8DDBF45AF621A71339AC854F85D7EC0C394DC0F03386F84F29FA4B6B2F7CF1C0F9C621C1CCE06161
      Malicious:false
      Reputation:unknown
      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch14\stshfloch0\stshfhich0\stshfbi0\deflang1033\deflangfe1041{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f14\froman\fcharset136\fprq2{\*\panose 02020300000000000000}PMingLiU{\*\falt \'a1\'50s2OcuAe};}{\f37\froman\fcharset136\fprq2{\*\panose 00000000000000000000}@PMingLiU;}{\f38\froman\fcharset238\fprq2 Times New Roman CE;}..{\f39\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f41\froman\fcharset161\fprq2 Times New Roman Greek;}{\f42\froman\fcharset162\fprq2 Times New Roman Tur;}{\f43\fbidi \froman\fcharset177\fprq2 Times New Roman (Hebrew);}..{\f44\fbidi \froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:MS Windows HtmlHelp Data
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:357986161B16F958D839397A23CE5DA1
      SHA1:BD9BD2D609F3B48E2D305832DB1AAB18185EBCAD
      SHA-256:83362D503BF1EEE75AAD9ABFF628064BD7CC733F51BE9E3E9A08C952E53E8DF0
      SHA-512:795EE390D2A0009DD9519D2ED95143D13E84215BC83D91845639E1A29DD1D74B2D6EC335C1D4F168835FBA8E82C902932A1B7B845AAE81CE9E9C0712DF3FE628
      Malicious:false
      Reputation:unknown
      Preview:ITSF....`.......@R...H.....|.{.......".....|.{......."..`...............x.......TP.......P..............{D..............ITSP....T...........................................j..].!......."..T...............PMGL?................/..../#IDXHDR......../#ITBITS..../#IVB...N.D./#STRINGS....?.D./#SYSTEM....9./#TOPICS......../#URLSTR......#./#URLTBL......../#WINDOWS.....L./$FIftiMain...(..t./$OBJINST...i.?./$WWAssociativeLinks/..../$WWAssociativeLinks/BTree...."..L./$WWAssociativeLinks/Data....n.../$WWAssociativeLinks/Map....B./$WWAssociativeLinks/Property...I ./$WWKeywordLinks/..../$WWKeywordLinks/BTree......L./$WWKeywordLinks/Data...^.../$WWKeywordLinks/Map....p.../$WWKeywordLinks/Property..... ./32bit64bit.htm.....s./adobe-reader.png...L.~./allvolumes.htm...y.g./allvolumes1.png......../allvolumes2.png....5..R./allvolumes3.png.......'./alternative.jpg...*..q./altpay.png....V.V./arrow-down.gif......S./arrow-empty.gif....j.:./arrow-none.gif....$.O./arrow-up.gif....s.S./arrow_left.png..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (392), with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:10CED5F5E381427970057261E9713892
      SHA1:1C8BE1893B4B51B4C7537316539AD2396EDB5106
      SHA-256:165E81689161F9E60E7BFF1FBFE5CDFFED9640BA192C396F685C80377AA4813C
      SHA-512:22B58AEB01C7A86595A36A05B8334A60B0D5A3A0AE7F856141DFD1FEA9E2573AD13A4ED09F753967E2EEBFBEA2617FF29A432C30193CB1AFBFC86A24F8258460
      Malicious:false
      Reputation:unknown
      Preview:.<?xml version="1.0" encoding="utf-8"?>..<assembly xsi:schemaLocation="urn:schemas-microsoft-com:asm.v1 assembly.adaptive.xsd" manifestVersion="1.0" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.. <assemblyIdentity name="SyncBackPro.exe" version="11.0.0.0" type="win32"/>.. <description>SyncBackPro File Backup Program</description>.... <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">.. <security>.. <requestedPrivileges>.. <requestedExecutionLevel level="asInvoker" uiAccess="false"/>.. </requestedPrivileges>.. </security>.. </trustInfo>.... <dependency>.. <dependentAssembly>.. <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" language="*"
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:1157F60ACE930CEB10FCA5BE9025452A
      SHA1:C3248DB908AFA8F98F2580DC97051E30162434ED
      SHA-256:94A2A5F7A3809AABBB1F83A24C1A2108662BA6FF40EC938A58DD51958E6D9F76
      SHA-512:1D2607049385EF5FCF559E5E587FC9B96BED44CA33564B613259B72A0CCA4C5BF9FC3C129A9B72594D2194BB1D5C92E5853A192A75CDB784A801BB03C6C37ACC
      Malicious:true
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7........................................................................................................................................PE..d...{Q8g.........."..........................@.....................................9.....`..........@............... ...............PH.s.....F.x............a.H........R....H..Y...........................pH.(...................p.F.@(....G......................text............................... ..`.data.....I.. ....I.................@....bss..........C..........................idata..x.....F.......B.............@....didata.......G.......C.............@....edata..s....PH......|D.............@..@.tls....`....`H..........................rdata..m....pH......~D.............@..@.reloc...Y....H..Z....D.............@..B.pdata..H.....a.......].............@..@.rsrc................}.............@..@.debug....w.......w.................@..@
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (392), with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:FAD34EF99C964FD63EC54CB788EB3466
      SHA1:E5D77F57E8F815A39C11B68909668E5514837229
      SHA-256:6B809287077C7F0AA8AB70A8D1E045EEA17692971ED2EDBBD2D6BD28EA8379B7
      SHA-512:06C2F54F7CE36B25E91F1C13401E76888DC52960954F6E4B582E183B1D523CE28DD0024CEAB86952A74240ABA2344E8A69508AA42BF8CC01B102CE0225DD0767
      Malicious:true
      Reputation:unknown
      Preview:.<?xml version="1.0" encoding="utf-8"?>..<assembly xsi:schemaLocation="urn:schemas-microsoft-com:asm.v1 assembly.adaptive.xsd" manifestVersion="1.0" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.. <assemblyIdentity name="SyncBackPro.exe" version="11.0.0.0" type="win32"/>.. <description>SyncBackPro File Backup Program</description>.... <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">.. <security>.. <requestedPrivileges>.. <requestedExecutionLevel level="highestAvailable" uiAccess="false"/>.. </requestedPrivileges>.. </security>.. </trustInfo>.... <dependency>.. <dependentAssembly>.. <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" langua
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:2177634BDCCD4CB42B17C944644E27EB
      SHA1:78855680CF657D0A277E8DDBA80846F8F048F857
      SHA-256:D6874F5B025AC4A54D461BAC1A4024081FEA39C9FC36BD7B7777C9F436E17D1B
      SHA-512:FD41139881675863F19B08D039D56208BAB841511557AFA1EA838C9BD7FFD606735E8689AC6EA86AB00C5FC8D37E73FAC2C3DE8EB5720877640A01C848FCAC1F
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that shows how..' translation works...'..' How to use this:..'..' - Copy the example.mo file to the \locale\FR\LC_MESSAGES\ ..' folder in the SyncBackPro installation folder..'..' - Install the script and enable it as a main interface..' script. Restart SyncBackPro...'..' - Change the language (via the Preferences main menu) to..' French..'..' - You'll see the column that was title "String 1" is now..' title "Translated String 1"..'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a main interface script..'..Function Description(ByRef ScriptType).. Description = "Translation example".. ScriptType = SCRIPTTYPE_MAIN..End Function....'..' Load our translations. Why do we not do this in MainStarted() ?..' Because the column titles are set before MainStarted is called...'..' Just one column..'..Function MainColumnsCount.. SBSystem.AddTranslationDomain("example").. MainColumnsCount = 1..End Function....'..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:063B9492499E7F5E62E4CC9A7CC2A1C2
      SHA1:5A2CDEB97BD9590FE07C8F7E68384336ACF4488D
      SHA-256:4FFF6AA11E79FCB897C749B9AB05142E00312C7D41FB2D397CC353A0FCD25CC0
      SHA-512:409A2F1C98A0354A434BF1B56F9446B0AD3E0D701B976B621D8AA9731A5D8307161FB72E28BA4706DE67B4DD3296ED130CFCD5538B67BB5D12E36178CEA5F6B0
      Malicious:false
      Reputation:unknown
      Preview:param([string]$drive, [string]$password)....$SecureString = ConvertTo-SecureString $password -AsPlainText -Force..$UnlockResult = Unlock-BitLocker -MountPoint $drive -Password $SecureString..if ($UnlockResult.ReturnValue -ne 0)..{.. # Retry.. Unlock-BitLocker -MountPoint $drive -Password $SecureString ..}..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:FFA526C0E7E1921FF1781511EA06E6D0
      SHA1:B05FB38BC0D047D4FC1B4971D49D53C74E115D3D
      SHA-256:96D81A9BBE73A0245265073F644708AAC6CBB1B515313C78AEAC4A21A24A3CE7
      SHA-512:A6BFDA1856AB15E581A9C5E9DAD1C52C824650E08CCAA004307C41F26A915D57F818A2E7FCAC578363D6017CE296B77BB6D054EECEE3DF9BE0A23F0349BA3CF2
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds an extra..' column in the main window that shows if a profile is using..' versioning or not...'..' This script is an example of how to use caching to avoid..' performance problems in the main user interface. It also shows..' how to use the new PollingRefresh and RefreshDisplayEx..' functions...'..' You need to install this script and enable it on the Main Interface..' tab...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....Dim gCache....'..' This is a main interface script..'..Function Description(ByRef ScriptType).. Description = "Show versioning information".. ScriptType = SCRIPTTYPE_MAIN..End Function....'..' One column only showing history count...'..Function MainColumnsCount.. MainColumnsCount = 1..End Function....'..' Column title...'..Function MainColumnTitle(Col, ByRef Width).. MainColumnTitle = "Versioning"..End Function....'..' Column text...'..Function MainColumnText(Col, IsGroup, ProfileName).. Co
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:CD928EAAE000DCD8B943ABA8DEF0432F
      SHA1:5D971D376B64FDD25E3DC31B68EA1BC9251ED4FE
      SHA-256:B1BA96C511659F6196B7D7F68801EB8EBE06171CE80572120FF30BDBC620AE69
      SHA-512:DF4EF2B370632F9691A61B389A48750AD5BC0BDFF4189D1FA34F84759AD3A6F499C2434F9D8F9C82E53E741507F8CF776767E00A4BE157BA30A0F3BE6F2B38C9
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that waits for a program to..' finish before running the profile. If its a simulated run, or a restore,..' then it can be run regardless...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The name of the process you want to have finished running..const ProcessName = "Notepad.exe"....' The number of seconds to wait before re-checking if it is still running..const RetrySecs = 5....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Wait for " & ProcessName & " to finish before starting profile".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' Remind user to edit this script before use..'..Function Install(Interactive).. If Interactive Then..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:0DC847E2F7BA8F240257C5428D47840F
      SHA1:7BB37833AB1E74DD54C61EFF2805DB017610FCCA
      SHA-256:B8D73E9ABB4BB510120CABF5F39CD74AA64606D4A197CA2221F58420B0FD9B0A
      SHA-512:5EEFDCD5774810AD2CC3455111FC323DA5B9B8AE0E4A7415E0491D2D1807034073C81E2F9DD63D4E4D6682691F0A3F6C8AD29ABBF2CA0B5967CB9F64590BB2E2
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that waits for a program to..' finish before running the profile. If its a simulated run, or a restore,..' then it can be run regardless...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The number of seconds to wait before re-checking if it is still running..const RetrySecs = 5....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a profile configuration and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Wait for a program to finish before starting profile".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' Do nothing..'..Function Install(Interactive).. Install = ""..End Function....'..'..Function RunDisabledCheck(NoLog).. ' Running simulated or as a restore?.. If
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:data
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:C21A265174084C846F12562F0329D3E9
      SHA1:A850555139982CCB8EDDEF67B5EFAB212A5A18F1
      SHA-256:6DA122E88913234BAF946317EB5D9AC6CD8C73ED1FF2BD5B77FC4097915AE947
      SHA-512:A49E294470F8A86006CC3B680FDD8E22C83676204AC33CD0373F7D858D605E39610CF494FBDCEF9BFE9A2CBBE5FBFA9B50156E28764BB30C932EBBE3A1191FF6
      Malicious:false
      Reputation:unknown
      Preview:VCL_STYLE 2.0x......._,.4;-.&. h. ..D.iEp..4 ...".....$.h..h4...!...&.F.N..1.9....u&...x..L...'....B?X]V......<..<.T...}..........2k....n..N.Z.K.Z.......c]a..VY.5../....m..YK..X..}.Z....g... k..l...8.N;...4{.WN....k...u..W....k7...^....v.j.Z.`k.....j..~.........................................................................................3f..>}....a.0a..(.9s.$......3....g.q..Y__..>.Z.q.`......4i...*...d....;...k..:w../I^.....N;..ab..K..i........f;..u}....<...@.tO.W...{.F..Q.M..q....Q...M.....2j...........q}..e.K..u..e`uu.R.i...W../...}T....@u=I.........U.6C..9{.);...7.E..-...~...q.@...<x..=......+..}...T.(~.}U.`.5KNPUU5.f..3nP.~..E..a.*..q|.m...x8....J.....P..Ic..!..Q.@}.t?]...1l.....>..-U..~p..'..6m...;.r.S{...G........:..c..7n}T.....{Q.u.w...x..n.m.Ry.....................o....\............~.A3...:u..Wm....Z.e.V:'.I......M.>........>|..Ry....].~.{s;N/.[...Jm_...-WX?.v.:t..^.T....|F.......P....Pl...G..#'N..u.....
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:data
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:A98DA4117C6DB09FDC90801061BAA3C3
      SHA1:589ECCC11ED7674BF9DC1051320E1EF7276DD34A
      SHA-256:CC6E80231F4C57E506F0829A741DDD26725C93E7B9DBBB81F7B3A7EC2A8CE799
      SHA-512:30796E227C761EA2AECB9E7A90F6F32654C740EC1C4F31D4433074B93442D6A2F5160963D02EE0EDF5CA3266E267666AFE302659E285194E22FDD499592324EF
      Malicious:false
      Reputation:unknown
      Preview:VCL_STYLE 2.0x....-Ey..{o.O.Q........Qy..../.@xo7q.......O|.M|.`Ps..Q...h.1!..\.....`.Q...1P.#.p..y..b.^.z....zV....|..f.....s~.....(...[.+.W.W.W..)...X.\.V\Tl+.+6..c.....U.Zq......(.......m.^i.\Y\n.V..+...y..f{.......eK.J:.~.....?..5...%.....*...k....n..boz.m.W.]7.............................................................................................................................................................................8.H].P.7...Zc.r.#.+........^[...c.z..........0.o4.4...2..U.KUy.\#$.h.......r....{.z....6.K......@_t-.....f.i.i.)+.....2].;...5^b..W..).\.....6......=.8.P.^k.c.l4.GmL...^.6.!....ip9E.b.f\e.gl4..5O7..o.7P...*.$cg.o......zuq..W...0...6.e..P.u...B.*.x.......k...j..j.]K.....M........h]..e..n......z..........e...a._n..*...J.....@....n.a....z....Tn.o..(/jL.f.@.k...kZ?....+....O0.l4..<.P?..0..o2.Oj.h.....K.X...].n.....D...n.k....[.m....Z.P7.z..u.Lm.Me.e..U.7..V_...&7x.q.."....Lj7..o.v.-.4.O...B.oh.....4.kY....C.Rn...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:data
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:E3C6D7A20915249AEE97C8D4C15618A6
      SHA1:2A5DD8E78D06F485FBD259003AA3B6E32B3BCF01
      SHA-256:50856750DE95F6A2940F6B399CE0252F1F44872CE095750AD62C3843A4FB2FDB
      SHA-512:5DC241078B9D6F83A60636755D14952259AB5BDE1BE39A2A4BABDCD6F1CE4815207C506FA0E27E472B7BD433EB1C3E1F1D43740987D3519C061F8B8B95F77919
      Malicious:false
      Reputation:unknown
      Preview:VCL_STYLE 2.0x.....U}.....!\..J.$$$!..BB.$o...p9`.D#.[........E.t....tc9.E..R/TZ*..*Z....s<;.9.1m...s....~...03..5.....o.g.Y.f....53.......0p......6..<...7u.,....W..d.L.8e.R...F......,..l..f.w...3.r......}......on......+M.S.N7.]n./.1.i........6.)....?...[...wn...+..W..c..[.n3...|..f!W..=r``.........................................................................................................................................................................q.a.....\o.S..2..3.`...U...u.!..*.l....U......C.K..a..e..<....W4....p.-G.W.u.v>...Y.R.D....P.....=o2.m.k(R.....q.....h......<.....>.7.^.]\.7.p.Au...^.TC.w....k.u..x.'......1h8.p.a.a.!OY.t....q....rW..2...t...U.<n..a.A>0..p.A.}O."?p..\c..e^.....\k.gP...C.s.(.v.KV}....<Z....\.6_..E.[.\.`.a..0C|..Q...../7.}.Y...}......4m.,......C..B..%...n...1....a.[.....wi_.z...r.2C..aCV....].P.F..Q...."........X.1...a.VVh7.........3..W.|......ru..7.6]..w.U.\F..4m.A........K...m.h8...'..$.7O...o.u?.O7pi
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:data
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:1583E1A23D5C353471E1AC65CF2E52A3
      SHA1:7D07DCB8EB6D2852B48FEE2CDF27C8ADFDE358DF
      SHA-256:CC578ECEB7FEBBDF3D874210F5F7EC799E734A3097C9A37856685A99AFE0A746
      SHA-512:E70246DCE3A02260566093F2388EAFF45BDE9E2067512B0227AC80B8C9137B9C03915EB7DFA769D2CDCB780F027947235622A53D338E8036586E1667B16D3AC4
      Malicious:false
      Reputation:unknown
      Preview:VCL_STYLE 2.0x.........o..\D.rs..X*...U..B..![t.K...D.-M.lo......Zl._v..6u...!u+B...Fi4Dq...fF.;.3g..9..9.g......|.3.{....g>.a.V;.vV...i..Kk..>..o..a.o..&..p.lY......3k..:..w..\....q./.N...u...k..?......:.......'9eoY.;.S....N\....a%...6.Y......|.E..8..... Uh...:.....$.M.9.9..o...o.....................................................................................................................................................................`....xJgg.n....A...........e..~....l..$.u.....W.r.3..<Xo.........y................;*KY........p\....L...h;..n......7.^j..v....sA.t./....}..Y/MYq. in....Y..)..).(..j{q.....4.Q...%n.:::.p..X.......ym....)a..9Y.....................y.o..Z.."N}..[..*.....Rg......Q.J..z.............8..*....k....\...1q....b...}....>}'....\.O...#..I.@c.t.....[.F...}..+..8...Yw.S..B.5J~.8..F..x}.Q.p.;...}........2'.l..w.v..fe.r.....u.....N...{..j.^..q.7n..;.t.F....F..8u.T.!..`....".......Xr'........mV.m7....u......j.^...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:6D9FC3B6C94A01160B7E33FB422E9932
      SHA1:2D310529AA950F82F0CA66B1DD0F9D1D9CFC8580
      SHA-256:172E8F1B2E5B2AFD76E754396927A9665A56D749192A64587FA31F4998729B1E
      SHA-512:E4E5E408375B178E6A725073113E58BC05410F5A514935D797A1E5F769945A090476FDD93296DBA5349C5874CA4A4ACE2CE5F7D62C0C36262BB842A2AE57096B
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 2%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............z...z...z..a5r..z....`..z....q..z....g.]z.......z.......z...z...{....m..z...(p..z....u..z..Rich.z..................PE..L......R.................2..........Y........P....@..........................P............@.................................$............"................... ..`....T..................................@............P..`............................text....0.......2.................. ..`.rdata..0c...P...d...6..............@..@.data....&..........................@....rsrc....".......$..................@..@.reloc...,... ......................@..B................................................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:6FCF0CD1F542348E6CED853CC09F3C20
      SHA1:88BF8838F10EE84060D5A5CE69B7C1C0C7A7B922
      SHA-256:1B088414A73FE77803A238C20A3658C739AC449DEA79C73964A107B7C01F7A8C
      SHA-512:4CEAE8C8BE1EF2323F4A882F66291A5D0A84BC6C464FE883AC1FE3F026530674F1D9E8F098C20B25EC026FC07C3B391A3BF50DF67F3DA7BB179884FB0E3FB485
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 4%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........5.X.[.X.[.X.[...Z.[.Q..l.[.Q..A.[.Q....[...6.Y.[... .K.[.X.Z.d.[.Q....[.F..Y.[.Q..Y.[.RichX.[.........PE..L......R.................X...................p....@.......................................@.................................T........@..."...................p..D ...t..............................(...@............p..`............................text...yW.......X.................. ..`.rdata..`....p.......\..............@..@.data....(..........................@....rsrc...."...@...$..................@..@.reloc.../...p...0...(..............@..B........................................................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:78DD7574D212FF72E2D7D5BEA5A8AEEA
      SHA1:45A5B1E24E0EFD232978D501024767151E7EF678
      SHA-256:3DD20F8A9300141E734D561524ACF3D01B127D5E610C77F26F1777DADE081DFC
      SHA-512:8E64FD5016BFA023C90A5E49EF46FE5F29EEF0EB8B3CAD367816E29FEC1D59B2AA42BF1A4C5267E9891FCB91E7AB9663AF140927D6B1B318E8285E7E8FCAF7B7
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g.A#...#...#.......!...*.m.....*.|.:...*.j......y.."....y..0...#...b...*.`.p...=.}."...*.x."...Rich#...........PE..L......R..................... ....................@.......................................@.................................t;...........#......................(!..................................H6..@...............`............................text............................... ..`.rdata..............................@..@.data....5...`... ...:..............@....rsrc....#.......$...Z..............@..@.reloc...0.......2...~..............@..B........................................................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:99689B5B7577D1458154371755CDFC39
      SHA1:2DE6E712777F6AB4234909D611BDEAC39636DC09
      SHA-256:98BD4034333C5CE95C226F34339B2AC485FFF610F904503E981052B31C056C34
      SHA-512:E1C4047C92C8866FA02FF99A5DB0296A493D8792191DD06B03F15C77CFB14F5C82AE93326FF3F2E9D14E42702F2061E638DF57C216282B95DDB16FFD67463F21
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g..N#...#...#...*.I.N...*._.*...*.N.........&.......0...#...M...*.@.v...*.X."...=.^."...*.[."...Rich#...........................PE..d.....?T.........." ................H.........gg....................................................................................0.......x............F......Tx...(..X....`..T... ................................................................................text............................... ..`.rdata..0...........................@..@.data...X[...0......................@....pdata..Tx.......z...L..............@..@.rsrc....F.......H..................@..@.reloc..X....`......................@..B................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):12288
      Entropy (8bit):3.61540125004844
      Encrypted:false
      SSDEEP:
      MD5:9C8BB340723E4126EB5A8FFC7487F8E1
      SHA1:08C40682758DBAF7CC09E6B031B2167A9BB022C6
      SHA-256:2BB5FA9ECE5F647AF257BAFC82CEFA0C6952082F6B88BD34D390C6759AFAB70D
      SHA-512:274091B76DD47CA02020AC2FF96ACF11984984CADB6434F54EC8ECA25CAB2923573D7E451B39F9035871B800A71B77E853FBE897AEDE6EB78B9A61E8C5545614
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........|...|...|.......|.......|..Rich.|..........................PE..L...R..H.........."!.........................................................@......F6....@..............................................-...........................................................................................................rsrc....-..........................@..@....................................................(.......@............................................................................... .......8.......P.......h.......................................................................................................................................................(.......................8.......................H.......................X.......................h.......................x...................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9C8BB340723E4126EB5A8FFC7487F8E1
      SHA1:08C40682758DBAF7CC09E6B031B2167A9BB022C6
      SHA-256:2BB5FA9ECE5F647AF257BAFC82CEFA0C6952082F6B88BD34D390C6759AFAB70D
      SHA-512:274091B76DD47CA02020AC2FF96ACF11984984CADB6434F54EC8ECA25CAB2923573D7E451B39F9035871B800A71B77E853FBE897AEDE6EB78B9A61E8C5545614
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........|...|...|.......|.......|..Rich.|..........................PE..L...R..H.........."!.........................................................@......F6....@..............................................-...........................................................................................................rsrc....-..........................@..@....................................................(.......@............................................................................... .......8.......P.......h.......................................................................................................................................................(.......................8.......................H.......................X.......................h.......................x...................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 4 messages, Project-Id-Version: Translation example 'Translated string 1'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:7C20DAFE540CE09721DF005F6E8B3C86
      SHA1:514DC6038E8700B2483F5F91DC9BFD92C4C4C346
      SHA-256:4E3E46FC3A681CD31A753E7868B1C4118BB9347ED6A810ED9027A0AC3DC38F15
      SHA-512:FFBC2E0E7E30196AE333D508E73459F2A8B88084A1F11C6467AA883B5650D422990C6F9DFEDB0229031BD1C00778121CB911C8A1B7B35D818C727936D3D65374
      Malicious:false
      Reputation:unknown
      Preview:................<.......\.......p.......q.......z........... ....................................................String 1.String 2.String 3.Project-Id-Version: Translation example.POT-Creation-Date: .PO-Revision-Date: .Last-Translator: Michael J. Leaver <MJLeaver@2BrightSparks.com>.Language-Team: 2BrightSparks.MIME-Version: 1.0.Content-Type: text/plain; charset=UTF-8.Content-Transfer-Encoding: 8bit.X-Poedit-Language: French..Translated string 1.Translated string 2.Translated string 3.
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU gettext message catalogue, ASCII text
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9AFF213DA8492FAE84C23F4EA7EFB6DE
      SHA1:F2228B4076EEFACD34B514291475BC56008B5246
      SHA-256:58B0298ACD8D8F1FE2E64F718629B554C8787B80E9F23AAF31544B8525540E8F
      SHA-512:028831F1BE80EC3C32A76E66B325B01675DD49A638D958B98356B8CB24FEB847A118173D030D191D68D2B723DFEF391B76C99408A7A32EFB7BE0D2B99826836F
      Malicious:false
      Reputation:unknown
      Preview:msgid "".msgstr ""."Project-Id-Version: Translation example\n"."POT-Creation-Date: \n"."PO-Revision-Date: \n"."Last-Translator: Michael J. Leaver <MJLeaver@2BrightSparks.com>\n"."Language-Team: 2BrightSparks\n"."MIME-Version: 1.0\n"."Content-Type: text/plain; charset=UTF-8\n"."Content-Transfer-Encoding: 8bit\n"."X-Poedit-Language: French\n"..msgid "String 1".msgstr "Translated string 1"..msgid "String 2".msgstr "Translated string 2"..msgid "String 3".msgstr "Translated string 3"..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:6E57B31690A20CA7F36CA0198BFA5C70
      SHA1:EBC2147A5A9610E874607C4DAEC2EB13F389F666
      SHA-256:C112F69F250617CCCA3AA5F7BD8CE1E47FE034D24DCCC733F77C7522E4782864
      SHA-512:AACF41E545B80F5272830C576C253609A813961D0F20CC545637367F2F17815357974E31F231AD76EDBABAEE723B6EB186D03AA22836C3E0674F8AE6A9BA9E34
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script to display a message dialog box if the free..' disk space on one or more drives is below a certain leve;..'..' You must pass the drive to check as a command line parameter...' For example:..'..' FreeSpace.vbs C:..'..' IMPORTANT: The drive letter must be in that format, e.g. C:\..' will fail. It must be drive letter followed by a colon only...'..const MBFREESPACEREQUIRED = 10 ' !!! Change as appropriate - this is in MBytes..const ONEMB = 1048576....Set objArgs = WScript.Arguments..If (objArgs.Count < 1) then.. WScript.Echo "No filename or dirname to copy was supplied."..else.. Set objWMIService = GetObject("winmgmts:").. For I = 0 To objArgs.Count - 1.. Set objLogicalDisk = objWMIService.Get("Win32_LogicalDisk.DeviceID='" & objArgs.Item(i) & "'").. if objLogicalDisk.FreeSpace / ONEMB < MBFREESPACEREQUIRED then.. MsgBox ("There is less than " & MBFREESPACEREQUIRED & "MBytes of free disk space available on " & objArgs.Item(i)).. ' Wscript.Echo "The
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):754
      Entropy (8bit):5.007474728305936
      Encrypted:false
      SSDEEP:
      MD5:484D934F7CEBB1A41C16FCB6B6A961B2
      SHA1:5C05BDE2875A0E63E846648F02C6817352EBA9AB
      SHA-256:8ACADAB63B9BD36020287467A04EB7862294385332A8CC38FE2C8180815582D7
      SHA-512:3DCDED6D3B5BF15F732F01F1B1881D18A9ED28DBF4A097F55910FDFE58AFEB0FDE9F67916760995823F30E9FE3F4E440D7326F137BB88A9EB1A80765412D463F
      Malicious:false
      Reputation:unknown
      Preview:' IsDriveReady by Dave Wilkins 2007....' either preload the drive letter in question (in which..' case suggest rename the script IsDriveXReady.vbs...)....DLetter = "X"....' OR ....' Set objArgs = WScript.Arguments..' DLetter = objArgs.Item(0)..' Cater for anyone who has "helpfully" included : or \..' DLetter = Left(DLetter,1)....Set fso = CreateObject("Scripting.FileSystemObject") ..Set dc = fso.Drives ' drive collection....Do.....For Each d In dc ' scan the drives looking for DLetter......If d.DriveLetter = DLetter Then.....retval = 0 ' "OK" value for SBSE to proceed.....Exit Do....End If...Next .....' we have a non-ready drive...retval = 1 ' not OK (in SBSE-speak - diff val to VBCancel)...Exit Do....Loop ' scan again....Wscript.quit(retval)..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:data
      Category:dropped
      Size (bytes):124824
      Entropy (8bit):7.938092734272097
      Encrypted:false
      SSDEEP:
      MD5:A98DA4117C6DB09FDC90801061BAA3C3
      SHA1:589ECCC11ED7674BF9DC1051320E1EF7276DD34A
      SHA-256:CC6E80231F4C57E506F0829A741DDD26725C93E7B9DBBB81F7B3A7EC2A8CE799
      SHA-512:30796E227C761EA2AECB9E7A90F6F32654C740EC1C4F31D4433074B93442D6A2F5160963D02EE0EDF5CA3266E267666AFE302659E285194E22FDD499592324EF
      Malicious:false
      Reputation:unknown
      Preview:VCL_STYLE 2.0x....-Ey..{o.O.Q........Qy..../.@xo7q.......O|.M|.`Ps..Q...h.1!..\.....`.Q...1P.#.p..y..b.^.z....zV....|..f.....s~.....(...[.+.W.W.W..)...X.\.V\Tl+.+6..c.....U.Zq......(.......m.^i.\Y\n.V..+...y..f{.......eK.J:.~.....?..5...%.....*...k....n..boz.m.W.]7.............................................................................................................................................................................8.H].P.7...Zc.r.#.+........^[...c.z..........0.o4.4...2..U.KUy.\#$.h.......r....{.z....6.K......@_t-.....f.i.i.)+.....2].;...5^b..W..).\.....6......=.8.P.^k.c.l4.GmL...^.6.!....ip9E.b.f\e.gl4..5O7..o.7P...*.$cg.o......zuq..W...0...6.e..P.u...B.*.x.......k...j..j.]K.....M........h]..e..n......z..........e...a._n..*...J.....@....n.a....z....Tn.o..(/jL.f.@.k...kZ?....+....O0.l4..<.P?..0..o2.Oj.h.....K.X...].n.....D...n.k....[.m....Z.P7.z..u.Lm.Me.e..U.7..V_...&7x.q.."....Lj7..o.v.-.4.O...B.oh.....4.kY....C.Rn...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1432
      Entropy (8bit):5.035772203593205
      Encrypted:false
      SSDEEP:
      MD5:D5274BBEB2F05AE1A63C9F9AE7852AA6
      SHA1:4B7A981A4F82537F7342E82999219151A6F8A4DA
      SHA-256:C1B9CE0332C53808CDF964EDB23CCFFE3F3381B660DFE4480F6E3175A0ECE42A
      SHA-512:C750C6BBD291AF524054CE1E4DB2AE198896CA8AB1644654EA6978185A76A9A21CEC214D1300F70ED76FA7977C9C5B32DD72A3104CCB9E4BAFC66AA45CEF5A91
      Malicious:false
      Reputation:unknown
      Preview:' ReSpace.VBS written by Dave Wilkins 2007....' complementary script to DeSpace.VBS..' (see comments in DeSpace.vbs for further details)....' Note that any pre-existing underscores in filenames will be turned..' into spaces by ReSpace.VBS, if used, ie....' original: My File_Name.ext..' DeSpaced: My_File_Name.ext..' ReSpaced: My File Name.ext....RootFolder = "X:\ROOT_FOLDER"....'OR....' Set objArgs = WScript.Arguments..' RootFolder = objArgs.Item(0) ..' note that any path argument with spaces must be wrapped in " "....RootFolder = RTB(RootFolder) ' remove trailing backslash (if any)....Set FSO = CreateObject("Scripting.FileSystemObject")..Set Folders = FSO.GetFolder(RootFolder)....Recurse Folders....' < = < =< = < = end of main logioc / start of subs & functions = > = > = > = >....Sub Recurse (ByRef Folders).... Set SubFolders = Folders.SubFolders.. Set Files = Folders.Files.. .. For Each File In Files.. Temp = Replace(File.Name, "_", " ").. If File.Name <> Temp Then
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2995
      Entropy (8bit):4.760547086305717
      Encrypted:false
      SSDEEP:
      MD5:7E4D917ADB32FAE6CD674DA5AD413F26
      SHA1:190A3341AC24AE43E45F8EB2887A86FEECC37CC0
      SHA-256:5C385FD1BEB6B4582DE3CA3A221B8B2F0DD7E4DB9721117C1B11BC57544DD745
      SHA-512:CE33091DC535E15DF7D9B3B4A2FC11465562FDDF8F67A5C4427AD70296275D3A111B589A62BC6BC4A20FF5EECAD9EBBA7BAE2D51606E145DD5B4DE706A27891B
      Malicious:false
      Reputation:unknown
      Preview:'------------------------------------------------------..' Add a timestamp to the start of the filename..' corresponding to the date the file was last changed...' (Alter line starting "timestamp =" to alter the..' format of the timestamp that is prepended.)..'..' (c) J.G.Clark 23.3.2004, with Functions from..' www.paulsadowski.com/WSH...'..' Modified by Michael J. Leaver (www.2BrightSparks.com)..' to concatenate arguments to avoid problems with..' spaces in filenames, display an error message if no..' filename was supplied, and also to copy the original..' file instead of moving it. This is to help its use..' with SyncBack (www.SyncBack.com)..'..' Free for non-commerical use...'..' Run by calling "cscript timestamp.vbs <arg>"..' where <arg> is full path of file to filestamp...' Works for UNC paths as well...'------------------------------------------------------....'------------------------------------------------------..'Return the pathname portion of a full pathname..'---------------
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):870
      Entropy (8bit):4.9409941654444625
      Encrypted:false
      SSDEEP:
      MD5:20B87BD98ACE81AB5E6041A5D0BB4BF7
      SHA1:D524A062EED20859F7F32D56C12A717E1C31AF1B
      SHA-256:93B541694DAC93B8DC756D77B885E1710DD8BE10A7645AFAD910474A971348AB
      SHA-512:522C194BF5D73D1CB4B9D26AF5E930517D94944D46323EDA07E11416B47F1AC9FED83AF608DD312F7B0BEA5405321C6AB98214A3EC00E72A8FAECA48826C60B7
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro that ignores..' any source file not modified yesterday...'..' SBLang=VBScript..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Ignores any source files not modified yesterday. Not used on Restore.".. ScriptType = 2..End Function....Sub RunBeforeFileCompare(Filename, ByRef Skip).. ' Ignore if this is a Restore.. If SBRunning.Restore then.. Exit Sub.. End If.... YesterdayDate = Date - 1.. YesterdatStr = CStr(Year(YesterdayDate)) & CStr(Month(YesterdayDate)) & CStr(Day(YesterdayDate)).. .. FileDate = SBRunning.GetFileDateTime(Filename, TRUE).. FileStr = CStr(Year(FileDate)) & CStr(Month(FileDate)) & CStr(Day(FileDate)).... If FileStr = YesterdatStr then.. Skip = FALSE.. Else.. Skip = TRUE.. End If..End Sub..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2928
      Entropy (8bit):4.943243852435187
      Encrypted:false
      SSDEEP:
      MD5:5DF38755279541C7471997D75271766F
      SHA1:F785B71F390F90527A34ED086B828A4E7144FA23
      SHA-256:D3FBAE36502F241C030C90B8520C452A4C6ED26878E1A4CC15A49AE5EC288A94
      SHA-512:9239C162E70D6CA9F76DAF28BAAEAD3FE27AA23191BA7E6E7C5BFF67EA2E49D73A164585371DDC576E826EB87FD12D8FE0435E433C6A1C936C844626DD36FDA3
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds an extra..' column in the main window that shows history information for..' the profile...'..' This script is an example of how to use caching to avoid..' performance problems in the main user interface. It also shows..' how to use the new PollingRefresh and RefreshDisplayEx..' functions...'..' You need to install this script and enable it on the Main Interface..' tab...'..' SBLang=VBScript..'..' http://www.2BrightSparks.com/..'....Dim gCache....'..' This is a main interface script..'..Function Description(ByRef ScriptType).. Description = "Show history count information".. ScriptType = SCRIPTTYPE_MAIN..End Function....'..' One column only showing history count...'..Function MainColumnsCount.. MainColumnsCount = 1..End Function....'..' Column title...'..Function MainColumnTitle(Col, ByRef Width).. MainColumnTitle = "History Count"..End Function....'..' Column text...'..Function MainColumnText(Col, IsGroup, ProfileName).
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1197
      Entropy (8bit):4.938954998836203
      Encrypted:false
      SSDEEP:
      MD5:97A285CA46DBF5670280C8E68876A903
      SHA1:0141A712888274B1F7CB372B8A40F2D8E8106B65
      SHA-256:A36542CACC14E75CFE1F1B8DC764D956BFDF1B22806650C663CE57CF38DE453B
      SHA-512:E635853691188E9EAACF4B3EBB73E65C9CBFFBDFF616CACF1C71F69F6B3730867D6572E462E3B209E315BFADE6BFF0EDFB5529A552DD97A6571883CE6EAE0BA1
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that uses NTFS..' compression on the copy of a file...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "NTFS compresses copies of a file".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' This function compresses the copy of a file...'..' Note this function is not called if it is a simulation...'..Sub RunAfterCopyFile(ToLeft, Filename, Failed).. ' If the copy failed then dont even try.. If Failed then.. SBRunning.DebugOut(Filename, "Failed", 1).. Exit Sub.. End If.... ' Only compress the copy if the original was compressed.. Attrs = SBRunning.GetFileAttrs(Filename, not ToLeft).. if Attrs >= 0 then.. if (Attrs and 2048) = 0 then.. Exit Sub.. End If.. End If.... ' Get the full filename.. If ToLeft then.. FullName = SBRunning.LeftFolder & Filename.. Else.. FullName = SBRunning.RightFolder & Filename..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):2934056
      Entropy (8bit):5.432410808399766
      Encrypted:false
      SSDEEP:
      MD5:7E86B65153AC6BA3BE51131DC19A61B6
      SHA1:606E4A2357B31971E0A998FE3E50CCC829CE9D29
      SHA-256:68B4BC2E138B7666F34FC17E0F555741ACE13C7C58F969C88A9E1B7F3616E05A
      SHA-512:1C6DF094A4C9D1241E8FBED41670A0EB10530757DA1445B859568738403B37D70A25ACEECC9A586AD8B59D78829262946B548D5A8AC986D664D5655F09030745
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........x........................................J.......................@...........................Rich............................PE..d...5L.J.........." ................4..........P..............................-.....ul-...@...........................................&.......&.,.....).....`(.......,.(.....,.Tb...................................................................................text.............................. ..`.orpc...l........................... ..`.rdata..............................@..@.data.........&..z....&.............@....pdata.......`(.......(.............@..@.rsrc........).......).............@..@.reloc...~....,......0,.............@..B........................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):5870304
      Entropy (8bit):5.96957492206154
      Encrypted:false
      SSDEEP:
      MD5:AB9259B7A918BCE2B3D37FA1079F49B7
      SHA1:05019B4F58CBA23964AEAA76FE101E08DB480A2E
      SHA-256:E23A1AE85E36744DCA0D6E2622690917CAB3DF820C23DE087873DB3740D6931D
      SHA-512:85C287DFBB562C35AFED16B40214CD13215D7A1D6164EF2F0EEDE69A1DC52481DE439B3DE34B9FED048B335E3D2DF5C7186CA025BBFCB8711F5B53DCDD251379
      Malicious:false
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7........................................................................................................................................PE..d....O8g.........." .....~I..........4G.......@...............................Z.....W.Y...`.......................... ................Q......0Q..Q....Y.......U......@Y..R....Q.@...................................................0DQ.......Q......................text....}I......~I................. ..`.data... .....I.......I.............@....bss.........PP..........................idata...Q...0Q..R...4P.............@....didata.......Q.......P.............@....edata........Q.......P.............@..@.rdata..E.....Q.......P.............@..@.reloc..@.....Q.......P.............@..B.pdata........U......JT.............@..@.rsrc.........Y......ZX.............@..@..............Z......@Y.............@..@........................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):981
      Entropy (8bit):5.029025886878976
      Encrypted:false
      SSDEEP:
      MD5:367D4FE2769349BA93BD9A9FC685FF5D
      SHA1:A00CB168B129FF0A9CEAE180CB248B1B69C2A2F7
      SHA-256:927303D72DD6A15B77B1C53AA3B12B9E24AF55FC2C1A3428AC08C5711091163C
      SHA-512:AF6B36F7C71B26E3263378F55DEE556972860250DD27855074CD99FF1FEBAC2392CFC45CC57BA5ECA7BCD4BF3405A67BD15B4ED089BDA3DBE2621C25E3D8E0E9
      Malicious:false
      Reputation:unknown
      Preview:' IsDriveReady by Dave Wilkins 2007....' either preload the drive letter in question (in which..' case suggest rename the script IsDriveXReady.vbs...)....DLetter = "X"....' OR ....' Set objArgs = WScript.Arguments..' DLetter = objArgs.Item(0)..' Cater for anyone who has "helpfully" included : or \..' DLetter = Left(DLetter,1)....Set fso = CreateObject("Scripting.FileSystemObject") ..Set dc = fso.Drives ' drive collection....Do.....For Each d In dc ' scan the drives looking for DLetter......If d.DriveLetter = DLetter Then.....retval = 0 ' "OK" value for SBSE to proceed.....Exit Do....End If...Next .....' we have a non-ready drive.....retval = MsgBox ("Please insert (or turn on) external drive " & DLetter, vbRetrycancel+Vbdefaultbutton1,"Backup Drive Not Ready").....If retval = VBCancel Then '....retval = 1 ' not OK (in SBSE-speak - diff val to VBCancel)....Exit Do...End If....Loop ' scan again; if still not ready, keep alerting till cancelled....Wscript.quit(retval)..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):5793
      Entropy (8bit):5.214787730149306
      Encrypted:false
      SSDEEP:
      MD5:BD77F8B2E77DC9108FAE77C256BFA3D1
      SHA1:298912D85941B6602C0A04EF2AF01732D714D7B4
      SHA-256:F19D42C27487B4003479DADAC1C6BE3F3A73D98C84884D5AADEB8D8BAD8359CD
      SHA-512:1D5101C1A45331896AAA5C3988A0EA39FCBB5A0C3447710DC52C5D8264EF4EB9819594B37A35246A01AF31D382AD3767F67A0F0F6FBDBB24A10AC20A3F390AF6
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sends an SMS..' if a profile fails (if the run is simulated then it does not)...'..' IMPORTANT, READ THE FOLLOWING:..'..' - You must first create an account at http://www.clickatell.com/..' - You will receive an API ID. You must set the profile to use that App ID...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a profile config and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Send SMS on profile failure".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' This routined is called after the profile has finished...'..Sub RunProfileResult(ProfileResult, ErrMsg).. Dim sUrl.. Dim sText.. Dim oXMLHTTP, sPostData, sRes
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):3628
      Entropy (8bit):4.931629768256086
      Encrypted:false
      SSDEEP:
      MD5:DBA90A58279E2D3705234D53877767BB
      SHA1:BE2D8F5C02E3B7C8CE7A87C3BCAC8DADE9D45784
      SHA-256:0F9CE94B04DE7C7793D4C12F73DD1139CF4CAC538EB781CCE731C48BD839D4D9
      SHA-512:B663B65493D4BB1B2F91EEF4BBD19344399D7662ED9017FB7BDC64CCB90885EA6097700BD5442DAFD20F1D4A2082EC734778EBC3FF37C67349D718C2F525D27B
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro that stops a profile..' from being run more than once per day. If its a simulated run,..' or a restore, then it can be run regardless...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a configuration script and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Run at most once per day".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' We use the LastRunDT value from the profiles settings. It contains..' the last run date and time of the profile. If it has already been..' run today then we stop the profile running, and no log is created...'..Function RunDisabledCheck(NoLog).. ' Get the current date now just in case it changes while.. ' the string is being built.. RightNow = Date.... ' Create a string that has the current date in the.. ' format of YYYYMMDD.. NowDate = CStr(Year(RightNow)).... If Month(RightNow) < 10 Then.. NowDate = NowDate & "0" & CStr(M
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):592
      Entropy (8bit):5.051716219605827
      Encrypted:false
      SSDEEP:
      MD5:9D6262FEF844370DB4B140800569EDEC
      SHA1:C6E40F38E99BBA102B0F7274F0FAE13E1A0D4F30
      SHA-256:2C1B5EEFD6697355B6A3D74E9CD1885E3FA70AF7F42C88F95BD1C1EC89D52B9D
      SHA-512:71769410EE853027F0925C0CB9B6616FDD08B6BD9B869B670E2F896EFAA25D5D9AFFA78A22744068E619321BC5FA8593FBD5CC1CCFFA9FB4BC183A72A6B14A1C
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds voice alert..' to the Differences window...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'..'..' This is a runtime script..'..Function Description(ByRef ScriptType).. Description = "Adds voice prompt if/when Differences window appears".. ScriptType = SCRIPTTYPE_RUN..End Function....Sub RunDiffOpened.. SBSystem.Say("Scan completed - review required" )' edit to phrase of choice..End Sub....' SBSystem.Say can also handle WAV files (not MP3 or similar)..' Simply replace spoken phrase with "X:\path\name.WAV" etc...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):810496
      Entropy (8bit):6.190059527449625
      Encrypted:false
      SSDEEP:
      MD5:CFB6429F28A8DAF4BA6548BE3D76CE13
      SHA1:FCA8A394CBECC0B92472417BBD8CA02C8538D563
      SHA-256:0A51F665B625AFE94F761BB962D62AA75EDBB4491631F687F4590AF75282AD57
      SHA-512:9551A70BB329606D09BA28E32436F817C385EFCFE641C5041E15381FC8AD733819CCDE9ADCEF216B4A5C8494AD5C0F7E744E91DC3396EC098CE355033FA71553
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........]...<.K.<.K.<.K\..K.<.K.mXK_<.K.mgK.<.K.mYK.<.K.D;K.<.K.D+K.<.K.<.K.=.Kw.XK.<.Kw.YK.<.Kw.dK.<.K.ncK.<.K.</K.<.Kw.fK.<.KRich.<.K........................PE..d...s..c.........." ......................................................................`......................................... ...................h....p..P^..................@...8........................... z..p...............x............................text...^........................... ..`.rdata..t...........................@..@.data...h{.......T..................@....pdata..P^...p...`...&..............@..@.rsrc...h...........................@..@.reloc...............D..............@..B........................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 4 messages, Project-Id-Version: Translation example 'Translated string 1'
      Category:dropped
      Size (bytes):489
      Entropy (8bit):5.010622184976721
      Encrypted:false
      SSDEEP:
      MD5:7C20DAFE540CE09721DF005F6E8B3C86
      SHA1:514DC6038E8700B2483F5F91DC9BFD92C4C4C346
      SHA-256:4E3E46FC3A681CD31A753E7868B1C4118BB9347ED6A810ED9027A0AC3DC38F15
      SHA-512:FFBC2E0E7E30196AE333D508E73459F2A8B88084A1F11C6467AA883B5650D422990C6F9DFEDB0229031BD1C00778121CB911C8A1B7B35D818C727936D3D65374
      Malicious:false
      Reputation:unknown
      Preview:................<.......\.......p.......q.......z........... ....................................................String 1.String 2.String 3.Project-Id-Version: Translation example.POT-Creation-Date: .PO-Revision-Date: .Last-Translator: Michael J. Leaver <MJLeaver@2BrightSparks.com>.Language-Team: 2BrightSparks.MIME-Version: 1.0.Content-Type: text/plain; charset=UTF-8.Content-Transfer-Encoding: 8bit.X-Poedit-Language: French..Translated string 1.Translated string 2.Translated string 3.
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2585
      Entropy (8bit):4.994275130582617
      Encrypted:false
      SSDEEP:
      MD5:ABA2966C1AEC583F30F96CB9AE69E69E
      SHA1:14BE61140C86AB14E062782A6CDB6377E06A8EE3
      SHA-256:6E50C9C4FF3320CC8624ED38155B826A6845955D97C7058AF4C74A32DF3DBAD3
      SHA-512:6D0775DBD9A20929DB9B6BB4665D3354D9CF53145CB456FE123E7F7A24B6D571B3685E587F0701E6E7F5D6844830A834ACE375BF4FFA24B5D86110DFE57213A3
      Malicious:false
      Reputation:unknown
      Preview:' MoveExpiredFiles by Dave Wilkins 2007....' a utility to strip out files over (as shown) 1 month old from a file-set...' This is to cater for the fact that SyncBackSE does not (at time of writing)..' have a facility For filtering by Months, only by secs, mins, hrs & days...' Because there are a varying number of days in a month, using (say) 30 days..' in the filter is inaccurate for more than half the year....' The script can be easily modified to handle 2 or 3 months (etc) by simply..' editing (or supplying) a different value of MonthBar....' The idea is to run this script in Programs - Before of a profile..' which uses the script's Destination as its (the profile's) Source...' The profile will then Zip the Moved files and transfer them to the..' "real" Destination, as set in profile...' Thus, requires the use of an interim staging-area with sufficient space....' Hard-code the Source and Dest (actually, staging-area)....SourcePath = "C:\TOPMOST FOLDER OF TARGET"..DestPath = "X:\TEMPL
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):802392
      Entropy (8bit):6.371702083106014
      Encrypted:false
      SSDEEP:
      MD5:99689B5B7577D1458154371755CDFC39
      SHA1:2DE6E712777F6AB4234909D611BDEAC39636DC09
      SHA-256:98BD4034333C5CE95C226F34339B2AC485FFF610F904503E981052B31C056C34
      SHA-512:E1C4047C92C8866FA02FF99A5DB0296A493D8792191DD06B03F15C77CFB14F5C82AE93326FF3F2E9D14E42702F2061E638DF57C216282B95DDB16FFD67463F21
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g..N#...#...#...*.I.N...*._.*...*.N.........&.......0...#...M...*.@.v...*.X."...=.^."...*.[."...Rich#...........................PE..d.....?T.........." ................H.........gg....................................................................................0.......x............F......Tx...(..X....`..T... ................................................................................text............................... ..`.rdata..0...........................@..@.data...X[...0......................@....pdata..Tx.......z...L..............@..@.rsrc....F.......H..................@..@.reloc..X....`......................@..B................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1693
      Entropy (8bit):5.091644468110981
      Encrypted:false
      SSDEEP:
      MD5:6B040A9EEDFE2BFF6CC3F21915CD0435
      SHA1:767F4CB437EF6367D930F945F37DB1FD727ACD3E
      SHA-256:0526037B9FBB960959C0130E424FA063F76D00A4076C5922BA024A3418EFC781
      SHA-512:9E11482AFB1EFC815758C81B276566405F38CF89389AD784DC062F3D03C8E5A68F636558E900B65E3D374B02A48569CF125515B8DD21AC731D613965500E7377
      Malicious:false
      Reputation:unknown
      Preview:' used in Programs - Before to check if PC is in 'home' office..' in current form, uses a config file on disk with DHCP addresses..' this should be in the form..' 10.0.0.1..' 123.124.125.126..' etcetera..' The file can contain other strings also - any that do not match..' the DHCP address supplied to the PC on arrival will be rejected ....' The config file name can be hard-coded, or supplied as a parameter, thus....ConfigName = "C:\DHCP.TXT"....'OR....'Set objArgs = WScript.Arguments..'ConfigName = objArgs.Item(0)....' actually the DHCP address itself could be hard coded if you prefer..' in which case the "Get contents of config" section can be discarded....' Get current DHCP....strComputer = "." ..strCurrentDHCP = "" ....Set objWMI = GetObject("winmgmts:\\" & strComputer & "\root\cimv2") ..Set colItems = objWMI.ExecQuery("SELECT * FROM Win32_NetworkAdapterConfiguration", , 48)....For Each objItem In colItems ...If Not IsNull(objItem.DHCPServer) Then ....strCurrentDHCP = objItem.DHCPSe
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:MS Windows icon resource - 4 icons, 48x48, 16 colors, 4 bits/pixel, 32x32, 16 colors, 4 bits/pixel
      Category:dropped
      Size (bytes):3238
      Entropy (8bit):3.6305748526534374
      Encrypted:false
      SSDEEP:
      MD5:AF8A443D818AA0ABA7F0BFBFEDA251B2
      SHA1:B2EFE75E95197B1F7F380B1A833D44F9A7A6C889
      SHA-256:6119D32E20EF298F6811BEEA628339A678523C3C1C3168FAC2A2A0645A853274
      SHA-512:06BC23A92B89152686A66FD9E9C131D087CCD5A33E75C3EA84F3B70EA42DA41A2BBF8E1E65994F79B64C32F9357FB851816031F50767D19FF9B7AA7E5FC525AD
      Malicious:false
      Reputation:unknown
      Preview:......00......h...F... ......................................(...~...(...0...`....................................................................................................ww...........wwp..........p............p...............D....{..p...........p...D@......p...........p..DDD......p...........p...........p...........{...........p.......{...tDDDDDDDG...............tDDDDDDDG{...p.....{...wfDDDDDDDfw.............vf`......fg{...p...{...wff`......ffw...........vff`......ffg{...p.....wfff`......fffw...p.....vfff`......fffg{..p......fff`......fff`{..p......fff`......fff.{..p.......ff`......ff`.{..p.......ff`......ff..{..p........f`......f`..{..p........f`......f...{..p.........f.....f`...{..p.........f.....f....{..p.........f.....f....{..p.........f.....f....{..p.........f.....f....{..p.........`......`...{..p........f`......f...{..p........f`......f`..{..p.......ff`......ff..{..p..{....ff`......ff`.{.........fff`......fff.{.p....ww.fff`......fff`ww........fff`......fff............ff`
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):2632912
      Entropy (8bit):6.7346639829894945
      Encrypted:false
      SSDEEP:
      MD5:3D1CA97C91174C8D607B2002E1DEE737
      SHA1:E615C304E32E3A1C24C59A0A16F8431AA516BB97
      SHA-256:5D3E331170ADACF4AA7B40A746EB681DF465A6AB232789636D76D8450034E92C
      SHA-512:CC0F919BC1196A5F0D13DB62EA58BA5319BA321C0F8827F8C14AD471D1EF6F69BC9335417D03325D4EF93004490360C67FCBA651126A5034AAD7C9D40676672C
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........0..IQl.IQl.IQl..9o.@Ql..9i..Ql.!h.YQl.!o.CQl.!i.eQl..9h.EQl.. o.SQl.. h..Pl..9m.[Ql.n...JQl.IQm.Ql.. i.CQl.. l.HQl.. ..HQl.IQ..HQl.. n.HQl.RichIQl.........PE..d...,.L_.........." .........r.......i........................................(.....l.)...`.........................................@.!.......!......P'.......%.Th....(......@(..P......T...............................0............... ............................text...l........................... ..`.rdata..............................@..@.data.........".......!.............@....pdata..Th....%..j...t%.............@..@_RDATA.......@'.......&.............@..@.rsrc........P'.......&.............@..@.reloc...P...@(..R....'.............@..B........................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):5567712
      Entropy (8bit):5.951046556865313
      Encrypted:false
      SSDEEP:
      MD5:FC9A4B0D1A62B9349C3639B315B9643A
      SHA1:40D2AB8DB57BB9107F222FA6315DF3E7AB8EBAF4
      SHA-256:F5629BD88FC39AA9FD6E822941AF09157582E4399FE3677CD7A7AFD540A95E14
      SHA-512:274C0CCF9265115FE64E4F9B1F714618FA2BF3D3B3F5FF1170B8AEA90AF73AFD95E1E8F974D752A1EA110FE84E49F3E3E1E42C1A7A00204EFE00292B1A0CAF7D
      Malicious:false
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7........................................................................................................................................PE..d...WQ8g..........".......D.........P.B.......@...............................V.....?.U...`..........@............... ...............@M.y.....L..L....T.......P.......T..R...pM..y...........................`M.(.....................L...... M.J....................text.....D.......D................. ..`.data...@?....D..@....D.............@....bss.........0K..........................idata...L....L..N...$K.............@....didata.J.... M......rK.............@....edata..y....@M.......K.............@..@.tls.........PM..........................rdata..m....`M.......K.............@..@.reloc...y...pM..z....K.............@..B.pdata........P.......O.............@..@.rsrc.........T.......R.............@..@..............V.......T.............@..@
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):663
      Entropy (8bit):4.913626714614655
      Encrypted:false
      SSDEEP:
      MD5:51195A005A1CF9C3B7F88B46C21959EF
      SHA1:104E625406284C11693CD062ED97E2E479DFE455
      SHA-256:7D66BCC19F082FFE769E31A1505D74695DC52C1979F7E5FBFE8D989E3ABDA6DE
      SHA-512:E4DFE0403963DF9D617C0812F01F0E77D330627A30B207FD6CC54C8E39591F8260C9F2A26682AE9164C40DF42B0CFE85E963692E7C2B6C4C0B0F60E7C5BFF1C3
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sets a file to..' be only on the source if its identical to the destination file...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "When files are identical change it to say its only on the source".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' Called when a file is compared and found to be identical..' See the Technical Reference->Scripting->Constants page for Diff values..'..Sub RunFileCompareSame(Filename, ByRef Diff).. ' Lets say its only in the source.. Diff = CDIFF_SRCONLY..End Sub..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):3202792
      Entropy (8bit):6.388733560985581
      Encrypted:false
      SSDEEP:
      MD5:E47E7C49D587E0FA9BFAE76474B1D09F
      SHA1:A66760BAA17A006D39A998825852C2250B0B4993
      SHA-256:0266FCB31A79B35BB4978D4FEA54075AC895041D9ABA8F6F02DF25C1F657F490
      SHA-512:E45B4CCCFFEF80F76931D885542A90F68D5B5AE0D32038EA75361CD5324DC6409B1002DC4AC7EE0177F71606FE56C72487A95AC98C40FE59B43BB75B4E2BD743
      Malicious:false
      Antivirus:
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......c.................L,..<......hf,......p,...@..........................p1.......1...@......@....................-.......-..9.......\............0..R...........................................................-.......-......................text.... ,......",................. ..`.itext...(...@,..*...&,............. ..`.data...X....p,......P,.............@....bss.....y....-..........................idata...9....-..:....,.............@....didata.......-.......-.............@....edata........-......*-.............@..@.tls....L.....-..........................rdata..]............,-.............@..@.rsrc....\.......^....-.............@..@..............1.......0.............@..@........................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):241674
      Entropy (8bit):6.615609259860676
      Encrypted:false
      SSDEEP:
      MD5:78DD7574D212FF72E2D7D5BEA5A8AEEA
      SHA1:45A5B1E24E0EFD232978D501024767151E7EF678
      SHA-256:3DD20F8A9300141E734D561524ACF3D01B127D5E610C77F26F1777DADE081DFC
      SHA-512:8E64FD5016BFA023C90A5E49EF46FE5F29EEF0EB8B3CAD367816E29FEC1D59B2AA42BF1A4C5267E9891FCB91E7AB9663AF140927D6B1B318E8285E7E8FCAF7B7
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g.A#...#...#.......!...*.m.....*.|.:...*.j......y.."....y..0...#...b...*.`.p...=.}."...*.x."...Rich#...........PE..L......R..................... ....................@.......................................@.................................t;...........#......................(!..................................H6..@...............`............................text............................... ..`.rdata..............................@..@.data....5...`... ...:..............@....rsrc....#.......$...Z..............@..@.reloc...0.......2...~..............@..B........................................................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2701
      Entropy (8bit):5.004087896886537
      Encrypted:false
      SSDEEP:
      MD5:437C5783743CD0425E0BD493FB19D3CB
      SHA1:DE818450C771CA045124CCFE51536BC1767D0640
      SHA-256:F9D10B28D68D67D1CE6E1A8070700E50F41438A2B7E554C559D3B84DC5E47422
      SHA-512:EBD4116681684950AC4DDA9ADFD6497411C9E81406041E4FE337D92B57D6E8048D41D1664F7C34822C4EA88743468AFBF66F9DC47AC3767360D15E767AA6F1B7
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds an extra..' column in the main window that shows the number of files that..' were copied, deleted, etc. in the last profile run...'..' You need to install this script and enable it on the Main Interface..' tab. You also need to enable for each profile that you want the column..' to be used with (modify the profile and go to the Scripts tab)...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is both a runtime script and a main interface script..'..Function Description(ByRef ScriptType).. Description = "Show number of files copied, deleted, etc.".. ScriptType = SCRIPTTYPE_MAIN + SCRIPTTYPE_RUN..End Function....'..' Called when the profile has finished running. We get the..' variables and create a description, which we save as a..' property of the profile. This description is then used in..' the main interface...'..Sub RunProfileResult(ProfileResult, ErrMsg).. SBVariables.SetProperty("XInfo", .. SBVa
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):3071
      Entropy (8bit):5.0792844172331195
      Encrypted:false
      SSDEEP:
      MD5:F1E87BD2012A8B50B64D804887E25601
      SHA1:013BFE5594BEC342A2956397AA2737F50DDE2259
      SHA-256:885B80E4F0467794129E517F682D8D4D325A3DFA31689B3B99C1786769B86DE8
      SHA-512:9DBB299004D423800347B86658973618095AFF031CCC9015AE5B87F600281C3EED6A68C0A4A4C584EA8129EB3683997D44A1645BA4FF58596F5B337FAE5F3520
      Malicious:false
      Reputation:unknown
      Preview://..// Example script for 2BrightSparks SyncBackPro that stops a profile..// from running if a specific file does NOT exist. The file can then..// be optionally deleted automatically if it does exist (to stop the..// profile being run again until the file is re-created)...//..// This can be useful when files are being copied to a folder and..// you do not want to copy them until they have all been copied...// This assume you are using a special "marker" file that will..// always be the last file to be copied/created...//..// SBLang=Pascal..//..// http://www.2BrightSparks.com/..//....//..// This is a configuration script and runtime script..//..function Description(var ScriptType);..begin.. Result:='The profile will not run unless a specific file exists';.. ScriptType:=SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG;..end;....function RunDisabledCheck(NoLog);..var.. markerfilename, deletemarker, FSO;..begin.. NoLog:=TRUE;.. Result:='';.... markerfilename:=SBVariables.GetProperty('MarkerFilenam
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):4401
      Entropy (8bit):5.258468123973744
      Encrypted:false
      SSDEEP:
      MD5:119576C7480B7E1DA14279671C17504B
      SHA1:3907EDD066FB93498356389678D9B727C180D6B9
      SHA-256:45926083A2856A8D779A8D703077CD6FC0FE6CE6101AE0CB173A8B87DF44DF87
      SHA-512:4BA76E6B9AE4FCC564B3C4EDCA1079A3737A85FC74859B1448E45A10DD6EC4EF7ACCF993DEB592449AF89DFBAF7E6688E7F86D07F71C30C91193450802617245
      Malicious:false
      Reputation:unknown
      Preview:'..' EMail services used by SyncBack (2BrightSparks Pte. Ltd.)..'..' Do not modify this file unless you know what you are doing...'..' IMPORTANT: THIS FILE IS REPLACED WHEN UPDATING OR UPGRADING SYNCBACK..'..' The section names are the names of the email service and are used by the user to make their selection...'..' [Unique name of email service]..' RType=P for POP3, I for IMAP4, W for Exchange Web Service (Exchange Server 2007 or newer), D for Exchange Web DAV (Exchange Server 2000/2003), O for Microsoft Outlook Personal, G for GMail OAUTH. Default is POP3...' RHostname=pop3/imap4/exchange hostname..' RPort=pop3/imap4 port. Ignored if Exchange. Usually port 993 if direct encryption or 143 for STLS encrpytion...' RLogin=0 if do not need to login, 1 if must login to pop3/imap4/exchange server, 2 for OAUTH2. Default is 0...' REncrypt=D for direct SSL/TLS, S for STLS (which is POP3 only), otherwise no encryption. Default is no encryption...' RUsername=default login username for POP3/IMAP
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1821
      Entropy (8bit):4.987807068009173
      Encrypted:false
      SSDEEP:
      MD5:202696329681E65ECD926BE8155043AF
      SHA1:70BC363C01AE0F0D4407E5342D8A475BBBF2E86E
      SHA-256:551E6BAB279E347800AD4188927415421446082D7E72EF4BE48C733723E1911E
      SHA-512:FC62B05A4BC19B300E3147397B4C5ACB0192BFF39F6795D0568EFB9B40BA818F534FE00C2BB19BCFF66AF52DFC05E9938C5CAF7206480244F6EC81FFC89C12DD
      Malicious:false
      Reputation:unknown
      Preview:' DeSpace.VBS written by Dave Wilkins 2007....' used to exchange spaces for underscores in file & folder names..' in a path starting from (but not including) the folder shown.....' Typically this would be used in Programs -Before to prepare a file..' set For backup to an FTP server (or similar) which did not support..' filesnames containing spaces. A complementary script (ReSpace.VBS)..' is supplied to revert files back to their old filenames if req'd. ..' This complementary script would be placed in Programs - After....' Note that any pre-existing underscores in filenames will be turned..' into spaces by ReSpace.VBS, if used, ie....' original: My File_Name.ext..' DeSpaced: My_File_Name.ext..' ReSpaced: My File Name.ext....RootFolder = "X:\ROOT_FOLDER"....'OR....' Set objArgs = WScript.Arguments..' RootFolder = objArgs.Item(0) ..' note that any path argument with spaces must be wrapped in " "....RootFolder = RTB(RootFolder) ' remove trailing backslash (if any)....Set FSO = CreateObject
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 192 messages, Project-Id-Version: SyncBackSE V4 'Afar'
      Category:dropped
      Size (bytes):6636
      Entropy (8bit):4.288217502936746
      Encrypted:false
      SSDEEP:
      MD5:D563FFE4977FEA6A82C472EB84734B9E
      SHA1:F89758D23B43DD7D44BE1C6D3EE206BA8A07A8CE
      SHA-256:C86AD74012521F05B448C821285A7E4A63805676BA27F270CBD651F6A7EAD2C1
      SHA-512:DB2712B74F4239E879FE2474F250EBF1929687E1F38F2CB5642DF50FAB22BC436DB83F2A0557E306634A0C5A15337C8CBF8A612E01DA8D845654B01B9E6843CB
      Malicious:false
      Reputation:unknown
      Preview:................................ .......!.......$.......'.......*.......-.......0.......3.......6.......9.......<.......?.......B.......E.......H.......K.......N.......Q.......T.......W.......Z.......].......`.......c.......f.......i.......l.......o.......r.......u.......x.......{.......~............................................................................................................................................................................................................................................................................................................................................................................................................... .......#.......&.......).......,......./.......2.......5.......8.......;.......>.......A.......D.......G.......J.......M.......P.......S.......V.......Y.......\......._.......b.......e.......h.......k.......n.......q.......t.......w.......z.......}...............................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):978
      Entropy (8bit):4.953606587939239
      Encrypted:false
      SSDEEP:
      MD5:BF53CF6237204DB7C061AB7C3FB6795A
      SHA1:A7B46ED2DB74104EAD97361E7F94072B73854809
      SHA-256:FA3240B3636EB0B68C3500F5E4292A0CB6351F4D57D74DE8D231F7F042CC34FE
      SHA-512:417000BE87A0366C8C1EDD46D133472BCA2DD4F3F9166BDC542A1AC1F1516C5985B4093A620F2C360EA1FC32F90B8EEEE286A4FB298B3A3FF0C82CA4D7D3FEC0
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that uses NTFS..' encryption on the copy of a file...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "NTFS encrypts copies of a file".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' This function encrypts the copy of a file...'..' Note this function is not called if it is a simulation...'..Sub RunAfterCopyFile(ToLeft, Filename, Failed).. ' If the copy failed then dont even try.. If Failed then.. SBRunning.DebugOut(Filename, "Failed", 1).. Exit Sub.. End If.... ' Get the full filename.. If ToLeft then.. FullName = SBRunning.LeftFolder & Filename.. Else.. FullName = SBRunning.RightFolder & Filename.. End If.... ' Encrypt it.. ErrorMsg = SBSystem.EncryptFile(FullName).. if ErrorMsg <> "" then.. SBRunning.NotCriticalError(Filename, "Could not encrypt: " & ErrorMsg).. End If..End Sub..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1662
      Entropy (8bit):4.903214475883961
      Encrypted:false
      SSDEEP:
      MD5:3524681BA8AC88CCDE6519D52009A88C
      SHA1:B0936AB174E2E1964834E87E76DE53829539D909
      SHA-256:1BDB5E996EE77C577199B3564BBDD6DC66E091A148F157A5D5508CFCC320845E
      SHA-512:682F3DBF62322B941C5F239595E3CA0CDB47BC387C6ACC6D543E9A81F4EEB7B18B30000CEFE0A6C6D56B0BC01D8892879DE607E1583E3E0A7483143F17D76C19
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro that stops a profile..' from being run more than once per day. If its a simulated run,..' or a restore, then it can be run regardless...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Run at most once per day".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' We use the LastRunDT value from the profiles settings. It contains..' the last run date and time of the profile. If it has already been..' run today then we stop the profile running, and no log is created...'..Function RunDisabledCheck(NoLog).. ' Get the current date now just in case it changes while.. ' the string is being built.. RightNow = Date.... ' Create a string that has the current date in the.. ' format of YYYYMMDD.. NowDate = CStr(Year(RightNow)).... If Month(RightNow) < 10 Then.. NowDate = NowDate & "0" & CStr(Month(RightNow)).. Else.. NowDate = NowDat
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):196106
      Entropy (8bit):6.531734984792669
      Encrypted:false
      SSDEEP:
      MD5:6D9FC3B6C94A01160B7E33FB422E9932
      SHA1:2D310529AA950F82F0CA66B1DD0F9D1D9CFC8580
      SHA-256:172E8F1B2E5B2AFD76E754396927A9665A56D749192A64587FA31F4998729B1E
      SHA-512:E4E5E408375B178E6A725073113E58BC05410F5A514935D797A1E5F769945A090476FDD93296DBA5349C5874CA4A4ACE2CE5F7D62C0C36262BB842A2AE57096B
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............z...z...z..a5r..z....`..z....q..z....g.]z.......z.......z...z...{....m..z...(p..z....u..z..Rich.z..................PE..L......R.................2..........Y........P....@..........................P............@.................................$............"................... ..`....T..................................@............P..`............................text....0.......2.................. ..`.rdata..0c...P...d...6..............@..@.data....&..........................@....rsrc....".......$..................@..@.reloc...,... ......................@..B................................................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2587
      Entropy (8bit):4.965098363605944
      Encrypted:false
      SSDEEP:
      MD5:CD928EAAE000DCD8B943ABA8DEF0432F
      SHA1:5D971D376B64FDD25E3DC31B68EA1BC9251ED4FE
      SHA-256:B1BA96C511659F6196B7D7F68801EB8EBE06171CE80572120FF30BDBC620AE69
      SHA-512:DF4EF2B370632F9691A61B389A48750AD5BC0BDFF4189D1FA34F84759AD3A6F499C2434F9D8F9C82E53E741507F8CF776767E00A4BE157BA30A0F3BE6F2B38C9
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that waits for a program to..' finish before running the profile. If its a simulated run, or a restore,..' then it can be run regardless...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The name of the process you want to have finished running..const ProcessName = "Notepad.exe"....' The number of seconds to wait before re-checking if it is still running..const RetrySecs = 5....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Wait for " & ProcessName & " to finish before starting profile".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' Remind user to edit this script before use..'..Function Install(Interactive).. If Interactive Then..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):621
      Entropy (8bit):5.067485771634757
      Encrypted:false
      SSDEEP:
      MD5:874D692EA3D520BC923C1B5EB2A48EEE
      SHA1:C37AA1C54B54894ACEBAC125DEC98C29BEF98376
      SHA-256:592125F7F0B51BB3B7E1C452A345A79A32887251EA57484E6B424656D85C36DD
      SHA-512:433310634CF90A18698628BDC2F157BC48AED828E47F62E552051BFFF9AAD1987809C53D23EADF57A8E98DFE9ACB4A61B39E0D5C922D5FBE11B84EEFE9CA91DE
      Malicious:false
      Reputation:unknown
      Preview:..=== DO NOT MOVE OR DELETE ANY FILES IN THIS FOLDER ===....If you want to move the SyncBack installation:.... 1. Export all your profiles (https://help.2brightsparks.com/support/solutions/articles/43000335681).. .. 2. Uninstall SyncBack. During the uninstall process, when prompted with "Would you like to keep your profiles and settings?" click Yes..... 3. Install SyncBack, and when asked which folder to install it into, choose your folder.......If you want to uninstall SyncBack then uninstall it just like any other Windows program:.... https://help.2brightsparks.com/support/solutions/articles/43000335665....
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (392), with CRLF line terminators
      Category:dropped
      Size (bytes):43640
      Entropy (8bit):5.364926106393464
      Encrypted:false
      SSDEEP:
      MD5:FAD34EF99C964FD63EC54CB788EB3466
      SHA1:E5D77F57E8F815A39C11B68909668E5514837229
      SHA-256:6B809287077C7F0AA8AB70A8D1E045EEA17692971ED2EDBBD2D6BD28EA8379B7
      SHA-512:06C2F54F7CE36B25E91F1C13401E76888DC52960954F6E4B582E183B1D523CE28DD0024CEAB86952A74240ABA2344E8A69508AA42BF8CC01B102CE0225DD0767
      Malicious:false
      Reputation:unknown
      Preview:.<?xml version="1.0" encoding="utf-8"?>..<assembly xsi:schemaLocation="urn:schemas-microsoft-com:asm.v1 assembly.adaptive.xsd" manifestVersion="1.0" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.. <assemblyIdentity name="SyncBackPro.exe" version="11.0.0.0" type="win32"/>.. <description>SyncBackPro File Backup Program</description>.... <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">.. <security>.. <requestedPrivileges>.. <requestedExecutionLevel level="highestAvailable" uiAccess="false"/>.. </requestedPrivileges>.. </security>.. </trustInfo>.... <dependency>.. <dependentAssembly>.. <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" langua
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1457
      Entropy (8bit):4.9553542645259725
      Encrypted:false
      SSDEEP:
      MD5:2177634BDCCD4CB42B17C944644E27EB
      SHA1:78855680CF657D0A277E8DDBA80846F8F048F857
      SHA-256:D6874F5B025AC4A54D461BAC1A4024081FEA39C9FC36BD7B7777C9F436E17D1B
      SHA-512:FD41139881675863F19B08D039D56208BAB841511557AFA1EA838C9BD7FFD606735E8689AC6EA86AB00C5FC8D37E73FAC2C3DE8EB5720877640A01C848FCAC1F
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that shows how..' translation works...'..' How to use this:..'..' - Copy the example.mo file to the \locale\FR\LC_MESSAGES\ ..' folder in the SyncBackPro installation folder..'..' - Install the script and enable it as a main interface..' script. Restart SyncBackPro...'..' - Change the language (via the Preferences main menu) to..' French..'..' - You'll see the column that was title "String 1" is now..' title "Translated String 1"..'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a main interface script..'..Function Description(ByRef ScriptType).. Description = "Translation example".. ScriptType = SCRIPTTYPE_MAIN..End Function....'..' Load our translations. Why do we not do this in MainStarted() ?..' Because the column titles are set before MainStarted is called...'..' Just one column..'..Function MainColumnsCount.. SBSystem.AddTranslationDomain("example").. MainColumnsCount = 1..End Function....'..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:data
      Category:dropped
      Size (bytes):122437
      Entropy (8bit):7.942299892588374
      Encrypted:false
      SSDEEP:
      MD5:E3C6D7A20915249AEE97C8D4C15618A6
      SHA1:2A5DD8E78D06F485FBD259003AA3B6E32B3BCF01
      SHA-256:50856750DE95F6A2940F6B399CE0252F1F44872CE095750AD62C3843A4FB2FDB
      SHA-512:5DC241078B9D6F83A60636755D14952259AB5BDE1BE39A2A4BABDCD6F1CE4815207C506FA0E27E472B7BD433EB1C3E1F1D43740987D3519C061F8B8B95F77919
      Malicious:false
      Reputation:unknown
      Preview:VCL_STYLE 2.0x.....U}.....!\..J.$$$!..BB.$o...p9`.D#.[........E.t....tc9.E..R/TZ*..*Z....s<;.9.1m...s....~...03..5.....o.g.Y.f....53.......0p......6..<...7u.,....W..d.L.8e.R...F......,..l..f.w...3.r......}......on......+M.S.N7.]n./.1.i........6.)....?...[...wn...+..W..c..[.n3...|..f!W..=r``.........................................................................................................................................................................q.a.....\o.S..2..3.`...U...u.!..*.l....U......C.K..a..e..<....W4....p.-G.W.u.v>...Y.R.D....P.....=o2.m.k(R.....q.....h......<.....>.7.^.]\.7.p.Au...^.TC.w....k.u..x.'......1h8.p.a.a.!OY.t....q....rW..2...t...U.<n..a.A>0..p.A.}O."?p..\c..e^.....\k.gP...C.s.(.v.KV}....<Z....\.6_..E.[.\.`.a..0C|..Q...../7.}.Y...}......4m.,......C..B..%...n...1....a.[.....wi_.z...r.2C..aCV....].P.F..Q...."........X.1...a.VVh7.........3..W.|......ru..7.6]..w.U.\F..4m.A........K...m.h8...'..$.7O...o.u?.O7pi
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1200
      Entropy (8bit):4.880766712444754
      Encrypted:false
      SSDEEP:
      MD5:9DC3FC8E151470ABC758AD684268C9C9
      SHA1:AD9A14AC03F1186CE67C72B67C4CD65C66834F33
      SHA-256:1CC0472C286A792E1A16095D1C2E9CA2C78C7AD6C188B9F241784164F0CB4567
      SHA-512:ED2D9925D79D3FED3BE6FF3723C955CD7EA6723D172CA1E4B983A797076C563105DC6A2158EA02374BBDF38F0B99F2D3242B6F5037F1ADD49FCF808179FA9A3E
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that creates a..' Restore Point in Windows. If its a simulated run, or a restore,..' no restore point is created...'..' In Windows you must have Administrator privileges to create..' restore points...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Create a Restore Point in Windows when the profile run".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' We create the restore point before files are copied, deleted, etc...' If it fails then we record a warning in the log...'..Sub RunAfterConfig.. ' Restore or simulation? .. If SBRunning.Restore or SBRunning.Simulated then.. Exit Sub.. End If.... ' Create restore point.. if not SBSystem.UpdateFileStatus("Creating restore point...") then.. Set obj = GetObject("winmgmts:{impersonationLevel=impersonate}!root/default:SystemRestore").. ErrCode = obj.CreateRestorePoint("Rest
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):193654768
      Entropy (8bit):5.752967870973102
      Encrypted:false
      SSDEEP:
      MD5:1157F60ACE930CEB10FCA5BE9025452A
      SHA1:C3248DB908AFA8F98F2580DC97051E30162434ED
      SHA-256:94A2A5F7A3809AABBB1F83A24C1A2108662BA6FF40EC938A58DD51958E6D9F76
      SHA-512:1D2607049385EF5FCF559E5E587FC9B96BED44CA33564B613259B72A0CCA4C5BF9FC3C129A9B72594D2194BB1D5C92E5853A192A75CDB784A801BB03C6C37ACC
      Malicious:false
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7........................................................................................................................................PE..d...{Q8g.........."..........................@.....................................9.....`..........@............... ...............PH.s.....F.x............a.H........R....H..Y...........................pH.(...................p.F.@(....G......................text............................... ..`.data.....I.. ....I.................@....bss..........C..........................idata..x.....F.......B.............@....didata.......G.......C.............@....edata..s....PH......|D.............@..@.tls....`....`H..........................rdata..m....pH......~D.............@..@.reloc...Y....H..Z....D.............@..B.pdata..H.....a.......].............@..@.rsrc................}.............@..@.debug....w.......w.................@..@
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):5723
      Entropy (8bit):5.072712325293726
      Encrypted:false
      SSDEEP:
      MD5:4AD069515B3EDB085D56D4764043399D
      SHA1:59D57FB3E394962745A77B041F8C64A4CD62A998
      SHA-256:AA5C4D612BBD649C529DFB31619480E8B6289030DBCBA19A4697ADFF08646F46
      SHA-512:C2E525C869A626EF32397C0906CCF5671A5B8FE61CEFBB88A3CA644175CFC708BB2060DA6CD2B4047B2B00231F4F86DEF9E19377F12E2456C4F04C23847C2027
      Malicious:false
      Reputation:unknown
      Preview:'..' Scans an SBSE backup destination for Versions (contents of $SBV$ folders) and exports..' them to [elsewhere]; file/folder deletion of original $SBV$ folders is included..'..' Why are $SBV$ folders not deleted immediately after copy of all contents?..' Because the recursion logic tries (on next iteration) to check if there are..' any subfolders OF the $SBV$, which is kinda hard to do if you've just deleted it.....'..' Thus, the storage of $SBV$ deletion-candidates in array for later attack.....'..' Note that this routine will not handle UNC paths...' It will be necessary to map a network drive to the resource, using something like....' If Not fso.DriveExists("X:") Then..' Set TempNet = WScript.CreateObject("WScript.Network")..' TempNet.MapNetworkDrive "X:", "\\server\path", False, "username", "password"..' End If....' False refers to make-permanent, i.e don't (I assume if you wanted a permanent..' mapped drive, it would be in place already :->..' False is the default, so If UN
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2887
      Entropy (8bit):5.094026435133874
      Encrypted:false
      SSDEEP:
      MD5:B545FD4FF8BCD6BC074ADF8AC6CFBDC1
      SHA1:9FFAC8A915B21D782DCA3E555E312843DCC57695
      SHA-256:52F689C2A84955879055C694230F5F09BC1362365C5478502DD18EA5F55D91DB
      SHA-512:740791CBFBC0E7CA5B77F2A1AD3FB205A0B6507A3B9899A421F67E85B292636DE53981CCF0589C25637BD219D90A9A9D0000E5E77BBF6756847299A2AE0A7E48
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sends an SMS..' if a profile fails (if the run is simulated then it does not)...'..' IMPORTANT, READ THE FOLLOWING:..'..' - You must first create an account at http://www.clickatell.com/..' - You will receive an API ID. You must set SMSAppID below to that ID...' - Set the connection details below..'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The connection details for Clickatell to send an SMS..const SMSUsername = "xxx"..const SMSPassword = "xxx"..const SMSMobileNum = "xxx" ' Recommended you include the country code..const SMSAppID = "xxx" ' See the comments above on how to get this....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Des
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):3125
      Entropy (8bit):4.952978614442731
      Encrypted:false
      SSDEEP:
      MD5:FFA526C0E7E1921FF1781511EA06E6D0
      SHA1:B05FB38BC0D047D4FC1B4971D49D53C74E115D3D
      SHA-256:96D81A9BBE73A0245265073F644708AAC6CBB1B515313C78AEAC4A21A24A3CE7
      SHA-512:A6BFDA1856AB15E581A9C5E9DAD1C52C824650E08CCAA004307C41F26A915D57F818A2E7FCAC578363D6017CE296B77BB6D054EECEE3DF9BE0A23F0349BA3CF2
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds an extra..' column in the main window that shows if a profile is using..' versioning or not...'..' This script is an example of how to use caching to avoid..' performance problems in the main user interface. It also shows..' how to use the new PollingRefresh and RefreshDisplayEx..' functions...'..' You need to install this script and enable it on the Main Interface..' tab...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....Dim gCache....'..' This is a main interface script..'..Function Description(ByRef ScriptType).. Description = "Show versioning information".. ScriptType = SCRIPTTYPE_MAIN..End Function....'..' One column only showing history count...'..Function MainColumnsCount.. MainColumnsCount = 1..End Function....'..' Column title...'..Function MainColumnTitle(Col, ByRef Width).. MainColumnTitle = "Versioning"..End Function....'..' Column text...'..Function MainColumnText(Col, IsGroup, ProfileName).. Co
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):311
      Entropy (8bit):4.935185319843183
      Encrypted:false
      SSDEEP:
      MD5:063B9492499E7F5E62E4CC9A7CC2A1C2
      SHA1:5A2CDEB97BD9590FE07C8F7E68384336ACF4488D
      SHA-256:4FFF6AA11E79FCB897C749B9AB05142E00312C7D41FB2D397CC353A0FCD25CC0
      SHA-512:409A2F1C98A0354A434BF1B56F9446B0AD3E0D701B976B621D8AA9731A5D8307161FB72E28BA4706DE67B4DD3296ED130CFCD5538B67BB5D12E36178CEA5F6B0
      Malicious:false
      Reputation:unknown
      Preview:param([string]$drive, [string]$password)....$SecureString = ConvertTo-SecureString $password -AsPlainText -Force..$UnlockResult = Unlock-BitLocker -MountPoint $drive -Password $SecureString..if ($UnlockResult.ReturnValue -ne 0)..{.. # Retry.. Unlock-BitLocker -MountPoint $drive -Password $SecureString ..}..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2870
      Entropy (8bit):5.170283962712926
      Encrypted:false
      SSDEEP:
      MD5:EBDECFE41DB73DFAA2FBF9CD37BD8FA2
      SHA1:28ED28FD17445D66C7BB744A961C65EA91FB43C8
      SHA-256:890D86AF76F6825CC461340A6663B8F857FE56EA170B4420A4ABE8AB57169939
      SHA-512:8228CF78D9A872990002B39A98775EDE20E2ACAD5C9AFB73DA38487965D380F0159F21C5DCDC09507C0A63972D70BC30E9898F75CE59367EB1D0D42DD454DDA0
      Malicious:false
      Reputation:unknown
      Preview://..// Example script for 2BrightSparks SyncBackPro that stops a profile..// from running if a specific file is detected as being corrupt...//..// This can be useful to guard against Ransomware corrupting your..// backups...//..// SBLang=Pascal..//..// http://www.2BrightSparks.com/..//....//..// This is a configuration script and runtime script..//..function Description(var ScriptType);..begin.. Result:='Check if a file is corrupt before running profile';.. ScriptType:=SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG;..end;....function RunDisabledCheck(NoLog);..var.. md5expected, md5actual, md5filename;..begin.. NoLog:=FALSE;.. Result:='';.... md5filename:=SBVariables.GetProperty('CorruptFilename', '', FALSE);.. md5expected:=SBVariables.GetProperty('CorruptMD5Hash', '', FALSE);.... if (md5filename <> '') and (md5expected <> '') then begin.. md5actual:=SBSystem.MD5(md5filename);.. if (md5actual <> md5expected) then.. Result:='File is corrupt: ' + md5filename;.. end;..end;....//../
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):6324
      Entropy (8bit):5.106980490813565
      Encrypted:false
      SSDEEP:
      MD5:578189387B30134D605EC3C0D6E83943
      SHA1:02626F42F329811292A78E4070EB5E8EAE5D7384
      SHA-256:CA6D6E5284BCE595560EE281F28AD4ADF5A222492EDB5A9BB542A0953D420ADF
      SHA-512:A05D6CC4848134A96534933837D086D79444183E2008620327904A5FC9055C485C4E45FD3CAF5107602D17515064174022F48D7299EEF5088C743BD3850B110C
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that lets you create your own..' incrementing variable. You can also configure if it should be a full backup..' once it goes over a certain number...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'..'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....' This is set to TRUE if it should be a full backup because the variables..' value went over MaxVarValue and FullBackupWhenOver is TRUE ..Dim DidReset....'..' This is a runtime script and a configuration script..'..' It must be a configuration script otherwise the variable will not be used..' when you modify the script..'..Function Description(ByRef ScriptType).. Description = "Custom incrementing variable".. .. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' Remind us
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):2293248
      Entropy (8bit):6.750919858219048
      Encrypted:false
      SSDEEP:
      MD5:E942A22F2FA3A0156F1A0447681761E1
      SHA1:3C9D8851721D2F1BC13A8DCB74549FA282A5A360
      SHA-256:E2908DEC495CC6E621358EB7C5D41403F25EB4BDBF3802866EADEA378422D412
      SHA-512:69C685675485103FC5C64C50EDCF1CA3A276F8B684B0D6AEFD6206D956B901EAE86B7AA66D2EC1125C57DAA6A6C0B124ACF8BA70752BF492EBBA5F2D9B3E9FB1
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........._..1..1..1...L..1..0.j.1...J..1..1...1...\...1...K..1...M..1...I..1.Rich.1.................PE..d...w..].........." .........L......0........................................p#.......#...............................................................#.0.....!..E............#..B...................................................................................text............................... ..`.rdata..(...........................@..@.data................t..............@....pdata...E....!..F...\!.............@..@.rsrc...0.....#.......".............@..@.reloc...U....#..V....".............@..B........................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):3811
      Entropy (8bit):4.956991985590269
      Encrypted:false
      SSDEEP:
      MD5:220667A9E826C3FEFA62BAF0B0F42D92
      SHA1:30992C5314DE296A632F1D2DA9292FAB90305A94
      SHA-256:F3687BD18BBC58B1DAB76FDF5A72E9052DA883598587EFCE68DCA60F73BAA109
      SHA-512:E64B9F977F509D4957884DEAD0B0B8D279006E076FD4A23534C46E081D0BB38129DC5AD399E9564AC7AF7825F8837910A0E4C1C4E728E58A8BB44758893DB68D
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that lets you create your own..' incrementing variable. You can also configure if it should be a full backup..' once it goes over a certain number...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The name of the variable you want. It should be unique...const MyVarName = "CustomIncVar"....' Set MinVarValue to what the variables minimum value should be..const MinVarValue = 1....' Set MaxVarValue to what the maximum variables value should be..const MaxVarValue = 12....' Should it be a full backup when it goes over the maximum value?..const FullBackupWhenOver = TRUE....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....' This is set to TRUE if it should be a full backup because the variables..' value went over MaxVarValue and FullBacku
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
      Category:dropped
      Size (bytes):41016
      Entropy (8bit):5.100051476736584
      Encrypted:false
      SSDEEP:
      MD5:C2B501F5E7E1C0088E4D114A3C99C472
      SHA1:DFAA26AE92398A7A46B55CC23C1075D9380407DA
      SHA-256:CC5342DC199EE143612A9EFE6AE79CC236E64A2AA9F7DE611CC63CD6DE60AC36
      SHA-512:0A110B33BDD8665366FE774F1BBD5F20A3DD2A563185D1B41094F8B9C9C3F74CB2233926497AC6A60B1478D4342258DF7E4B84EECB0331DB8156697A4454A536
      Malicious:false
      Reputation:unknown
      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch0\stshfhich0\stshfbi0\deflang18441\deflangfe18441\themelang18441\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f43\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Segoe UI;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\f
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):386560
      Entropy (8bit):6.063220215284271
      Encrypted:false
      SSDEEP:
      MD5:DA5F38FAE439B909DF848D11F68AF629
      SHA1:08CD02051F1FC3EDBE3672706EE1051F6D626124
      SHA-256:2250EDF8968F04EEFC1B10502A7A6F5A70461127E892C9F8CDB460D16065B01B
      SHA-512:9373685E1F01B85F08C77791BEFB30B3305BBFD5710214594AF23260BC1C9C8E097EB9F575E7013364E9FC036217DAE2CA455366BB4D11EF245A6B01AAB2991A
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2...2...2...Dq..0...Dq..5...2.......Dq......Dq..3...Dq..3...Dq..3...Rich2...........PE..d...w..].........." ................p........................................ ......................................................0....)......P.......0........+...................................................................................................text............................... ..`.rdata..............................@..@.data...P...........................@....pdata...+.......,..................@..@.rsrc...0...........................@..@.reloc..J...........................@..B........................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1860
      Entropy (8bit):4.878513891847196
      Encrypted:false
      SSDEEP:
      MD5:88DA258BC093874EF4AA7D2D6A23EF2C
      SHA1:0EB8860F47B103B81C1D09E4A14C8CA22ABF95EF
      SHA-256:C54F02A872B629F2A1F875C577E1A1AA78A0D949588A4508466AC65241C4FEBC
      SHA-512:3203A7831649E0DE7E7582750E13B4E830AD66DFF5F30784ADBAF1CA94FEB59BADADB5A32EC1140AA75B43F7AF6E1F8B0D953AE9B11EF5A67D1E24670FAC1AA9
      Malicious:false
      Reputation:unknown
      Preview:'------------------------------------------------------..' Script to remove file or folder. File or folder is..' argument 1 when calling the script...'..' Created by Alex, based on code from timestamp.vbs as..' provided by Michael J. Leaver (www.2BrightSparks.com)..'..' Free for non-commercial use...'..' Run by calling "cscript removeSource.vbs <arg>"..' where <arg> is full path of the to-be-removed file or..' folder...' Files should be full filenames (path included)..' and without any wildcards...' Folders can either end with a "\" or not...'------------------------------------------------------......'------------------------------------------------------..'Main code..'------------------------------------------------------....Set objArgs = WScript.Arguments..Set fso = CreateObject("Scripting.FileSystemObject")....If (objArgs.Count < 1) then..WScript.Echo "No filename or dirname to remove was supplied."..Else..' Concatenate all the arguments to create on file/dirname..' This is to avoi
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):6791
      Entropy (8bit):5.151531078457423
      Encrypted:false
      SSDEEP:
      MD5:4CEC781684F1F35B2879C4D919360940
      SHA1:ACC428EA36D814130FB4CDB48A61A785D5FBF9E0
      SHA-256:4D5FB4E7BCE9B983E6C56DAC4A10D34A28A9D8C1EDBC3A08E51C9C91728C4386
      SHA-512:3FCA229232EDBCD4247109571EF7D7304A18ED9D0DCA58B947E8A17EB74AC4743EE6C793A6C9D9A166C324B4D138D89BC2836CAB6C452B27A486ABCDCBDB7D3B
      Malicious:false
      Reputation:unknown
      Preview://..// Example script for 2BrightSparks SyncBackPro that filters out..// files and folders. This is different from using filters in ..// SyncBack itself as these are applied to the scan results and ..// file and folder selectios and filters have been applied...//..// This can be useful if you want to only include certain..// sub-folders, for example. Because these custom filters are ..// applied to the final list of filenames (after any file and ..// folder selections and filters) it does not act like normal..// filters which are applied top-down...//..// For example, you have the following folders:..//..// \abc\..// \abc\xyz\..// \abc\123\..// \def\..// \def\456\xyz\..//..// In this exmaple, you only want to include files and sub-folders..// within folders named 'xyz'. With normal SyncBack filters you..// would need to have the filter *\ and *\xyz\*. That would include..// all folders (but not their files or sub-folders) because of the..// need to have *\ (because filters are applied
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):5052
      Entropy (8bit):5.173276383742728
      Encrypted:false
      SSDEEP:
      MD5:53BCCC0D004DC0C4818D1976953C7182
      SHA1:9DC3D22642A55D939BEA7349E17E8D3D2DB6AA4E
      SHA-256:7D849B53125D4B8249EB9431E6351DFF467BB9050D412DD56B17D05CF85D1292
      SHA-512:505B5CCC306CC315E27FBBA683B5E406FE2CF4860A9422E769AC37067B5FBBA3236EE95B4AF7A2549CC254FDEF899F27E494408DC6988831F07FE24BB6C751D8
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that stops a profile from..' running if too many files will be copied or moved. Does nothing if it..' is a restore...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a profile configuration and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Stops a profile from running if too many files will be copied or moved".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' Do nothing..'..Function Install(Interactive).. Install = ""..End Function....'..' Called before any copying etc. is done..'..Function RunPreCopyCheck.. ' Restoring?.. If SBRunning.Restore then.. RunPreCopyCheck = "".. Exit Function.. End If.... ' Too man
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
      Category:dropped
      Size (bytes):77892
      Entropy (8bit):4.949241785580957
      Encrypted:false
      SSDEEP:
      MD5:28948E2B2AE93F91C25A6C4843C30119
      SHA1:66CB3D1C66AA1FBB3532744EEAC7C428ED316C55
      SHA-256:4F244E4B7E37A92E20A8FBC2AA087E64D399D539A1306B540993B9322B51C386
      SHA-512:D3637A108CF017EEC695FF6ABFBCCD76793FF0C0EBD34ACF8DDBF45AF621A71339AC854F85D7EC0C394DC0F03386F84F29FA4B6B2F7CF1C0F9C621C1CCE06161
      Malicious:false
      Reputation:unknown
      Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch14\stshfloch0\stshfhich0\stshfbi0\deflang1033\deflangfe1041{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f14\froman\fcharset136\fprq2{\*\panose 02020300000000000000}PMingLiU{\*\falt \'a1\'50s2OcuAe};}{\f37\froman\fcharset136\fprq2{\*\panose 00000000000000000000}@PMingLiU;}{\f38\froman\fcharset238\fprq2 Times New Roman CE;}..{\f39\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f41\froman\fcharset161\fprq2 Times New Roman Greek;}{\f42\froman\fcharset162\fprq2 Times New Roman Tur;}{\f43\fbidi \froman\fcharset177\fprq2 Times New Roman (Hebrew);}..{\f44\fbidi \froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):3710208
      Entropy (8bit):6.6734492650323505
      Encrypted:false
      SSDEEP:
      MD5:C05FF13DC039E0579AC12FA2CDED108F
      SHA1:5AFA755289A72784E5C73BDA559ED4E29014AE9B
      SHA-256:7E90094AEE8D9411EC47E96D42125206DFBBA44A9615276145251F7EDDE11ED7
      SHA-512:583694DDF3DA08604867D1F1B0C6A1102B97EF288BD23E55A0F7CC88C4363EC9782A67E06E815689B8367473016612A499F1D3BF20F5633B8E8BD84D6E576044
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......2>D.v_*.v_*.v_*.-7).._*.-7/._*./..g_*./).|_*.//.Y_*.-7..x_*...).l_*.....o]*.-7+.c_*.v_+.P^*.../.c_*...*.w_*.....w_*.v_..w_*...(.w_*.Richv_*.................PE..d....}d_.........." .....:%.........\..........m............................. 9.....U.9...`.........................................../.....X./.......6.h.....5.......8.......8..i..h1,.T....................2,.(....1,.0............P%..............................text....8%......:%................. ..`.rdata.......P%......>%.............@..@.data...,....0/..h..../.............@....pdata........5.......4.............@..@_RDATA........6......^6.............@..@.rsrc...h.....6......`6.............@..@.reloc...i....8..j....8.............@..B........................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2079
      Entropy (8bit):5.116691894381355
      Encrypted:false
      SSDEEP:
      MD5:D6A4D806933EE0E9D96ACCBFD3AD1820
      SHA1:6E31449E3411EB6CA162183C2102EFF111297C65
      SHA-256:20DAE620C1F84E553F99B967D3970941EC5D946C25CC562997BC48A2C9032819
      SHA-512:6188032C6A636E3B241AF7CFA7C29E5062BA3D334F8D03CAA97067B4203F8B834A7E8C1ADF2A79BF6DD6A85742ADB480079717B3686D41B405C8906E1A8315BF
      Malicious:false
      Reputation:unknown
      Preview:..' Subroutines to map next available drive letter to UNC path (create network drive)..' and UnMap it again after temporary use....' testing code below can be removed except recommend keep the Dim statement ..' as a "reminder" it is being used as a Public variable (sort of), not only..' to keep track of the drive letter between Subs but also for use in main logic (!)....' the Wscript.Echo commands used purely for monitoring progress can be removed, but suggest..' keep the "can't find a letter" in error-trap at end of MapNextAvailableDriveLetter sub....' Written 13 Nov 2007 by Dave Wilkins....Dim MappedDriveLetter ....MapNextAvailableDriveLetter "\\DWHOME\C$" ' substitute your own UNC path for testing....UnMapTempNetDrive......'= = = = = = = = = = END OF MAIN LOGIC / START OF SUBS & FUNCTIONS = = = = = = =......Sub MapNextAvailableDriveLetter (UNCpath) ' OR (UNCpath, Uname, Upwd).....Set objDict = CreateObject("Scripting.Dictionary")...Set objWMI = GetObject("winmgmts:\\.\root\cimv2").
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1171
      Entropy (8bit):5.161718804548312
      Encrypted:false
      SSDEEP:
      MD5:6E57B31690A20CA7F36CA0198BFA5C70
      SHA1:EBC2147A5A9610E874607C4DAEC2EB13F389F666
      SHA-256:C112F69F250617CCCA3AA5F7BD8CE1E47FE034D24DCCC733F77C7522E4782864
      SHA-512:AACF41E545B80F5272830C576C253609A813961D0F20CC545637367F2F17815357974E31F231AD76EDBABAEE723B6EB186D03AA22836C3E0674F8AE6A9BA9E34
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script to display a message dialog box if the free..' disk space on one or more drives is below a certain leve;..'..' You must pass the drive to check as a command line parameter...' For example:..'..' FreeSpace.vbs C:..'..' IMPORTANT: The drive letter must be in that format, e.g. C:\..' will fail. It must be drive letter followed by a colon only...'..const MBFREESPACEREQUIRED = 10 ' !!! Change as appropriate - this is in MBytes..const ONEMB = 1048576....Set objArgs = WScript.Arguments..If (objArgs.Count < 1) then.. WScript.Echo "No filename or dirname to copy was supplied."..else.. Set objWMIService = GetObject("winmgmts:").. For I = 0 To objArgs.Count - 1.. Set objLogicalDisk = objWMIService.Get("Win32_LogicalDisk.DeviceID='" & objArgs.Item(i) & "'").. if objLogicalDisk.FreeSpace / ONEMB < MBFREESPACEREQUIRED then.. MsgBox ("There is less than " & MBFREESPACEREQUIRED & "MBytes of free disk space available on " & objArgs.Item(i)).. ' Wscript.Echo "The
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2476
      Entropy (8bit):4.930149240266269
      Encrypted:false
      SSDEEP:
      MD5:EDB75BC30A3759C0E48282964FA3EC19
      SHA1:10EA34A730FF4620395CBD315B49703B6E15C23F
      SHA-256:095C39517E76F8378AF50C36645C99FAA3E26C6A1E444E26A11CDC3376BE85CF
      SHA-512:462C1D16BA4404D6E42DCFA204541002BA5AAADB21EAF7874C49BC98532E5F34449C2AEF84ABEF72AF99A1F2E1CEFEEDAAF590DFDD48DF22DBF410705CF65A88
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that adds..' extra columns to the Differences window...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script..'..Function Description(ByRef ScriptType).. Description = "Adds creation date and time, attributes and NTFS security columns".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' Tell SyncBack how many columns we are adding to the Differences window..'..Function RunDiffColumnsCount.. RunDiffColumnsCount=6..End Function....'..' The column captions..'..Function RunDiffColumnTitle(Col, Width).. If Col = 0 Then.. RunDiffColumnTitle = "Created (" + SBRunning.LeftName + ")".. Width = 150.. ElseIf Col = 1 then.. RunDiffColumnTitle = "Created (" + SBRunning.RightName + ")".. Width = 150.. ElseIf Col = 2 then.. RunDiffColumnTitle = "Attrs (" + SBRunning.LeftName + ")".. Width = 150.. ElseIf Col = 3 then.. RunDiffColumnTitle = "Attrs (" + SBRunning.RightName + ")".. Widt
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):3656936
      Entropy (8bit):6.641324234931741
      Encrypted:false
      SSDEEP:
      MD5:8258961B87B427B924B0A3C3B6CE58E1
      SHA1:9B58C2AA1D0A6545348088763FB7132382F031A5
      SHA-256:FEC2FEDFD59325F82E1CFAB67B0DDEB986980C47969C4454469BB1E3CA5DB6CD
      SHA-512:59CC308F5434B8C6306E90B543DEF58A813146FF2B56DCE5D232AEAF749C12B4F8F471D676441DC7A860819E94EB25AF2761A739B0762334AD43E60ED77F25F0
      Malicious:false
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....O8g...........!......1..H......$A1......P1...@..........................P8......n8...@...........................2.......2..=...`7..............z7..R....3..Y....................................................2.h.....2......................text...<.0.......0................. ..`.itext..<1....1..2....1............. ..`.data...8....P1......21.............@....bss.....v....2..........................idata...=....2..>....1.............@....didata.......2...... 2.............@....edata........2......62.............@..@.rdata..E.....2......82.............@..@.reloc...Y....3..Z...:2.............@..B.rsrc........`7.......6.............@..@.............P8......z7.............@..@........................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:data
      Category:dropped
      Size (bytes):138846
      Entropy (8bit):7.947297331374375
      Encrypted:false
      SSDEEP:
      MD5:C21A265174084C846F12562F0329D3E9
      SHA1:A850555139982CCB8EDDEF67B5EFAB212A5A18F1
      SHA-256:6DA122E88913234BAF946317EB5D9AC6CD8C73ED1FF2BD5B77FC4097915AE947
      SHA-512:A49E294470F8A86006CC3B680FDD8E22C83676204AC33CD0373F7D858D605E39610CF494FBDCEF9BFE9A2CBBE5FBFA9B50156E28764BB30C932EBBE3A1191FF6
      Malicious:false
      Reputation:unknown
      Preview:VCL_STYLE 2.0x......._,.4;-.&. h. ..D.iEp..4 ...".....$.h..h4...!...&.F.N..1.9....u&...x..L...'....B?X]V......<..<.T...}..........2k....n..N.Z.K.Z.......c]a..VY.5../....m..YK..X..}.Z....g... k..l...8.N;...4{.WN....k...u..W....k7...^....v.j.Z.`k.....j..~.........................................................................................3f..>}....a.0a..(.9s.$......3....g.q..Y__..>.Z.q.`......4i...*...d....;...k..:w../I^.....N;..ab..K..i........f;..u}....<...@.tO.W...{.F..Q.M..q....Q...M.....2j...........q}..e.K..u..e`uu.R.i...W../...}T....@u=I.........U.6C..9{.);...7.E..-...~...q.@...<x..=......+..}...T.(~.}U.`.5KNPUU5.f..3nP.~..E..a.*..q|.m...x8....J.....P..Ic..!..Q.@}.t?]...1l.....>..-U..~p..'..6m...;.r.S{...G........:..c..7n}T.....{Q.u.w...x..n.m.Ry.....................o....\............~.A3...:u..Wm....Z.e.V:'.I......M.>........>|..Ry....].~.{s;N/.[...Jm_...-WX?.v.:t..^.T....|F.......P....Pl...G..#'N..u.....
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):1355776
      Entropy (8bit):6.12743807165408
      Encrypted:false
      SSDEEP:
      MD5:7AE8414521FEB5ED4AAE66776D0FCAC1
      SHA1:CC53A95470A02411BBB763CAE7A2E92B2CBF56D9
      SHA-256:D2E7E2871B7C6E39E7D50F5800CA82906AB2583D41A5FAA621669B890E43373D
      SHA-512:630F8046C887ADCCF9AE5EEC2A79C409C9AE9997D35B3E76B7048D0B8F49BD1FF08212B40487195F4768938C26D91A9E42F34CAA540D407E08B8C11AFA4F0FE4
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........e.x...+...+...+..!+...+.U.+...+.U9+...+.U.+...+.|e+...+.|u+...+...+...+-..+...+-..+...+-.:+...+.V=+...+..q+...+-.8+...+Rich...+........PE..d....}.e.........." .........$......t.....................................................`..........................................w.......x.......... &...@...y......................8...........................P...p............................................text...^........................... ..`.rdata..............................@..@.data...........v...x..............@....pdata...y...@...z..................@..@.rsrc... &.......(...h..............@..@.reloc........... ..................@..B........................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):902
      Entropy (8bit):5.199350560434815
      Encrypted:false
      SSDEEP:
      MD5:E268BE202646CF0FF53F1044DF858862
      SHA1:3C145C4A65F11DACBB6516D7B15820E889CE5862
      SHA-256:CC7DEE104665A143047624F73FBB712034EACD91E9BE042E0748D73C92D69BDB
      SHA-512:5AABD2721A84A4AD9E1DDF54E28D900F65D204742A05DFA202D57BBF2296FA7C643B2E58740DBBB072A70BE9B2FF05B69A19F05B42553D68AC3A2B36851FF35C
      Malicious:false
      Reputation:unknown
      Preview:'..' Google Storage bucket locations used by SyncBackPro (2BrightSparks Pte. Ltd.)..'..' Do not modify this file unless you know what you are doing...'..' IMPORTANT: THIS FILE IS REPLACED WHEN UPDATING OR UPGRADING SYNCBACK..'..' The section names are the location constraint strings as defined by Google:..'..' https://cloud.google.com/storage/docs/bucket-locations..' https://cloud.google.com/storage/docs/regional-buckets..'..[ASIA]..Desc=Asia....[EU]..Desc=European Union....[US]..Desc=United States....[ASIA-EAST1]..Desc=Eastern Asia-Pacific..Regional=Y....[US-CENTRAL1]..Desc=Central United States..Regional=Y....[US-CENTRAL2]..Desc=Central United States (2)..Regional=Y....[US-EAST1]..Desc=Eastern United States..Regional=Y....[US-EAST2]..Desc=Eastern United States (2)..Regional=Y....[US-EAST3]..Desc=Eastern United States (3)..Regional=Y....[US-WEST1]..Desc=Western United States..Regional=Y..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU gettext message catalogue, ASCII text
      Category:dropped
      Size (bytes):485
      Entropy (8bit):4.95496103697601
      Encrypted:false
      SSDEEP:
      MD5:9AFF213DA8492FAE84C23F4EA7EFB6DE
      SHA1:F2228B4076EEFACD34B514291475BC56008B5246
      SHA-256:58B0298ACD8D8F1FE2E64F718629B554C8787B80E9F23AAF31544B8525540E8F
      SHA-512:028831F1BE80EC3C32A76E66B325B01675DD49A638D958B98356B8CB24FEB847A118173D030D191D68D2B723DFEF391B76C99408A7A32EFB7BE0D2B99826836F
      Malicious:false
      Reputation:unknown
      Preview:msgid "".msgstr ""."Project-Id-Version: Translation example\n"."POT-Creation-Date: \n"."PO-Revision-Date: \n"."Last-Translator: Michael J. Leaver <MJLeaver@2BrightSparks.com>\n"."Language-Team: 2BrightSparks\n"."MIME-Version: 1.0\n"."Content-Type: text/plain; charset=UTF-8\n"."Content-Transfer-Encoding: 8bit\n"."X-Poedit-Language: French\n"..msgid "String 1".msgstr "Translated string 1"..msgid "String 2".msgstr "Translated string 2"..msgid "String 3".msgstr "Translated string 3"..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):5228
      Entropy (8bit):5.133459995761587
      Encrypted:false
      SSDEEP:
      MD5:9A14BBFE294FB1589465D9366C41CE28
      SHA1:AD0AB01C89672173A6B81275917C8E07F9AFF8EA
      SHA-256:B44ABDB9AE2163875BC3D5E6D021B391E1598134E79C87CF9CD78251E75A90D4
      SHA-512:2937DC6019045B6941707EB802F9FF98ABD64C3BD37C294202625A9B136902B1DE7D69BAF5EFAD767A07C11011806425F096F234084566CFB2B5F9617B63A0AB
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sends a Twitter message ..' after a profile runs (if the run is simulated then it does not)...'..' IMPORTANT, READ THE FOLLOWING:..'..' - THIS SCRIPT IS FOR REFERENCE ONLY. THIS SCRIPT NO LONGER WORKS...' - You must first create an account at http://www.twitter.com/..'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a profile configuration and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Send Twitter message after a profile run".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' This routine is called after the profile has finished...'..Sub RunProfileResult(ProfileResult, ErrMsg).. Dim sUrl.. Dim sText.. Dim oXML
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):3690
      Entropy (8bit):5.054922686128055
      Encrypted:false
      SSDEEP:
      MD5:0C3FEF9E885E33745E840157D261A943
      SHA1:6BD91A5658D8EFD3E7448EB47C4AAEDF36325F16
      SHA-256:41047DF5EF044AC67503E34DE03D94E5C2AA4FABBBC0D86CFDF661169FD107E1
      SHA-512:A926022A33E970D73B16D4D703276C5764C502D0500FBDD92CD06D1D3AA80FB6A033DD0172D5E1A5DFE7C036AF3C5A95E823BA6535F0160C1EABDF14BD8CEC1D
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that exports..' the differences in files and folders when the Differences ..' window is displayed...'..' Note that the Differences window has an Export ability already..' via the main menu...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script and a configuration script..'..Function Description(ByRef ScriptType).. Description = "Differences export".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....Sub DoTheExport.. ' Export files.. ExportFilename = CStr(SBVariables.GetProperty("DEFiles", "", FALSE)).. If ExportFilename <> "" then.. Set objFileToWrite = CreateObject("Scripting.FileSystemObject").OpenTextFile(ExportFilename, 2, true, -1).. For I = 0 to SBRunning.FileCount - 1 step 1.. ExportName = SBRunning.GetFilename(i).. .. ' Filename,Difference,Action.. objFileToWrite.WriteLine(ExportName + "," + CStr(SBRunning.GetFileDiff(ExportName)) + "," + CStr
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):3722
      Entropy (8bit):5.302579776915396
      Encrypted:false
      SSDEEP:
      MD5:0EC529A3E56F54B00FE1A66985545076
      SHA1:9214E810CEBD401B2EB71CBA4BDB0E0CAE489356
      SHA-256:E1C9CCE1026588B3640876A1D7CE2070488AC40BAC07AA8DC8019B40D7D7661E
      SHA-512:B7AC4B753AFCE6785567A198360AEEACB11389978D84A2560DF8D692FC945703AF07141AD77A84F57FB31C68D240F698F94C7E4B9EBDC27AA9DC8FCD3BDDE920
      Malicious:false
      Reputation:unknown
      Preview:'..' Amazon S3 bucket locations used by SyncBackPro (2BrightSparks Pte. Ltd.)..'..' Do not modify this file unless you know what you are doing or have been instructed to do so. ..'..' IMPORTANT: THIS FILE IS REPLACED WHEN UPDATING OR UPGRADING SYNCBACK..'..' The section names are the location constraint strings as defined by Amazon:..'..' http://docs.aws.amazon.com/general/latest/gr/rande.html#s3_region..'..' default is used (instead of an empty string, which is not a valid section name) for the..' default S3 location (US Standard)...'..' Last modified 17 September 2024..' See https://docs.aws.amazon.com/general/latest/gr/s3.html for official list of regions..' ..[default]..Desc=US Standard..URL=s3.amazonaws.com....[us-west-1]..Desc=US-West (Northern userfornia)..URL=s3-us-west-1.amazonaws.com....[us-west-2]..Desc=US-West (Oregon)..URL=s3-us-west-2.amazonaws.com....; Uses AWS4-HMAC-SHA256 security..[us-east-2]..Desc=US-East (Ohio)..URL=s3-us-east-2.amazonaws.com....[eu-west-1]..Desc=Eu
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):219146
      Entropy (8bit):6.6019266128302805
      Encrypted:false
      SSDEEP:
      MD5:6FCF0CD1F542348E6CED853CC09F3C20
      SHA1:88BF8838F10EE84060D5A5CE69B7C1C0C7A7B922
      SHA-256:1B088414A73FE77803A238C20A3658C739AC449DEA79C73964A107B7C01F7A8C
      SHA-512:4CEAE8C8BE1EF2323F4A882F66291A5D0A84BC6C464FE883AC1FE3F026530674F1D9E8F098C20B25EC026FC07C3B391A3BF50DF67F3DA7BB179884FB0E3FB485
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........5.X.[.X.[.X.[...Z.[.Q..l.[.Q..A.[.Q....[...6.Y.[... .K.[.X.Z.d.[.Q....[.F..Y.[.Q..Y.[.RichX.[.........PE..L......R.................X...................p....@.......................................@.................................T........@..."...................p..D ...t..............................(...@............p..`............................text...yW.......X.................. ..`.rdata..`....p.......\..............@..@.data....(..........................@....rsrc...."...@...$..................@..@.reloc.../...p...0...(..............@..B........................................................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:data
      Category:dropped
      Size (bytes):126045
      Entropy (8bit):7.948888020353814
      Encrypted:false
      SSDEEP:
      MD5:1583E1A23D5C353471E1AC65CF2E52A3
      SHA1:7D07DCB8EB6D2852B48FEE2CDF27C8ADFDE358DF
      SHA-256:CC578ECEB7FEBBDF3D874210F5F7EC799E734A3097C9A37856685A99AFE0A746
      SHA-512:E70246DCE3A02260566093F2388EAFF45BDE9E2067512B0227AC80B8C9137B9C03915EB7DFA769D2CDCB780F027947235622A53D338E8036586E1667B16D3AC4
      Malicious:false
      Reputation:unknown
      Preview:VCL_STYLE 2.0x.........o..\D.rs..X*...U..B..![t.K...D.-M.lo......Zl._v..6u...!u+B...Fi4Dq...fF.;.3g..9..9.g......|.3.{....g>.a.V;.vV...i..Kk..>..o..a.o..&..p.lY......3k..:..w..\....q./.N...u...k..?......:.......'9eoY.;.S....N\....a%...6.Y......|.E..8..... Uh...:.....$.M.9.9..o...o.....................................................................................................................................................................`....xJgg.n....A...........e..~....l..$.u.....W.r.3..<Xo.........y................;*KY........p\....L...h;..n......7.^j..v....sA.t./....}..Y/MYq. in....Y..)..).(..j{q.....4.Q...%n.:::.p..X.......ym....)a..9Y.....................y.o..Z.."N}..[..*.....Rg......Q.J..z.............8..*....k....\...1q....b...}....>}'....\.O...#..I.@c.t.....[.F...}..+..8...Yw.S..B.5J~.8..F..x}.Q.p.;...}........2'.l..w.v..fe.r.....u.....N...{..j.^..q.7n..;.t.F....F..8u.T.!..`....".......Xr'........mV.m7....u......j.^...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1010
      Entropy (8bit):4.955580325228301
      Encrypted:false
      SSDEEP:
      MD5:0EF0D4FD29777824444C212327752CED
      SHA1:F63D6F538382D8AB5CD2325835B53A20BB48F25B
      SHA-256:D428F07320CDA2763AF0CC3E2B66BE9A1BE7AF70545EEF11976D3EA85E8A8963
      SHA-512:4F1E122214659CCFF5ED0ED980D151E65166C99C411A050F7399A895265CC65C5F48F89F8A7A833989058620080761B4E3200231797C9820E8E36979B001E99F
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that removes the..' NTFS encryption from the copy of a file...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Removes the NTFS encryption from the copy of a file".. ScriptType = SCRIPTTYPE_RUN..End Function....'..' This function unencrypts the copy of a file...'..' Note this function is not called if it is a simulation...'..Sub RunAfterCopyFile(ToLeft, Filename, Failed).. ' If the copy failed then dont even try.. If Failed then.. SBRunning.DebugOut(Filename, "Failed", 1).. Exit Sub.. End If.... ' Get the full filename.. If ToLeft then.. FullName = SBRunning.LeftFolder & Filename.. Else.. FullName = SBRunning.RightFolder & Filename.. End If.... ' Decrypt it.. ErrorMsg = SBSystem.DecryptFile(FullName).. if ErrorMsg <> "" then.. SBRunning.NotCriticalError(Filename, "Could not decrypt: " & ErrorMsg).. End If.
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):3395
      Entropy (8bit):5.059034849673354
      Encrypted:false
      SSDEEP:
      MD5:5021C120C98F304699CC0A62628ECD3D
      SHA1:B0F481939B2E9F3CE8138AECC842CF7A90556D39
      SHA-256:01B74E7E7E5F41F0E4EDE8CE15CF6EF583468593D4DB12A60F0DCD635F8718E1
      SHA-512:A3256FFF4F2E66A42C5C2ACE0BAEDE0CCC313CD3D1CBD12E9C687DC25BC44FCBB34B7007252923C2A4997F5520BABA7E4B8A88E4288B23CA657EF1DF6F9E8E0D
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that sends a Twitter message ..' after a profile runs (if the run is simulated then it does not)...'..' IMPORTANT, READ THE FOLLOWING:..'..' - THIS SCRIPT IS FOR REFERENCE ONLY. THIS SCRIPT NO LONGER WORKS...' - You must first create an account at http://www.twitter.com/..' - Set the connection details below..'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The connection details for Twitter to send a message..const TwitterUsername = "YOUR TWITTER USERNAME"..const TwitterPassword = "YOUR TWITTER PASSWORD"....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a runtime script ..'..Function Description(ByRef ScriptType).. Description = "Send Twitter message after a profile run".. ScriptType = SCRIPTTYPE_RUN..End Function
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:DOS batch file, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1505
      Entropy (8bit):5.005075923788756
      Encrypted:false
      SSDEEP:
      MD5:0CEB531C3EF2829E42B2535AEC9A076A
      SHA1:53DC9010CC6D37F1C66587D8528C21A9A5A3C074
      SHA-256:9649E1DDDAB98E9C0758F18025AB0166C4188A2CE4FC00752A585842410BD469
      SHA-512:5A4F674A1232E54FFA63DD9A5BE329617B6ABE24A6D2147500996AC5E467DCF554EE40D7E5EA6571CC3EC50CA4C884A924916E85F2C5403879B271A55B402CD5
      Malicious:false
      Reputation:unknown
      Preview:@echo off..REM..REM Batch file that attempts to reset and fix the Volume Shadow Copy (VSS) installation...REM..REM IMPORTANT: THIS FILE IS REPLACED WHEN UPDATING OR UPGRADING SYNCBACK..REM..REM 2BrightSparks Pte Ltd..REM https://www.2BrightSparks.com/..REM..echo --- This batch file must be run as an Administrator. If you are using Windows..echo --- Vista or newer then run it by right-clicking on the batch file and..echo --- selecting Run as administrator..%SYSTEMDRIVE%..cd %SystemRoot%\System32..echo...echo --- Ignore any messages saying a service is not started...echo...Net stop vss..Net stop swprv..regsvr32 ole32.dll..regsvr32 oleaut32.dll..regsvr32 vss_ps.dll..Vssvc /Register..regsvr32 /i swprv.dll..echo --- eventcls.dll will fail to register on Windows Vista and newer...regsvr32 /i eventcls.dll..echo --- es.dll will fail to register on Windows Vista and newer...regsvr32 es.dll..regsvr32 stdprov.dll..echo...echo --- vssui.dll only exists on Windows 2003. Ignore the error if not usin
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):4473
      Entropy (8bit):5.099207819095457
      Encrypted:false
      SSDEEP:
      MD5:D3BF54E7BD17EC71A1C0B88ADEDF7850
      SHA1:5EE8D926812930FB5C565148E87A90DFEC29EB87
      SHA-256:80C8A216147938CD29A92AFF889628BE8B3627922DFB35F05C1344FD1B81EC51
      SHA-512:9772D3D4F5395D50AFD9A117C398951EEB484FAE81D380D5F7365ECBE6BB1A2D79ABABD8683F15F493A9B3E0B0DBFA62378AD8DBC6766ED6F865C364DA83D842
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that shows how..' to have a "Message Of The Day" which is retrieved from a..' web server and displayed (if it is new)...'..' How this works:..'..' - Put a message of the day file on your web server. It would..' be a good idea to make it a small file otherwise there..' will be a delay when starting SyncBackPro...'..' - Put the full URL of that file into the MOTD setting below..'..' - Change the MOTDEXT setting below to the extension of that..' Message Of The Day file...'..' - Install the script into SyncBackPro, enable it, and then..' restart SyncBackPro..'..' How to improve this script:..'..' Instead of downloading the entire message of the day file..' each time, you could instead have two files on your web..' server: a counter file, and the message of the day file. The..' counter file would be a small file that you change each time..' the message of the day file is changed. So instead of this..' script downloading the messag
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1503
      Entropy (8bit):5.0714671416053765
      Encrypted:false
      SSDEEP:
      MD5:16A80D522383C49C6265F54E9A242829
      SHA1:F6AF8E32699E7A286310AE84D30E474E264C040C
      SHA-256:967D4E579167E410F0DCDA8D7F2F1A3B7406479F7F4C74A1434EC48EBAD012EF
      SHA-512:8FCA97BD8679FB3A727B90A3F6678ECEE5F2EE7BE674BFABC7B2614D1F78317F7F2A39914A508B6B871D57894DC0B1636FE8C48FA3A1E032F9FC0C0698F15BBA
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that removes the leading zeros..' from the day and month variables...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The name of the variables..const MyDayName = "NoZeroDay"..const MyMonthName = "NoZeroMonth"....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a runtime script and a configuration script..'..' It must be a configuration script otherwise the variable will not be used..' when you modify the script..'..Function Description(ByRef ScriptType).. Description = "Adds new variables " & MyDayName & " and " & MyMonthName .. .. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' This subroutine is called when the variables are initialised. This is either..' when the profile is run, or when the
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):17787104
      Entropy (8bit):5.975074101924487
      Encrypted:false
      SSDEEP:
      MD5:765BBB546E5D7F45AF8347202C208787
      SHA1:B45A13FBFA8CA110593923C65F2A039855AF30C9
      SHA-256:221BAD9CA5A2AD3E34FF442ADE86D2AB83C30A9E4A043C7F304AE630F5DC0BA1
      SHA-512:B337767D3474A95CE68FB53362504D4DC3FE8E83A9855FE22D0470BECC9B16486F03AB6D67BF2AEA15CF016AB28508C53B23C4468646A8019FC4455C0E3A980F
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................n......~.......~................x..............i.......o.......j.....Rich............................PE..d......g.........." .....&...pg..........................................................@..........................................:...............p.......`.......<...,......l....................................................@.. ............................text...2%.......&.................. ..`.rdata..H.G..@....G..*..............@..@.data........@.......&..............@....pdata.......`......................@..@.rsrc........p......................@..@.reloc..:...........................@..B........................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):1611776
      Entropy (8bit):6.546705954773448
      Encrypted:false
      SSDEEP:
      MD5:F08C559E004A0317E91B7BFF6D3D34A8
      SHA1:6E6B8D3ED2A479140AE20EEA7C4B36986FDCB1CA
      SHA-256:A06F6B767D3A93B5498AE46E1BA75734BEDA955774D722A3404E8AD2400B71A5
      SHA-512:B1E3C398E4F5D0EE105CEBE63909079013B77429B9D6D4246BE5609D9F025A20C5A6D35683ECCD06647D353EA801BF5A3D507141B3350F7A52D47158A4B3EB7F
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........U...;...;...;.*....;......;......;......;...:...;......;....`.;......;......;......;.Rich..;.................PE..d....`.J.........." .........................................................`.......V....@..........................................x...Q...i..x.......0........................I...%............................................... ...............................text............................... ..`.rdata....... ......................@..@.data...............................@....pdata...............H..............@..@.rsrc...0............:..............@..@.reloc...W.......X...@..............@..B........................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):6943
      Entropy (8bit):5.004444763344969
      Encrypted:false
      SSDEEP:
      MD5:3DA62630DF43A6F0760251F6CAF5FCF1
      SHA1:A39B7DEE988981F4C7C9B6B3E21BD432A6A0BA93
      SHA-256:859B66EF39215E03AD64C6B19E9F4CEE58E7CCE5217AAEF3561E4B1CE91D76E8
      SHA-512:5490A4819848D0A4D7805D3A273DE04DBCD13021F8315788C59BAD5B429AE40FC3F45B64478E90E832625B07D0B9DDD2507367913705060A52714A987A1CC0C6
      Malicious:false
      Reputation:unknown
      Preview:'------------------------------------------------------..' Save historic versions of the backup, so that you can..' backtrack to previous versions. This script will, if..' ran BEFORE the SyncBack-backup, copy the last backup..' (either directory or zip-file) to a historic version..' in the same destination directory...'..' The historic set consists of folders/files in the..' backup-directory that have a "1_", "2_" etc prefixed..' to the original backupfilename or -foldername. After..' the (in this script configured) maximum number of..' historic versions is reached, the script starts over..' at "1_" and repeats the cyclus...'..' That way, by looking at the modifation-date of the..' historic files or folders, you can always find the..' previous backups. Because of this, you can not..' automatically assume that the "1_" version is the..' oldest or newest version, it all depends on the..' modification-date of the files or folders...'..' Created by Alex, based on code from timestamp.vbs as
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):4448
      Entropy (8bit):5.088378051421046
      Encrypted:false
      SSDEEP:
      MD5:0DC847E2F7BA8F240257C5428D47840F
      SHA1:7BB37833AB1E74DD54C61EFF2805DB017610FCCA
      SHA-256:B8D73E9ABB4BB510120CABF5F39CD74AA64606D4A197CA2221F58420B0FD9B0A
      SHA-512:5EEFDCD5774810AD2CC3455111FC323DA5B9B8AE0E4A7415E0491D2D1807034073C81E2F9DD63D4E4D6682691F0A3F6C8AD29ABBF2CA0B5967CB9F64590BB2E2
      Malicious:false
      Reputation:unknown
      Preview:'..' Example script for 2BrightSparks SyncBackPro V8 that waits for a program to..' finish before running the profile. If its a simulated run, or a restore,..' then it can be run regardless...'..' SBLang=Basic..'..' http://www.2BrightSparks.com/..'....' The number of seconds to wait before re-checking if it is still running..const RetrySecs = 5....'-----------------------------------------------------------------------------..'-DO NOT MODIFY ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU ARE DOING !-..'-----------------------------------------------------------------------------....'..' This is a profile configuration and runtime script ..'..Function Description(ByRef ScriptType).. Description = "Wait for a program to finish before starting profile".. ScriptType = SCRIPTTYPE_RUN + SCRIPTTYPE_CONFIG..End Function....'..' Do nothing..'..Function Install(Interactive).. Install = ""..End Function....'..'..Function RunDisabledCheck(NoLog).. ' Running simulated or as a restore?.. If
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (392), with CRLF line terminators
      Category:dropped
      Size (bytes):43633
      Entropy (8bit):5.3649815353297665
      Encrypted:false
      SSDEEP:
      MD5:10CED5F5E381427970057261E9713892
      SHA1:1C8BE1893B4B51B4C7537316539AD2396EDB5106
      SHA-256:165E81689161F9E60E7BFF1FBFE5CDFFED9640BA192C396F685C80377AA4813C
      SHA-512:22B58AEB01C7A86595A36A05B8334A60B0D5A3A0AE7F856141DFD1FEA9E2573AD13A4ED09F753967E2EEBFBEA2617FF29A432C30193CB1AFBFC86A24F8258460
      Malicious:false
      Reputation:unknown
      Preview:.<?xml version="1.0" encoding="utf-8"?>..<assembly xsi:schemaLocation="urn:schemas-microsoft-com:asm.v1 assembly.adaptive.xsd" manifestVersion="1.0" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.. <assemblyIdentity name="SyncBackPro.exe" version="11.0.0.0" type="win32"/>.. <description>SyncBackPro File Backup Program</description>.... <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">.. <security>.. <requestedPrivileges>.. <requestedExecutionLevel level="asInvoker" uiAccess="false"/>.. </requestedPrivileges>.. </security>.. </trustInfo>.... <dependency>.. <dependentAssembly>.. <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" language="*"
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):18284
      Entropy (8bit):5.071536444054424
      Encrypted:false
      SSDEEP:
      MD5:8571CBC9CB03FC24056C7F210F49FDA2
      SHA1:F364D98AD1B653A89D8456CA7ECDFE6CA9F9585C
      SHA-256:B1F50411747F1E44A0EEC950700017517BBE382DA80EA3B7C5C2C2932F3625AC
      SHA-512:54601CD7083D3648644F7602109272891F70C046E6A7AF102703B115C506D3DC0690BA4B04E8AAEBF0C4F6CB2E6F2C89065FAA17318453891F0B2129C425A4F3
      Malicious:false
      Reputation:unknown
      Preview://..// Example script for 2BrightSparks SyncBackPro V8 that lets you treat..// all drives as a single drive...//..// SBLang=Pascal..//..// http://www.2BrightSparks.com/..// February 2016..//..var gFSO, IsMainThread, DebugLog, IsDebugging;....//..// This is a location script..//..Function Description(var ScriptType);..begin.. Result:='All Drives Location';.. ScriptType:=SCRIPTTYPE_LOCATION;..End;....//..// This is called when the user adds the script to SyncBack..//..Function Install(Interactive);..begin.. Result:='';..// If Interactive Then..// SBSystem.Say 'Installed'..// end;..End;....//..// This is called when the user removes the script to SyncBack..//..procedure Uninstall;..begin..// SBSystem.Say 'Uninstalled'..End;....//..// The script is being exported..//..Function FilesToExport(Interactive, Cnt);..begin.. Result:='';..// If Cnt = 0 Then..// FilesToExport = 'D:\temp\junction.exe'..// ELseIf Cnt = 1 Then..// FilesToExport = 'C:\temp\test.txt'..// Else..// F
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:MS Windows HtmlHelp Data
      Category:dropped
      Size (bytes):9454715
      Entropy (8bit):7.998504087447307
      Encrypted:true
      SSDEEP:
      MD5:357986161B16F958D839397A23CE5DA1
      SHA1:BD9BD2D609F3B48E2D305832DB1AAB18185EBCAD
      SHA-256:83362D503BF1EEE75AAD9ABFF628064BD7CC733F51BE9E3E9A08C952E53E8DF0
      SHA-512:795EE390D2A0009DD9519D2ED95143D13E84215BC83D91845639E1A29DD1D74B2D6EC335C1D4F168835FBA8E82C902932A1B7B845AAE81CE9E9C0712DF3FE628
      Malicious:false
      Reputation:unknown
      Preview:ITSF....`.......@R...H.....|.{.......".....|.{......."..`...............x.......TP.......P..............{D..............ITSP....T...........................................j..].!......."..T...............PMGL?................/..../#IDXHDR......../#ITBITS..../#IVB...N.D./#STRINGS....?.D./#SYSTEM....9./#TOPICS......../#URLSTR......#./#URLTBL......../#WINDOWS.....L./$FIftiMain...(..t./$OBJINST...i.?./$WWAssociativeLinks/..../$WWAssociativeLinks/BTree...."..L./$WWAssociativeLinks/Data....n.../$WWAssociativeLinks/Map....B./$WWAssociativeLinks/Property...I ./$WWKeywordLinks/..../$WWKeywordLinks/BTree......L./$WWKeywordLinks/Data...^.../$WWKeywordLinks/Map....p.../$WWKeywordLinks/Property..... ./32bit64bit.htm.....s./adobe-reader.png...L.~./allvolumes.htm...y.g./allvolumes1.png......../allvolumes2.png....5..R./allvolumes3.png.......'./alternative.jpg...*..q./altpay.png....V.V./arrow-down.gif......S./arrow-empty.gif....j.:./arrow-none.gif....$.O./arrow-up.gif....s.S./arrow_left.png..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (console) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):3510496
      Entropy (8bit):6.608809180569996
      Encrypted:false
      SSDEEP:
      MD5:1E5540941342933F836EA6F69DF5D9D7
      SHA1:7E41CA42523DAE2326ACDC4346A19CBF5CB86EA1
      SHA-256:CA4A636E3981AA99C223A3E487FD208D44A45C01819B862DC00CAB840E78EC2D
      SHA-512:EB024693FECA57DE9BFC05537B39C7771CF1F105025A2DB7BDF22BC49F742B7F387B5E28BAF92EFBE30CCAECD2FAA40C626C7D51A3DE95967E610D4302B772E4
      Malicious:false
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....O8g.................v........................@..........................06.......5...@......@................... 0.t...../..<....4..............>5..R...P0..!...........................@0.....................T./.(.....0......................text....D.......F.................. ..`.itext.......`...0...J.............. ..`.data................z..............@....bss.....r...@/..........................idata...<..../..>..../.............@....didata.......0......Z/.............@....edata..t.... 0......p/.............@..@.tls....`....00..........................rdata..]....@0......r/.............@..@.reloc...!...P0.."...t/.............@..B.rsrc.........4.......3.............@..@.............06......>5.............@..@................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:XML 1.0 document, ASCII text, with very long lines (717), with CRLF line terminators
      Category:dropped
      Size (bytes):742
      Entropy (8bit):5.857634571468141
      Encrypted:false
      SSDEEP:
      MD5:FAD614A14ECEF7689DAF5B9379A83627
      SHA1:08CDE000D8ADCEB46AFB9E4D682CAD55268D3BD9
      SHA-256:65D4D3D2624BA01B2D9777005CC4A2A95BF9C0D7BA896365681F1523D0B4CB64
      SHA-512:CE70C0CEA1EEE22E175698500B1CA99448A7CDB790228CAEFA3ACBCF4DCD8C9E115CF36068C6234210AF95A6D2CD759957B8DEFF2C4DAC7EAEDF0F2152E81729
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0"?>..<License><Version>2.0</Version><Id>400016053</Id><Name>Michael Leaver</Name><Email>MJLeaver@2BrightSparks.com</Email><Company>2BrightSparks Pte Ltd</Company><Product>SmartFTP FTP Library</Product><Features><Feature>FTP</Feature><Feature>SFTP</Feature></Features><Users>1</Users><Maintenance>2010-02-22</Maintenance><Issue>2007-02-14</Issue><Signature>HzpkVdG5JmjuwuzsisEMfqxgMpN9nElGNux82pmePV3MCMNycZ3i6MBt9TXSuTq8K6aQTLumQolOXdNjfwA2vWomEKNocIrlGqJRb893bzAqb5JolZsKJgsvGPk3F8s8O2qsnSzRJMG80TSWL3g3R9efB2NKQ60Q5pDI/xPZ1a/Ff53lsYQkAmx10yfnFllYyV2SSHFEYZRi5h5O56HhdgFB3O64TZswrb0lBRQwxX2GSh6e5YmDXUsTdBB6CRzjjWMVx2K3aOkRlJRki933D/AoQQMGV2YeTlHhADK+R8OcTMPwrV3vjWQUqTlk392inwFVKbCfbtZzmIC3qmaNbw==</Signature></License>..
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 192 messages, Project-Id-Version: SyncBackSE V4 'Afar'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:D563FFE4977FEA6A82C472EB84734B9E
      SHA1:F89758D23B43DD7D44BE1C6D3EE206BA8A07A8CE
      SHA-256:C86AD74012521F05B448C821285A7E4A63805676BA27F270CBD651F6A7EAD2C1
      SHA-512:DB2712B74F4239E879FE2474F250EBF1929687E1F38F2CB5642DF50FAB22BC436DB83F2A0557E306634A0C5A15337C8CBF8A612E01DA8D845654B01B9E6843CB
      Malicious:false
      Reputation:unknown
      Preview:................................ .......!.......$.......'.......*.......-.......0.......3.......6.......9.......<.......?.......B.......E.......H.......K.......N.......Q.......T.......W.......Z.......].......`.......c.......f.......i.......l.......o.......r.......u.......x.......{.......~............................................................................................................................................................................................................................................................................................................................................................................................................... .......#.......&.......).......,......./.......2.......5.......8.......;.......>.......A.......D.......G.......J.......M.......P.......S.......V.......Y.......\......._.......b.......e.......h.......k.......n.......q.......t.......w.......z.......}...............................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:E942A22F2FA3A0156F1A0447681761E1
      SHA1:3C9D8851721D2F1BC13A8DCB74549FA282A5A360
      SHA-256:E2908DEC495CC6E621358EB7C5D41403F25EB4BDBF3802866EADEA378422D412
      SHA-512:69C685675485103FC5C64C50EDCF1CA3A276F8B684B0D6AEFD6206D956B901EAE86B7AA66D2EC1125C57DAA6A6C0B124ACF8BA70752BF492EBBA5F2D9B3E9FB1
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........._..1..1..1...L..1..0.j.1...J..1..1...1...\...1...K..1...M..1...I..1.Rich.1.................PE..d...w..].........." .........L......0........................................p#.......#...............................................................#.0.....!..E............#..B...................................................................................text............................... ..`.rdata..(...........................@..@.data................t..............@....pdata...E....!..F...\!.............@..@.rsrc...0.....#.......".............@..@.reloc...U....#..V....".............@..B........................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:F08C559E004A0317E91B7BFF6D3D34A8
      SHA1:6E6B8D3ED2A479140AE20EEA7C4B36986FDCB1CA
      SHA-256:A06F6B767D3A93B5498AE46E1BA75734BEDA955774D722A3404E8AD2400B71A5
      SHA-512:B1E3C398E4F5D0EE105CEBE63909079013B77429B9D6D4246BE5609D9F025A20C5A6D35683ECCD06647D353EA801BF5A3D507141B3350F7A52D47158A4B3EB7F
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........U...;...;...;.*....;......;......;......;...:...;......;....`.;......;......;......;.Rich..;.................PE..d....`.J.........." .........................................................`.......V....@..........................................x...Q...i..x.......0........................I...%............................................... ...............................text............................... ..`.rdata....... ......................@..@.data...............................@....pdata...............H..............@..@.rsrc...0............:..............@..@.reloc...W.......X...@..............@..B........................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2409 messages, Project-Id-Version: SyncBackSE '"%s" est\303\240 aturat'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:B7C90BF12F761A599CAE048BCDB02BF3
      SHA1:9AD3D73A2759BB2F9C12F856539422F1AA0DF44E
      SHA-256:581AA32E93EAD9A0547B11B95ABB7DAF4BC0E28C6BCFCF783AAA3373994B37AD
      SHA-512:82D15A990BA65BBF81F1D95B120ABB43B02CA80C30B3E618045BAA53EDC55319FE73364675A3403F8A5781E33FFF402A42BEDFB3BB320C81E00C5B8ED6CD5E23
      Malicious:false
      Reputation:unknown
      Preview:........i.......dK..............................................+.......E.......c... ...@.......a.......z...................!...............%.......%...$...!...J.......l...........#...........C.......^...J...h...^...................*.......5.......I...m...R..........................................."...........).......?.......U...-...^...........&....... ...............)..."...@...L...................................%....................... ......................................./...........A.......H.......N.......Z.......b.......j.......r.......{...................................................................d.......V...s...........................................................5.......7...T...................7...............%...........................&......./...e...B...................................K...........".......(...............8.......<.......G.......S.......W.......a.......l.......x.................../.......................................,...................'.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2409 messages, Project-Id-Version: SyncBackSE '"%s" est\303\240 aturat'
      Category:dropped
      Size (bytes):249290
      Entropy (8bit):5.233631751493021
      Encrypted:false
      SSDEEP:
      MD5:B7C90BF12F761A599CAE048BCDB02BF3
      SHA1:9AD3D73A2759BB2F9C12F856539422F1AA0DF44E
      SHA-256:581AA32E93EAD9A0547B11B95ABB7DAF4BC0E28C6BCFCF783AAA3373994B37AD
      SHA-512:82D15A990BA65BBF81F1D95B120ABB43B02CA80C30B3E618045BAA53EDC55319FE73364675A3403F8A5781E33FFF402A42BEDFB3BB320C81E00C5B8ED6CD5E23
      Malicious:false
      Reputation:unknown
      Preview:........i.......dK..............................................+.......E.......c... ...@.......a.......z...................!...............%.......%...$...!...J.......l...........#...........C.......^...J...h...^...................*.......5.......I...m...R..........................................."...........).......?.......U...-...^...........&....... ...............)..."...@...L...................................%....................... ......................................./...........A.......H.......N.......Z.......b.......j.......r.......{...................................................................d.......V...s...........................................................5.......7...T...................7...............%...........................&......./...e...B...................................K...........".......(...............8.......<.......G.......S.......W.......a.......l.......x.................../.......................................,...................'.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhaz'
      Category:dropped
      Size (bytes):4268
      Entropy (8bit):4.665418985004488
      Encrypted:false
      SSDEEP:
      MD5:10369AC1EB906CFDB41A565E7287B430
      SHA1:FF764DA64B0B3DBA29926E4F14E6939EE4C142FA
      SHA-256:70304F768D5A98F79AE8FD13B1F529C880E9B1D6B21480BE6E456BD51EB764AD
      SHA-512:A6032D27E1AC7F7B0A25EA7D255CD00E08F7AE81C59BA40820F3465AD2FE4288F0775E02BE758A7C00FA09B717A7DE3D78C26D98ED31EFCE2DA16ADCC401A2BC
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................^...........K.......R.......\.......e.......v.......|.......................................................................................................................'.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhaz'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:10369AC1EB906CFDB41A565E7287B430
      SHA1:FF764DA64B0B3DBA29926E4F14E6939EE4C142FA
      SHA-256:70304F768D5A98F79AE8FD13B1F529C880E9B1D6B21480BE6E456BD51EB764AD
      SHA-512:A6032D27E1AC7F7B0A25EA7D255CD00E08F7AE81C59BA40820F3465AD2FE4288F0775E02BE758A7C00FA09B717A7DE3D78C26D98ED31EFCE2DA16ADCC401A2BC
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................^...........K.......R.......\.......e.......v.......|.......................................................................................................................'.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3203 messages, Project-Id-Version: SyncBackPro v10 '%s je pozastaven'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:7D69A2E81A51E64E8C77BE0C05716006
      SHA1:C5EAB6D5355AF6D07D0EFC90D9623F940B581FF2
      SHA-256:1098B25F345E800E0F085A8EB0F85B5E93FE3133AB01D148956141EADF0447FE
      SHA-512:5053B6056BEC63FAF9F57DD5AA236606A1F15CF5626539A03C146C427013BBDAFF6EFE109F6814113FF29E0183A75C17D546F0F38D8E0DBAC11D5117D522C36E
      Malicious:false
      Reputation:unknown
      Preview:................4d......L...............................,.......C.......].......{.......X... ...........5.......N.......c...............|...M...........O.......k...,...|...........!.......................%.......%...8...!...^...................#...3.......W...+...r...........J.......^...........R.......^.......v...................m...........................&.......3.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'...%...T.......z...................................%....................... ......................................./...........J.......Q.......W.......c.......k.......s.......x...................................................................................d.......V...........................................................$...5...,...7...b...................7...............%...........$.......*.......4.......<.......E...e...X...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 60 messages, Project-Id-Version: Delphi 'Chyba %s %s: (%d)%s'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:E1866618CC43614CB58AD0ACCEACC465
      SHA1:9548B4B903DCADBEDFC7D8DFE1291C7579A89D7A
      SHA-256:7A1ADEF9506B722B595E3EF35CBE5FD20A7CB7944781796D990C43F9F18460CE
      SHA-512:1CCC98A2001A94951A227F69B7633ADCE57C53385F73A7D67A75C014CB145595A2F22423F8DFF390788272B063CC777ED73B4E5CE6F67A68B348145826C590DE
      Malicious:false
      Reputation:unknown
      Preview:........<...........S...........(.......).......=.......K.......R.......W......._.......j.......r...........................................................................................................................e...#...........................................................:...................!.......'......./.......6.......;.......@.......N.......Z.......c.......u.......{...................%.......................................................,...........E.......Z.......h.......s.......{...0...................................................................................*.......;.......G.......R.......V.......`.......m.......r.......z...........................................p...........h.......w.......~...................................D...........................................#.......*.......5.......F.......P.......Z.......k.......t...................2.......................................................9...:.......t...............................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 60 messages, Project-Id-Version: Delphi 'Chyba %s %s: (%d)%s'
      Category:dropped
      Size (bytes):3534
      Entropy (8bit):5.208989802280141
      Encrypted:false
      SSDEEP:
      MD5:E1866618CC43614CB58AD0ACCEACC465
      SHA1:9548B4B903DCADBEDFC7D8DFE1291C7579A89D7A
      SHA-256:7A1ADEF9506B722B595E3EF35CBE5FD20A7CB7944781796D990C43F9F18460CE
      SHA-512:1CCC98A2001A94951A227F69B7633ADCE57C53385F73A7D67A75C014CB145595A2F22423F8DFF390788272B063CC777ED73B4E5CE6F67A68B348145826C590DE
      Malicious:false
      Reputation:unknown
      Preview:........<...........S...........(.......).......=.......K.......R.......W......._.......j.......r...........................................................................................................................e...#...........................................................:...................!.......'......./.......6.......;.......@.......N.......Z.......c.......u.......{...................%.......................................................,...........E.......Z.......h.......s.......{...0...................................................................................*.......;.......G.......R.......V.......`.......m.......r.......z...........................................p...........h.......w.......~...................................D...........................................#.......*.......5.......F.......P.......Z.......k.......t...................2.......................................................9...:.......t...............................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3203 messages, Project-Id-Version: SyncBackPro v10 '%s je pozastaven'
      Category:dropped
      Size (bytes):342803
      Entropy (8bit):5.488824772138423
      Encrypted:false
      SSDEEP:
      MD5:7D69A2E81A51E64E8C77BE0C05716006
      SHA1:C5EAB6D5355AF6D07D0EFC90D9623F940B581FF2
      SHA-256:1098B25F345E800E0F085A8EB0F85B5E93FE3133AB01D148956141EADF0447FE
      SHA-512:5053B6056BEC63FAF9F57DD5AA236606A1F15CF5626539A03C146C427013BBDAFF6EFE109F6814113FF29E0183A75C17D546F0F38D8E0DBAC11D5117D522C36E
      Malicious:false
      Reputation:unknown
      Preview:................4d......L...............................,.......C.......].......{.......X... ...........5.......N.......c...............|...M...........O.......k...,...|...........!.......................%.......%...8...!...^...................#...3.......W...+...r...........J.......^...........R.......^.......v...................m...........................&.......3.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'...%...T.......z...................................%....................... ......................................./...........J.......Q.......W.......c.......k.......s.......x...................................................................................d.......V...........................................................$...5...,...7...b...................7...............%...........$.......*.......4.......<.......E...e...X...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3055 messages, Project-Id-Version: SyncBackPro/SE '"%s" er sat p\303\245 pause'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:3B7A605B60FCAEEB6E8461C33981D862
      SHA1:73A8DF40760960BF42C9BC2C5A5FD2F44180C080
      SHA-256:65F02179C24035D8B91D74BCFEB8AB20A4E50F2C98DA11A78FAC376994593E1D
      SHA-512:4ED8A09876865EBD5BD171DE0D3E954FAC7C985A60AC24F0E08A532559C45E7B03D1C8931A92A361E710A88A9B65C820B0C382BDFE90B9DB78E18FA2F163AD7E
      Malicious:false
      Reputation:unknown
      Preview:................._..............................................................#........... ...........................................$...M...............,...........@...!...U.......w...........%.......%.......!.......................#...............+...........5...J...?...^...........................................,...m...5..................................................."...........".......8...0...N...........-...............&.......1.......(...>...&...g... ...............).......:.......@...3...I...t...,.......%...................-.......J.......g.......o...%...................E... ...].......~.........................../........................................................................... .......8.......G.......U.......j.......r.......z...................d.......V...........o.......|...........................................5.......7...........1.......9...7...E.......}...%...............................................e...........U......._.......g.......o...K...........
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3408 messages, Project-Id-Version: Delphi 2005 RTL
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:3FE389C1024B354D40980B1AB4D7F80F
      SHA1:9F57A0FA14B315348E4CF7A383F86DD683B194A3
      SHA-256:EEFF9C707CD32D9E8771C2CBE6C343B24AA873BE67E0293317C99C0672605758
      SHA-512:968A47958D95491F4893F3ABE08FAAFAAF15E4FDE1F0A032529A6BAAAD859BB86D3FC1B3DCB44BE53F460A7A01C806AEE3D52FFB114666D1C839CFF61F42FE14
      Malicious:false
      Reputation:unknown
      Preview:........P........j..............(.......)...#...+.......O.......m...).......%......."...............,.......;...H...).......................................".......'...>.......f.......l.......r........................... ...................................................................1.......H.......[...3...f...................................................!............ ......= ..+...L ......x ..).... ....... ....... ..#.... .......!......&!......A!..1...\!.......!..$....!.......!..0....!..(...."......H"..E..._".."...."..-...."..E...."......<#......?#......S#......d#......l#......|#../....#.......#.......#.......#..*....#......#$......1$......I$......i$......v$..1....$..1....$.......$.......%......)%.. ...B%..!...c%.......%.......%.......%.......%..)....%.......&.. ....&..U...<&..Y....&..Y....&..Y...F'..Y....'.......'.......(......$(......@(......^(......{(.......(..E....(..*....(......#)......A)..$...O)......t)......})..(....).......).......).......).......).......).......*......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3055 messages, Project-Id-Version: SyncBackPro/SE '"%s" er sat p\303\245 pause'
      Category:dropped
      Size (bytes):320489
      Entropy (8bit):5.245762204478095
      Encrypted:false
      SSDEEP:
      MD5:3B7A605B60FCAEEB6E8461C33981D862
      SHA1:73A8DF40760960BF42C9BC2C5A5FD2F44180C080
      SHA-256:65F02179C24035D8B91D74BCFEB8AB20A4E50F2C98DA11A78FAC376994593E1D
      SHA-512:4ED8A09876865EBD5BD171DE0D3E954FAC7C985A60AC24F0E08A532559C45E7B03D1C8931A92A361E710A88A9B65C820B0C382BDFE90B9DB78E18FA2F163AD7E
      Malicious:false
      Reputation:unknown
      Preview:................._..............................................................#........... ...........................................$...M...............,...........@...!...U.......w...........%.......%.......!.......................#...............+...........5...J...?...^...........................................,...m...5..................................................."...........".......8...0...N...........-...............&.......1.......(...>...&...g... ...............).......:.......@...3...I...t...,.......%...................-.......J.......g.......o...%...................E... ...].......~.........................../........................................................................... .......8.......G.......U.......j.......r.......z...................d.......V...........o.......|...........................................5.......7...........1.......9...7...E.......}...%...............................................e...........U......._.......g.......o...K...........
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3408 messages, Project-Id-Version: Delphi 2005 RTL
      Category:dropped
      Size (bytes):275486
      Entropy (8bit):5.384289872434793
      Encrypted:false
      SSDEEP:
      MD5:3FE389C1024B354D40980B1AB4D7F80F
      SHA1:9F57A0FA14B315348E4CF7A383F86DD683B194A3
      SHA-256:EEFF9C707CD32D9E8771C2CBE6C343B24AA873BE67E0293317C99C0672605758
      SHA-512:968A47958D95491F4893F3ABE08FAAFAAF15E4FDE1F0A032529A6BAAAD859BB86D3FC1B3DCB44BE53F460A7A01C806AEE3D52FFB114666D1C839CFF61F42FE14
      Malicious:false
      Reputation:unknown
      Preview:........P........j..............(.......)...#...+.......O.......m...).......%......."...............,.......;...H...).......................................".......'...>.......f.......l.......r........................... ...................................................................1.......H.......[...3...f...................................................!............ ......= ..+...L ......x ..).... ....... ....... ..#.... .......!......&!......A!..1...\!.......!..$....!.......!..0....!..(...."......H"..E..._".."...."..-...."..E...."......<#......?#......S#......d#......l#......|#../....#.......#.......#.......#..*....#......#$......1$......I$......i$......v$..1....$..1....$.......$.......%......)%.. ...B%..!...c%.......%.......%.......%.......%..)....%.......&.. ....&..U...<&..Y....&..Y....&..Y...F'..Y....'.......'.......(......$(......@(......^(......{(.......(..E....(..*....(......#)......A)..$...O)......t)......})..(....).......).......).......).......).......).......*......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4286
      Entropy (8bit):4.582430460451203
      Encrypted:false
      SSDEEP:
      MD5:456B3872D797C603FA9BB6066DBE95A7
      SHA1:9FFEC6A1EB4814CC6E7297DD4DBC913B813F1C0C
      SHA-256:068087C85966D1E9851BB5712A917C3EFD2AE3C262A8AD3AD873A1D7009C0FBC
      SHA-512:C373C3718C705254028FBDA45205598E7236C71D891419363A63EF7669B188C0EA579967A421BC34A8FB6CA823FF20BEF7BB7CEBE662A4DFF7A9B6D531E76844
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......K.......U.......^.......o.......v.......~...............................................................................................................(.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:456B3872D797C603FA9BB6066DBE95A7
      SHA1:9FFEC6A1EB4814CC6E7297DD4DBC913B813F1C0C
      SHA-256:068087C85966D1E9851BB5712A917C3EFD2AE3C262A8AD3AD873A1D7009C0FBC
      SHA-512:C373C3718C705254028FBDA45205598E7236C71D891419363A63EF7669B188C0EA579967A421BC34A8FB6CA823FF20BEF7BB7CEBE662A4DFF7A9B6D531E76844
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......K.......U.......^.......o.......v.......~...............................................................................................................(.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3202 messages, Project-Id-Version: SyncBackSE '"%s" ist pausiert'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:11A6F86EA589B305742BA7C584D00CA0
      SHA1:3DA81DFC0CC17E988C986ED9EF8FFE7DD6FB61D8
      SHA-256:37E886D7A60CC5508A0C5482822CA73D7E104EBF84DBB2F7517C9EEDB7A6F12C
      SHA-512:693023F027DCACB0AAC9D65D3C4BC61CEA1D43311FCCF98F109B728838BF4B550894AA1B2FADB595BA9C0158A7175F62AD770D0E2169E2F2C9802663A7115851
      Malicious:false
      Reputation:unknown
      Preview:................,d......<.......................................3.......M.......k.......H... ...........%.......>.......S...............l...M...........?.......[...,...l...........!.......................%.......%...(...!...N.......p...........#...#.......G...+...b...........J.......^...........B.......N.......f.......q...........m...................................#.......;.......B..."...X.......{...........0...............-...............&...>...1...e...(.......&....... ...............)...'...:...Q...@.......I.......,.......%...D.......j...................................%....................... ......................................./...........:.......A.......G.......S.......[.......c.......h.......p.......y...................................................................d.......V...q...........................................................5.......7...R...................7...............%...........................$.......,.......5...e...H...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2848 messages, Project-Id-Version: Delphi7 german ' B&ilder '
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:ECB112A56EC558F7F9A1BDD8C318D099
      SHA1:B8BF56035A9E46DB48BD80A3BBE21CCAD6366E92
      SHA-256:3A9FBA20D2817CF0623FBDDDBC9ED045E5215A51441B745C16D4A985AC6A58C2
      SHA-512:A754B20589DC8A36D6B6D46B9EA720326016E59C2D85D5B75B6FF54AF9714607707F851C611C198FE87E797D8AEEF3F2B38ECD7B146A1EAC8FFFC7F6EBA37DEF
      Malicious:false
      Reputation:unknown
      Preview:........ ........Y..............p.......q.......{.......................................................................................,...!...E.......g...................B.......>...........-...)...K.../...u...................".......1...........'...$...E.......j...0.......(.......................E......."...D...-...g...E.............................................../...........K.......\.......l...*...............................1.......1...........L.......d.......|... .......!.......................................)...,... ...V.......w...U...................................2.......O...E...j...*.......$...................................0.......C.......M.......].......p...........................................................$... .......E.......\.......r.......z...............................................................................................................................".......'.......:.......A.......N.......W.......l.......r.......~...............................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2848 messages, Project-Id-Version: Delphi7 german ' B&ilder '
      Category:dropped
      Size (bytes):240534
      Entropy (8bit):5.390676879251821
      Encrypted:false
      SSDEEP:
      MD5:ECB112A56EC558F7F9A1BDD8C318D099
      SHA1:B8BF56035A9E46DB48BD80A3BBE21CCAD6366E92
      SHA-256:3A9FBA20D2817CF0623FBDDDBC9ED045E5215A51441B745C16D4A985AC6A58C2
      SHA-512:A754B20589DC8A36D6B6D46B9EA720326016E59C2D85D5B75B6FF54AF9714607707F851C611C198FE87E797D8AEEF3F2B38ECD7B146A1EAC8FFFC7F6EBA37DEF
      Malicious:false
      Reputation:unknown
      Preview:........ ........Y..............p.......q.......{.......................................................................................,...!...E.......g...................B.......>...........-...)...K.../...u...................".......1...........'...$...E.......j...0.......(.......................E......."...D...-...g...E.............................................../...........K.......\.......l...*...............................1.......1...........L.......d.......|... .......!.......................................)...,... ...V.......w...U...................................2.......O...E...j...*.......$...................................0.......C.......M.......].......p...........................................................$... .......E.......\.......r.......z...............................................................................................................................".......'.......:.......A.......N.......W.......l.......r.......~...............................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3202 messages, Project-Id-Version: SyncBackSE '"%s" ist pausiert'
      Category:dropped
      Size (bytes):352835
      Entropy (8bit):5.2603622893682775
      Encrypted:false
      SSDEEP:
      MD5:11A6F86EA589B305742BA7C584D00CA0
      SHA1:3DA81DFC0CC17E988C986ED9EF8FFE7DD6FB61D8
      SHA-256:37E886D7A60CC5508A0C5482822CA73D7E104EBF84DBB2F7517C9EEDB7A6F12C
      SHA-512:693023F027DCACB0AAC9D65D3C4BC61CEA1D43311FCCF98F109B728838BF4B550894AA1B2FADB595BA9C0158A7175F62AD770D0E2169E2F2C9802663A7115851
      Malicious:false
      Reputation:unknown
      Preview:................,d......<.......................................3.......M.......k.......H... ...........%.......>.......S...............l...M...........?.......[...,...l...........!.......................%.......%...(...!...N.......p...........#...#.......G...+...b...........J.......^...........B.......N.......f.......q...........m...................................#.......;.......B..."...X.......{...........0...............-...............&...>...1...e...(.......&....... ...............)...'...:...Q...@.......I.......,.......%...D.......j...................................%....................... ......................................./...........:.......A.......G.......S.......[.......c.......h.......p.......y...................................................................d.......V...q...........................................................5.......7...R...................7...............%...........................$.......,.......5...e...H...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4352
      Entropy (8bit):4.614013855014573
      Encrypted:false
      SSDEEP:
      MD5:D63A5EE496F208308E94FCBACD6EA62A
      SHA1:B619EC88A42D61AD957372EF4029D026438B68B5
      SHA-256:C6085E05B69A162A41760CFC0EE30A9AD7210D1FE9118DA4BC6B96074585D630
      SHA-512:E8DF8C70C1E9AA7B2BB0D3B10D453E6BA41AE0F7ABC772D939541B5654CEF3D1820814AE09E053C8B54CBDCBD7BF18E3954019D36344C8C8C3C7B84964155E23
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......K.......U.......^.......o.......v............................................................................................................... .......,.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:D63A5EE496F208308E94FCBACD6EA62A
      SHA1:B619EC88A42D61AD957372EF4029D026438B68B5
      SHA-256:C6085E05B69A162A41760CFC0EE30A9AD7210D1FE9118DA4BC6B96074585D630
      SHA-512:E8DF8C70C1E9AA7B2BB0D3B10D453E6BA41AE0F7ABC772D939541B5654CEF3D1820814AE09E053C8B54CBDCBD7BF18E3954019D36344C8C8C3C7B84964155E23
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......K.......U.......^.......o.......v............................................................................................................... .......,.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3204 messages, Project-Id-Version: SyncBac-GR '\316\244\316\277 "%s" \316\265\316\257\316\275\316\261\316\271 \317\203\316\265 \317\200\316\261\317\215\317\203\316\267'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:D9E4F328CDF997708131D6567313F284
      SHA1:5C479F61988C944AEBADD29C34CEAA8FF1FF26E9
      SHA-256:4D92643B6EE9485656DE48FA40F757248B847DD71156D2DADF65A4D4CB76D311
      SHA-512:153455086532F8DD4CB9C818959E2A8C19EF9B77A5152BEEE662772A526F31E5489144CA49A23F0BB597B0FF4AAC90DD89FCD3E13048978755C46C58BEE14F14
      Malicious:false
      Reputation:unknown
      Preview:................<d......\....... .......!.......0.......D.......[.......u...............p... ...,.......M.......f.......{...................M...........g...........,...............!.......................%...*...%...P...!...v.............../...#...K.......o...+...............J.......^...........j.......v...........................m...........$.......0.......>.......K.......c.......j...".......................0...............-...........7...&...f...1.......(.......&....... ...........0...)...O...:...y...@.......I.......,...?...%...l...........................................%...........1........... ...........................&.......+.../...2.......b.......i.......o.......{.......................................................................................................#...d...4...V...........................................'.......-.......<...5...D...7...z...................7...............%...........<.......B.......L.......T.......]...e...p...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 5 messages, Project-Id-Version: '\316\225\317\200\316\271\316\262\316\265\316\262\316\261\316\257\317\211\317\203\316\267'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9FDEDB725110B1C82D33DA89FDF9A8B5
      SHA1:A335F1A674EA2D6226B3DDF4751A24C398B726E9
      SHA-256:7DEDE80B81773C2BC8E52F7DF52A2B2273551D6D827B791A4191B45DCF70A98B
      SHA-512:C926DE7BF7EC17892C0B3AD7141E4C3316788A4A6B597BF3A304A1FFBF09FA3FF477AC1CFD36EC4CE51C9E2C02C4E6934192B5CD19562F0BC644720A8FB6A701
      Malicious:false
      Reputation:unknown
      Preview:................D.......l...........................................%................................... ................................Confirm.Information.Warning.Yes to &All.Project-Id-Version: .POT-Creation-Date: 2006-08-04 12:26.PO-Revision-Date: 2017-05-29 18:47+0800.Last-Translator: Somebody <your.email@address.com>.MIME-Version: 1.0.Content-Type: text/plain; charset=UTF-8.Content-Transfer-Encoding: 8bit.X-Generator: Poedit 2.0.2.Language-Team: .Language: el..........................................., ... ......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3204 messages, Project-Id-Version: SyncBac-GR '\316\244\316\277 "%s" \316\265\316\257\316\275\316\261\316\271 \317\203\316\265 \317\200\316\261\317\215\317\203\316\267'
      Category:dropped
      Size (bytes):489323
      Entropy (8bit):5.416255658993801
      Encrypted:false
      SSDEEP:
      MD5:D9E4F328CDF997708131D6567313F284
      SHA1:5C479F61988C944AEBADD29C34CEAA8FF1FF26E9
      SHA-256:4D92643B6EE9485656DE48FA40F757248B847DD71156D2DADF65A4D4CB76D311
      SHA-512:153455086532F8DD4CB9C818959E2A8C19EF9B77A5152BEEE662772A526F31E5489144CA49A23F0BB597B0FF4AAC90DD89FCD3E13048978755C46C58BEE14F14
      Malicious:false
      Reputation:unknown
      Preview:................<d......\....... .......!.......0.......D.......[.......u...............p... ...,.......M.......f.......{...................M...........g...........,...............!.......................%...*...%...P...!...v.............../...#...K.......o...+...............J.......^...........j.......v...........................m...........$.......0.......>.......K.......c.......j...".......................0...............-...........7...&...f...1.......(.......&....... ...........0...)...O...:...y...@.......I.......,...?...%...l...........................................%...........1........... ...........................&.......+.../...2.......b.......i.......o.......{.......................................................................................................#...d...4...V...........................................'.......-.......<...5...D...7...z...................7...............%...........<.......B.......L.......T.......]...e...p...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4526
      Entropy (8bit):4.844448029698703
      Encrypted:false
      SSDEEP:
      MD5:98980FFDAD15D4F7B7982F3EF8BD8AEF
      SHA1:2A6E9E9CED05B65A7B055AF06845CD6FBBECB730
      SHA-256:E466F81859808A78D98D4CC7681C3AA9A4E8AA1624D04BE9C94F8D35A380A77E
      SHA-512:55C7AFD99D3FFFE917A55D89A97175C2827033A714CC6B97106F4061ED238A621F096890CBBADA97EBA78DDA4CA99BE6DBFD2D953854FF6BDA4513B8C89E087E
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................U...........B.......L.......V......._.......p.......w...............................................................................................................(.......=.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 5 messages, Project-Id-Version: '\316\225\317\200\316\271\316\262\316\265\316\262\316\261\316\257\317\211\317\203\316\267'
      Category:dropped
      Size (bytes):570
      Entropy (8bit):5.460419491679814
      Encrypted:false
      SSDEEP:
      MD5:9FDEDB725110B1C82D33DA89FDF9A8B5
      SHA1:A335F1A674EA2D6226B3DDF4751A24C398B726E9
      SHA-256:7DEDE80B81773C2BC8E52F7DF52A2B2273551D6D827B791A4191B45DCF70A98B
      SHA-512:C926DE7BF7EC17892C0B3AD7141E4C3316788A4A6B597BF3A304A1FFBF09FA3FF477AC1CFD36EC4CE51C9E2C02C4E6934192B5CD19562F0BC644720A8FB6A701
      Malicious:false
      Reputation:unknown
      Preview:................D.......l...........................................%................................... ................................Confirm.Information.Warning.Yes to &All.Project-Id-Version: .POT-Creation-Date: 2006-08-04 12:26.PO-Revision-Date: 2017-05-29 18:47+0800.Last-Translator: Somebody <your.email@address.com>.MIME-Version: 1.0.Content-Type: text/plain; charset=UTF-8.Content-Transfer-Encoding: 8bit.X-Generator: Poedit 2.0.2.Language-Team: .Language: el..........................................., ... ......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:98980FFDAD15D4F7B7982F3EF8BD8AEF
      SHA1:2A6E9E9CED05B65A7B055AF06845CD6FBBECB730
      SHA-256:E466F81859808A78D98D4CC7681C3AA9A4E8AA1624D04BE9C94F8D35A380A77E
      SHA-512:55C7AFD99D3FFFE917A55D89A97175C2827033A714CC6B97106F4061ED238A621F096890CBBADA97EBA78DDA4CA99BE6DBFD2D953854FF6BDA4513B8C89E087E
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................U...........B.......L.......V......._.......p.......w...............................................................................................................(.......=.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3193 messages, Project-Id-Version: SyncBackSE '"%s" pausado'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:FAC99D6D26EB123A0F130C2E3C3A09A6
      SHA1:6FBCB16B1ECB61435E732E9012FB28B7A9062EA4
      SHA-256:8268717200AD9B07B925F9CCD402BB5D0E183164C8153CE1FF8B574B5471A471
      SHA-512:7E64EA3E1B1F4C339ED6AE7F1FFF0438EE3AF208B77134DEE82E34B427CEC72E78F3408186F6F2334D874C369002571A4067ECC20E5CE7D32EFAA2C600844007
      Malicious:false
      Reputation:unknown
      Preview:........y........c..............8.......9.......H.......\.......s........................... ...D.......e.......~...............,...........M...1...................,...............!...................&...%...B...%...h...!...................G...#...c...........+...............J.......^...#...........................................m...........<.......H.......V.......c.......{...........".......................0...............-...!.......O...&...~...1.......(.......&....... ...'.......H...)...g...:.......@.......I.......,...W...%...............................................%...#.......I........... ...................7.......>.......C.../...J.......z.......................................................................................................................).......;...d...L...V...........................*.......3.......?.......E.......T...5...\...7.......................7...............%...........T.......Z.......d.......l.......u...e.......................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 1168 messages, Project-Id-Version: Delphi ' (%dx%d)'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:FB02C52EF6AF8FE1F326CD5D281F8546
      SHA1:11E671893D8F48EE8D32775408CA7E752D9A9F15
      SHA-256:E88A6A347BDBDA4707722C68482715593DE33D9C2CC6A9C54C4077288822C04B
      SHA-512:CFAE6C2F5C8DB7D085976489238BD04297CE6EC950D126B09E1311100A1F6AD83A552C09456D6D925CE90957D3ECD96D7F402B45B031BB6F887F7B7C00DDA08B
      Malicious:false
      Reputation:unknown
      Preview:.................$.......I......xa......ya.......a.......a.......a..!....a.......a.......b..B....b..>...Zb../....b.."....b.......b..E....b.."...8c......[c......^c......oc......}c.......c.. ....c.......c.......c.......c..*....d......?d......Hd......ad......qd.......d.......d.......d.......d.......d.......d.......d.......d.......d.......d.......e.......e......#e......5e......@e......Le......Ze......`e......he......oe.......e.......e.......e.......e.......e.......e.......e.......e.......e.......e.. ....e..!....f......%f......;f..!...Zf.."...|f.......f..!....f..(....f..!....g......%g......>g......Lg......Zg......ag......kg..!...vg.......g.......g.......g.......g.......g.......g..!....g..l....h......oh......wh.......h.......h.......h..B....h..G....h.......i......'i......Ci..;...ci..*....i..J....i..,....j......Bj......Sj......\j......bj..#...hj.......j.......j.......j.......j.......j..?....j..4....k..0...Mk......~k..$....k.......k.......k.......k.......k.......k.......k..0....k......+l..,...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 1168 messages, Project-Id-Version: Delphi ' (%dx%d)'
      Category:dropped
      Size (bytes):89709
      Entropy (8bit):5.178810511011495
      Encrypted:false
      SSDEEP:
      MD5:FB02C52EF6AF8FE1F326CD5D281F8546
      SHA1:11E671893D8F48EE8D32775408CA7E752D9A9F15
      SHA-256:E88A6A347BDBDA4707722C68482715593DE33D9C2CC6A9C54C4077288822C04B
      SHA-512:CFAE6C2F5C8DB7D085976489238BD04297CE6EC950D126B09E1311100A1F6AD83A552C09456D6D925CE90957D3ECD96D7F402B45B031BB6F887F7B7C00DDA08B
      Malicious:false
      Reputation:unknown
      Preview:.................$.......I......xa......ya.......a.......a.......a..!....a.......a.......b..B....b..>...Zb../....b.."....b.......b..E....b.."...8c......[c......^c......oc......}c.......c.. ....c.......c.......c.......c..*....d......?d......Hd......ad......qd.......d.......d.......d.......d.......d.......d.......d.......d.......d.......d.......e.......e......#e......5e......@e......Le......Ze......`e......he......oe.......e.......e.......e.......e.......e.......e.......e.......e.......e.......e.. ....e..!....f......%f......;f..!...Zf.."...|f.......f..!....f..(....f..!....g......%g......>g......Lg......Zg......ag......kg..!...vg.......g.......g.......g.......g.......g.......g..!....g..l....h......oh......wh.......h.......h.......h..B....h..G....h.......i......'i......Ci..;...ci..*....i..J....i..,....j......Bj......Sj......\j......bj..#...hj.......j.......j.......j.......j.......j..?....j..4....k..0...Mk......~k..$....k.......k.......k.......k.......k.......k.......k..0....k......+l..,...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4248
      Entropy (8bit):4.537282773993561
      Encrypted:false
      SSDEEP:
      MD5:8A41BFE854B3D4B0F2D576AD080C31BC
      SHA1:2964598BD8F793CFF12506B08B80878FCE9F2CA2
      SHA-256:F160429DAFC7B9A667980A31A686B9CE2F4A61EBB04E8F70B2E3790F8E91664D
      SHA-512:BDBE5B562DD636FCA32E735D7EA03EA11319A721A864886DC3218012ADEE52F2081F3C6D89178D350360212819C6A3E6A2623DA1DB1FC234AFD795F3E24EAC56
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................0...................'.......1.......:.......K.......R.......[.......n.......~.......................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3193 messages, Project-Id-Version: SyncBackSE '"%s" pausado'
      Category:dropped
      Size (bytes):338769
      Entropy (8bit):5.208605667445336
      Encrypted:false
      SSDEEP:
      MD5:FAC99D6D26EB123A0F130C2E3C3A09A6
      SHA1:6FBCB16B1ECB61435E732E9012FB28B7A9062EA4
      SHA-256:8268717200AD9B07B925F9CCD402BB5D0E183164C8153CE1FF8B574B5471A471
      SHA-512:7E64EA3E1B1F4C339ED6AE7F1FFF0438EE3AF208B77134DEE82E34B427CEC72E78F3408186F6F2334D874C369002571A4067ECC20E5CE7D32EFAA2C600844007
      Malicious:false
      Reputation:unknown
      Preview:........y........c..............8.......9.......H.......\.......s........................... ...D.......e.......~...............,...........M...1...................,...............!...................&...%...B...%...h...!...................G...#...c...........+...............J.......^...#...........................................m...........<.......H.......V.......c.......{...........".......................0...............-...!.......O...&...~...1.......(.......&....... ...'.......H...)...g...:.......@.......I.......,...W...%...............................................%...#.......I........... ...................7.......>.......C.../...J.......z.......................................................................................................................).......;...d...L...V...........................*.......3.......?.......E.......T...5...\...7.......................7...............%...........T.......Z.......d.......l.......u...e.......................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:8A41BFE854B3D4B0F2D576AD080C31BC
      SHA1:2964598BD8F793CFF12506B08B80878FCE9F2CA2
      SHA-256:F160429DAFC7B9A667980A31A686B9CE2F4A61EBB04E8F70B2E3790F8E91664D
      SHA-512:BDBE5B562DD636FCA32E735D7EA03EA11319A721A864886DC3218012ADEE52F2081F3C6D89178D350360212819C6A3E6A2623DA1DB1FC234AFD795F3E24EAC56
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................0...................'.......1.......:.......K.......R.......[.......n.......~.......................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3203 messages, Project-Id-Version: FINNISH TRANSLATION '"%s" tauotetaan'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:B85B95A98F2F3686B8AB16E6F39ED969
      SHA1:5E8BE9C6F53D2276D52DE4647D403E168430049F
      SHA-256:13CF13132FC75650747E6AB3D084586EDA6C6DDA7EB8D0E6F1C0A569182DCE7B
      SHA-512:AA5758297773690B1CAD8B2E8DDABA871F6EC9EA9E3388FBBAD67D7E50D4279889843B5AE1283E23FD0D19F66EF4CF2583893AF5A417B0049D3125BD60847FC3
      Malicious:false
      Reputation:unknown
      Preview:................4d......L...............................,.......C.......].......{.......X... ...........5.......N.......c...............|...M...........O.......k...,...|...........!.......................%.......%...8...!...^...................#...3.......W...+...r...........J.......^...........R.......^.......v...................m...........................&.......3.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'...%...T.......z...................................%....................... ......................................./...........J.......Q.......W.......c.......k.......s.......x...................................................................................d.......V...........................................................$...5...,...7...b...................7...............%...........$.......*.......4.......<.......E...e...X...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 80 messages, Project-Id-Version: FINNISH TRANSLATION 'Keskeyt\303\244'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:D31FC91FD8D21086E9299FA142D1A70F
      SHA1:16F6258008036D08AD33D232CA940FAA8C2B28AB
      SHA-256:CEB9028E6CFD89140F4F8C86CF5F45D417477E593A2851EB45AB3244B2DBF6A8
      SHA-512:A274F8D1839EEAD33F895FBC299C5376DAEF969491730465464678B2F0B22F993956023A50F220BA515584350AA5532449E33F648DCA08BF8EE0AF1C399F7B7C
      Malicious:false
      Reputation:unknown
      Preview:........P...........k...........................................................................................................................#.......-.......6.......<.......A.......I.......U.......[.......m.......t.......|...............................................................................................................................-.......@.......R.......e.......~...............................................................................................................................................................$.......-.......9.......F.......R.......W.......\.......n.......s...........................................................s...........6.......@.......K.......T.......].......c.......j.......o.......v.......................................................................................................................................................).......1.......<.......D.......N.......X.......f.......k.......q.......w...............................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 80 messages, Project-Id-Version: FINNISH TRANSLATION 'Keskeyt\303\244'
      Category:dropped
      Size (bytes):3772
      Entropy (8bit):4.87355684518494
      Encrypted:false
      SSDEEP:
      MD5:D31FC91FD8D21086E9299FA142D1A70F
      SHA1:16F6258008036D08AD33D232CA940FAA8C2B28AB
      SHA-256:CEB9028E6CFD89140F4F8C86CF5F45D417477E593A2851EB45AB3244B2DBF6A8
      SHA-512:A274F8D1839EEAD33F895FBC299C5376DAEF969491730465464678B2F0B22F993956023A50F220BA515584350AA5532449E33F648DCA08BF8EE0AF1C399F7B7C
      Malicious:false
      Reputation:unknown
      Preview:........P...........k...........................................................................................................................#.......-.......6.......<.......A.......I.......U.......[.......m.......t.......|...............................................................................................................................-.......@.......R.......e.......~...............................................................................................................................................................$.......-.......9.......F.......R.......W.......\.......n.......s...........................................................s...........6.......@.......K.......T.......].......c.......j.......o.......v.......................................................................................................................................................).......1.......<.......D.......N.......X.......f.......k.......q.......w...............................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3203 messages, Project-Id-Version: FINNISH TRANSLATION '"%s" tauotetaan'
      Category:dropped
      Size (bytes):344594
      Entropy (8bit):5.262988411947254
      Encrypted:false
      SSDEEP:
      MD5:B85B95A98F2F3686B8AB16E6F39ED969
      SHA1:5E8BE9C6F53D2276D52DE4647D403E168430049F
      SHA-256:13CF13132FC75650747E6AB3D084586EDA6C6DDA7EB8D0E6F1C0A569182DCE7B
      SHA-512:AA5758297773690B1CAD8B2E8DDABA871F6EC9EA9E3388FBBAD67D7E50D4279889843B5AE1283E23FD0D19F66EF4CF2583893AF5A417B0049D3125BD60847FC3
      Malicious:false
      Reputation:unknown
      Preview:................4d......L...............................,.......C.......].......{.......X... ...........5.......N.......c...............|...M...........O.......k...,...|...........!.......................%.......%...8...!...^...................#...3.......W...+...r...........J.......^...........R.......^.......v...................m...........................&.......3.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'...%...T.......z...................................%....................... ......................................./...........J.......Q.......W.......c.......k.......s.......x...................................................................................d.......V...........................................................$...5...,...7...b...................7...............%...........$.......*.......4.......<.......E...e...X...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4280
      Entropy (8bit):4.567196530517316
      Encrypted:false
      SSDEEP:
      MD5:2C4FB567A30D12066C8EE66A78D057B2
      SHA1:9B6F74D3C3F82515B07FF851B0A68818407C3260
      SHA-256:31DE7BB75CE1AB277745C6ACC98D4B250BDED9E7982AD916247AA38F38CEA17A
      SHA-512:51BA28698E07823FDFF89384EFD1A0967975ADC02F6E14050551AD8F19593F64C24018A4ED4CD91B4B3992809C4B67F63C3A63D4CE0E940710E29925D52D70A1
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................^...........K.......U......._.......h.......y.......................................................................................................................(.......2.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:2C4FB567A30D12066C8EE66A78D057B2
      SHA1:9B6F74D3C3F82515B07FF851B0A68818407C3260
      SHA-256:31DE7BB75CE1AB277745C6ACC98D4B250BDED9E7982AD916247AA38F38CEA17A
      SHA-512:51BA28698E07823FDFF89384EFD1A0967975ADC02F6E14050551AD8F19593F64C24018A4ED4CD91B4B3992809C4B67F63C3A63D4CE0E940710E29925D52D70A1
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................^...........K.......U......._.......h.......y.......................................................................................................................(.......2.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3191 messages, Project-Id-Version: SyncBack V8.0 '"%s" est interrompu'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:344CCEFD13F77C3B839B592440399B52
      SHA1:EB269D2D56FFC86D694D24402D948C48EA00F426
      SHA-256:9EE2ED76F24441BFB524A0EF5130372277BCE2ECB8F2EA72845447B896D62FE8
      SHA-512:E425650F4C06178783E599D305EB1F975FD1843802039B28A4DB63F15946C91783884299EF9E5429C1F7D10C587ED50EBAF7FAD438DEAAFF082DCC547BE479DD
      Malicious:false
      Reputation:unknown
      Preview:........w........c..............................(.......<.......S.......m...............h... ...$.......E.......^.......s...................M..........._.......{...,...............!.......................%..."...%...H...!...n...............'...#...C.......g...+...............J.......^...........b.......n...........................m...................(.......6.......C.......[.......b..."...x...................0...............-.........../...&...^...1.......(.......&....... ...........(...)...G...:...q...@.......I.......,...7...%...d...........................................%...........)........... ...................................#.../...*.......Z.......a.......g.......s.......{...................................................................................................d...,...V...................................................%.......4...5...<...7...r...................7...............%...........4.......:.......D.......L.......U...e...h...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2847 messages, Project-Id-Version: ' &Images '
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:97F4884172D0E7E43CC81D25B02F3046
      SHA1:E4233E22A5B8200C22785B944961679E7A06E684
      SHA-256:CC108A410A620ED9CA6969F45D362FEA5D87424AD840FBA25FB74969C3EBD4E9
      SHA-512:612F500BD564A4C541F6BA06A9A666199B587E325026304942D3A82A9A9C79D851C0343D7A12DB75957681E3207351CDE63358C7DACB8C191AAD13F7AD668937
      Malicious:false
      Reputation:unknown
      Preview:.................Y..............`.......a.......k.......}...................................................................................!...5.......W.......w...........B.......>...............)...;.../...e...................".......1...............$...5.......Z...0...w...(.......................E......."...4...-...W...E.............................................../...........;.......L.......\...*...s...........................1.......1...........<.......T.......l... .......!.......................................)....... ...F.......g...U...................................".......?...E...Z...*.......$................................... .......3.......=.......M.......`.......r.......~...........................................$...........5.......L.......b.......j.......q.......x...............................................................................................................................*.......1.......>.......G.......\.......b.......n.......y.......................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2847 messages, Project-Id-Version: ' &Images '
      Category:dropped
      Size (bytes):241953
      Entropy (8bit):5.340677160822171
      Encrypted:false
      SSDEEP:
      MD5:97F4884172D0E7E43CC81D25B02F3046
      SHA1:E4233E22A5B8200C22785B944961679E7A06E684
      SHA-256:CC108A410A620ED9CA6969F45D362FEA5D87424AD840FBA25FB74969C3EBD4E9
      SHA-512:612F500BD564A4C541F6BA06A9A666199B587E325026304942D3A82A9A9C79D851C0343D7A12DB75957681E3207351CDE63358C7DACB8C191AAD13F7AD668937
      Malicious:false
      Reputation:unknown
      Preview:.................Y..............`.......a.......k.......}...................................................................................!...5.......W.......w...........B.......>...............)...;.../...e...................".......1...............$...5.......Z...0...w...(.......................E......."...4...-...W...E.............................................../...........;.......L.......\...*...s...........................1.......1...........<.......T.......l... .......!.......................................)....... ...F.......g...U...................................".......?...E...Z...*.......$................................... .......3.......=.......M.......`.......r.......~...........................................$...........5.......L.......b.......j.......q.......x...............................................................................................................................*.......1.......>.......G.......\.......b.......n.......y.......................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3191 messages, Project-Id-Version: SyncBack V8.0 '"%s" est interrompu'
      Category:dropped
      Size (bytes):360777
      Entropy (8bit):5.212464362382218
      Encrypted:false
      SSDEEP:
      MD5:344CCEFD13F77C3B839B592440399B52
      SHA1:EB269D2D56FFC86D694D24402D948C48EA00F426
      SHA-256:9EE2ED76F24441BFB524A0EF5130372277BCE2ECB8F2EA72845447B896D62FE8
      SHA-512:E425650F4C06178783E599D305EB1F975FD1843802039B28A4DB63F15946C91783884299EF9E5429C1F7D10C587ED50EBAF7FAD438DEAAFF082DCC547BE479DD
      Malicious:false
      Reputation:unknown
      Preview:........w........c..............................(.......<.......S.......m...............h... ...$.......E.......^.......s...................M..........._.......{...,...............!.......................%..."...%...H...!...n...............'...#...C.......g...+...............J.......^...........b.......n...........................m...................(.......6.......C.......[.......b..."...x...................0...............-.........../...&...^...1.......(.......&....... ...........(...)...G...:...q...@.......I.......,...7...%...d...........................................%...........)........... ...................................#.../...*.......Z.......a.......g.......s.......{...................................................................................................d...,...V...................................................%.......4...5...<...7...r...................7...............%...........4.......:.......D.......L.......U...e...h...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4255
      Entropy (8bit):4.538779083914569
      Encrypted:false
      SSDEEP:
      MD5:554D7539A9FC012641AE5ADFC73AEDC9
      SHA1:0E6421837E50C71B875A2AF87C71299B96035DF3
      SHA-256:D62C56077EA91A5175040E7FC0DB73C1F57AD51A6E179410C56FFC5F123E0D59
      SHA-512:6FF40CB5485689647F079D0AE4B9973ADFD02B9E47954E0D56A762570A1A3DACCADEB91F813B48794746244C8AE9B36EDE67E1BC1F05B7F5DDD0072C82021C05
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................4...........!.......+.......5.......>.......O.......V......._.......r...............................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:554D7539A9FC012641AE5ADFC73AEDC9
      SHA1:0E6421837E50C71B875A2AF87C71299B96035DF3
      SHA-256:D62C56077EA91A5175040E7FC0DB73C1F57AD51A6E179410C56FFC5F123E0D59
      SHA-512:6FF40CB5485689647F079D0AE4B9973ADFD02B9E47954E0D56A762570A1A3DACCADEB91F813B48794746244C8AE9B36EDE67E1BC1F05B7F5DDD0072C82021C05
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................4...........!.......+.......5.......>.......O.......V......._.......r...............................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3203 messages, Project-Id-Version: SyncBackSE 'A(z) "%s" sz\303\274netel'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:56DD9AB4337D04ECAD537B2FE0BD7A37
      SHA1:078E0382E63B13143681FBDD3EA9665541CDC30F
      SHA-256:E83862732CF8A417D7D9498A3E5BDA4DC8A402E08CEDE3E2F743A0B1D01BB5F0
      SHA-512:D49842C0837E51ABD12603D24224110FE798B444AA0DAC82B3A1A70CE397159B16985575E8DB0A548CB2325B07993281E0640C11387E68CBD6D6A34D59E47A97
      Malicious:false
      Reputation:unknown
      Preview:................4d......L...............................,.......C.......].......{.......X... ...........5.......N.......c...............|...M...........O.......k...,...|...........!.......................%.......%...8...!...^...................#...3.......W...+...r...........J.......^...........R.......^.......v...................m...........................&.......3.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'...%...T.......z...................................%....................... ......................................./...........J.......Q.......W.......c.......k.......s.......x...................................................................................d.......V...........................................................$...5...,...7...b...................7...............%...........$.......*.......4.......<.......E...e...X...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4268
      Entropy (8bit):4.609711981927702
      Encrypted:false
      SSDEEP:
      MD5:3C31737A78BE8745A8FFEAAA664E298C
      SHA1:A580B359273E865BD6707136996085AE438368FA
      SHA-256:AF048D5713F7510F2B88D7D34660203A336148BFF5A6C51D8755E770ADFED860
      SHA-512:8947DB3F45D418B4FDE25DCA928D39CD5C4F06256E31D12F3AEE95C1D18C75714166C903506C05CCC3F2E3EAE3F006F3F1D4A9689C1F755719DE28A3FD01BBAC
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................[...........H.......R.......\.......e.......v.......}...............................................................................................................&......./.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3203 messages, Project-Id-Version: SyncBackSE 'A(z) "%s" sz\303\274netel'
      Category:dropped
      Size (bytes):362511
      Entropy (8bit):5.429667094676591
      Encrypted:false
      SSDEEP:
      MD5:56DD9AB4337D04ECAD537B2FE0BD7A37
      SHA1:078E0382E63B13143681FBDD3EA9665541CDC30F
      SHA-256:E83862732CF8A417D7D9498A3E5BDA4DC8A402E08CEDE3E2F743A0B1D01BB5F0
      SHA-512:D49842C0837E51ABD12603D24224110FE798B444AA0DAC82B3A1A70CE397159B16985575E8DB0A548CB2325B07993281E0640C11387E68CBD6D6A34D59E47A97
      Malicious:false
      Reputation:unknown
      Preview:................4d......L...............................,.......C.......].......{.......X... ...........5.......N.......c...............|...M...........O.......k...,...|...........!.......................%.......%...8...!...^...................#...3.......W...+...r...........J.......^...........R.......^.......v...................m...........................&.......3.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'...%...T.......z...................................%....................... ......................................./...........J.......Q.......W.......c.......k.......s.......x...................................................................................d.......V...........................................................$...5...,...7...b...................7...............%...........$.......*.......4.......<.......E...e...X...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:3C31737A78BE8745A8FFEAAA664E298C
      SHA1:A580B359273E865BD6707136996085AE438368FA
      SHA-256:AF048D5713F7510F2B88D7D34660203A336148BFF5A6C51D8755E770ADFED860
      SHA-512:8947DB3F45D418B4FDE25DCA928D39CD5C4F06256E31D12F3AEE95C1D18C75714166C903506C05CCC3F2E3EAE3F006F3F1D4A9689C1F755719DE28A3FD01BBAC
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................[...........H.......R.......\.......e.......v.......}...............................................................................................................&......./.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3203 messages, Project-Id-Version: HY '"%s"-\325\250 \325\244\325\241\325\244\325\241\326\200\325\253 \325\264\325\245\325\273 \325\247'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:6096EED8D4F447A829CD9758B3548D34
      SHA1:6F7AE7E3E48402DF824A5129176F6A797E879ABC
      SHA-256:E0BA1EE831F4659926880644E8D3868A84C380C0D6AB300D3FCE254BAE90778B
      SHA-512:F6ACEB6141CFD16914A8F5401FF501110A552A32FD0605C0C79D7914F8C1CF7BD1096598E7461B2FDB005073CCF84E4CE70814B71554351528E6422EBFBBCAA3
      Malicious:false
      Reputation:unknown
      Preview:................4d......L...............................,.......C.......].......{.......X... ...........5.......N.......c...............|...M...........O.......k...,...|...........!.......................%.......%...8...!...^...................#...3.......W...+...r...........J.......^...........R.......^.......v...................m...........................&.......3.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'...%...T.......z...................................%....................... ......................................./...........J.......Q.......W.......c.......k.......s.......x...................................................................................d.......V...........................................................$...5...,...7...b...................7...............%...........$.......*.......4.......<.......E...e...X...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4498
      Entropy (8bit):4.8233151829294085
      Encrypted:false
      SSDEEP:
      MD5:A76CEEDD01638CE64B714126E4EB72A5
      SHA1:3028592C67D25C5F2CC4641D2B96C1BE4E3DBF7F
      SHA-256:D95837E17ED4B7BE9180BF5B3DB45D4A277DD5DAC70EB283F18161B58A124FA4
      SHA-512:778B048BFD49474FD3FFF02B48B00F4EF377A2D708217B8712764447E7FB6C114454462841201F96CFDDEAB85D7663D48383D569F750B02ED6BF2120A4B13473
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................3........... .......*.......4.......=.......N.......U.......d.......w...............................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3203 messages, Project-Id-Version: HY '"%s"-\325\250 \325\244\325\241\325\244\325\241\326\200\325\253 \325\264\325\245\325\273 \325\247'
      Category:dropped
      Size (bytes):426893
      Entropy (8bit):5.486486615785815
      Encrypted:false
      SSDEEP:
      MD5:6096EED8D4F447A829CD9758B3548D34
      SHA1:6F7AE7E3E48402DF824A5129176F6A797E879ABC
      SHA-256:E0BA1EE831F4659926880644E8D3868A84C380C0D6AB300D3FCE254BAE90778B
      SHA-512:F6ACEB6141CFD16914A8F5401FF501110A552A32FD0605C0C79D7914F8C1CF7BD1096598E7461B2FDB005073CCF84E4CE70814B71554351528E6422EBFBBCAA3
      Malicious:false
      Reputation:unknown
      Preview:................4d......L...............................,.......C.......].......{.......X... ...........5.......N.......c...............|...M...........O.......k...,...|...........!.......................%.......%...8...!...^...................#...3.......W...+...r...........J.......^...........R.......^.......v...................m...........................&.......3.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'...%...T.......z...................................%....................... ......................................./...........J.......Q.......W.......c.......k.......s.......x...................................................................................d.......V...........................................................$...5...,...7...b...................7...............%...........$.......*.......4.......<.......E...e...X...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:A76CEEDD01638CE64B714126E4EB72A5
      SHA1:3028592C67D25C5F2CC4641D2B96C1BE4E3DBF7F
      SHA-256:D95837E17ED4B7BE9180BF5B3DB45D4A277DD5DAC70EB283F18161B58A124FA4
      SHA-512:778B048BFD49474FD3FFF02B48B00F4EF377A2D708217B8712764447E7FB6C114454462841201F96CFDDEAB85D7663D48383D569F750B02ED6BF2120A4B13473
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................3........... .......*.......4.......=.......N.......U.......d.......w...............................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3336 messages, Project-Id-Version: SyncBack - Italian (06.12.2022) ''%s' \303\250 in pausa'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:29B1037DF5F7EB8C118959C3B675FFBE
      SHA1:5B069D3E322BE55EC70F51CEE105B36557FE4F27
      SHA-256:1B40863F7E8FAB748EF0282C3F46AC1900E6F6E4ABD0F66AC54977BB9719673B
      SHA-512:065907E436C222A50F72CC77D708A5F6D4B3950BA4F28D7E5B3A47243E36B2BF2A55FFAED16CAC81082F97A099E5C9C22125504EF56E1A8CE97F686CCCF53089
      Malicious:false
      Reputation:unknown
      Preview:................\h..c...........(.......).......8.......L.......c.......}...............x... ...4.......U.......n...........................M...!.......o...........,...............!.......................%...2...%...X...!...~...............7...#...S.......w...+...............J.......^...........r.......~...........................m...........,.......8.......F.......S.......k.......r...".......................0...............-...........?...&...n...1.......(.......&....... .... ......8 ..)...W ..:.... ..@...."..I...."..,...G#..%...t#.......#.......#.......#.......#.......#..%....$......9$.......$.. ....$.......%......'%.......%......3%../...:%......j%......q%......w%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......&.......&......+&..d...<&..V....&.......&.......'.......'......#'....../'......5'......D'..5...L'..7....'.......'.......'..7....'.......(..%....(......D(......J(......T(......\(......e(..e...x(.......(.......(.......(.......(..K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 394 messages, Project-Id-Version: Delphi v. 10.06.2023 ' (%dx%d)'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:F92F88C58E56F9185533A57A3A846338
      SHA1:5FF7BB5844312FEA9D70A3224DAF0DB7D0BC9438
      SHA-256:155A0E0BF55538D9F4D81F1053AEF790F27E54B9FB9D206B491AE1B2806B857A
      SHA-512:5F60E0690B6C9F0A1B4C86499F1D8B1B7D407BE37759E9E2D9924494614FA56235D5295F0EAB94625E9562E8FE60919FE8CA01A0BDDA1BC5F2DCD90F01A2105A
      Malicious:false
      Reputation:unknown
      Preview:................l...............0!......1!......:!......V!..E...m!..E....!.. ....!..*...."......E"......N"......g"......w"......."......."......."......."......."......."......."......."......."......."......."......."......."..0....#..7...E#..0...}#.......#.......#.. ....#.......$.......$.......$.......$..!...9$..l...[$..*....$.......$.......%.......%..,....%......@%......D%......Q%..e...e%.......%..Z....%.."...+&......N&......}&.......&.......&.......&.......&.......&.......&.......&.......&.......&.......&.......'..0....'..*...I'......t'..#...{'..$....'.......'..^....'..)...B(..!...l(.......(..3....(..-....(..5....)......F)..Z...Y)..+....)..2....).......*..&...1*..#...X*.."...|*..:....*..!....*.......*.......+..2..."+..1...U+..2....+..1....+..1....+..0....,..$...O,..8...t,.......,.."....,.......,.. ....-....../-......5-......=-......]-..!...s-.......-.......-.......-.......-.......-.......-.......-../....-..............0...,...M...9...z..................."............/......./../...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 394 messages, Project-Id-Version: Delphi v. 10.06.2023 ' (%dx%d)'
      Category:dropped
      Size (bytes):33177
      Entropy (8bit):4.9952840581370985
      Encrypted:false
      SSDEEP:
      MD5:F92F88C58E56F9185533A57A3A846338
      SHA1:5FF7BB5844312FEA9D70A3224DAF0DB7D0BC9438
      SHA-256:155A0E0BF55538D9F4D81F1053AEF790F27E54B9FB9D206B491AE1B2806B857A
      SHA-512:5F60E0690B6C9F0A1B4C86499F1D8B1B7D407BE37759E9E2D9924494614FA56235D5295F0EAB94625E9562E8FE60919FE8CA01A0BDDA1BC5F2DCD90F01A2105A
      Malicious:false
      Reputation:unknown
      Preview:................l...............0!......1!......:!......V!..E...m!..E....!.. ....!..*...."......E"......N"......g"......w"......."......."......."......."......."......."......."......."......."......."......."......."......."..0....#..7...E#..0...}#.......#.......#.. ....#.......$.......$.......$.......$..!...9$..l...[$..*....$.......$.......%.......%..,....%......@%......D%......Q%..e...e%.......%..Z....%.."...+&......N&......}&.......&.......&.......&.......&.......&.......&.......&.......&.......&.......&.......'..0....'..*...I'......t'..#...{'..$....'.......'..^....'..)...B(..!...l(.......(..3....(..-....(..5....)......F)..Z...Y)..+....)..2....).......*..&...1*..#...X*.."...|*..:....*..!....*.......*.......+..2..."+..1...U+..2....+..1....+..1....+..0....,..$...O,..8...t,.......,.."....,.......,.. ....-....../-......5-......=-......]-..!...s-.......-.......-.......-.......-.......-.......-.......-../....-..............0...,...M...9...z..................."............/......./../...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4310
      Entropy (8bit):4.570277050117975
      Encrypted:false
      SSDEEP:
      MD5:00B345C673C5287AF59423913042D3AA
      SHA1:B3A2EF3748E45E2C222DE03908F57FA40A57CFF8
      SHA-256:D7F57D37BC8380D4197F1B9E8C2B6AC9AE7AC1F52EC9525560377EA242C046A2
      SHA-512:A6B933C68811B9C4BCAD4F756F8E9D1CF7B02103DFF134918221EA810648583669FCB82EFAA45C48F7BF3B0CD35DCE45CB2258184ECA8D71CCAAF1A33DE1A5D6
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......K.......U.......^.......p.......v.......}.......................................................................................................$.......-.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3336 messages, Project-Id-Version: SyncBack - Italian (06.12.2022) ''%s' \303\250 in pausa'
      Category:dropped
      Size (bytes):365194
      Entropy (8bit):5.168648781310887
      Encrypted:false
      SSDEEP:
      MD5:29B1037DF5F7EB8C118959C3B675FFBE
      SHA1:5B069D3E322BE55EC70F51CEE105B36557FE4F27
      SHA-256:1B40863F7E8FAB748EF0282C3F46AC1900E6F6E4ABD0F66AC54977BB9719673B
      SHA-512:065907E436C222A50F72CC77D708A5F6D4B3950BA4F28D7E5B3A47243E36B2BF2A55FFAED16CAC81082F97A099E5C9C22125504EF56E1A8CE97F686CCCF53089
      Malicious:false
      Reputation:unknown
      Preview:................\h..c...........(.......).......8.......L.......c.......}...............x... ...4.......U.......n...........................M...!.......o...........,...............!.......................%...2...%...X...!...~...............7...#...S.......w...+...............J.......^...........r.......~...........................m...........,.......8.......F.......S.......k.......r...".......................0...............-...........?...&...n...1.......(.......&....... .... ......8 ..)...W ..:.... ..@...."..I...."..,...G#..%...t#.......#.......#.......#.......#.......#..%....$......9$.......$.. ....$.......%......'%.......%......3%../...:%......j%......q%......w%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......&.......&......+&..d...<&..V....&.......&.......'.......'......#'....../'......5'......D'..5...L'..7....'.......'.......'..7....'.......(..%....(......D(......J(......T(......\(......e(..e...x(.......(.......(.......(.......(..K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:00B345C673C5287AF59423913042D3AA
      SHA1:B3A2EF3748E45E2C222DE03908F57FA40A57CFF8
      SHA-256:D7F57D37BC8380D4197F1B9E8C2B6AC9AE7AC1F52EC9525560377EA242C046A2
      SHA-512:A6B933C68811B9C4BCAD4F756F8E9D1CF7B02103DFF134918221EA810648583669FCB82EFAA45C48F7BF3B0CD35DCE45CB2258184ECA8D71CCAAF1A33DE1A5D6
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......K.......U.......^.......p.......v.......}.......................................................................................................$.......-.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2230 messages, Project-Id-Version: SyncBackSE '"%s" \343\202\222\344\270\200\346\231\202\345\201\234\346\255\242'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:04BD32A089727C54D821BD9108546F23
      SHA1:879D683E2B6F1DA720B180EC0D44C46AD420BB8C
      SHA-256:0813D96F92A2928244A794197CCA74F2682465567D18DF6394C37B0C01F9C724
      SHA-512:44BA86D9F9A00AC902D441919E022E96D60C919F81CD6F90AB6CB53A3586DEFFCEEBE62E8F4EE8DBD56120C29559083EF1FF23001F98384C9B389CFC9AE7BD52
      Malicious:false
      Reputation:unknown
      Preview:.................E......|.......X.......Y.......h.......|.......................... .............................M...|.................!...................3...%...O...%...u...!...................T...#...p...................J.......^...........c.......{...........m..........................."......./.......G..."...N.......q...................-...............&....... ...*.......K...)...j...@.......I...................<.......Y.......a...%...|...............7... ...O.......p.........................../...................................................................................0.......8.......@.......V.......h...d...y...V...........5.......B.......W.......`.......l.......r...........7.......7...............%...........7.......=.......G.......P...e...c...................................K...........C.......I.......S.......W.......[.......e.......q.......{.........../.......................................,................... .......8...#...N.......r...*...x...0...................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 1602 messages, Project-Id-Version: SyncBackSE '\343\203\207\343\203\274\343\202\277\343\201\256\345\211\262\343\202\212\345\275\223\343\201\246'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:570057F706519775F9211F62722C6690
      SHA1:87B7B6A7BEAEF63EAFFD42E181B9791F648F0423
      SHA-256:DF65B4D6ADEBD9B95041A0F5363CA16F8C5D87075DF000E2449E209D9C640B9B
      SHA-512:536672FCF3CA42F98E007588632D8DBBAB64A730BB8159188FB33BB1B035373381FA157AF0CF9C2C0611FCE9452E036786D3664394E8FF0CB21DE3A603318392
      Malicious:false
      Reputation:unknown
      Preview:........B.......,2..Y...<d........................................................!...........".......B...E..._...-.......E..........................-.......5.../...E.......u...1.......1..............................)....... ...D...U...e..................E......*...:...$...e....................................................................................0.......F.......\.......d.......k.......r.......{.................................................................................................................................'.......-.......5.......A.......L.......U.......].......j.......{...................................................................................................................6.......H.......T.......a...#...~............................................................................. .......).......1.......<.......M.......i.......s.......y............................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 82 messages, Project-Id-Version: cupsdconf '\343\202\242\343\203\225\343\203\252\343\202\253\343\203\274\343\203\263\343\202\272\350\252\236'
      Category:dropped
      Size (bytes):4153
      Entropy (8bit):5.0129525904833665
      Encrypted:false
      SSDEEP:
      MD5:90D15D590C2CCE7B357E8112D06864C7
      SHA1:D47449C46614FF7B4C21F7AB8D846D8165E9B3FF
      SHA-256:74F4FC6E6FEF690BF2FBAB8A6B699552105A4EE70312549FB8657512AB52A151
      SHA-512:071448215287D51437A25315133165D4F9D6A5D858E206A256E8B043F58948D8EDEF45FC088B35212B023369767E14980BC540F7706E0F5CB417E307016E56D8
      Malicious:false
      Reputation:unknown
      Preview:........R...........m...<....................................................... .......'.......2.......:.......B.......I.......S.......[.......c.......k.......s.......|.......................................................................................................................................................................$.......*.......2.......;.......D.......M.......T.......Z.......b.......i.......q.......w.......................................................................................................................................................".......*.......2.......8.......>.......C.......K.......S.......[.......e.......j.......p.......{...........Z...........................................0.......L.......Y.......l.......|.......................................................................................2.......B.......I......._.......r.......................................................................................(.......;.......Q.......g.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 1602 messages, Project-Id-Version: SyncBackSE '\343\203\207\343\203\274\343\202\277\343\201\256\345\211\262\343\202\212\345\275\223\343\201\246'
      Category:dropped
      Size (bytes):144542
      Entropy (8bit):5.942555984959378
      Encrypted:false
      SSDEEP:
      MD5:570057F706519775F9211F62722C6690
      SHA1:87B7B6A7BEAEF63EAFFD42E181B9791F648F0423
      SHA-256:DF65B4D6ADEBD9B95041A0F5363CA16F8C5D87075DF000E2449E209D9C640B9B
      SHA-512:536672FCF3CA42F98E007588632D8DBBAB64A730BB8159188FB33BB1B035373381FA157AF0CF9C2C0611FCE9452E036786D3664394E8FF0CB21DE3A603318392
      Malicious:false
      Reputation:unknown
      Preview:........B.......,2..Y...<d........................................................!...........".......B...E..._...-.......E..........................-.......5.../...E.......u...1.......1..............................)....... ...D...U...e..................E......*...:...$...e....................................................................................0.......F.......\.......d.......k.......r.......{.................................................................................................................................'.......-.......5.......A.......L.......U.......].......j.......{...................................................................................................................6.......H.......T.......a...#...~............................................................................. .......).......1.......<.......M.......i.......s.......y............................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2230 messages, Project-Id-Version: SyncBackSE '"%s" \343\202\222\344\270\200\346\231\202\345\201\234\346\255\242'
      Category:dropped
      Size (bytes):279367
      Entropy (8bit):5.908775531975947
      Encrypted:false
      SSDEEP:
      MD5:04BD32A089727C54D821BD9108546F23
      SHA1:879D683E2B6F1DA720B180EC0D44C46AD420BB8C
      SHA-256:0813D96F92A2928244A794197CCA74F2682465567D18DF6394C37B0C01F9C724
      SHA-512:44BA86D9F9A00AC902D441919E022E96D60C919F81CD6F90AB6CB53A3586DEFFCEEBE62E8F4EE8DBD56120C29559083EF1FF23001F98384C9B389CFC9AE7BD52
      Malicious:false
      Reputation:unknown
      Preview:.................E......|.......X.......Y.......h.......|.......................... .............................M...|.................!...................3...%...O...%...u...!...................T...#...p...................J.......^...........c.......{...........m..........................."......./.......G..."...N.......q...................-...............&....... ...*.......K...)...j...@.......I...................<.......Y.......a...%...|...............7... ...O.......p.........................../...................................................................................0.......8.......@.......V.......h...d...y...V...........5.......B.......W.......`.......l.......r...........7.......7...............%...........7.......=.......G.......P...e...c...................................K...........C.......I.......S.......W.......[.......e.......q.......{.........../.......................................,................... .......8...#...N.......r...*...x...0...................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 82 messages, Project-Id-Version: cupsdconf '\343\202\242\343\203\225\343\203\252\343\202\253\343\203\274\343\203\263\343\202\272\350\252\236'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:90D15D590C2CCE7B357E8112D06864C7
      SHA1:D47449C46614FF7B4C21F7AB8D846D8165E9B3FF
      SHA-256:74F4FC6E6FEF690BF2FBAB8A6B699552105A4EE70312549FB8657512AB52A151
      SHA-512:071448215287D51437A25315133165D4F9D6A5D858E206A256E8B043F58948D8EDEF45FC088B35212B023369767E14980BC540F7706E0F5CB417E307016E56D8
      Malicious:false
      Reputation:unknown
      Preview:........R...........m...<....................................................... .......'.......2.......:.......B.......I.......S.......[.......c.......k.......s.......|.......................................................................................................................................................................$.......*.......2.......;.......D.......M.......T.......Z.......b.......i.......q.......w.......................................................................................................................................................".......*.......2.......8.......>.......C.......K.......S.......[.......e.......j.......p.......{...........Z...........................................0.......L.......Y.......l.......|.......................................................................................2.......B.......I......._.......r.......................................................................................(.......;.......Q.......g.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3194 messages, Project-Id-Version: '"%s" \354\235\274\354\213\234 \354\240\225\354\247\200\353\220\250'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:FFB92F02FF8D21E921D8A3C19F570A67
      SHA1:B54C6D6A09349D13D4D4CC271769E8CF4D1AFD4A
      SHA-256:AC4C2A5FCD1C2C0436B3A6A860BEAE61DB17FE4C392A408F230E0BAAF7F4D992
      SHA-512:3795DEC10DA27B5FA8881635021530101A02A3CFC518012B04B904F19EA6143E17FF4B6DC835021530B850B557FDD405AA9BA0A9A2A59D4DA9941DBBF93E5307
      Malicious:false
      Reputation:unknown
      Preview:........z........c..............H.......I.......X.......l........................... ...=.......^.......w...............%...........M...*.......x...........,...............!.......................%...;...%...a...!...................@...#...\...........+...............J.......^...........{...........................m...........,.......8.......F.......S.......k.......r...".......................0...............-...........?...&...n...1.......(.......&....... ...........8...)...W...:.......@.......I.......,...G...%...t...........................................%...........9........... ...................'...............3.../...:.......j.......q.......w...............................................................................................................+...d...<...V...................................#......./.......5.......D...5...L...7.......................7...............%...........D.......J.......T.......\.......e...e...x...................................K...........X.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3194 messages, Project-Id-Version: '"%s" \354\235\274\354\213\234 \354\240\225\354\247\200\353\220\250'
      Category:dropped
      Size (bytes):358074
      Entropy (8bit):6.041962746564571
      Encrypted:false
      SSDEEP:
      MD5:FFB92F02FF8D21E921D8A3C19F570A67
      SHA1:B54C6D6A09349D13D4D4CC271769E8CF4D1AFD4A
      SHA-256:AC4C2A5FCD1C2C0436B3A6A860BEAE61DB17FE4C392A408F230E0BAAF7F4D992
      SHA-512:3795DEC10DA27B5FA8881635021530101A02A3CFC518012B04B904F19EA6143E17FF4B6DC835021530B850B557FDD405AA9BA0A9A2A59D4DA9941DBBF93E5307
      Malicious:false
      Reputation:unknown
      Preview:........z........c..............H.......I.......X.......l........................... ...=.......^.......w...............%...........M...*.......x...........,...............!.......................%...;...%...a...!...................@...#...\...........+...............J.......^...........{...........................m...........,.......8.......F.......S.......k.......r...".......................0...............-...........?...&...n...1.......(.......&....... ...........8...)...W...:.......@.......I.......,...G...%...t...........................................%...........9........... ...................'...............3.../...:.......j.......q.......w...............................................................................................................+...d...<...V...................................#......./.......5.......D...5...L...7.......................7...............%...........D.......J.......T.......\.......e...e...x...................................K...........X.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4439
      Entropy (8bit):4.912243768121563
      Encrypted:false
      SSDEEP:
      MD5:5F86EE7571CC6D93168F50ACB2366906
      SHA1:2009D14CEA299F3EA6FE931BD9120EF6F568149D
      SHA-256:64F7A1C6BA2E90DF1A2CB164B86556163C118A7F195304E6EBF6EEB51A821FFB
      SHA-512:A6EC0DC7B1C496A88B6BFA48B4D928A54C88B49F0142A5205B8F57DA368AD8778AB626FE00B2D3DD2DE13F8F32ACD82A88DDCE3335CFB258AFF43DAE29737933
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......K.......U.......^.......o.......v...............................................................................................................0.......C.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:5F86EE7571CC6D93168F50ACB2366906
      SHA1:2009D14CEA299F3EA6FE931BD9120EF6F568149D
      SHA-256:64F7A1C6BA2E90DF1A2CB164B86556163C118A7F195304E6EBF6EEB51A821FFB
      SHA-512:A6EC0DC7B1C496A88B6BFA48B4D928A54C88B49F0142A5205B8F57DA368AD8778AB626FE00B2D3DD2DE13F8F32ACD82A88DDCE3335CFB258AFF43DAE29737933
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......K.......U.......^.......o.......v...............................................................................................................0.......C.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2825 messages, Project-Id-Version: SyncBackSE '"%s" er satt p\303\245 pause'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:5FA71A260146161B193569BD3F25739E
      SHA1:75A47F2A353393ED44FE583D969037725DD1E7CE
      SHA-256:DED865D5CC8E77CA867EF31383B6070033727226479BAB279FD17BFDF93433BD
      SHA-512:43FA4BB0497758BAF67FBD94F146EDD3F7294D2D4A864661B4123BDE2166A57707F162F704BD79EC96BAED25A6D37C8F6ADEC74305DFE0CD14AC3C56777D321B
      Malicious:false
      Reputation:unknown
      Preview:................dX.......................................................................... ...............................M...h...........,...............!...........6.......L...%...h...%.......!...................m...#.......................J.......^...........|...........................m...........*.......6.......D.......Q.......i..."...p...................0...............-...........'...&...V...1...}...(.......&....... ........... ...)...?...:...i...@.......I.......,.../...%...\...................................%....................... ......................................./...........6.......=.......C.......O.......W......._.......g.......p...................................................................d.......V...h...........................................................5.......7...I...................7...............%...................................$...e...7...................................K...........................#.......-.......1.......<.......H.......L.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4264
      Entropy (8bit):4.569524517722588
      Encrypted:false
      SSDEEP:
      MD5:782518B58E88315F488DDA9A0B1E659B
      SHA1:211C4C509826990A4284D4F7FFDF419546D70FD7
      SHA-256:7E2CBAF2F4E0C2CD3B78FA1E2D751F42D942FE31298A27A0B613D850523320A7
      SHA-512:AB568BDF7A295C207C60DF7DE7C4CCEF2C3DB62BC34E8613B3E102621DEFD4488EC346D478997F498DF6CBF6EE1EB916123365A19807CC3844D0F3FB23DED2CB
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................0...................'.......1.......9.......L.......T.......\.......n...............................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2825 messages, Project-Id-Version: SyncBackSE '"%s" er satt p\303\245 pause'
      Category:dropped
      Size (bytes):296578
      Entropy (8bit):5.230501863067443
      Encrypted:false
      SSDEEP:
      MD5:5FA71A260146161B193569BD3F25739E
      SHA1:75A47F2A353393ED44FE583D969037725DD1E7CE
      SHA-256:DED865D5CC8E77CA867EF31383B6070033727226479BAB279FD17BFDF93433BD
      SHA-512:43FA4BB0497758BAF67FBD94F146EDD3F7294D2D4A864661B4123BDE2166A57707F162F704BD79EC96BAED25A6D37C8F6ADEC74305DFE0CD14AC3C56777D321B
      Malicious:false
      Reputation:unknown
      Preview:................dX.......................................................................... ...............................M...h...........,...............!...........6.......L...%...h...%.......!...................m...#.......................J.......^...........|...........................m...........*.......6.......D.......Q.......i..."...p...................0...............-...........'...&...V...1...}...(.......&....... ........... ...)...?...:...i...@.......I.......,.../...%...\...................................%....................... ......................................./...........6.......=.......C.......O.......W......._.......g.......p...................................................................d.......V...h...........................................................5.......7...I...................7...............%...................................$...e...7...................................K...........................#.......-.......1.......<.......H.......L.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:782518B58E88315F488DDA9A0B1E659B
      SHA1:211C4C509826990A4284D4F7FFDF419546D70FD7
      SHA-256:7E2CBAF2F4E0C2CD3B78FA1E2D751F42D942FE31298A27A0B613D850523320A7
      SHA-512:AB568BDF7A295C207C60DF7DE7C4CCEF2C3DB62BC34E8613B3E102621DEFD4488EC346D478997F498DF6CBF6EE1EB916123365A19807CC3844D0F3FB23DED2CB
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................0...................'.......1.......9.......L.......T.......\.......n...............................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2883 messages, Project-Id-Version: SyncBackSE/Pro '"%s" is gepauzeerd'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:2F16C2C11B27E73D7969333540F0C621
      SHA1:3B9F1AC0718018BB3C960AB5A553BAF1C6F0D3A1
      SHA-256:9706FB1664A89BD610F2BC50B0A10C1C3E9A1726375F48E8FAE8D6A54FA8CEBC
      SHA-512:BC8082B0BD4070CBEB64151024BB9F41253DC41B8359F1F20B6617129091E570D379D2DFA0371CBA5F3CBC38BC69C8BCEFB1112519C8F516D64096CFD3240ED7
      Malicious:false
      Reputation:unknown
      Preview:........C.......4Z......L.......h.......i.......x................................... ...Z.......{...................M...........g...........,...............!.......................%...*...%...P...!...v.............../...#...K.......o...+...............J.......^...........j.......v...........................m...........$.......0.......>.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'.......T.......p...........................%....................... ......................................./...........$.......+.......3.......;.......@.......H.......V.......k.......s.......{...................d.......V...........p.......}...................7.......7...............%...&.......L.......R.......\.......d.......m...e...............................K...........V.......\.......`.......k.......w.......{.................................../.......................,...........(.......9.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 945 messages, Project-Id-Version: Delphi7Rtl ' (%dx%d)'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:FEC8C0EA6E15D24FDA12DBD9AC732498
      SHA1:84D4D4210EB80F256DCA2DE9AF0B3E0DD4E9F185
      SHA-256:D7CD8F95738BCE5FFFAE68A0BF10C30BE722A00598381FD97FF41FA9DB46BA5B
      SHA-512:D4F22F6DCA2FEE41B28383B30DEA5934E5007385C734756A1FB878598BE2ACA58F1C5461EFF744D60815FDF49B3357FD3D80BD5AC4C898BD4DCD596387A37632
      Malicious:false
      Reputation:unknown
      Preview:........................,;...... O......!O......*O......FO......]O......dO......yO..-....O..E....O.......O.......P.. ....P..!...2P......TP......dP......pP..)....P.. ....P.......P..E....P..*...5Q..$...`Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......R.......R.......R......%R......)R......0R......7R......?R......QR.. ...VR..!...wR.......R.......R..!....R..0....R.."...+S......NS..!...gS..(....S..7....S..!....S..0....T.."...=T......`T......yT..$....T.......T..#....T..#....T.......U..0...,U......]U......wU.. ....U..$....U..,....U..2....V..5...7V......mV......tV..f...~V.......V.......V.......W......+W..#...KW..;...oW..*....W..*....W..,....X.......X......4X......CX......YX......hX..?...|X..4....X..0....X......"Y......+Y......6Y......<Y..,...@Y......mY......qY.......Y.......Y..&....Y.......Y.......Y..Z....Y..1...=Z......oZ.......Z.......Z../....Z.......Z.......Z.......Z.......Z.......Z..+....[......F[......d[......u[.......[.......[......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 945 messages, Project-Id-Version: Delphi7Rtl ' (%dx%d)'
      Category:dropped
      Size (bytes):67519
      Entropy (8bit):5.096537411006675
      Encrypted:false
      SSDEEP:
      MD5:FEC8C0EA6E15D24FDA12DBD9AC732498
      SHA1:84D4D4210EB80F256DCA2DE9AF0B3E0DD4E9F185
      SHA-256:D7CD8F95738BCE5FFFAE68A0BF10C30BE722A00598381FD97FF41FA9DB46BA5B
      SHA-512:D4F22F6DCA2FEE41B28383B30DEA5934E5007385C734756A1FB878598BE2ACA58F1C5461EFF744D60815FDF49B3357FD3D80BD5AC4C898BD4DCD596387A37632
      Malicious:false
      Reputation:unknown
      Preview:........................,;...... O......!O......*O......FO......]O......dO......yO..-....O..E....O.......O.......P.. ....P..!...2P......TP......dP......pP..)....P.. ....P.......P..E....P..*...5Q..$...`Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......R.......R.......R......%R......)R......0R......7R......?R......QR.. ...VR..!...wR.......R.......R..!....R..0....R.."...+S......NS..!...gS..(....S..7....S..!....S..0....T.."...=T......`T......yT..$....T.......T..#....T..#....T.......U..0...,U......]U......wU.. ....U..$....U..,....U..2....V..5...7V......mV......tV..f...~V.......V.......V.......W......+W..#...KW..;...oW..*....W..*....W..,....X.......X......4X......CX......YX......hX..?...|X..4....X..0....X......"Y......+Y......6Y......<Y..,...@Y......mY......qY.......Y.......Y..&....Y.......Y.......Y..Z....Y..1...=Z......oZ.......Z.......Z../....Z.......Z.......Z.......Z.......Z.......Z..+....[......F[......d[......u[.......[.......[......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Taalnamen 'Abchazisch'
      Category:dropped
      Size (bytes):4352
      Entropy (8bit):4.614909219713965
      Encrypted:false
      SSDEEP:
      MD5:657240D942D579B1B1FD089DE4F87DD4
      SHA1:41944B9566B9FB7B25CFA4914B059C9CFE40E7ED
      SHA-256:A2BEF9BD7B8B9895E055BE02E6383B80EF68554E4B7F028B641581B0E3E041B4
      SHA-512:1E2434BAE22F2C5255336A0FE7F2D7AB69B323B5EF4E316856982C99B47EB54548094C4CA5EC9BD3F297CB4FDB2F4B1AC7C47E3F1547EF09C179D77543550463
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................|...........i.......t.......~.......................................................................................................$.......1.......:.......B.......R.......\.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2883 messages, Project-Id-Version: SyncBackSE/Pro '"%s" is gepauzeerd'
      Category:dropped
      Size (bytes):319254
      Entropy (8bit):5.155889857943966
      Encrypted:false
      SSDEEP:
      MD5:2F16C2C11B27E73D7969333540F0C621
      SHA1:3B9F1AC0718018BB3C960AB5A553BAF1C6F0D3A1
      SHA-256:9706FB1664A89BD610F2BC50B0A10C1C3E9A1726375F48E8FAE8D6A54FA8CEBC
      SHA-512:BC8082B0BD4070CBEB64151024BB9F41253DC41B8359F1F20B6617129091E570D379D2DFA0371CBA5F3CBC38BC69C8BCEFB1112519C8F516D64096CFD3240ED7
      Malicious:false
      Reputation:unknown
      Preview:........C.......4Z......L.......h.......i.......x................................... ...Z.......{...................M...........g...........,...............!.......................%...*...%...P...!...v.............../...#...K.......o...+...............J.......^...........j.......v...........................m...........$.......0.......>.......K.......R..."...h...................0...............-...............&...N...1...u...(.......&....... ...............)...7...:...a...@.......I.......,...'.......T.......p...........................%....................... ......................................./...........$.......+.......3.......;.......@.......H.......V.......k.......s.......{...................d.......V...........p.......}...................7.......7...............%...&.......L.......R.......\.......d.......m...e...............................K...........V.......\.......`.......k.......w.......{.................................../.......................,...........(.......9.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Taalnamen 'Abchazisch'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:657240D942D579B1B1FD089DE4F87DD4
      SHA1:41944B9566B9FB7B25CFA4914B059C9CFE40E7ED
      SHA-256:A2BEF9BD7B8B9895E055BE02E6383B80EF68554E4B7F028B641581B0E3E041B4
      SHA-512:1E2434BAE22F2C5255336A0FE7F2D7AB69B323B5EF4E316856982C99B47EB54548094C4CA5EC9BD3F297CB4FDB2F4B1AC7C47E3F1547EF09C179D77543550463
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................|...........i.......t.......~.......................................................................................................$.......1.......:.......B.......R.......\.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3192 messages, Project-Id-Version: SyncBack10_PL_verA '"%s" jest wstrzymany'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:B6134BF27D334243C8B2DEE627025356
      SHA1:F8C640868BFC2D725BC3075A4D6F7F368DCDF4C6
      SHA-256:D5853368594FB5960A3F1B766F87C0E97A185924D76743E7A4EE8981376D9BE6
      SHA-512:490B24DA4862CA13275CB6F9C9E6D889F764BB7BF119D20BECFAEB79CCBAFF45ADBA82D00C45A0D8F380705D469EB94D2239F9EC4F790293B8959ADC8FCAD625
      Malicious:false
      Reputation:unknown
      Preview:........x........c..............(.......).......8.......L.......c.......}...............x... ...4.......U.......n...........................M...!.......o...........,...............!.......................%...2...%...X...!...~...............7...#...S.......w...+...............J.......^...........r.......~...........................m...........,.......8.......F.......S.......k.......r...".......................0...............-...........?...&...n...1.......(.......&....... ...........8...)...W...:.......@.......I.......,...G...%...t...........................................%...........9........... ...................'...............3.../...:.......j.......q.......w...............................................................................................................+...d...<...V...................................#......./.......5.......D...5...L...7.......................7...............%...........D.......J.......T.......\.......e...e...x...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3192 messages, Project-Id-Version: SyncBack10_PL_verA '"%s" jest wstrzymany'
      Category:dropped
      Size (bytes):348749
      Entropy (8bit):5.424116160038139
      Encrypted:false
      SSDEEP:
      MD5:B6134BF27D334243C8B2DEE627025356
      SHA1:F8C640868BFC2D725BC3075A4D6F7F368DCDF4C6
      SHA-256:D5853368594FB5960A3F1B766F87C0E97A185924D76743E7A4EE8981376D9BE6
      SHA-512:490B24DA4862CA13275CB6F9C9E6D889F764BB7BF119D20BECFAEB79CCBAFF45ADBA82D00C45A0D8F380705D469EB94D2239F9EC4F790293B8959ADC8FCAD625
      Malicious:false
      Reputation:unknown
      Preview:........x........c..............(.......).......8.......L.......c.......}...............x... ...4.......U.......n...........................M...!.......o...........,...............!.......................%...2...%...X...!...~...............7...#...S.......w...+...............J.......^...........r.......~...........................m...........,.......8.......F.......S.......k.......r...".......................0...............-...........?...&...n...1.......(.......&....... ...........8...)...W...:.......@.......I.......,...G...%...t...........................................%...........9........... ...................'...............3.../...:.......j.......q.......w...............................................................................................................+...d...<...V...................................#......./.......5.......D...5...L...7.......................7...............%...........D.......J.......T.......\.......e...e...x...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abchaski'
      Category:dropped
      Size (bytes):4478
      Entropy (8bit):4.707035854794775
      Encrypted:false
      SSDEEP:
      MD5:B1FB618D43A82AC04347734E179A11B3
      SHA1:3B12849160C6AF5660284EE4D31416E9643378C0
      SHA-256:27DFBEAEEE975A98824D80BEBB6E4E5961F9FFFE119C24138A8EEC189862FC97
      SHA-512:927839057F1C2806950E936DC1DFC428372ED7B88721230958362120EFB5356D54F868A62A896700E43010B058D89A5FAA667916481DDF1F87E45FAA0EF60A1D
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......J.......W.......a.......x...............................................................................................%.......0.......8.......M.......Y.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abchaski'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:B1FB618D43A82AC04347734E179A11B3
      SHA1:3B12849160C6AF5660284EE4D31416E9643378C0
      SHA-256:27DFBEAEEE975A98824D80BEBB6E4E5961F9FFFE119C24138A8EEC189862FC97
      SHA-512:927839057F1C2806950E936DC1DFC428372ED7B88721230958362120EFB5356D54F868A62A896700E43010B058D89A5FAA667916481DDF1F87E45FAA0EF60A1D
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................T...........A.......J.......W.......a.......x...............................................................................................%.......0.......8.......M.......Y.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3202 messages, Project-Id-Version: SyncBackSE '"%s" suspenso'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:5D0F2D888BAA85BDF052346F3FF733F3
      SHA1:2503975D39E7CB45B9FE1E1E13A98E6187B75070
      SHA-256:B23966ECDB82532C212B11B4CBA12C28BF7F732DDCD9ECE83565167445A1F151
      SHA-512:F41AAFEBB17BDC378828FA1F5D978294406D38D8EB6C9A69154501A6CC8F46095DD92ED7918EF6C312A436540BE5006ACA7E8C9A33E864F428E8F4C53BF461D9
      Malicious:false
      Reputation:unknown
      Preview:................,d......<.......................................3.......M.......k.......H... ...........%.......>.......S...............l...M...........?.......[...,...l...........!.......................%.......%...(...!...N.......p...........#...#.......G...+...b...........J.......^...........B.......N.......f.......q...........m...................................#.......;.......B..."...X.......{...........0...............-...............&...>...1...e...(.......&....... ...............)...'...:...Q...@.......I.......,.......%...D.......j...................................%....................... ......................................./...........:.......A.......G.......S.......[.......c.......h.......p.......y...................................................................d.......V...q...........................................................5.......7...R...................7...............%...........................$.......,.......5...e...H...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 1145 messages, Project-Id-Version: Delphi 7 ' (%dx%d)'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:AAB03503664EBFDD47A9AEB0524F16C7
      SHA1:FFEAA421EAF578F6C6357A8B2C5E7865CB02520D
      SHA-256:C4E04C53869D4A57C311888F7AAF3E8733D255A16D50A0FF3EA1400FE3EBAF88
      SHA-512:02F1B688B9A47A71D52C58FD54B5C4CC0B896C6C3FA4AB030EDFF8FCD90F9C0D188C356FAA95C706DE0777E6D93423FC118BF081915028B63E371DC43A450A89
      Malicious:false
      Reputation:unknown
      Preview:........y........#.......G......._......._......._......._......._......._......._..!....`.......`..B...N`../....`.......`.......`..E....`..E...;a.......a.......a..1....a..1....a.......b.......b......-b..)...9b.. ...cb..U....b.......b..E....b..*...<c......gc......pc......~c.......c.......c.......c.......c.......c.......c.......d.......d.......d......&d......-d......6d......<d......Ed......Ld......Sd......[d......rd......wd......}d.......d.......d.......d.......d.......d.......d.......d.......d.......d.......e.......e......(e......4e......:e......Ge......Pe......^e......de......le......te.......e.......e.......e.......e.......e.......e.......e.......e.......e.......e.......e.......f......!f......,f......8f......@f......If......`f......uf......zf.......f.......f..0....f.......f..!....g..(...%g..7...Ng..!....g..0....g.."....g.......g.......h..$...%h......Jh..#...eh..#....h.......h..0....h.......h.......i.. ...-i......Ni......Ti......bi......ji......si.......i.......i.......i.......i......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4374
      Entropy (8bit):4.653535857702553
      Encrypted:false
      SSDEEP:
      MD5:6D625AC8EC4E95F93B767782B50717AE
      SHA1:4D2990F0A01BA62347BDECBB190468BE3E101D2E
      SHA-256:9CB70D91111BF93D01A837F883645E39122FED7AD72A0C36729BA875E9FF5681
      SHA-512:DB894D36DBE7200FB36430F4315136C5B1FA0D80D1A37EEB85CA8336A001E5D045E2D65ED9650ADB18CE0D362DB1B5646E37299957EF231C546703B260D4F685
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...............................................................................................................................................................................................................................................-.......4.......D.......N.......V.......g.......p.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 1145 messages, Project-Id-Version: Delphi 7 ' (%dx%d)'
      Category:dropped
      Size (bytes):98715
      Entropy (8bit):5.211281996235875
      Encrypted:false
      SSDEEP:
      MD5:AAB03503664EBFDD47A9AEB0524F16C7
      SHA1:FFEAA421EAF578F6C6357A8B2C5E7865CB02520D
      SHA-256:C4E04C53869D4A57C311888F7AAF3E8733D255A16D50A0FF3EA1400FE3EBAF88
      SHA-512:02F1B688B9A47A71D52C58FD54B5C4CC0B896C6C3FA4AB030EDFF8FCD90F9C0D188C356FAA95C706DE0777E6D93423FC118BF081915028B63E371DC43A450A89
      Malicious:false
      Reputation:unknown
      Preview:........y........#.......G......._......._......._......._......._......._......._..!....`.......`..B...N`../....`.......`.......`..E....`..E...;a.......a.......a..1....a..1....a.......b.......b......-b..)...9b.. ...cb..U....b.......b..E....b..*...<c......gc......pc......~c.......c.......c.......c.......c.......c.......c.......d.......d.......d......&d......-d......6d......<d......Ed......Ld......Sd......[d......rd......wd......}d.......d.......d.......d.......d.......d.......d.......d.......d.......d.......e.......e......(e......4e......:e......Ge......Pe......^e......de......le......te.......e.......e.......e.......e.......e.......e.......e.......e.......e.......e.......e.......f......!f......,f......8f......@f......If......`f......uf......zf.......f.......f..0....f.......f..!....g..(...%g..7...Ng..!....g..0....g.."....g.......g.......h..$...%h......Jh..#...eh..#....h.......h..0....h.......h.......i.. ...-i......Ni......Ti......bi......ji......si.......i.......i.......i.......i......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3202 messages, Project-Id-Version: SyncBackSE '"%s" suspenso'
      Category:dropped
      Size (bytes):341459
      Entropy (8bit):5.265832598860386
      Encrypted:false
      SSDEEP:
      MD5:5D0F2D888BAA85BDF052346F3FF733F3
      SHA1:2503975D39E7CB45B9FE1E1E13A98E6187B75070
      SHA-256:B23966ECDB82532C212B11B4CBA12C28BF7F732DDCD9ECE83565167445A1F151
      SHA-512:F41AAFEBB17BDC378828FA1F5D978294406D38D8EB6C9A69154501A6CC8F46095DD92ED7918EF6C312A436540BE5006ACA7E8C9A33E864F428E8F4C53BF461D9
      Malicious:false
      Reputation:unknown
      Preview:................,d......<.......................................3.......M.......k.......H... ...........%.......>.......S...............l...M...........?.......[...,...l...........!.......................%.......%...(...!...N.......p...........#...#.......G...+...b...........J.......^...........B.......N.......f.......q...........m...................................#.......;.......B..."...X.......{...........0...............-...............&...>...1...e...(.......&....... ...............)...'...:...Q...@.......I.......,.......%...D.......j...................................%....................... ......................................./...........:.......A.......G.......S.......[.......c.......h.......p.......y...................................................................d.......V...q...........................................................5.......7...R...................7...............%...........................$.......,.......5...e...H...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:6D625AC8EC4E95F93B767782B50717AE
      SHA1:4D2990F0A01BA62347BDECBB190468BE3E101D2E
      SHA-256:9CB70D91111BF93D01A837F883645E39122FED7AD72A0C36729BA875E9FF5681
      SHA-512:DB894D36DBE7200FB36430F4315136C5B1FA0D80D1A37EEB85CA8336A001E5D045E2D65ED9650ADB18CE0D362DB1B5646E37299957EF231C546703B260D4F685
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...............................................................................................................................................................................................................................................-.......4.......D.......N.......V.......g.......p.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2876 messages, Project-Id-Version: SyncBack '"%s" este \303\256n pauz\304\203'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:2A8784E91512980D842243D5FF2B3729
      SHA1:796590D07F01AD5B509E76A30C501EFA38B0B8D1
      SHA-256:06061E0DE0D44E4C4BAD08D8F27D8B65D995AEC593650313B4385A37815386C8
      SHA-512:90284DDE969B4848B9D11C6AA6B0B38544F57B904A27029CA77E87BD3D92C35227951C44A43201FEDFC41CD07DC4FD5B7FB27BC99BD9CDA50F545E02F66E3B95
      Malicious:false
      Reputation:unknown
      Preview:........<........Y.............................................3.......M.......k.......H... ...........%.......>.......S...M...........&...,...B.......o...!.......................%.......%.......!...$.......F...........#...................8...J...B...^...................................#...m...,...........................................".......................0.../.......`...-...i...........&.......1.......(.......&...H... ...o...........).......:.......@.......I...U...,.......%...........................,.......4...%...O.......u........... ...".......C.......c.......j.......o.../...v...............................................................................................*.......2.......:.......P.......b...d...s...V.........../.......<.......Q.......Z.......f.......l.......{...5.......7.......................7...........=...%...U.......{...................................e...........................'......./...K...C...............................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4480
      Entropy (8bit):4.724289842835725
      Encrypted:false
      SSDEEP:
      MD5:39E04F7E56858D4B0CD066CE4C2E61C0
      SHA1:91777E438C7D898EFC4E54DC1BF3B3B4C54C6659
      SHA-256:5C49CC9F95CCA86433D13B359FF6914DE6FA80D12D7E536FFBA0560246AD15F5
      SHA-512:098F796E1327B74A89DE2A5C793C855A421962E474F43C7907798A2BAA2A4E184EBE4026AE4160E076500391858DD4573E58624EC5A56C80B9303A97F140ED0C
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{.......................................................................................................................................................................................0.......@.......L.......S.......^.......f.......n...............................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2876 messages, Project-Id-Version: SyncBack '"%s" este \303\256n pauz\304\203'
      Category:dropped
      Size (bytes):315129
      Entropy (8bit):5.264043636327512
      Encrypted:false
      SSDEEP:
      MD5:2A8784E91512980D842243D5FF2B3729
      SHA1:796590D07F01AD5B509E76A30C501EFA38B0B8D1
      SHA-256:06061E0DE0D44E4C4BAD08D8F27D8B65D995AEC593650313B4385A37815386C8
      SHA-512:90284DDE969B4848B9D11C6AA6B0B38544F57B904A27029CA77E87BD3D92C35227951C44A43201FEDFC41CD07DC4FD5B7FB27BC99BD9CDA50F545E02F66E3B95
      Malicious:false
      Reputation:unknown
      Preview:........<........Y.............................................3.......M.......k.......H... ...........%.......>.......S...M...........&...,...B.......o...!.......................%.......%.......!...$.......F...........#...................8...J...B...^...................................#...m...,...........................................".......................0.../.......`...-...i...........&.......1.......(.......&...H... ...o...........).......:.......@.......I...U...,.......%...........................,.......4...%...O.......u........... ...".......C.......c.......j.......o.../...v...............................................................................................*.......2.......:.......P.......b...d...s...V.........../.......<.......Q.......Z.......f.......l.......{...5.......7.......................7...........=...%...U.......{...................................e...........................'......./...K...C...............................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:39E04F7E56858D4B0CD066CE4C2E61C0
      SHA1:91777E438C7D898EFC4E54DC1BF3B3B4C54C6659
      SHA-256:5C49CC9F95CCA86433D13B359FF6914DE6FA80D12D7E536FFBA0560246AD15F5
      SHA-512:098F796E1327B74A89DE2A5C793C855A421962E474F43C7907798A2BAA2A4E184EBE4026AE4160E076500391858DD4573E58624EC5A56C80B9303A97F140ED0C
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{.......................................................................................................................................................................................0.......@.......L.......S.......^.......f.......n...............................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3206 messages, Project-Id-Version: SyncBackSE '"%s" \320\277\321\200\320\270\320\276\321\201\321\202\320\260\320\275\320\276\320\262\320\273\320\265\320\275\320\276'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:F8C2CB41B97023821A32C13C216F50AB
      SHA1:BAA49263AE3D5D183FF2F9CC8522ECBA2704A064
      SHA-256:5276575C4486025D45D1520B8426D242D3AA2EBB7A55EB35444956DD58D2B00A
      SHA-512:D2BFE4AB0F16AF864B53CCEE625EC1BEAFDB426A07EFC7D8B0E4DCE4C9DB74F8FD7B445DC27B827EA6897E189199D6452CED0A98E61EB9C2B55875D174160169
      Malicious:false
      Reputation:unknown
      Preview:................Ld......|.......h.......i.......x........................................... ...t...............................\...........M...a...................,...............!...........@.......V...%...r...%.......!...................w...#...............+...............J.......^...S...........................................m...........l.......x...................................".......................0...........H...-...Q...........&.......1.......(.......&...0... ...W.......x...).......:.......@.......I...=...,.......%...................................0.......8...%...S.......y........... ...&.......G.......g.......n.......s.../...z.......................................................................................................3.......;.......C.......Y.......k...d...|...V...........8.......E.......Z.......c.......o.......u...........5.......7.......................7...........F...%...^...........................................e...................(.......0.......8...K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2173 messages, Project-Id-Version: Delphi ' (%dx%d)'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:79C3EC0BA73B0DFD49D565137F5B0FE4
      SHA1:2FD1AE96FA1F9819EA7ED9441E11CF911759F3B2
      SHA-256:9050219293CA045D75F3758494A5C91822D342428EBA7F8B7CC4BC8CE9667F5F
      SHA-512:580746FFFD95C31B8D512A860F894A7DEA6923F0F0FBE509F6A5FD9DE2CDA824AC7F3DE4812AAFD3BA0BF1AFCA3A6AF7459F935A9B3B7D87021AA5D64E1C4124
      Malicious:false
      Reputation:unknown
      Preview:........}........D..Q..........0.......1.......:.......>.......B.......^.......u.......|...!.............................)...............1...<.......n...$...............0......(...........(...E...?...".......-.......E..........................3.......D.......L.......\.......m.......}...*.............................1.......1...+.......].......u........... .......!.................................%...)...=... ...g...U.................................$.......A...E...\...*.......$.................................".......5.......E.......X.......j.......v.................................................$...........?.......V.......l.......t.......{.......................................................................................................... ...........#...K.......o...................................................................................................(.......0.......9.......@.......T.......k...................e....... .......!... .......B.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3206 messages, Project-Id-Version: SyncBackSE '"%s" \320\277\321\200\320\270\320\276\321\201\321\202\320\260\320\275\320\276\320\262\320\273\320\265\320\275\320\276'
      Category:dropped
      Size (bytes):443384
      Entropy (8bit):5.481698601450619
      Encrypted:false
      SSDEEP:
      MD5:F8C2CB41B97023821A32C13C216F50AB
      SHA1:BAA49263AE3D5D183FF2F9CC8522ECBA2704A064
      SHA-256:5276575C4486025D45D1520B8426D242D3AA2EBB7A55EB35444956DD58D2B00A
      SHA-512:D2BFE4AB0F16AF864B53CCEE625EC1BEAFDB426A07EFC7D8B0E4DCE4C9DB74F8FD7B445DC27B827EA6897E189199D6452CED0A98E61EB9C2B55875D174160169
      Malicious:false
      Reputation:unknown
      Preview:................Ld......|.......h.......i.......x........................................... ...t...............................\...........M...a...................,...............!...........@.......V...%...r...%.......!...................w...#...............+...............J.......^...S...........................................m...........l.......x...................................".......................0...........H...-...Q...........&.......1.......(.......&...0... ...W.......x...).......:.......@.......I...=...,.......%...................................0.......8...%...S.......y........... ...&.......G.......g.......n.......s.../...z.......................................................................................................3.......;.......C.......Y.......k...d...|...V...........8.......E.......Z.......c.......o.......u...........5.......7.......................7...........F...%...^...........................................e...................(.......0.......8...K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names '\320\220\320\261\321\205\320\260\320\267\321\201\320\272\320\270\320\271'
      Category:dropped
      Size (bytes):5615
      Entropy (8bit):5.063488681310545
      Encrypted:false
      SSDEEP:
      MD5:72BDF6F238AF26F052983541D2D9D864
      SHA1:C0E2A48D0EAD3C8724E134D119F7B96A11C05590
      SHA-256:BE7CAC9D819ABFA0B5C47719179A3AD8DE6B7C529E0981749877FFC423D89CD4
      SHA-512:A48333EEFA66F0B630565DD370D76E970148CCC4318A154D8FE908BF82C4DC23558DC7965D2DB9CDBCCE584E6965D237ED2C37250ADD59CB7BC3A0215B3BD389
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...........................................................................................................................................................................)...,...!...V.......x...................................-...............D...,.......q...........#...........................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2173 messages, Project-Id-Version: Delphi ' (%dx%d)'
      Category:dropped
      Size (bytes):227185
      Entropy (8bit):5.57604661388999
      Encrypted:false
      SSDEEP:
      MD5:79C3EC0BA73B0DFD49D565137F5B0FE4
      SHA1:2FD1AE96FA1F9819EA7ED9441E11CF911759F3B2
      SHA-256:9050219293CA045D75F3758494A5C91822D342428EBA7F8B7CC4BC8CE9667F5F
      SHA-512:580746FFFD95C31B8D512A860F894A7DEA6923F0F0FBE509F6A5FD9DE2CDA824AC7F3DE4812AAFD3BA0BF1AFCA3A6AF7459F935A9B3B7D87021AA5D64E1C4124
      Malicious:false
      Reputation:unknown
      Preview:........}........D..Q..........0.......1.......:.......>.......B.......^.......u.......|...!.............................)...............1...<.......n...$...............0......(...........(...E...?...".......-.......E..........................3.......D.......L.......\.......m.......}...*.............................1.......1...+.......].......u........... .......!.................................%...)...=... ...g...U.................................$.......A...E...\...*.......$.................................".......5.......E.......X.......j.......v.................................................$...........?.......V.......l.......t.......{.......................................................................................................... ...........#...K.......o...................................................................................................(.......0.......9.......@.......T.......k...................e....... .......!... .......B.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names '\320\220\320\261\321\205\320\260\320\267\321\201\320\272\320\270\320\271'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:72BDF6F238AF26F052983541D2D9D864
      SHA1:C0E2A48D0EAD3C8724E134D119F7B96A11C05590
      SHA-256:BE7CAC9D819ABFA0B5C47719179A3AD8DE6B7C529E0981749877FFC423D89CD4
      SHA-512:A48333EEFA66F0B630565DD370D76E970148CCC4318A154D8FE908BF82C4DC23558DC7965D2DB9CDBCCE584E6965D237ED2C37250ADD59CB7BC3A0215B3BD389
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...........................................................................................................................................................................)...,...!...V.......x...................................-...............D...,.......q...........#...........................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3201 messages, Project-Id-Version: SyncBackSE '"%s" \303\244r pausad'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:14D0DA724AD5A736DFD9BE72481D15F8
      SHA1:1BF06CC31413A6B2AD5202F71FC9D6A141331A24
      SHA-256:EC6093DB2869F5F78E594B8B858E970617CB4B901755F8CBA872527F685CDDE4
      SHA-512:0966F59241E024C6838B6D3A20706945B0180F88DC7CF8225035A5DC57C3AB4F1954FA489B91BC8EE79C7FE5F612D033B460F58B3A8A6790A69306846B3C9A4F
      Malicious:false
      Reputation:unknown
      Preview:................$d......,.......................................#.......=.......[.......8... ...........................C...............\...M.........../.......K...,...\...........!.......................%.......%.......!...>.......`...........#...........7...+...R.......~...J.......^...........2.......>.......V.......a.......u...m...~.......................................+.......2..."...H.......k...........0...............-...............&.......1...U...(.......&....... ...............).......:...A...@...|...I.......,.......%...4.......Z.......v...........................%....................... ......................................./...........*.......1.......7.......C.......K.......S.......X.......`.......i...................................................................d.......V...a...........................................................5.......7...B.......z...........7...............%...........................................%...e...8...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 1401 messages, Project-Id-Version: Delphi7 ' (%dx%d)'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:25241448C8CAD3F33BC0BC76DBC59033
      SHA1:AC916148214BA05B6B7F632E8E5AC020F86BE048
      SHA-256:43E0A98E0BBC5229EC0C332471E2D638CDB4F0ACC19D587EAA6E734BD9938863
      SHA-512:F46568DE81265754BACAE23D249BBADF81B1A43895CF8DA0D851084C995285686C28D2208AF8AA1202115380DEFE356BA03EDB7EC240227D0A36401E5F5C0A67
      Malicious:false
      Reputation:unknown
      Preview:........y........+..O....W.......t.......t.......t.......t..!....u......4u......Tu..)...cu.......u..E....u.."....u.......v.......v......*v......2v......Bv......Sv......cv..*...zv.......v.......v.......v.. ....v..!....w......,w......Lw......\w......tw.......w.......w.......w.......w.......w.......w.......w.......x.......x......-x......@x......Vx......lx......tx......{x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......y.......y......7y......?y......Qy......_y......ky..#....y.......y.......y.......y.......y.......y.......y.......y.......z.......z.......z......$z......,z......9z......Bz......Rz......Yz......cz......xz......~z.......z.......z.......z.......z.......z.......z.......z.......z.......z.......z.......z.......{.......{.......{.......{......&{.......{......?{......H{......V{......_{......o{......w{.......{.......{.......{..e....{.. ....|..!....|......P|......p|..!....|.."....|.......|..!....|..(....}..!...8}......Z}......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):4274
      Entropy (8bit):4.5496707340815234
      Encrypted:false
      SSDEEP:
      MD5:99BEDD867993A68DF42285EADE05CA29
      SHA1:2B62D6FD44D83658BFDC522B7743D5D7E37A1893
      SHA-256:67F82FFED92E7319916AC4B6719570B42A201A71512101E1A1995FEC36C75C71
      SHA-512:F7344984DE450A2EE8239B095904E6D3DA63310FB27EEF2BFE08B45380587644FEEDBC8847FDD9F64883B7B05F4E8CAF8437C0314730CC4D6EC78B65F3A48D86
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................2...................).......3.......<.......M.......T.......^.......q...............................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 1401 messages, Project-Id-Version: Delphi7 ' (%dx%d)'
      Category:dropped
      Size (bytes):102924
      Entropy (8bit):5.353385610485778
      Encrypted:false
      SSDEEP:
      MD5:25241448C8CAD3F33BC0BC76DBC59033
      SHA1:AC916148214BA05B6B7F632E8E5AC020F86BE048
      SHA-256:43E0A98E0BBC5229EC0C332471E2D638CDB4F0ACC19D587EAA6E734BD9938863
      SHA-512:F46568DE81265754BACAE23D249BBADF81B1A43895CF8DA0D851084C995285686C28D2208AF8AA1202115380DEFE356BA03EDB7EC240227D0A36401E5F5C0A67
      Malicious:false
      Reputation:unknown
      Preview:........y........+..O....W.......t.......t.......t.......t..!....u......4u......Tu..)...cu.......u..E....u.."....u.......v.......v......*v......2v......Bv......Sv......cv..*...zv.......v.......v.......v.. ....v..!....w......,w......Lw......\w......tw.......w.......w.......w.......w.......w.......w.......w.......x.......x......-x......@x......Vx......lx......tx......{x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......x.......y.......y......7y......?y......Qy......_y......ky..#....y.......y.......y.......y.......y.......y.......y.......y.......z.......z.......z......$z......,z......9z......Bz......Rz......Yz......cz......xz......~z.......z.......z.......z.......z.......z.......z.......z.......z.......z.......z.......z.......{.......{.......{.......{......&{.......{......?{......H{......V{......_{......o{......w{.......{.......{.......{..e....{.. ....|..!....|......P|......p|..!....|.."....|.......|..!....|..(....}..!...8}......Z}......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3201 messages, Project-Id-Version: SyncBackSE '"%s" \303\244r pausad'
      Category:dropped
      Size (bytes):338591
      Entropy (8bit):5.273059899445719
      Encrypted:false
      SSDEEP:
      MD5:14D0DA724AD5A736DFD9BE72481D15F8
      SHA1:1BF06CC31413A6B2AD5202F71FC9D6A141331A24
      SHA-256:EC6093DB2869F5F78E594B8B858E970617CB4B901755F8CBA872527F685CDDE4
      SHA-512:0966F59241E024C6838B6D3A20706945B0180F88DC7CF8225035A5DC57C3AB4F1954FA489B91BC8EE79C7FE5F612D033B460F58B3A8A6790A69306846B3C9A4F
      Malicious:false
      Reputation:unknown
      Preview:................$d......,.......................................#.......=.......[.......8... ...........................C...............\...M.........../.......K...,...\...........!.......................%.......%.......!...>.......`...........#...........7...+...R.......~...J.......^...........2.......>.......V.......a.......u...m...~.......................................+.......2..."...H.......k...........0...............-...............&.......1...U...(.......&....... ...............).......:...A...@...|...I.......,.......%...4.......Z.......v...........................%....................... ......................................./...........*.......1.......7.......C.......K.......S.......X.......`.......i...................................................................d.......V...a...........................................................5.......7...B.......z...........7...............%...........................................%...e...8...................................K...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: Language names 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:99BEDD867993A68DF42285EADE05CA29
      SHA1:2B62D6FD44D83658BFDC522B7743D5D7E37A1893
      SHA-256:67F82FFED92E7319916AC4B6719570B42A201A71512101E1A1995FEC36C75C71
      SHA-512:F7344984DE450A2EE8239B095904E6D3DA63310FB27EEF2BFE08B45380587644FEEDBC8847FDD9F64883B7B05F4E8CAF8437C0314730CC4D6EC78B65F3A48D86
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................2...................).......3.......<.......M.......T.......^.......q...............................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2222 messages, Project-Id-Version: SyncBackPro Ukrainian 1.0 '"%s" \320\277\321\200\320\270\320\267\321\203\320\277\320\270\320\275\320\265\320\275\320\276'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:F3AD0ABB693765494F529BD8F9DEC0C4
      SHA1:674FFB15A137B560F813103F002B868F0CF14664
      SHA-256:110151797C580063A81308A140D6F1F23577F873EEDA73F01C3555345FB26009
      SHA-512:9B53447D800A5D02F465F434875E3CF0CC8C9E5A551F953C37BC8904A7469C238023ADF8B40B586D686661D6A13644DACE442B04DDA6C10B9A3775BF62A1E0FD
      Malicious:false
      Reputation:unknown
      Preview:.................E..............H.......I.......X.......l........................... .............................M...l..................!..................#...%...?...%...e...!...................D...#...`...................J.......^...........S.......k.......v...m...........................................7..."...>.......a.......w...........-..............&...... ...........;...)...Z...@.......I...................,.......I.......Q...%...l...............'... ...?.......`.........................../...................................................................................".......*.......@.......R...d...c...V...................,.......A.......J.......V.......\.......k...7...s...7...............%...........!.......'.......1.......:...e...M...................................K...........-.......3.......=.......A.......E.......O.......[.......e.......o.../...x...................................,..........................."...#...8.......\...*...b...0...........................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: SyncBackPro Ukrainian 1.0 'Abkhazian'
      Category:dropped
      Size (bytes):4522
      Entropy (8bit):4.85050963335026
      Encrypted:false
      SSDEEP:
      MD5:9E3779313829D6EAA98DAC387EBD8E30
      SHA1:E8E3AA6F3D42A0A0EC62983D3060F049B3BD6E0B
      SHA-256:F5B6E7DCD6EDC3641A247E8CABB55DF9F32D82FB6C868F7A1F5A5535324D7B17
      SHA-512:BE6A62BF63865D007031E5D6D4DC55335A766A5FB3FE7E491EC5BD9312039DAFF239B63E90FCFCCAB877F793698400A7C056B9FCDEF2B64F6F906035145DC9E6
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................o...........\.......f.......p.......y.......................................................................................................%......./.......7.......H.......a.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 2222 messages, Project-Id-Version: SyncBackPro Ukrainian 1.0 '"%s" \320\277\321\200\320\270\320\267\321\203\320\277\320\270\320\275\320\265\320\275\320\276'
      Category:dropped
      Size (bytes):312153
      Entropy (8bit):5.47162377675583
      Encrypted:false
      SSDEEP:
      MD5:F3AD0ABB693765494F529BD8F9DEC0C4
      SHA1:674FFB15A137B560F813103F002B868F0CF14664
      SHA-256:110151797C580063A81308A140D6F1F23577F873EEDA73F01C3555345FB26009
      SHA-512:9B53447D800A5D02F465F434875E3CF0CC8C9E5A551F953C37BC8904A7469C238023ADF8B40B586D686661D6A13644DACE442B04DDA6C10B9A3775BF62A1E0FD
      Malicious:false
      Reputation:unknown
      Preview:.................E..............H.......I.......X.......l........................... .............................M...l..................!..................#...%...?...%...e...!...................D...#...`...................J.......^...........S.......k.......v...m...........................................7..."...>.......a.......w...........-..............&...... ...........;...)...Z...@.......I...................,.......I.......Q...%...l...............'... ...?.......`.........................../...................................................................................".......*.......@.......R...d...c...V...................,.......A.......J.......V.......\.......k...7...s...7...............%...........!.......'.......1.......:...e...M...................................K...........-.......3.......=.......A.......E.......O.......[.......e.......o.../...x...................................,..........................."...#...8.......\...*...b...0...........................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 99 messages, Project-Id-Version: SyncBackPro Ukrainian 1.0 'Abkhazian'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9E3779313829D6EAA98DAC387EBD8E30
      SHA1:E8E3AA6F3D42A0A0EC62983D3060F049B3BD6E0B
      SHA-256:F5B6E7DCD6EDC3641A247E8CABB55DF9F32D82FB6C868F7A1F5A5535324D7B17
      SHA-512:BE6A62BF63865D007031E5D6D4DC55335A766A5FB3FE7E491EC5BD9312039DAFF239B63E90FCFCCAB877F793698400A7C056B9FCDEF2B64F6F906035145DC9E6
      Malicious:false
      Reputation:unknown
      Preview:........c.......4.......L.......p.......q.......{.......................................................................................................................,.......6.......>.......O.......W......._.......g.......p.......y...............................................................................................................................................................................).......4.......:.......B.......K.......T.......].......d.......j.......r.......y.......................................................................................................................................!.......,.......:.......C.......K.......S.......Z.......d.......k.......s.......{...................................................................................................................o...........\.......f.......p.......y.......................................................................................................%......./.......7.......H.......a.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3028 messages, Project-Id-Version: SyncBackSE '\345\267\262\347\273\217\346\232\202\345\201\234\342\200\234%s\342\200\235'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:48A85991AFFFE13F67D3625A8A3F6008
      SHA1:2B8A0D7F4C085DD3A7031CE6D81DB178408FECCF
      SHA-256:114CFA9BDF99CCB21AC130D9F030540AE357EC5E7E790DD3B8B8C18D419B6C2E
      SHA-512:DD0CAD681D0A3F563717EDAE43D3FA5884E7C10122EDCCE5E0570092614CAB8AF79686BDF770230AF60A568C168788D6170D432945BA20718604CC974F74A12B
      Malicious:false
      Reputation:unknown
      Preview:.................^......\................................................................... ...............................................M...............,...........0...!...E.......g.......}...%.......%.......!.......................#...............+...........%...J.../...^...z...........................................m...%..................................................."...................(...0...>.......o...-...x...........&.......1.......(.......&...W... ...~...........).......:.......@...#...I...d...,.......%...........................:.......W......._...%...z...............5... ...M.......n.........................../...................................................................................(.......7.......E.......Z.......b.......j...................d.......V..........._.......l...........................................5.......7...........!.......)...7...5.......m...%...............................................e...........E.......O.......W......._...K...s.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 100 messages, Project-Id-Version: SyncBackSE '\351\230\277\345\270\203\345\223\210\345\205\271\346\226\207'
      Category:dropped
      Size (bytes):4466
      Entropy (8bit):5.0309526905252975
      Encrypted:false
      SSDEEP:
      MD5:D9476DC9E435D96DDFFE99719E1C8654
      SHA1:D4C4768D6ABF42D4F9EFC8ADBA8BAC832EA3A23E
      SHA-256:9682B25F5FB7B3C29ACC452C28272D64896EEE343B8EEBBA354FB43D7CDD4D50
      SHA-512:8C91C73A345D021B731616224E886F27D71679A1FC285932611E561FCB48ECC97AE636BB1B16A75E6ACA8088A1795080FE97DE6EF645D09C9E27EEE7108567A6
      Malicious:false
      Reputation:unknown
      Preview:........d.......<.......\.......................................................................................................................................'.......1.......9.......J.......R.......Z.......b.......x....................................................................................................................................................................... .......&.......0.......:.......E.......K.......S.......\.......e.......n.......u.......{.......................................................................................................................................#.......+.......2.......=.......T.......b.......k.......s.......{...........................................................................................................................................................T...........i.......y...............................................................................................*.......:.......G.......Q.......Y.......i.......|.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3028 messages, Project-Id-Version: SyncBackSE '\345\267\262\347\273\217\346\232\202\345\201\234\342\200\234%s\342\200\235'
      Category:dropped
      Size (bytes):310797
      Entropy (8bit):6.264754718408571
      Encrypted:false
      SSDEEP:
      MD5:48A85991AFFFE13F67D3625A8A3F6008
      SHA1:2B8A0D7F4C085DD3A7031CE6D81DB178408FECCF
      SHA-256:114CFA9BDF99CCB21AC130D9F030540AE357EC5E7E790DD3B8B8C18D419B6C2E
      SHA-512:DD0CAD681D0A3F563717EDAE43D3FA5884E7C10122EDCCE5E0570092614CAB8AF79686BDF770230AF60A568C168788D6170D432945BA20718604CC974F74A12B
      Malicious:false
      Reputation:unknown
      Preview:.................^......\................................................................... ...............................................M...............,...........0...!...E.......g.......}...%.......%.......!.......................#...............+...........%...J.../...^...z...........................................m...%..................................................."...................(...0...>.......o...-...x...........&.......1.......(.......&...W... ...~...........).......:.......@...#...I...d...,.......%...........................:.......W......._...%...z...............5... ...M.......n.........................../...................................................................................(.......7.......E.......Z.......b.......j...................d.......V..........._.......l...........................................5.......7...........!.......)...7...5.......m...%...............................................e...........E.......O.......W......._...K...s.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 100 messages, Project-Id-Version: SyncBackSE '\351\230\277\345\270\203\345\223\210\345\205\271\346\226\207'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:D9476DC9E435D96DDFFE99719E1C8654
      SHA1:D4C4768D6ABF42D4F9EFC8ADBA8BAC832EA3A23E
      SHA-256:9682B25F5FB7B3C29ACC452C28272D64896EEE343B8EEBBA354FB43D7CDD4D50
      SHA-512:8C91C73A345D021B731616224E886F27D71679A1FC285932611E561FCB48ECC97AE636BB1B16A75E6ACA8088A1795080FE97DE6EF645D09C9E27EEE7108567A6
      Malicious:false
      Reputation:unknown
      Preview:........d.......<.......\.......................................................................................................................................'.......1.......9.......J.......R.......Z.......b.......x....................................................................................................................................................................... .......&.......0.......:.......E.......K.......S.......\.......e.......n.......u.......{.......................................................................................................................................#.......+.......2.......=.......T.......b.......k.......s.......{...........................................................................................................................................................T...........i.......y...............................................................................................*.......:.......G.......Q.......Y.......i.......|.......
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3555 messages, Project-Id-Version: SyncBackSE '"%s" \345\267\262\346\232\253\345\201\234'
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:B3E8AD0D16A4AF0F4FA4100BA336F0DE
      SHA1:3D4EBF7C74909DEB42E6455B151AB45C5FB6D7D8
      SHA-256:BF00A3638B23F11D2C2E1983E0B8F8F41A4E665291FACEC19902E8A9F150F82C
      SHA-512:F2C943AA0AAB80C742DBFBE936AA15E5E5948023479CA287436CAFE4CB7706286D48044D6E5FDB803E5A65D873D9D1901CD2132A03912D6D4438C5B3F93C872A
      Malicious:false
      Reputation:unknown
      Preview:................4o......L........(.......(.......(.......(.......(.......(.......(.......).. ....*.......*.......*.......*......|+.......+..M....,.......,.......,..,....,......)-..!...>-......`-......v-..%....-..%....-..!....-..................#...............+............/..J...(/..^...s/......./......./......./.......0.......0..m....0.......0.......0.......0.......0.......0.......0.."....0.......1......!1..0...71......h1..-...q1.......1..&....1..1....1..(...'2..&...P2.. ...w2.......2..)....2..:....2..@....5..I...]5..,....5..%....5.......5.......6......36......P6......X6..%...s6.......6.......7.. ...F7......g7.......7.......7.......7.......7../....7.......7.......7.......7.......7.......8.......8.......8.......8......$8......,8......B8......Z8......c8......k8.......8.......8.......8.......8.......8..)....8.......8..&....9......)9......19......G9......Y9..d...j9..V....9......&:......3:......H:......Q:......Z:......u:......~:..2....:.......:.......:.......:.......:.......:.......;..5...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:GNU message catalog (little endian), revision 0.0, 3555 messages, Project-Id-Version: SyncBackSE '"%s" \345\267\262\346\232\253\345\201\234'
      Category:dropped
      Size (bytes):348602
      Entropy (8bit):6.225635476114119
      Encrypted:false
      SSDEEP:
      MD5:B3E8AD0D16A4AF0F4FA4100BA336F0DE
      SHA1:3D4EBF7C74909DEB42E6455B151AB45C5FB6D7D8
      SHA-256:BF00A3638B23F11D2C2E1983E0B8F8F41A4E665291FACEC19902E8A9F150F82C
      SHA-512:F2C943AA0AAB80C742DBFBE936AA15E5E5948023479CA287436CAFE4CB7706286D48044D6E5FDB803E5A65D873D9D1901CD2132A03912D6D4438C5B3F93C872A
      Malicious:false
      Reputation:unknown
      Preview:................4o......L........(.......(.......(.......(.......(.......(.......(.......).. ....*.......*.......*.......*......|+.......+..M....,.......,.......,..,....,......)-..!...>-......`-......v-..%....-..%....-..!....-..................#...............+............/..J...(/..^...s/......./......./......./.......0.......0..m....0.......0.......0.......0.......0.......0.......0.."....0.......1......!1..0...71......h1..-...q1.......1..&....1..1....1..(...'2..&...P2.. ...w2.......2..)....2..:....2..@....5..I...]5..,....5..%....5.......5.......6......36......P6......X6..%...s6.......6.......7.. ...F7......g7.......7.......7.......7.......7../....7.......7.......7.......7.......7.......8.......8.......8.......8......$8......,8......B8......Z8......c8......k8.......8.......8.......8.......8.......8..)....8.......8..&....9......)9......19......G9......Y9..d...j9..V....9......&:......3:......H:......Q:......Z:......u:......~:..2....:.......:.......:.......:.......:.......:.......;..5...
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:7E86B65153AC6BA3BE51131DC19A61B6
      SHA1:606E4A2357B31971E0A998FE3E50CCC829CE9D29
      SHA-256:68B4BC2E138B7666F34FC17E0F555741ACE13C7C58F969C88A9E1B7F3616E05A
      SHA-512:1C6DF094A4C9D1241E8FBED41670A0EB10530757DA1445B859568738403B37D70A25ACEECC9A586AD8B59D78829262946B548D5A8AC986D664D5655F09030745
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........x........................................J.......................@...........................Rich............................PE..d...5L.J.........." ................4..........P..............................-.....ul-...@...........................................&.......&.,.....).....`(.......,.(.....,.Tb...................................................................................text.............................. ..`.orpc...l........................... ..`.rdata..............................@..@.data.........&..z....&.............@....pdata.......`(.......(.............@..@.rsrc........).......).............@..@.reloc...~....,......0,.............@..B........................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:MS Windows icon resource - 4 icons, 48x48, 16 colors, 4 bits/pixel, 32x32, 16 colors, 4 bits/pixel
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:AF8A443D818AA0ABA7F0BFBFEDA251B2
      SHA1:B2EFE75E95197B1F7F380B1A833D44F9A7A6C889
      SHA-256:6119D32E20EF298F6811BEEA628339A678523C3C1C3168FAC2A2A0645A853274
      SHA-512:06BC23A92B89152686A66FD9E9C131D087CCD5A33E75C3EA84F3B70EA42DA41A2BBF8E1E65994F79B64C32F9357FB851816031F50767D19FF9B7AA7E5FC525AD
      Malicious:false
      Reputation:unknown
      Preview:......00......h...F... ......................................(...~...(...0...`....................................................................................................ww...........wwp..........p............p...............D....{..p...........p...D@......p...........p..DDD......p...........p...........p...........{...........p.......{...tDDDDDDDG...............tDDDDDDDG{...p.....{...wfDDDDDDDfw.............vf`......fg{...p...{...wff`......ffw...........vff`......ffg{...p.....wfff`......fffw...p.....vfff`......fffg{..p......fff`......fff`{..p......fff`......fff.{..p.......ff`......ff`.{..p.......ff`......ff..{..p........f`......f`..{..p........f`......f...{..p.........f.....f`...{..p.........f.....f....{..p.........f.....f....{..p.........f.....f....{..p.........f.....f....{..p.........`......`...{..p........f`......f...{..p........f`......f`..{..p.......ff`......ff..{..p..{....ff`......ff`.{.........fff`......fff.{.p....ww.fff`......fff`ww........fff`......fff............ff`
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:DA5F38FAE439B909DF848D11F68AF629
      SHA1:08CD02051F1FC3EDBE3672706EE1051F6D626124
      SHA-256:2250EDF8968F04EEFC1B10502A7A6F5A70461127E892C9F8CDB460D16065B01B
      SHA-512:9373685E1F01B85F08C77791BEFB30B3305BBFD5710214594AF23260BC1C9C8E097EB9F575E7013364E9FC036217DAE2CA455366BB4D11EF245A6B01AAB2991A
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2...2...2...Dq..0...Dq..5...2.......Dq......Dq..3...Dq..3...Dq..3...Rich2...........PE..d...w..].........." ................p........................................ ......................................................0....)......P.......0........+...................................................................................................text............................... ..`.rdata..............................@..@.data...P...........................@....pdata...+.......,..................@..@.rsrc...0...........................@..@.reloc..J...........................@..B........................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:7E4D917ADB32FAE6CD674DA5AD413F26
      SHA1:190A3341AC24AE43E45F8EB2887A86FEECC37CC0
      SHA-256:5C385FD1BEB6B4582DE3CA3A221B8B2F0DD7E4DB9721117C1B11BC57544DD745
      SHA-512:CE33091DC535E15DF7D9B3B4A2FC11465562FDDF8F67A5C4427AD70296275D3A111B589A62BC6BC4A20FF5EECAD9EBBA7BAE2D51606E145DD5B4DE706A27891B
      Malicious:false
      Reputation:unknown
      Preview:'------------------------------------------------------..' Add a timestamp to the start of the filename..' corresponding to the date the file was last changed...' (Alter line starting "timestamp =" to alter the..' format of the timestamp that is prepended.)..'..' (c) J.G.Clark 23.3.2004, with Functions from..' www.paulsadowski.com/WSH...'..' Modified by Michael J. Leaver (www.2BrightSparks.com)..' to concatenate arguments to avoid problems with..' spaces in filenames, display an error message if no..' filename was supplied, and also to copy the original..' file instead of moving it. This is to help its use..' with SyncBack (www.SyncBack.com)..'..' Free for non-commerical use...'..' Run by calling "cscript timestamp.vbs <arg>"..' where <arg> is full path of file to filestamp...' Works for UNC paths as well...'------------------------------------------------------....'------------------------------------------------------..'Return the pathname portion of a full pathname..'---------------
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:InnoSetup Log SyncBackPro, version 0x418, 77797 bytes, 216041\37\user\376\, C:\Program Files\2BrightSparks\SyncBackPro
      Category:dropped
      Size (bytes):77797
      Entropy (8bit):3.8524733854961117
      Encrypted:false
      SSDEEP:
      MD5:423C8C5E10F1B8379146EE0694A77365
      SHA1:8EDAD040D7434EDC04E23777AADF49B3C0F81097
      SHA-256:854BFF039D08F9D8DF4874AC3E2624A3BC57D0C4C94F0D0CDB6501F7F3797A8E
      SHA-512:7FAB73EEA37C64ECB3F2D03CD83DD12DA5D775DD7FD9D37814B3D4B221E8F81DF6C3C0FD1C591A85504CEE7CE9B2B4781E804E733C0863BE1D16F5CD53D1F635
      Malicious:false
      Reputation:unknown
      Preview:Inno Setup Uninstall Log (b)....................................SyncBackPro64_is1...............................................................................................................SyncBackPro............................................................................................................................../..................................................................................................................9.16..........................2.1.6.0.4.1......c.a.l.i......C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o..................0.... ...........n..IFPS....)...6....................................................................................................ANYMETHOD.....................................................................BOOLEAN..............TWIZARDFORM....TWIZARDFORM.........TMAINFORM....TMAINFORM.........TUNINSTALLPROGRESSFORM....TUNINSTALLPROGRESSFORM................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:E47E7C49D587E0FA9BFAE76474B1D09F
      SHA1:A66760BAA17A006D39A998825852C2250B0B4993
      SHA-256:0266FCB31A79B35BB4978D4FEA54075AC895041D9ABA8F6F02DF25C1F657F490
      SHA-512:E45B4CCCFFEF80F76931D885542A90F68D5B5AE0D32038EA75361CD5324DC6409B1002DC4AC7EE0177F71606FE56C72487A95AC98C40FE59B43BB75B4E2BD743
      Malicious:false
      Reputation:unknown
      Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......c.................L,..<......hf,......p,...@..........................p1.......1...@......@....................-.......-..9.......\............0..R...........................................................-.......-......................text.... ,......",................. ..`.itext...(...@,..*...&,............. ..`.data...X....p,......P,.............@....bss.....y....-..........................idata...9....-..:....,.............@....didata.......-.......-.............@....edata........-......*-.............@..@.tls....L.....-..........................rdata..]............,-.............@..@.rsrc....\.......^....-.............@..@..............1.......0.............@..@........................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:InnoSetup messages, version 6.0.0, 261 messages (UTF-16), Cancel installation
      Category:dropped
      Size (bytes):24097
      Entropy (8bit):3.2749730459064845
      Encrypted:false
      SSDEEP:
      MD5:313D0CC5D1A64D2565E35937991775A6
      SHA1:B8ACB11878C485865C9E4679248E53B83A8F3AD4
      SHA-256:5ED0233C0922E9F20307315E24B4F33C3D56AB9F42B2F75AE91E7A27FD313B66
      SHA-512:7C2DB4A3A4A8DF09F8119A7BA4CA9EBFE562F0A34D431928344E21A5853931EEFBFD910DC4026C6788AC22423BBB125F2B700326D8A1D82B134E2B486C3D0684
      Malicious:false
      Reputation:unknown
      Preview:Inno Setup Messages (6.0.0) (u)......................................]..+..... .C.a.n.c.e.l. .i.n.s.t.a.l.l.a.t.i.o.n...S.e.l.e.c.t. .a.c.t.i.o.n...&.I.g.n.o.r.e. .t.h.e. .e.r.r.o.r. .a.n.d. .c.o.n.t.i.n.u.e...&.T.r.y. .a.g.a.i.n...&.A.b.o.u.t. .S.e.t.u.p.........%.1. .v.e.r.s.i.o.n. .%.2.....%.3.........%.1. .h.o.m.e. .p.a.g.e.:.....%.4.....A.b.o.u.t. .S.e.t.u.p...Y.o.u. .m.u.s.t. .b.e. .l.o.g.g.e.d. .i.n. .a.s. .a.n. .a.d.m.i.n.i.s.t.r.a.t.o.r. .w.h.e.n. .i.n.s.t.a.l.l.i.n.g. .t.h.i.s. .p.r.o.g.r.a.m.....T.h.e. .f.o.l.l.o.w.i.n.g. .a.p.p.l.i.c.a.t.i.o.n.s. .a.r.e. .u.s.i.n.g. .f.i.l.e.s. .t.h.a.t. .n.e.e.d. .t.o. .b.e. .u.p.d.a.t.e.d. .b.y. .S.e.t.u.p... .I.t. .i.s. .r.e.c.o.m.m.e.n.d.e.d. .t.h.a.t. .y.o.u. .a.l.l.o.w. .S.e.t.u.p. .t.o. .a.u.t.o.m.a.t.i.c.a.l.l.y. .c.l.o.s.e. .t.h.e.s.e. .a.p.p.l.i.c.a.t.i.o.n.s.....T.h.e. .f.o.l.l.o.w.i.n.g. .a.p.p.l.i.c.a.t.i.o.n.s. .a.r.e. .u.s.i.n.g. .f.i.l.e.s. .t.h.a.t. .n.e.e.d. .t.o. .b.e. .u.p.d.a.t.e.d. .b.y. .S.e.t.u.p... .I.t. .i.s. .r.e.
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:DOS batch file, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:0CEB531C3EF2829E42B2535AEC9A076A
      SHA1:53DC9010CC6D37F1C66587D8528C21A9A5A3C074
      SHA-256:9649E1DDDAB98E9C0758F18025AB0166C4188A2CE4FC00752A585842410BD469
      SHA-512:5A4F674A1232E54FFA63DD9A5BE329617B6ABE24A6D2147500996AC5E467DCF554EE40D7E5EA6571CC3EC50CA4C884A924916E85F2C5403879B271A55B402CD5
      Malicious:false
      Reputation:unknown
      Preview:@echo off..REM..REM Batch file that attempts to reset and fix the Volume Shadow Copy (VSS) installation...REM..REM IMPORTANT: THIS FILE IS REPLACED WHEN UPDATING OR UPGRADING SYNCBACK..REM..REM 2BrightSparks Pte Ltd..REM https://www.2BrightSparks.com/..REM..echo --- This batch file must be run as an Administrator. If you are using Windows..echo --- Vista or newer then run it by right-clicking on the batch file and..echo --- selecting Run as administrator..%SYSTEMDRIVE%..cd %SystemRoot%\System32..echo...echo --- Ignore any messages saying a service is not started...echo...Net stop vss..Net stop swprv..regsvr32 ole32.dll..regsvr32 oleaut32.dll..regsvr32 vss_ps.dll..Vssvc /Register..regsvr32 /i swprv.dll..echo --- eventcls.dll will fail to register on Windows Vista and newer...regsvr32 /i eventcls.dll..echo --- es.dll will fail to register on Windows Vista and newer...regsvr32 es.dll..regsvr32 stdprov.dll..echo...echo --- vssui.dll only exists on Windows 2003. Ignore the error if not usin
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:3D1CA97C91174C8D607B2002E1DEE737
      SHA1:E615C304E32E3A1C24C59A0A16F8431AA516BB97
      SHA-256:5D3E331170ADACF4AA7B40A746EB681DF465A6AB232789636D76D8450034E92C
      SHA-512:CC0F919BC1196A5F0D13DB62EA58BA5319BA321C0F8827F8C14AD471D1EF6F69BC9335417D03325D4EF93004490360C67FCBA651126A5034AAD7C9D40676672C
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........0..IQl.IQl.IQl..9o.@Ql..9i..Ql.!h.YQl.!o.CQl.!i.eQl..9h.EQl.. o.SQl.. h..Pl..9m.[Ql.n...JQl.IQm.Ql.. i.CQl.. l.HQl.. ..HQl.IQ..HQl.. n.HQl.RichIQl.........PE..d...,.L_.........." .........r.......i........................................(.....l.)...`.........................................@.!.......!......P'.......%.Th....(......@(..P......T...............................0............... ............................text...l........................... ..`.rdata..............................@..@.data.........".......!.............@....pdata..Th....%..j...t%.............@..@_RDATA.......@'.......&.............@..@.rsrc........P'.......&.............@..@.reloc...P...@(..R....'.............@..B........................................................................................................................................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:C05FF13DC039E0579AC12FA2CDED108F
      SHA1:5AFA755289A72784E5C73BDA559ED4E29014AE9B
      SHA-256:7E90094AEE8D9411EC47E96D42125206DFBBA44A9615276145251F7EDDE11ED7
      SHA-512:583694DDF3DA08604867D1F1B0C6A1102B97EF288BD23E55A0F7CC88C4363EC9782A67E06E815689B8367473016612A499F1D3BF20F5633B8E8BD84D6E576044
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......2>D.v_*.v_*.v_*.-7).._*.-7/._*./..g_*./).|_*.//.Y_*.-7..x_*...).l_*.....o]*.-7+.c_*.v_+.P^*.../.c_*...*.w_*.....w_*.v_..w_*...(.w_*.Richv_*.................PE..d....}d_.........." .....:%.........\..........m............................. 9.....U.9...`.........................................../.....X./.......6.h.....5.......8.......8..i..h1,.T....................2,.(....1,.0............P%..............................text....8%......:%................. ..`.rdata.......P%......>%.............@..@.data...,....0/..h..../.............@....pdata........5.......4.............@..@_RDATA........6......^6.............@..@.rsrc...h.....6......`6.............@..@.reloc...i....8..j....8.............@..B........................................................................................................................................................................
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:ASCII text, with no line terminators
      Category:dropped
      Size (bytes):4
      Entropy (8bit):1.5
      Encrypted:false
      SSDEEP:
      MD5:6FAB6E3AA34248EC1E34A4AEEDECDDC8
      SHA1:CD0D2AD152D89C488EA91D5BEF32F022D590DE99
      SHA-256:8B0A2DA322FA2E15191541608D62DE2A20D803B4F2F1DA10B6D21E0E8F227A28
      SHA-512:CD5974CD9C736DA79C650809DBB1D03D9EA2D914C1F0335205CB0A1E97E9D8C0E183788453FBEE98F4E177D6DBAA09F85120C2F08A87FB90CA1FDD315CCB7F4A
      Malicious:false
      Reputation:unknown
      Preview:3302
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:ASCII text
      Category:dropped
      Size (bytes):10175
      Entropy (8bit):4.390857511666375
      Encrypted:false
      SSDEEP:
      MD5:C75985E733726BEABA57BC5253E96D04
      SHA1:C5C8A68F4B80929B3E66F054F37BB9E16078847F
      SHA-256:7D5450CB2D142651B8AFA315B5F238EFC805DAD827D91BA367D8516BC9D49E7A
      SHA-512:07BDEB77B6EBE1F18BA5285D98A05AC53502A82837118E194D81384BBB9C1A8E7BB7BA627DF288C770E9E97599E24A5135E45546CBF493330773C6B9921FF5B6
      Malicious:false
      Reputation:unknown
      Preview:. Apache License. Version 2.0, January 2004. https://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial ow
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:ASCII text, with no line terminators
      Category:dropped
      Size (bytes):6
      Entropy (8bit):1.9182958340544893
      Encrypted:false
      SSDEEP:
      MD5:661716A2CA9B484E7C0215D5D78EA78C
      SHA1:6E5283AD4CF18ABD998970A1C562C6F99422CA93
      SHA-256:BF1B73FD42FB546A277AFD9C6C28B312ECCF6EEA7C7B103EC40094CD949D6A7A
      SHA-512:5CBAC243CC9181155223AAEC2E198A537007F16F714F0223C36CC641A12A257DBED6A014DFA4B645A4B264F10FDDA165DDCCE421065D9A8A5C46D98E77A5FAFB
      Malicious:false
      Reputation:unknown
      Preview:V3.3.2
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):515808
      Entropy (8bit):6.4162111061217155
      Encrypted:false
      SSDEEP:
      MD5:7B23913D69718B924C6477270DA76EB6
      SHA1:48E53BB6E96CD6A5DA2F28399764CBF265FE4DCF
      SHA-256:D670BA5769847C93BAD35F1EA2443B8804513EBBB44EB58760262F76716658EA
      SHA-512:75F28FB7D96DE1B8FEC16883D84E4AC4A181DE75CB6F870B280751E65060D8EE5CFC9BF761E70009D4E632D491B3297671B4E0C578150894C1E6645621DE5F4E
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......./.M.km#.km#.km#...'.`m#... .nm#...&..m#...".im#.9.&.um#.9.'.em#.9. .cm#...".hm#.km"..m#.km#.om#...'.Nm#...#.jm#....jm#...!.jm#.Richkm#.........PE..d...a..f.........." ................................................................f.....`..........................................;..P...@<..<...............@V......................T............................................................................text............................... ..`.rdata..`...........................@..@.data....&...`.......:..............@....pdata..@V.......X...F..............@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):5553888
      Entropy (8bit):6.739210327002556
      Encrypted:false
      SSDEEP:
      MD5:BC11F171E089545E17FB1B4A97A03A27
      SHA1:EEA0DE91058747F6D894C4F0D655AC8C8FC55D75
      SHA-256:C7F397A95A43BA8A53140B74CA70904C6397C68F16403C70AD345981AFC518ED
      SHA-512:505084CE43ABB71B247467C11DA798FAD9134943468484DAA9CF9F9632AF21F2A091C8AD6FA4EEB4D5A9B9271F38F025321CCDA09C3A45FF19BCD502E332BDDB
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............iR..iR..iR..mS..iR..jS..iR..lS..iR..lS..iR..mS..iR..jS..iR..hS..iR..hR..iR..iR..iR..mS5.iR..iS..iR...R..iR..kS..iRRich..iR........PE..d...F..f.........." ......>..........j7...................................... U.......U...`.........................................P.M. ...p.P.x....`T......@Q.......T......pT.0.....J.T.............................J..............0>..............................text.....>.......>................. ..`.rdata...c...0>..d....>.............@..@.data........P..T....P.............@....pdata.......@Q.......P.............@..@.rsrc........`T.......S.............@..@.reloc..0....pT.......S.............@..B........................................................................................................................................................................................................................................
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):1389280
      Entropy (8bit):6.393007098881482
      Encrypted:false
      SSDEEP:
      MD5:624F55814345A2BDC4C6142D5F5CEB7B
      SHA1:4000CBC08641E8C5E651277D61452C98DEA29301
      SHA-256:71D03EA56907206351966642B701BD166DCA6C6CEE800264CE51D54BE1E7A928
      SHA-512:3BF93E5B66AF474B7B5D326E9DB590D4D16E2D12283CEFCD4EF6FEE569BEF3777766F6333ECA67D8A64DA02F65FB124EB691301DAD0CBA2050D25776DDD4D374
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......#.H.g.&.g.&.g.&.s.".l.&.s.%.a.&.s.#...&.5.#.y.&.5.".h.&.5.%.n.&.s.'.c.&..'.d.&.g.'...&.."...&..&.f.&....f.&..$.f.&.Richg.&.................PE..d...7..f.........." ................`~.......................................P............`......................................... 4...K......P.... .......0...............0..........T............................................................................text...0........................... ..`.rdata..N(.......*..................@..@.data...._.......D..................@....pdata.......0......................@..@.rsrc........ ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2405
      Entropy (8bit):4.960390114479308
      Encrypted:false
      SSDEEP:
      MD5:C566EE8BF9F4F418ACA02C527B36CE5E
      SHA1:49A72E90EE3C2E28186F11DCC1ACF5CA7F154651
      SHA-256:83533895CBCCEF536F4F9F018E8A600A0610BCAA5FABA66CA2C54EE3631FD45F
      SHA-512:DEDF8DC964CD6BD9B7516607E79E87B2811F99BBCABA26E48C7C7C0C1E9CFE1A70D6DE7FA3304050CE7574C65AB0A581CDFF988E1CEB38DEB6701ADACD55F3C0
      Malicious:false
      Reputation:unknown
      Preview:-----------------------------------------------------------------------..OpenSSL v3.3.2 Win64 for ICS, http://www.overbyte.be..-----------------------------------------------------------------------....More recent versions may be available from:....https://wiki.overbyte.eu/wiki/index.php/ICS_Download#Download_OpenSSL_Binaries....Only supports Windows Vista/Server 2008, and later, not Windows XP.....The legacy.dll provider is optional to support deprecated algorithms,..it needs to be loaded specifically before the following algorithms are..available: ciphers CAST, IDEA, SEED, RC2, RC4, RC5, DESX and DES and..digests MD2, MD4, MDC2 and WHIRLPOOL.....ICS V8.67 or later are required to use these DLLs.....The OpenSSL DLLs and EXE files are digitally code signed 'Magenta..Systems Ltd', one of the organisations that maintains ICS. ICS can be..set to optonally check the DLLs are correctly signed when opening them...Beware that Windows needs recent root certificates to check newly signed..code
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
      Category:dropped
      Size (bytes):906
      Entropy (8bit):3.1388820320291617
      Encrypted:false
      SSDEEP:
      MD5:F4FB1A6E1C48009AB87AFC5638E5FDB9
      SHA1:4893F78340678ED9AB4AF7BE4592C4193019A936
      SHA-256:55B9263E6E95C4813F097E32571F50E3F8BC61D0E7E2F16E8A2072D90BF23C67
      SHA-512:61EF69D8CF731759EFD122FEE9F010FBF6EE601BE9E608BFA8A3475BAF46B5163458F15CDF712E7386E10E6940942FA93E5E2CE497E73323FB0E6BAEC3CABB90
      Malicious:false
      Reputation:unknown
      Preview:L..................F.............................................................P.O. .:i.....+00.../C:\...................h.1...........Program Files.L............................................P.r.o.g.r.a.m. .F.i.l.e.s.....h.1...........2BrightSparks.L............................................2.B.r.i.g.h.t.S.p.a.r.k.s.....b.1...........SyncBackPro.H............................................S.y.n.c.B.a.c.k.P.r.o.....x.2...........SyncBackPro.NE.exe..V............................................S.y.n.c.B.a.c.k.P.r.o...N.E...e.x.e..."...I.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o.\.S.y.n.c.B.a.c.k.P.r.o...N.E...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o.u.......i...1SPSU(L.y.9K....-...M............:...2.B.r.i.g.h.t.S.p.a.r.k.s...S.y.n.c.B.a.c.k.P.r.o...N.E.................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon Nov 18 00:31:48 2024, mtime=Mon Nov 18 00:31:53 2024, atime=Sat Nov 16 20:02:14 2024, length=193654768, window=hide
      Category:dropped
      Size (bytes):1168
      Entropy (8bit):4.526377744925875
      Encrypted:false
      SSDEEP:
      MD5:9708E1AEF0094A4B4D811C8FFC49D52F
      SHA1:C8911A9C95739C1BFA531144343C7A1677FA1934
      SHA-256:816D8D568914C6269029D9911D163D1A262BBE3805026534C7FBC9EDA664F732
      SHA-512:0AAA32B805DF0819FA9245FDE3570B26C0A10C7D66453EFFE3362483C99A14E454C96A948C8AC169372F06C1E45921B602EDE200706DFEA38276133024E7D7BD
      Malicious:false
      Reputation:unknown
      Preview:L..................F.... ....t..Y9..P...Y9......j8..............................P.O. .:i.....+00.../C:\.....................1.....rY....PROGRA~1..t......O.IrY......B...............J.....};..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....d.1.....rY....2BRIGH~1..L......rY..rY...........................};..2.B.r.i.g.h.t.S.p.a.r.k.s.....`.1.....rY....SYNCBA~1..H......rY..rY...........................mz..S.y.n.c.B.a.c.k.P.r.o.....l.2....pYG. .SYNCBA~1.EXE..P......rY..rY...............................S.y.n.c.B.a.c.k.P.r.o...e.x.e.......i...............-.......h.............1......C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe..F.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o.\.S.y.n.c.B.a.c.k.P.r.o...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o.`.......X.......216041...........hT..CrF.f4... ..............%..hT..CrF.f4... ..............%...
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
      File Type:ASCII text
      Category:dropped
      Size (bytes):290
      Entropy (8bit):5.136995927439063
      Encrypted:false
      SSDEEP:
      MD5:8B6897907FAF1517E23F21F38642CB2B
      SHA1:0ED8F6A01A2B0EAF2651DD13452CE65689178BCF
      SHA-256:EE8EE1C4D4D1831F7DA9BFB036899257B160A9DF1BE3F61EA2D184FA9F69FB7D
      SHA-512:9B81C9CA938BEAEEF67CB352D3D0CFFF7352511F7ABDF758AC134F73402150E051FC536F5079109DB6172626A29867E6BD7F2658602B17E2BA37A7EEC0D8AE2D
      Malicious:false
      Reputation:unknown
      Preview:2024/11/17-20:32:51.507 1300 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2024/11/17-20:32:51.509 1300 Recovering log #3.2024/11/17-20:32:51.510 1300 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
      File Type:ASCII text
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:8B6897907FAF1517E23F21F38642CB2B
      SHA1:0ED8F6A01A2B0EAF2651DD13452CE65689178BCF
      SHA-256:EE8EE1C4D4D1831F7DA9BFB036899257B160A9DF1BE3F61EA2D184FA9F69FB7D
      SHA-512:9B81C9CA938BEAEEF67CB352D3D0CFFF7352511F7ABDF758AC134F73402150E051FC536F5079109DB6172626A29867E6BD7F2658602B17E2BA37A7EEC0D8AE2D
      Malicious:false
      Reputation:unknown
      Preview:2024/11/17-20:32:51.507 1300 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2024/11/17-20:32:51.509 1300 Recovering log #3.2024/11/17-20:32:51.510 1300 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
      File Type:ASCII text
      Category:dropped
      Size (bytes):334
      Entropy (8bit):5.151848677546409
      Encrypted:false
      SSDEEP:
      MD5:42EB48DA9799A9E66D7DD7D305D4F9A1
      SHA1:ADC0F55F292ECA18205680C55119193C68DFD26D
      SHA-256:A85FC3F2D016386FBFBD84F918FC8A34AA1E1C8D2EC85B4FABDD6288C727C886
      SHA-512:945DD3CFA9450D0AAC7ED0FF770D4B03DD297D8937A68AA0B636DCFA21967EA7793F5D8C80845DFBDBFB59B38AE453AD4C70BCF84EC936049D38720BDB529D95
      Malicious:false
      Reputation:unknown
      Preview:2024/11/17-20:32:51.386 11ec Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2024/11/17-20:32:51.390 11ec Recovering log #3.2024/11/17-20:32:51.390 11ec Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
      File Type:ASCII text
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:42EB48DA9799A9E66D7DD7D305D4F9A1
      SHA1:ADC0F55F292ECA18205680C55119193C68DFD26D
      SHA-256:A85FC3F2D016386FBFBD84F918FC8A34AA1E1C8D2EC85B4FABDD6288C727C886
      SHA-512:945DD3CFA9450D0AAC7ED0FF770D4B03DD297D8937A68AA0B636DCFA21967EA7793F5D8C80845DFBDBFB59B38AE453AD4C70BCF84EC936049D38720BDB529D95
      Malicious:false
      Reputation:unknown
      Preview:2024/11/17-20:32:51.386 11ec Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2024/11/17-20:32:51.390 11ec Recovering log #3.2024/11/17-20:32:51.390 11ec Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
      File Type:JSON data
      Category:dropped
      Size (bytes):371
      Entropy (8bit):4.991101827534053
      Encrypted:false
      SSDEEP:
      MD5:B6B6B56309C445219D87D8A24076698D
      SHA1:8B66F112BFFF248BF1E7C1C476D8E4C15111C467
      SHA-256:83502B88B2EAC6AAAB591871D3C7CB2C4AC0621385C92C4D75A733B4E9CB9C50
      SHA-512:906BC53CFCE7C0181C3746E73466CFAA8220920E454D0155E06E3AF1410E23BAF089795C48E5F5B03E7DCFF3F8B4CC389EF486D88AD5FDB00215EC0067155A3B
      Malicious:false
      Reputation:unknown
      Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13376453577171609","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.16","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
      File Type:data
      Category:dropped
      Size (bytes):4509
      Entropy (8bit):5.230427445803608
      Encrypted:false
      SSDEEP:
      MD5:67D5B8553F3B5E5FBC43D9769E73FCD6
      SHA1:4A0DB9DB8307C745940AE6D94FC086534E2B4987
      SHA-256:BFD3A15A329B88F7B1C0AFF9D8EA6A20B7CA848325E6CC2E4C5509D8ABB74DB7
      SHA-512:A75C2E3784BA0B9797B9AB471C2C757CE4AAA5C34BB618A7490D6ADA6DA16103FA8DCAFC0A922D28D3CF9DAD87AC59831A8EC4ED8E973C28A28F4E35D3CB4A6B
      Malicious:false
      Reputation:unknown
      Preview:*...#................version.1..namespace-e...o................next-map-id.1.Pnamespace-1d95df23_a38f_44a8_b732_4e62dd896a16-https://rna-resource.acrobat.com/.0y.S_r................next-map-id.2.Snamespace-2a884c18_b39c_4e3d_942f_252e530ca4bd-https://rna-v2-resource.acrobat.com/.16.X:r................next-map-id.3.Snamespace-2e78bfda_7188_4688_a4aa_1ff81b6e5eaa-https://rna-v2-resource.acrobat.com/.2.P.@o................next-map-id.4.Pnamespace-09c119c2_97bc_4467_8f67_f92472c9e5dc-https://rna-resource.acrobat.com/.346.+^...............Pnamespace-1d95df23_a38f_44a8_b732_4e62dd896a16-https://rna-resource.acrobat.com/....^...............Pnamespace-09c119c2_97bc_4467_8f67_f92472c9e5dc-https://rna-resource.acrobat.com/..?&a...............Snamespace-2a884c18_b39c_4e3d_942f_252e530ca4bd-https://rna-v2-resource.acrobat.com/_...a...............Snamespace-2e78bfda_7188_4688_a4aa_1ff81b6e5eaa-https://rna-v2-resource.acrobat.com/...o................next-map-id.5.Pnamespace-07af9ee9_2076_4f12_94b5_
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
      File Type:ASCII text
      Category:dropped
      Size (bytes):322
      Entropy (8bit):5.143512580928821
      Encrypted:false
      SSDEEP:
      MD5:E5B520AEFDE145DBAF00C7977F548CA9
      SHA1:B7C43DB992D8C49F458ED7166D1AB3135E256153
      SHA-256:02EB3B19CC37279E8B1BE10455C7EEE465660C4A3CD04C7F9105D79B9994F4F4
      SHA-512:A7B184D363B3DAC279751F72961DFBAF6B23FB7AE0FF180A73684ABC29F043479E0FEC5DBD08554A98D7C7F4570923B52A5DC76D19F70B985CABE78FBDC83660
      Malicious:false
      Reputation:unknown
      Preview:2024/11/17-20:32:51.552 11ec Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2024/11/17-20:32:51.553 11ec Recovering log #3.2024/11/17-20:32:51.556 11ec Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
      File Type:ASCII text
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:E5B520AEFDE145DBAF00C7977F548CA9
      SHA1:B7C43DB992D8C49F458ED7166D1AB3135E256153
      SHA-256:02EB3B19CC37279E8B1BE10455C7EEE465660C4A3CD04C7F9105D79B9994F4F4
      SHA-512:A7B184D363B3DAC279751F72961DFBAF6B23FB7AE0FF180A73684ABC29F043479E0FEC5DBD08554A98D7C7F4570923B52A5DC76D19F70B985CABE78FBDC83660
      Malicious:false
      Reputation:unknown
      Preview:2024/11/17-20:32:51.552 11ec Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2024/11/17-20:32:51.553 11ec Recovering log #3.2024/11/17-20:32:51.556 11ec Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
      Category:dropped
      Size (bytes):71954
      Entropy (8bit):7.996617769952133
      Encrypted:true
      SSDEEP:
      MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
      SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
      SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
      SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
      Malicious:false
      Reputation:unknown
      Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:data
      Category:dropped
      Size (bytes):328
      Entropy (8bit):3.2539954282295116
      Encrypted:false
      SSDEEP:
      MD5:3F655F3E01F35FD95168F9CAEF5DBBF9
      SHA1:80867E600C02CA8FBF4272FD7D7BE2AC4F497B8D
      SHA-256:27FDB4A771F75E3012EE154B618C13257F3BFC9CA014F516EB3CC9699DD9E1DF
      SHA-512:88F6411B872A24C3BFCBA39965A2F9A712EC7546904E425BF2F545D64252CE8A76083F34407C34672E10A6BFBFC3B0C820C43EBE66D9ACA4D4F94BAB80F9AF28
      Malicious:false
      Reputation:unknown
      Preview:p...... ........OS..Y9..(....................................................... ........G..@.......&......X........h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):96
      Entropy (8bit):4.978745605946288
      Encrypted:false
      SSDEEP:
      MD5:ECCA755036566E561381D3EE930A4CC1
      SHA1:29210FBB573637E35BD9B9A429C394803D9492E2
      SHA-256:69E53E8854EE2F432EA457D6E3DC20EFC55E85EAEEB00E40E34010061078054F
      SHA-512:4CA300F5D84A88444601EFBA507A11B91537815BB7D763E227FEA623B8CD7E08962871995DE9405CAFE7D82DBE9208855D1F8C6C9B0D643699D9DE56CC28D46A
      Malicious:false
      Reputation:unknown
      Preview:.[General]..Path2SyncBackApp=C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.NE.exe....
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Unicode text, UTF-16, little-endian text, with very long lines (548), with CRLF line terminators
      Category:dropped
      Size (bytes):1214
      Entropy (8bit):2.670706730010473
      Encrypted:false
      SSDEEP:
      MD5:AB5F231DEF527A6D0ADCFD23E080B343
      SHA1:98CD1B377CC7189AAD74C0D79D0340E15435CE2E
      SHA-256:FAC31B33B9D4EDCEB9D36AB1D44D44D4329D78D3CBA00C542EDAC45B9D10FBA1
      SHA-512:8951EC3B404EBD14F6EA1F07377A02083FB922EBB2DB59D6EBC7F95CA14A1109E28AA2974E4F78D671D5120D1BF8348811EDF5CA443306DAA709B8B253B2B0F2
      Malicious:false
      Reputation:unknown
      Preview:......[.R.e.s.u.l.t.].....4.9.E.2.F.C.6.5.8.0.B.0.4.D.4.7.5.0.D.0.F.4.5.A.1.B.3.8.9.9.9.F.=.7.....[.T.e.x.t.].....4.9.E.2.F.C.6.5.8.0.B.0.4.D.4.7.5.0.D.0.F.4.5.A.1.B.3.8.9.9.9.F.=.8.4. .1.0.4. .1.0.1. .1.1.4. .1.0.1. .3.2. .9.7. .1.1.4. .1.0.1. .3.2. .1.1.2. .1.1.4. .1.1.1. .1.0.2. .1.0.5. .1.0.8. .1.0.1. .1.1.5. .3.2. .4.0. .3.7. .4.8. .5.8. .1.1.5. .4.1. .3.2. .1.0.2. .1.1.4. .1.1.1. .1.0.9. .3.2. .9.7. .1.1.0. .3.2. .1.1.1. .1.0.8. .1.0.0. .1.0.1. .1.1.4. .3.2. .1.1.8. .1.0.1. .1.1.4. .1.1.5. .1.0.5. .1.1.1. .1.1.0. .3.2. .1.1.1. .1.0.2. .3.2. .3.7. .4.9. .5.8. .1.1.5. .3.2. .1.0.5. .1.1.0. .3.2. .1.1.6. .1.0.4. .1.0.1. .3.2. .1.1.4. .1.0.1. .1.0.3. .1.0.5. .1.1.5. .1.1.6. .1.1.4. .1.2.1. .4.6. .3.2. .8.7. .1.1.1. .1.1.7. .1.0.8. .1.0.0. .3.2. .1.2.1. .1.1.1. .1.1.7. .3.2. .1.0.8. .1.0.5. .1.0.7. .1.0.1. .3.2. .1.1.6. .1.1.1. .3.2. .9.9. .1.1.1. .1.1.0. .1.1.8. .1.0.1. .1.1.4. .1.1.6. .3.2. .1.1.6. .1.0.4. .1.0.1. .1.0.9. .3.2. .1.1.5. .1.1.1. .3.2. .1.1.6. .1.0.4. .1.0.1. .1.2.1. .
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
      Category:modified
      Size (bytes):1180
      Entropy (8bit):3.6025154926481315
      Encrypted:false
      SSDEEP:
      MD5:347BA36E1CE50CF2044E72FDD80C1F59
      SHA1:E22DB8714F401FCBF3929A0260CF741F8A21F5F1
      SHA-256:2CF33B9441968D66C7F6BF13BF70558013E2E1C1A27D1518838A893718384F42
      SHA-512:C094514200D5A263D4A0E3ED6B59D7CC3B0ECD963A2677BDE31798B9BD70535A56F61E95167048DD85B16791F0F72EC1CA5173A9F083F8CBBC16DBB2CC15E33E
      Malicious:false
      Reputation:unknown
      Preview:..[.0.6.C.6.1.8.2.E.].....D.=.2.0.2.4.1.1.1.7.....F.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o.\.P.r.o.f.i.l.e.s. .B.a.c.k.u.p.\.S.u.n.\.S.e.t.t.i.n.g.s...i.n.i.....[.6.A.F.F.9.B.0.3.].....D.=.2.0.2.4.1.1.1.7.....F.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o.\.P.r.o.f.i.l.e.s. .B.a.c.k.u.p.\.S.u.n.\.S.e.t.t.i.n.g.s.S.y.s...i.n.i.....[.A.9.4.E.4.C.E.E.].....D.=.2.0.2.4.1.1.1.7.....F.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o.\.P.r.o.f.i.l.e.s. .B.a.c.k.u.p.\.S.u.n.\.D.S.e.t.t.i.n.g.s...i.n.i.....[.9.C.5.C.D.2.F.E.].....D.=.2.0.2.4.1.1.1.7.....F.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.2.B.r.i.g.h.t.S.p.a.r.k.s.\.S.y.n.c.B.a.c.k.P.r.o.\.P.r.o.f.i.l.e.s. .B.a.c.k.u.p.\.S.u.n.\.D.e.f.P.r.o.f.S.e.t.t.i.n.g.s...i.n.i.....[.7.6.A.9.3.4.3.D.].....D.=.2.0.2.4.1.1.1.7.....F.=.C.:.\.U.s.e.
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Unicode text, UTF-16, little-endian text, with very long lines (548), with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:AB5F231DEF527A6D0ADCFD23E080B343
      SHA1:98CD1B377CC7189AAD74C0D79D0340E15435CE2E
      SHA-256:FAC31B33B9D4EDCEB9D36AB1D44D44D4329D78D3CBA00C542EDAC45B9D10FBA1
      SHA-512:8951EC3B404EBD14F6EA1F07377A02083FB922EBB2DB59D6EBC7F95CA14A1109E28AA2974E4F78D671D5120D1BF8348811EDF5CA443306DAA709B8B253B2B0F2
      Malicious:false
      Reputation:unknown
      Preview:......[.R.e.s.u.l.t.].....4.9.E.2.F.C.6.5.8.0.B.0.4.D.4.7.5.0.D.0.F.4.5.A.1.B.3.8.9.9.9.F.=.7.....[.T.e.x.t.].....4.9.E.2.F.C.6.5.8.0.B.0.4.D.4.7.5.0.D.0.F.4.5.A.1.B.3.8.9.9.9.F.=.8.4. .1.0.4. .1.0.1. .1.1.4. .1.0.1. .3.2. .9.7. .1.1.4. .1.0.1. .3.2. .1.1.2. .1.1.4. .1.1.1. .1.0.2. .1.0.5. .1.0.8. .1.0.1. .1.1.5. .3.2. .4.0. .3.7. .4.8. .5.8. .1.1.5. .4.1. .3.2. .1.0.2. .1.1.4. .1.1.1. .1.0.9. .3.2. .9.7. .1.1.0. .3.2. .1.1.1. .1.0.8. .1.0.0. .1.0.1. .1.1.4. .3.2. .1.1.8. .1.0.1. .1.1.4. .1.1.5. .1.0.5. .1.1.1. .1.1.0. .3.2. .1.1.1. .1.0.2. .3.2. .3.7. .4.9. .5.8. .1.1.5. .3.2. .1.0.5. .1.1.0. .3.2. .1.1.6. .1.0.4. .1.0.1. .3.2. .1.1.4. .1.0.1. .1.0.3. .1.0.5. .1.1.5. .1.1.6. .1.1.4. .1.2.1. .4.6. .3.2. .8.7. .1.1.1. .1.1.7. .1.0.8. .1.0.0. .3.2. .1.2.1. .1.1.1. .1.1.7. .3.2. .1.0.8. .1.0.5. .1.0.7. .1.0.1. .3.2. .1.1.6. .1.1.1. .3.2. .9.9. .1.1.1. .1.1.0. .1.1.8. .1.0.1. .1.1.4. .1.1.6. .3.2. .1.1.6. .1.0.4. .1.0.1. .1.0.9. .3.2. .1.1.5. .1.1.1. .3.2. .1.1.6. .1.0.4. .1.0.1. .1.2.1. .
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Unicode text, UTF-16, little-endian text, with no line terminators
      Category:dropped
      Size (bytes):2
      Entropy (8bit):1.0
      Encrypted:false
      SSDEEP:
      MD5:F3B25701FE362EC84616A93A45CE9998
      SHA1:D62636D8CAEC13F04E28442A0A6FA1AFEB024BBB
      SHA-256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
      SHA-512:98C5F56F3DE340690C139E58EB7DAC111979F0D4DFFE9C4B24FF849510F4B6FFA9FD608C0A3DE9AC3C9FD2190F0EFAF715309061490F9755A9BFDF1C54CA0D84
      Malicious:false
      Reputation:unknown
      Preview:..
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:1BA4D129AFDD6896D25CA9640014C8CE
      SHA1:897CADD2EA2CD0BC9E4FA63B128CA08FFCCE0B14
      SHA-256:6DB8DEC13DC36DDC322871B8159340BE95420D8A2DFA6D4DED9F3D42429C9415
      SHA-512:52EEF5422FDDD03265A675387F8D50A40B4030AAE4D6806F162F86D76A3ED7CA0D5C13F4CFA4F50E2AB4CEED35E6BD26276E6516B64F65AAF913411C553F2BD1
      Malicious:false
      Reputation:unknown
      Preview:......[.S.e.t.t.i.n.g.s.].....I.D.=.3.5. .1.2. .1.0.0. .5.2. .1.3.7. .1.5.2. .7.6. .1.1.5. .1.0.0. .1.2. .1.0.2. .1.0.2. .2.5. .2.6. .6. .1.2.9. .1.5.2. .1.4.0. .1.5.3.....L.o.g.F.o.r.m.a.t.=.0.....L.o.g.F.i.l.e.n.a.m.e.=.%.P.R.O.F.I.L.E.N.A.M.E.%._.L.o.g._.P.a.g.e.%.P.A.G.E.%...h.t.m.l.....P.r.o.f.i.l.e.D.i.r.=.3.....L.o.g.H.i.s.t.o.r.y.=.5.....G.r.o.u.p.s.O.n.l.y.=.Y.....S.t.o.p.B.g.=.Y.....V.e.r.s.i.o.n.=.3.0.....S.B.M.S._.P.o.r.t.=.8.1.0.0.....U.p.d.C.h.e.c.k.D.a.y.s.=.3.0.....S.t.y.l.e.=.W.i.n.d.o.w.s.1.0.....P.r.e.f.e.r.C.o.l.o.u.r.I.m.a.g.e.s.=.N.....F.P._.f.r.m.M.a.i.n.=.2.4.0.,.2.2.8.,.8.2.4.,.5.0.4.,.0.,.9.6.....M.i.n.T.o.T.r.a.y.=.Y.....D.i.s.a.b.l.e.P.o.w.e.r.=.N.....N.o.A.u.t.o.P.a.u.s.e.=.N.....M.i.n.O.n.C.l.o.s.e.=.N.....M.i.n.O.n.R.u.n.=.N.....A.u.t.o.S.h.o.w.D.e.t.a.i.l.s.=.Y.....H.o.t.T.r.a.c.k.=.N.....H.o.r.i.z.L.i.n.e.s.=.Y.....V.e.r.t.L.i.n.e.s.=.N.....W.h.e.n.F.i.n.i.s.h.e.d.=.1.....S.e.l.e.c.t.e.d.P.r.o.f.i.l.e.s.=.....E.x.p.a.n.d.e.d.P.r.o.f.i.l.e.s.=.....S.o.r.
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
      Category:dropped
      Size (bytes):1284
      Entropy (8bit):3.6983474287622786
      Encrypted:false
      SSDEEP:
      MD5:1BA4D129AFDD6896D25CA9640014C8CE
      SHA1:897CADD2EA2CD0BC9E4FA63B128CA08FFCCE0B14
      SHA-256:6DB8DEC13DC36DDC322871B8159340BE95420D8A2DFA6D4DED9F3D42429C9415
      SHA-512:52EEF5422FDDD03265A675387F8D50A40B4030AAE4D6806F162F86D76A3ED7CA0D5C13F4CFA4F50E2AB4CEED35E6BD26276E6516B64F65AAF913411C553F2BD1
      Malicious:false
      Reputation:unknown
      Preview:......[.S.e.t.t.i.n.g.s.].....I.D.=.3.5. .1.2. .1.0.0. .5.2. .1.3.7. .1.5.2. .7.6. .1.1.5. .1.0.0. .1.2. .1.0.2. .1.0.2. .2.5. .2.6. .6. .1.2.9. .1.5.2. .1.4.0. .1.5.3.....L.o.g.F.o.r.m.a.t.=.0.....L.o.g.F.i.l.e.n.a.m.e.=.%.P.R.O.F.I.L.E.N.A.M.E.%._.L.o.g._.P.a.g.e.%.P.A.G.E.%...h.t.m.l.....P.r.o.f.i.l.e.D.i.r.=.3.....L.o.g.H.i.s.t.o.r.y.=.5.....G.r.o.u.p.s.O.n.l.y.=.Y.....S.t.o.p.B.g.=.Y.....V.e.r.s.i.o.n.=.3.0.....S.B.M.S._.P.o.r.t.=.8.1.0.0.....U.p.d.C.h.e.c.k.D.a.y.s.=.3.0.....S.t.y.l.e.=.W.i.n.d.o.w.s.1.0.....P.r.e.f.e.r.C.o.l.o.u.r.I.m.a.g.e.s.=.N.....F.P._.f.r.m.M.a.i.n.=.2.4.0.,.2.2.8.,.8.2.4.,.5.0.4.,.0.,.9.6.....M.i.n.T.o.T.r.a.y.=.Y.....D.i.s.a.b.l.e.P.o.w.e.r.=.N.....N.o.A.u.t.o.P.a.u.s.e.=.N.....M.i.n.O.n.C.l.o.s.e.=.N.....M.i.n.O.n.R.u.n.=.N.....A.u.t.o.S.h.o.w.D.e.t.a.i.l.s.=.Y.....H.o.t.T.r.a.c.k.=.N.....H.o.r.i.z.L.i.n.e.s.=.Y.....V.e.r.t.L.i.n.e.s.=.N.....W.h.e.n.F.i.n.i.s.h.e.d.=.1.....S.e.l.e.c.t.e.d.P.r.o.f.i.l.e.s.=.....E.x.p.a.n.d.e.d.P.r.o.f.i.l.e.s.=.....S.o.r.
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
      Category:modified
      Size (bytes):1138
      Entropy (8bit):3.5432820789475676
      Encrypted:false
      SSDEEP:
      MD5:D88FA93319E6178625157F74A661F50C
      SHA1:13FC08B654425274BF897EDF97AD1DC1285B8974
      SHA-256:9C14A41EC40CDE703E8A91E9852D46F0BB9B48E622538B74CDDABEF00829FAA5
      SHA-512:61531B71507158C8FF48390CE4F7C2301BC1076BB5992B85E8F538E49FCE9257A921EFB2A9385C758ACB9CF981EAE90D7374FD3F509C507822FE5759E994255C
      Malicious:false
      Reputation:unknown
      Preview:......[.S.e.t.t.i.n.g.s.].....V.e.r.s.i.o.n.C.o.u.n.t.e.r.=.1.....P.r.o.d.u.c.t.N.a.m.e.=.S.y.n.c.B.a.c.k.P.r.o.....P.r.o.g.V.e.r.s.i.o.n.=.1.1...3...6.2...0.....P.r.o.g.V.e.r.s.i.o.n.D.T.=.2.0.2.4.1.1.1.8.0.1.3.3.2.4.0.0.2.4.9.....P.r.e.v.P.r.o.g.V.e.r.s.i.o.n.=.1.1...3...6.2...0.....P.r.e.v.P.r.o.g.V.e.r.s.i.o.n.D.T.=.2.0.2.4.1.1.1.8.0.1.3.3.2.4.0.0.2.4.9.....P.r.e.v.W.i.n.V.e.r.s.i.o.n.=.W.i.n.d.o.w.s. .1.0. .(.6.4.-.b.i.t.). .(.1.0...0...1.9.0.4.5.). .(.P.r.o.f.e.s.s.i.o.n.a.l. .2.2.H.2. .2.0.0.9.). .(.P.r.o.).....P.r.e.v.W.i.n.V.e.r.s.i.o.n.D.T.=.2.0.2.4.1.1.1.8.0.1.3.3.2.4.0.0.2.6.5.....L.a.t.e.s.t.S.B.F.S.V.e.r.s.i.o.n.=.1...7...9...0.....L.a.s.t.S.B.F.S.U.p.d.C.h.e.c.k.=.2.0.2.4.1.1.1.7.2.0.3.3.3.7.0.0.6.3.3.....L.a.s.t.U.p.d.C.h.e.c.k.=.2.0.2.4.1.1.1.7.2.0.3.3.3.7.0.0.6.3.3.....U.A.C.a.c.h.e.d.D.T.=.2.0.2.4.1.1.1.8.0.1.3.3.3.7.0.0.6.3.3.....U.A.O.=.....U.A.D.a.t.e.=.1.8.9.9.1.2.3.1.0.0.0.0.0.0.0.0.0.0.0.....U.A.C.D.a.t.e.=.1.8.9.9.1.2.3.1.0.0.0.0.0.0.0.0.0.0.0.....U.A.D.D.a.t.
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:SQLite 3.x database, last written using SQLite version 3046001, file counter 4, database pages 2, cookie 0x1, schema 4, UTF-8, version-valid-for 4
      Category:dropped
      Size (bytes):8192
      Entropy (8bit):0.5824040440635917
      Encrypted:false
      SSDEEP:
      MD5:85DAE41DB99101AD35FDA045B9A6AA38
      SHA1:EC00B09CA87A153D802C78D9B950BD064DC7A24A
      SHA-256:0D14632B10AEEFF3EFDBF24192694C6AFC1864C2AA6AD9FBC31528C1EC42FA0C
      SHA-512:C574913E37A8E674C9A51418850C94417DC131B5CF9A3B55301FD8C5261A2F863EEC8E16BE13C06B60D076CB8DAB090FF5A58564E053C72DDE51C03EA7AE6E94
      Malicious:false
      Reputation:unknown
      Preview:SQLite format 3......@ ..........................................................................zq....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:SQLite Rollback Journal
      Category:dropped
      Size (bytes):8720
      Entropy (8bit):0.4849553411011644
      Encrypted:false
      SSDEEP:
      MD5:9886B5AAB1D19C5E617D8F9159B46E1B
      SHA1:508E87F4C1C6B7C19EECFC585536C136B7847B1C
      SHA-256:C1A3D34474AA1E6AA8788653EC4F57D059AEFF4261481BFA137B6C1D4931F969
      SHA-512:32317C76450E14DB44BF3B88446782225CEC51AE3C80A0B13C0C41BFD4D1B9D822CE89A972362213EE485659655CF59463D675ABA7732527012D16F23AD4161D
      Malicious:false
      Reputation:unknown
      Preview:.... .c..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................b....b........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:PostScript document text
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:8BA9D8BEBA42C23A5DB405994B54903F
      SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
      SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
      SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
      Malicious:false
      Reputation:unknown
      Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:PostScript document text
      Category:dropped
      Size (bytes):1233
      Entropy (8bit):5.233980037532449
      Encrypted:false
      SSDEEP:
      MD5:8BA9D8BEBA42C23A5DB405994B54903F
      SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
      SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
      SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
      Malicious:false
      Reputation:unknown
      Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:PostScript document text
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:8BA9D8BEBA42C23A5DB405994B54903F
      SHA1:FC1B1646EC8A7015F492AA17ADF9712B54858361
      SHA-256:862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C
      SHA-512:26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A
      Malicious:false
      Reputation:unknown
      Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:PostScript document text
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:B60EE534029885BD6DECA42D1263BDC0
      SHA1:4E801BA6CA503BDAE7E54B7DB65BE641F7C23375
      SHA-256:B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856
      SHA-512:52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE
      Malicious:false
      Reputation:unknown
      Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:PostScript document text
      Category:dropped
      Size (bytes):10880
      Entropy (8bit):5.214360287289079
      Encrypted:false
      SSDEEP:
      MD5:B60EE534029885BD6DECA42D1263BDC0
      SHA1:4E801BA6CA503BDAE7E54B7DB65BE641F7C23375
      SHA-256:B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856
      SHA-512:52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE
      Malicious:false
      Reputation:unknown
      Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-H.Registry:Adobe.Ordering:Identity.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-H.FileLength:8228.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:Identity-V.Registry:Adobe.Ordering:Identity.UseCMap:Identity-H.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Identity-V.FileLength:2761.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UCS2-GBK-EUC.Registry:Adobe.Ordering:UCS2_GBK_EUC.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC.FileLength:243835.FileModTime:1612212568.%EndFont..%BeginFont.Handler:DirectoryHandler.FontType:CMap.CMapName:UniKS-UTF16-H.Registry:Adobe.Ordering:Korea1.OutlineFileName:C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H.FileLength:131902.FileModTime:1612212568.%EndFont..%BeginFont.Handler:D
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:data
      Category:dropped
      Size (bytes):227002
      Entropy (8bit):3.392780893644728
      Encrypted:false
      SSDEEP:
      MD5:265E3E1166312A864FB63291EA661C6A
      SHA1:80DFF3187FF929596EB22E1DB9021BAD6F97178C
      SHA-256:C13E08B1887A4E44DC39609D7234E8D732A6BC11313B55D6F4ECFB060CD87728
      SHA-512:48776A2BFE8F25E5601DCC0137F7AB103D5684517334B806E3ACF61683DD9B283828475FC85CE0CBE4E8AF88E6F8B25EED0A77640E2CFFF2CC73708726519AFA
      Malicious:false
      Reputation:unknown
      Preview:Adobe Acrobat Reader (64-bit) 23.6.20320....?A12_AV2_Search_18px.............................................................................................................KKK KKK.KKK.KKK.KKK.KKK.KKK@........................................KKK`KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.............................KKKPKKK.KKK.KKK.KKK.........KKKPKKK.KKK.KKK.........................KKK.KKK.KKK.KKK0....................KKK.KKK.KKK.KKK`....................KKK`KKK.KKK.............................KKK@KKK.KKK.....................KKK.KKK.KKK0................................KKK.KKK.....................KKK.KKK.....................................KKK.KKK.....................KKK.KKK.KKK0................................KKK.KKK.....................KKK`KKK.KKK.............................KKK@KKK.KKK.....................KKK.KKK.KKK.KKK@....................KKK.KKK.KKK.KKK`........................KKKPKKK.KKK.KKK.KKK.........KKKPKKK.KKK.KKK.KKK.............................KKK`KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:data
      Category:dropped
      Size (bytes):4
      Entropy (8bit):0.8112781244591328
      Encrypted:false
      SSDEEP:
      MD5:DC84B0D741E5BEAE8070013ADDCC8C28
      SHA1:802F4A6A20CBF157AAF6C4E07E4301578D5936A2
      SHA-256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
      SHA-512:65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71
      Malicious:false
      Reputation:unknown
      Preview:....
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:JSON data
      Category:dropped
      Size (bytes):1969
      Entropy (8bit):5.060655148803049
      Encrypted:false
      SSDEEP:
      MD5:99D32A084B69D3E565FD3B995CF7A2CE
      SHA1:1B335CC5DC9E008BC0F6EA3BEDCE7655879E0502
      SHA-256:66B697CB16D6A6FEA615093E0ABAA9847D288FED263B1E3AD4BB6B70806EF7B9
      SHA-512:2314E79F6476314E1AB457F28415B380305BDF481C23F85105315F5B168BBBDDD0ABB8618F89DB62AC8F0937F7D7B7D1CFCCD6D6105D894FBAD123E3ED5AA9FF
      Malicious:false
      Reputation:unknown
      Preview:{"all":[{"id":"TESTING","info":{"dg":"DG","sid":"TESTING"},"mimeType":"file","size":4,"ts":1731893571000},{"id":"DC_Reader_Home_LHP_Trial_Banner","info":{"dg":"f44756c6e08822e64c0e471a2499e34d","sid":"DC_Reader_Home_LHP_Trial_Banner"},"mimeType":"file","size":295,"ts":1696585148000},{"id":"DC_Reader_Disc_LHP_Banner","info":{"dg":"e8f53b6740aba22a83a1a569cebedbcc","sid":"DC_Reader_Disc_LHP_Banner"},"mimeType":"file","size":1250,"ts":1696585148000},{"id":"DC_Reader_Sign_LHP_Banner","info":{"dg":"ab062dea95f25ef019cc2f5f5f0121d4","sid":"DC_Reader_Sign_LHP_Banner"},"mimeType":"file","size":1250,"ts":1696583346000},{"id":"DC_Reader_Convert_LHP_Banner","info":{"dg":"65580efad4bc88b91040ff50d71bfae9","sid":"DC_Reader_Convert_LHP_Banner"},"mimeType":"file","size":1255,"ts":1696583346000},{"id":"DC_Reader_Edit_LHP_Banner","info":{"dg":"f8ce16c8d78d640728012d308f601433","sid":"DC_Reader_Edit_LHP_Banner"},"mimeType":"file","size":1230,"ts":1696583346000},{"id":"DC_Reader_RHP_Banner","info":{"dg":
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 19, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 19
      Category:dropped
      Size (bytes):12288
      Entropy (8bit):0.9889018382175545
      Encrypted:false
      SSDEEP:
      MD5:BF1456B56BE8C1A5072F0E2792883839
      SHA1:4B14EF638DED10E9C9A86C186A7F2484AFA29109
      SHA-256:5A716E566069BEDD94C98531144DE3304B388BF47890B017378BB98FD872FF8E
      SHA-512:08A0F423CD0774B8842AE6DC71A379B02172A111C5121EDB086951D5222096DA03E306CBC13108ED27E5D39BDCD42E93A0106EB1E59617FA60EC71F2648BBBC2
      Malicious:false
      Reputation:unknown
      Preview:SQLite format 3......@ ..........................................................................c.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:SQLite Rollback Journal
      Category:dropped
      Size (bytes):8720
      Entropy (8bit):1.344398944619862
      Encrypted:false
      SSDEEP:
      MD5:B85AA67961E3C613F573AF411F447798
      SHA1:845467E93F69F53D222E7C1EFF17FA0AF7260BDA
      SHA-256:C0CAFAE7A0687C2085FEE776929524E58894E7676263BBF18F415940EB27BC50
      SHA-512:A0801088CFC715CFA8E571A5E89F9B0B9BB95D162755B663EB7A10AA0E71826A963437E88FB585F7757AADB537E78A9AC9E212461937455F687F7D9B0C7BED2C
      Malicious:false
      Reputation:unknown
      Preview:.... .c.......?T......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................j...#..#.#.#.#.#.#.#.#.7.7........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:data
      Category:dropped
      Size (bytes):66726
      Entropy (8bit):5.392739213842091
      Encrypted:false
      SSDEEP:
      MD5:C4546E0BBB2C5A90B2770A11B61383F7
      SHA1:045380CEAB545C40793F78C85FC6606E0A49902A
      SHA-256:B52B3321C3B70E5134CFAE7F2F206C062879EC4571A303EC4C4CA40E34D33B53
      SHA-512:AB86F00EE41634EDE921ED27D1CCED932899625C4DCB6369E9F74B3089E32CD69A487B3E0E563EC379B0B19494975C6A2909A3187070453E66EF8EAD39619A9E
      Malicious:false
      Reputation:unknown
      Preview:4.397.90.FID.2:o:..........:F:AgencyFB-Reg.P:Agency FB.L:$.........................."F:Agency FB.#.96.FID.2:o:..........:F:AgencyFB-Bold.P:Agency FB Bold.L:%.........................."F:Agency FB.#.84.FID.2:o:..........:F:Algerian.P:Algerian.L:$..........................RF:Algerian.#.95.FID.2:o:..........:F:ArialNarrow.P:Arial Narrow.L:$.........................."F:Arial Narrow.#.109.FID.2:o:..........:F:ArialNarrow-Italic.P:Arial Narrow Italic.L:$.........................."F:Arial Narrow.#.105.FID.2:o:..........:F:ArialNarrow-Bold.P:Arial Narrow Bold.L:%.........................."F:Arial Narrow.#.118.FID.2:o:..........:F:ArialNarrow-BoldItalic.P:Arial Narrow Bold Italic.L:%.........................."F:Arial Narrow.#.77.FID.2:o:..........:F:ArialMT.P:Arial.L:$.........................."F:Arial.#.91.FID.2:o:..........:F:Arial-ItalicMT.P:Arial Italic.L:$.........................."F:Arial.#.87.FID.2:o:..........:F:Arial-BoldMT.P:Arial Bold.L:$.........................."F:Arial.#.100.FID.2
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:ASCII text, with very long lines (393)
      Category:dropped
      Size (bytes):16525
      Entropy (8bit):5.353642815103214
      Encrypted:false
      SSDEEP:
      MD5:91F06491552FC977E9E8AF47786EE7C1
      SHA1:8FEB27904897FFCC2BE1A985D479D7F75F11CEFC
      SHA-256:06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB
      SHA-512:A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082
      Malicious:false
      Reputation:unknown
      Preview:SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:073+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:073+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="SetConfig:
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:ASCII text, with very long lines (393), with CRLF line terminators
      Category:dropped
      Size (bytes):16603
      Entropy (8bit):5.368053253920968
      Encrypted:false
      SSDEEP:
      MD5:B8E94CCDAF5411C136D69BB1598DDB1A
      SHA1:FEAF16780C5524BC5716918F012F16BCD5930EE4
      SHA-256:24F3CAAFDBE4D2832F8B72B033658EEC48C45B42A44340DDCE1DBEBE0DDA3573
      SHA-512:5EE4744BD2961CF24DDBA5DE655359A2655411C3772474FFBF084A439B37DCDEE99F2AB4910AC47B1CA86C3A2E58171856C6620CA26653B01DF65B587D97252D
      Malicious:false
      Reputation:unknown
      Preview:SessionID=d8918ab6-9156-4b25-afcc-07adca30bc67.1731893570721 Timestamp=2024-11-17T20:32:50:721-0500 ThreadID=1312 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------"..SessionID=d8918ab6-9156-4b25-afcc-07adca30bc67.1731893570721 Timestamp=2024-11-17T20:32:50:723-0500 ThreadID=1312 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found"..SessionID=d8918ab6-9156-4b25-afcc-07adca30bc67.1731893570721 Timestamp=2024-11-17T20:32:50:723-0500 ThreadID=1312 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!"..SessionID=d8918ab6-9156-4b25-afcc-07adca30bc67.1731893570721 Timestamp=2024-11-17T20:32:50:723-0500 ThreadID=1312 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1"..SessionID=d8918ab6-9156-4b25-afcc-07adca30bc67.1731893570721 Timestamp=2024-11-17T20:32:50:724-0500 ThreadID=1312 Component=ngl-lib_NglAppLib Description="SetConf
      Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):29845
      Entropy (8bit):5.420025315933696
      Encrypted:false
      SSDEEP:
      MD5:0D7E608D6933F149A1F3317F1AEFA127
      SHA1:BA8E3A3BA28EA09D5F51E58D369FCAFBC25DF11C
      SHA-256:5D30409A09850B834C6C017113EA241E13BDEE147EDD686A3347AF01848342D5
      SHA-512:3483CEFD10370EE46092B94454F27BA6F57BCA6D3BBE2CBBBFCE509E9681E065D11176821B8F8D0024A790C7778B0E820208FF276B508BF73440F60FA9FFA183
      Malicious:false
      Reputation:unknown
      Preview:06-10-2023 10:08:42:.---2---..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ***************************************..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ***************************************..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ******** Starting new session ********..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : Starting NGL..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : Setting synchronous launch...06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 ::::: Configuring as AcrobatReader1..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : NGLAppVersion 23.6.20320.6..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : NGLAppMode NGL_INIT..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : AcroCEFPath, NGLCEFWorkflowModulePath - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1 C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : isNGLExternalBrowserDisabled - No..06-10-2023 10:08:42:.Closing File..06-10-
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):6144
      Entropy (8bit):4.720366600008286
      Encrypted:false
      SSDEEP:
      MD5:E4211D6D009757C078A9FAC7FF4F03D4
      SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
      SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
      SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
      Process:C:\Program Files\Windows Defender\MpCmdRun.exe
      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
      Category:modified
      Size (bytes):4926
      Entropy (8bit):3.247867656168033
      Encrypted:false
      SSDEEP:
      MD5:D80E864D99A737B9D05258805A38CE65
      SHA1:482B82BB22E13E9D8F60887E2F18F1D224F719FB
      SHA-256:05A064B74EAE22EC856EF00E8F76A5F8B11C4F00F046238EBD6AFD7C2A8D7737
      SHA-512:B2A8A74408396BF13A41649CBCE0B6F998E2CE86EE15C5297A49BDFB5825268E1D459AE97589A6048EECB01CA91A5DD4DC544AD67E6A6655217540D6D6C597BC
      Malicious:false
      Reputation:unknown
      Preview:..........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. F.r.i. .. O.c.t. .. 0.6. .. 2.0.2.3. .1.1.:.3.5.:.2.9.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .W.S.C. .S.t.a.t.e. .I.n.f.o. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .A.n.t.i.V.i.r.u.s.P.r.o.d.u.c.t. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....d.i.s.p.l.a.y.N.a.m.e. .=. .[.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.].....p.a.t.h.T.o.S.i.g.n.e.d.P.r.o.d.u.c.t.E.x.e. .=. .[.w.i.n.d.o.w.s.d.
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:5E93F4E33E9053A4743FCD7C0F515D49
      SHA1:1ED761D82185FAB264E423F554B2C2DB04CF6391
      SHA-256:3A4613C9AF7FDFA8FCA7B0D1C60A74FD08FE1DA09BDBCA360A7669F6ECD93443
      SHA-512:EBEAC14754EFA82BA377AA570B8AD502580CC9E0C0346AE45ECEE45CD3C6172EC30B79FE92E4A34E01593245F786EE50F1052AB236EBBE5F5937552277F7EE73
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 3%
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...s.Ie...........!.........$....................@..........................`............@.......................... ..t.......n....P.......................@..H...............................................................$....................text.............................. ..`.itext.............................. ..`.data...H...........................@....bss.....5...............................idata..n...........................@....didata.$...........................@....edata..t.... ......................@..@.rdata..E....0......................@..@.reloc..H....@......................@..B.rsrc........P......................@..@.............`......................@..@........................................................
      Process:C:\Users\user\AppData\Local\Temp\is-TC366.tmp\SyncBackPro64_Setup.tmp
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):46080
      Entropy (8bit):6.1451789764308336
      Encrypted:false
      SSDEEP:
      MD5:5E93F4E33E9053A4743FCD7C0F515D49
      SHA1:1ED761D82185FAB264E423F554B2C2DB04CF6391
      SHA-256:3A4613C9AF7FDFA8FCA7B0D1C60A74FD08FE1DA09BDBCA360A7669F6ECD93443
      SHA-512:EBEAC14754EFA82BA377AA570B8AD502580CC9E0C0346AE45ECEE45CD3C6172EC30B79FE92E4A34E01593245F786EE50F1052AB236EBBE5F5937552277F7EE73
      Malicious:false
      Reputation:unknown
      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...s.Ie...........!.........$....................@..........................`............@.......................... ..t.......n....P.......................@..H...............................................................$....................text.............................. ..`.itext.............................. ..`.data...H...........................@....bss.....5...............................idata..n...........................@....didata.$...........................@....edata..t.... ......................@..@.rdata..E....0......................@..@.reloc..H....@......................@..B.rsrc........P......................@..@.............`......................@..@........................................................
      Process:C:\Program Files\2BrightSparks\SyncBackPro\SyncBackPro.exe
      File Type:data
      Category:dropped
      Size (bytes):64
      Entropy (8bit):3.6818583242053364
      Encrypted:false
      SSDEEP:
      MD5:4B3BAF0AA2C34C3F0EA0E41D452B5EE8
      SHA1:031CCC3D6FE5FA20E49AF2AB4F8D0B10CDD60885
      SHA-256:8296A5F301E709B96B01A5D6511A611E5D856FF8518E230D023CB45ECEF7E075
      SHA-512:41FFC84869AEC4C8589FF5970484DF9D95098A5E66C43BA301115CEC831DC0F7A905708C8574B99B32ADBE185127203A825E61EBEFA0CB9C372B3E02CDCAD3D4
      Malicious:false
      Reputation:unknown
      Preview:....2.1.6.0.4.1.....\MAILSLOT\NET\GETDC58638A9E.................
      File type:PE32 executable (GUI) Intel 80386, for MS Windows
      Entropy (8bit):7.9983831416606535
      TrID:
      • Win32 Executable (generic) a (10002005/4) 98.04%
      • Inno Setup installer (109748/4) 1.08%
      • InstallShield setup (43055/19) 0.42%
      • Win32 EXE PECompact compressed (generic) (41571/9) 0.41%
      • Win16/32 Executable Delphi generic (2074/23) 0.02%
      File name:SyncBackPro64_Setup.exe
      File size:56'285'520 bytes
      MD5:2b6068d3087ac283c4cc8822927bd711
      SHA1:d05c97e93755b892bf36534b48e4dda9839f8707
      SHA256:481c69d452ca4699994ef6b80fd26a85427edfc723dbc9a0b0476ef89179946b
      SHA512:7ac8484a42ad4553a0f58c5d3c994fecb6d953a0e65ed24f04d6baafee8a92844f912d1de77ac1f10a6269d5942fc7d346ede65138ac2675b5b7d8d757a63349
      SSDEEP:1572864:K4qLSqLWI0cvGEZvBXS5eVTfqamw4U73BNF:K4ibJHP4el1mNUrHF
      TLSH:B6C7333FF118663EC06E0F32577657249DBBBAA16507CC1A6BE8418DCF156202E3F689
      File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
      Icon Hash:17317131974dd029
      Entrypoint:0x4b5eec
      Entrypoint Section:.itext
      Digitally signed:true
      Imagebase:0x400000
      Subsystem:windows gui
      Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
      DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
      Time Stamp:0x63ECF218 [Wed Feb 15 14:54:16 2023 UTC]
      TLS Callbacks:
      CLR (.Net) Version:
      OS Version Major:6
      OS Version Minor:0
      File Version Major:6
      File Version Minor:0
      Subsystem Version Major:6
      Subsystem Version Minor:0
      Import Hash:e569e6f445d32ba23766ad67d1e3787f
      Signature Valid:true
      Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
      Signature Validation Error:The operation completed successfully
      Error Number:0
      Not Before, Not After
      • 03/03/2023 01:00:00 27/05/2025 01:59:59
      Subject Chain
      • CN=2BrightSparks Pte. Ltd., OU=2BrightSparks Pte Ltd, O=2BrightSparks Pte. Ltd., L=Singapore, C=SG, SERIALNUMBER=200415517N, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=SG
      Version:3
      Thumbprint MD5:4236F0C7E1FF4F5EC47850A1E0A605EF
      Thumbprint SHA-1:885F7E968BBD6C006E630A2CB0CA6F4F0D7FF269
      Thumbprint SHA-256:C258051B6698255CA80F8CE3049E5769D9BD80A93A6454B53F6B54C0BD911882
      Serial:08B25109CB7D59AF94D350E59F23B5E0
      Instruction
      push ebp
      mov ebp, esp
      add esp, FFFFFFA4h
      push ebx
      push esi
      push edi
      xor eax, eax
      mov dword ptr [ebp-3Ch], eax
      mov dword ptr [ebp-40h], eax
      mov dword ptr [ebp-5Ch], eax
      mov dword ptr [ebp-30h], eax
      mov dword ptr [ebp-38h], eax
      mov dword ptr [ebp-34h], eax
      mov dword ptr [ebp-2Ch], eax
      mov dword ptr [ebp-28h], eax
      mov dword ptr [ebp-14h], eax
      mov eax, 004B14B8h
      call 00007FE4C55FDA25h
      xor eax, eax
      push ebp
      push 004B65E2h
      push dword ptr fs:[eax]
      mov dword ptr fs:[eax], esp
      xor edx, edx
      push ebp
      push 004B659Eh
      push dword ptr fs:[edx]
      mov dword ptr fs:[edx], esp
      mov eax, dword ptr [004BE634h]
      call 00007FE4C56A0517h
      call 00007FE4C56A006Ah
      lea edx, dword ptr [ebp-14h]
      xor eax, eax
      call 00007FE4C56134C4h
      mov edx, dword ptr [ebp-14h]
      mov eax, 004C1D84h
      call 00007FE4C55F8617h
      push 00000002h
      push 00000000h
      push 00000001h
      mov ecx, dword ptr [004C1D84h]
      mov dl, 01h
      mov eax, dword ptr [004238ECh]
      call 00007FE4C5614647h
      mov dword ptr [004C1D88h], eax
      xor edx, edx
      push ebp
      push 004B654Ah
      push dword ptr fs:[edx]
      mov dword ptr fs:[edx], esp
      call 00007FE4C56A059Fh
      mov dword ptr [004C1D90h], eax
      mov eax, dword ptr [004C1D90h]
      cmp dword ptr [eax+0Ch], 01h
      jne 00007FE4C56A67BAh
      mov eax, dword ptr [004C1D90h]
      mov edx, 00000028h
      call 00007FE4C5614F3Ch
      mov edx, dword ptr [004C1D90h]
      NameVirtual AddressVirtual Size Is in Section
      IMAGE_DIRECTORY_ENTRY_EXPORT0xc40000x9a.edata
      IMAGE_DIRECTORY_ENTRY_IMPORT0xc20000xfdc.idata
      IMAGE_DIRECTORY_ENTRY_RESOURCE0xc70000x14104.rsrc
      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
      IMAGE_DIRECTORY_ENTRY_SECURITY0x35a86680x52e8
      IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
      IMAGE_DIRECTORY_ENTRY_TLS0xc60000x18.rdata
      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
      IMAGE_DIRECTORY_ENTRY_IAT0xc22f40x254.idata
      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xc30000x1a4.didata
      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
      .text0x10000xb39e40xb3a0043af0a9476ca224d8e8461f1e22c94daFalse0.34525867693110646data6.357635049994181IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      .itext0xb50000x16880x1800185e04b9a1f554e31f7f848515dc890cFalse0.54443359375data5.971425428435973IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      .data0xb70000x37a40x3800cab2107c933b696aa5cf0cc6c3fd3980False0.36097935267857145data5.048648594372454IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .bss0xbb0000x6de80x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .idata0xc20000xfdc0x1000e7d1635e2624b124cfdce6c360ac21cdFalse0.3798828125data5.029087481102678IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .didata0xc30000x1a40x2008ced971d8a7705c98b173e255d8c9aa7False0.345703125data2.7509822285969876IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .edata0xc40000x9a0x2008d4e1e508031afe235bf121c80fd7d5fFalse0.2578125data1.877162954504408IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .tls0xc50000x180x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .rdata0xc60000x5d0x2008f2f090acd9622c88a6a852e72f94e96False0.189453125data1.3838943752217987IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .rsrc0xc70000x141040x14200ae33d441973fe0139027cced9dc5f886False0.4292629076086957data5.705244123502162IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      NameRVASizeTypeLanguageCountryZLIB Complexity
      RT_ICON0xc76780x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640EnglishUnited States0.42473118279569894
      RT_ICON0xc79600x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.5236486486486487
      RT_ICON0xc7a880xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2688EnglishUnited States0.4701492537313433
      RT_ICON0xc89300x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1152EnglishUnited States0.6024368231046932
      RT_ICON0xc91d80x568Device independent bitmap graphic, 16 x 32 x 8, image size 320EnglishUnited States0.6705202312138728
      RT_ICON0xc97400x41ebPNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9805037037037037
      RT_ICON0xcd92c0x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.1653873405762872
      RT_ICON0xd1b540x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.23609958506224066
      RT_ICON0xd40fc0x1a68Device independent bitmap graphic, 40 x 80 x 32, image size 6720EnglishUnited States0.2794378698224852
      RT_ICON0xd5b640x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.3219981238273921
      RT_ICON0xd6c0c0x988Device independent bitmap graphic, 24 x 48 x 32, image size 2400EnglishUnited States0.42295081967213116
      RT_ICON0xd75940x6b8Device independent bitmap graphic, 20 x 40 x 32, image size 1680EnglishUnited States0.5017441860465116
      RT_ICON0xd7c4c0x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.5593971631205674
      RT_STRING0xd80b40x360data0.34375
      RT_STRING0xd84140x260data0.3256578947368421
      RT_STRING0xd86740x45cdata0.4068100358422939
      RT_STRING0xd8ad00x40cdata0.3754826254826255
      RT_STRING0xd8edc0x2d4data0.39226519337016574
      RT_STRING0xd91b00xb8data0.6467391304347826
      RT_STRING0xd92680x9cdata0.6410256410256411
      RT_STRING0xd93040x374data0.4230769230769231
      RT_STRING0xd96780x398data0.3358695652173913
      RT_STRING0xd9a100x368data0.3795871559633027
      RT_STRING0xd9d780x2a4data0.4275147928994083
      RT_RCDATA0xda01c0x10data1.5
      RT_RCDATA0xda02c0x2c4data0.6384180790960452
      RT_RCDATA0xda2f00x2cdata1.2045454545454546
      RT_GROUP_ICON0xda31c0xbcdataEnglishUnited States0.6808510638297872
      RT_VERSION0xda3d80x584dataEnglishUnited States0.2797450424929179
      RT_MANIFEST0xda95c0x7a8XML 1.0 document, ASCII text, with very long lines (391), with CRLF line terminatorsEnglishUnited States0.3464285714285714
      DLLImport
      kernel32.dllGetACP, GetExitCodeProcess, LocalFree, CloseHandle, SizeofResource, VirtualProtect, VirtualFree, GetFullPathNameW, ExitProcess, HeapAlloc, GetCPInfoExW, RtlUnwind, GetCPInfo, GetStdHandle, GetModuleHandleW, FreeLibrary, HeapDestroy, ReadFile, CreateProcessW, GetLastError, GetModuleFileNameW, SetLastError, FindResourceW, CreateThread, CompareStringW, LoadLibraryA, ResetEvent, GetVersion, RaiseException, FormatMessageW, SwitchToThread, GetExitCodeThread, GetCurrentThread, LoadLibraryExW, LockResource, GetCurrentThreadId, UnhandledExceptionFilter, VirtualQuery, VirtualQueryEx, Sleep, EnterCriticalSection, SetFilePointer, LoadResource, SuspendThread, GetTickCount, GetFileSize, GetStartupInfoW, GetFileAttributesW, InitializeCriticalSection, GetSystemWindowsDirectoryW, GetThreadPriority, SetThreadPriority, GetCurrentProcess, VirtualAlloc, GetSystemInfo, GetCommandLineW, LeaveCriticalSection, GetProcAddress, ResumeThread, GetVersionExW, VerifyVersionInfoW, HeapCreate, GetWindowsDirectoryW, VerSetConditionMask, GetDiskFreeSpaceW, FindFirstFileW, GetUserDefaultUILanguage, lstrlenW, QueryPerformanceCounter, SetEndOfFile, HeapFree, WideCharToMultiByte, FindClose, MultiByteToWideChar, LoadLibraryW, SetEvent, CreateFileW, GetLocaleInfoW, GetSystemDirectoryW, DeleteFileW, GetLocalTime, GetEnvironmentVariableW, WaitForSingleObject, WriteFile, ExitThread, DeleteCriticalSection, TlsGetValue, GetDateFormatW, SetErrorMode, IsValidLocale, TlsSetValue, CreateDirectoryW, GetSystemDefaultUILanguage, EnumCalendarInfoW, LocalAlloc, GetUserDefaultLangID, RemoveDirectoryW, CreateEventW, SetThreadLocale, GetThreadLocale
      comctl32.dllInitCommonControls
      version.dllGetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
      user32.dllCreateWindowExW, TranslateMessage, CharLowerBuffW, CallWindowProcW, CharUpperW, PeekMessageW, GetSystemMetrics, SetWindowLongW, MessageBoxW, DestroyWindow, CharUpperBuffW, CharNextW, MsgWaitForMultipleObjects, LoadStringW, ExitWindowsEx, DispatchMessageW
      oleaut32.dllSysAllocStringLen, SafeArrayPtrOfIndex, VariantCopy, SafeArrayGetLBound, SafeArrayGetUBound, VariantInit, VariantClear, SysFreeString, SysReAllocStringLen, VariantChangeType, SafeArrayCreate
      netapi32.dllNetWkstaGetInfo, NetApiBufferFree
      advapi32.dllConvertStringSecurityDescriptorToSecurityDescriptorW, RegQueryValueExW, AdjustTokenPrivileges, GetTokenInformation, ConvertSidToStringSidW, LookupPrivilegeValueW, RegCloseKey, OpenProcessToken, RegOpenKeyExW
      NameOrdinalAddress
      TMethodImplementationIntercept30x4541a8
      __dbk_fcall_wrapper20x40d0a0
      dbkFCallWrapperAddr10x4be63c
      Language of compilation systemCountry where language is spokenMap
      EnglishUnited States