Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
grand-theft-auto-5-theme-1-installer_qb8W-j1.exe

Overview

General Information

Sample name:grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Analysis ID:1581319
MD5:1d5608c770dd48f9f15c6a303c08cdd5
SHA1:70b377e6d25ae801d563ccab02cfae72467f3027
SHA256:d93ea0680d85088ea784e5eb3ab1d0bbb220e7500d8b4e3cc760a00ed7040a47
Tags:exemalwaremimikatzps1user-Joker
Infos:

Detection

Score:40
Range:0 - 100
Whitelisted:false
Confidence:100%

Compliance

Score:36
Range:0 - 100

Signatures

Drops password protected ZIP file
Possible COM Object hijacking
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Adds / modifies Windows certificates
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to communicate with device drivers
Contains functionality to create guard pages, often used to hinder reverse engineering and debugging
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops certificate files (DER)
EXE planting / hijacking vulnerabilities found
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file does not import any functions
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Searches the installation path of Mozilla Firefox
Stores large binary data to the registry
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
query blbeacon for getting browser version

Classification

  • System is w10x64
  • grand-theft-auto-5-theme-1-installer_qb8W-j1.exe (PID: 3128 cmdline: "C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe" MD5: 1D5608C770DD48F9F15C6A303C08CDD5)
    • saBSI.exe (PID: 2292 cmdline: "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe" /affid 91088 PaidDistribution=true CountryCode=US MD5: 143255618462A577DE27286A272584E1)
      • installer.exe (PID: 6984 cmdline: "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\\installer.exe" /setOem:Affid=91088 /s /thirdparty /upgrade MD5: 7DD0FAA9C00391333B2A12D21CA028BF)
        • installer.exe (PID: 4500 cmdline: "C:\Program Files\McAfee\Temp2744101987\installer.exe" /setOem:Affid=91088 /s /thirdparty /upgrade MD5: 9B6FDFBC11B51E810F01598730A002F4)
    • OperaSetup.exe (PID: 5732 cmdline: "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe" --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b MD5: 7576A1BF33EDB92CE3CAC344DE107AFB)
      • setup.exe (PID: 1408 cmdline: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b --server-tracking-blob=NDg5MmM0M2NiZmYxOTc2MjY3ZDE3MGIyMzA3NGYyODVjNDZhOGNmNjg5YTA1ZDg5NTRhNThiN2MxZWIzZDk4OTp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijoib3BlcmEiLCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInRpbWVzdGFtcCI6IjE3MzUwMzgwMTIuNzc0NSIsInVzZXJhZ2VudCI6InB5dGhvbi1yZXF1ZXN0cy8yLjMyLjMiLCJ1dG0iOnt9LCJ1dWlkIjoiYWFmNjZmNDQtNWMyYy00ZmJmLTg0YmQtN2Y2OTE0MGY0MGRiIn0= MD5: 71AD4FFF7C190194C8A544776B54DCC5)
        • setup.exe (PID: 6556 cmdline: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x32c,0x330,0x334,0x308,0x340,0x6bef9d44,0x6bef9d50,0x6bef9d5c MD5: 71AD4FFF7C190194C8A544776B54DCC5)
        • setup.exe (PID: 4984 cmdline: "C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --version MD5: 71AD4FFF7C190194C8A544776B54DCC5)
        • setup.exe (PID: 2232 cmdline: "C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\user\AppData\Local\Programs\Opera" --profile-folder --language=en-GB --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=1408 --package-dir-prefix="C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20241227050959" --session-guid=878fa370-40e0-48bb-911a-de2b24f3f5ca --server-tracking-blob="MTZmNWMzYjllYmU1ODE2ZGQ1N2E1NWMxYWU1OTAyMTkyMDM2ZjNhNmZmZmE4NmM3ZGJhNTQ2Yjk2MzU4Y2FmMjp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInN5c3RlbSI6eyJwbGF0Zm9ybSI6eyJhcmNoIjoieDg2XzY0Iiwib3BzeXMiOiJXaW5kb3dzIiwib3BzeXMtdmVyc2lvbiI6IjEwIiwicGFja2FnZSI6IkVYRSJ9fSwidGltZXN0YW1wIjoiMTczNTAzODAxMi43NzQ1IiwidXNlcmFnZW50IjoicHl0aG9uLXJlcXVlc3RzLzIuMzIuMyIsInV0bSI6eyJjYW1wYWlnbiI6Im9wZXJhX25ld19iIiwibWVkaXVtIjoiYXBiIiwic291cmNlIjoiYWlzIn0sInV1aWQiOiJhYWY2NmY0NC01YzJjLTRmYmYtODRiZC03ZjY5MTQwZjQwZGIifQ== " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=F005000000000000 MD5: 71AD4FFF7C190194C8A544776B54DCC5)
          • setup.exe (PID: 6324 cmdline: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x320,0x324,0x328,0x2fc,0x338,0x6b309d44,0x6b309d50,0x6b309d5c MD5: 71AD4FFF7C190194C8A544776B54DCC5)
  • servicehost.exe (PID: 6968 cmdline: "C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe" MD5: F7C7039D19E16D05B6194D74E128DFE4)
    • uihost.exe (PID: 1516 cmdline: "C:\Program Files\McAfee\WebAdvisor\UIHost.exe" MD5: C75ACD4F363FEC78A32439364E82021C)
    • updater.exe (PID: 2920 cmdline: "C:\Program Files\McAfee\WebAdvisor\updater.exe" MD5: 9A4C26D4AA627CA1C69D40C9091B4A74)
      • cmd.exe (PID: 3004 cmdline: C:\Windows\system32\cmd.exe /c IF EXIST "C:\Program Files\McAfee\WebAdvisor\Download" ( DEL "C:\Program Files\McAfee\WebAdvisor\Download\*.bak" ) MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
        • conhost.exe (PID: 1132 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • cmd.exe (PID: 3480 cmdline: C:\Windows\system32\cmd.exe /c DEL "C:\Program Files\McAfee\WebAdvisor\*.tmp" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
        • conhost.exe (PID: 7088 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 1568 cmdline: C:\Windows\system32\cmd.exe /c dir "C:\Program Files (x86)\McAfee Security Scan" 2>nul MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 5744 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D714F0 CryptMsgGetParam,CryptMsgGetParam,CryptMsgGetParam,CryptMsgGetParam,CertGetSubjectCertificateFromStore,CryptMsgGetParam,CertFreeCRLContext,CertFreeCRLContext,4_2_00D714F0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D717A0 CryptQueryObject,CryptMsgClose,CertCloseStore,CryptMsgClose,CertCloseStore,CryptMsgClose,CryptQueryObject,CryptMsgClose,CertCloseStore,CertCloseStore,CryptMsgClose,CertCloseStore,CryptMsgClose,CertCloseStore,CertCloseStore,CryptMsgClose,CertCloseStore,CryptMsgClose,CertCloseStore,CryptMsgClose,CertCloseStore,4_2_00D717A0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D25870 GetCurrentProcessId,GetCurrentThreadId,CreateFileW,CreateFileW,CreateFileW,CreateFileW,CreateFileW,CreateFileW,UuidCreate,UuidCreate,CryptAcquireContextW,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext,CryptAcquireContextW,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext,4_2_00D25870
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D26220 GetCurrentProcessId,GetCurrentThreadId,CryptAcquireContextW,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext,DeviceIoControl,DeviceIoControl,4_2_00D26220
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D5E610 CryptMsgClose,4_2_00D5E610
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D267B0 GetCurrentProcessId,GetCurrentThreadId,CryptAcquireContextW,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext,DeviceIoControl,DeviceIoControl,4_2_00D267B0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D5EB60 CryptQueryObject,CryptMsgClose,CertCloseStore,CryptMsgClose,CertCloseStore,CryptQueryObject,CryptMsgClose,CryptMsgClose,CertCloseStore,CertCloseStore,CryptMsgClose,CertCloseStore,CryptMsgClose,CryptMsgClose,CertCloseStore,CertCloseStore,CryptMsgClose,CertCloseStore,CryptMsgClose,CertCloseStore,CryptMsgClose,CertCloseStore,4_2_00D5EB60
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D5F150 CryptMsgGetParam,CryptMsgGetParam,CryptMsgGetParam,CertGetSubjectCertificateFromStore,CertFreeCRLContext,4_2_00D5F150
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D5F3C0 CryptMsgGetParam,CryptMsgGetParam,CryptMsgGetParam,CertGetSubjectCertificateFromStore,CertGetNameStringW,CertGetNameStringW,CertGetCertificateChain,CertFreeCertificateChain,CertFreeCertificateChain,CertVerifyCertificateChainPolicy,CertFreeCertificateChain,CertFreeCRLContext,CertFreeCRLContext,4_2_00D5F3C0
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeEXE: C:\Users\user\Downloads\grand-theft-auto-5-theme-1-installer.exeJump to behavior

Compliance

barindex
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeEXE: C:\Users\user\Downloads\grand-theft-auto-5-theme-1-installer.exeJump to behavior
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeWindow detected: Grand Theft Auto 5 ThemeAcceptDeclineSkip AllWhen you click "Accept" you agree to the installation of "McAfee WebAdvisor" and that you have read the <a href="https://www.mcafee.com/consumer/en-us/policy/legal.html">Privacy Policy</a> and agree to the terms of its <a href="https://www.mcafee.com/consumer/en-us/policy/legal.html">End User License Agreement</a>. Check "Add/Remove Programs" to uninstall.
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfeeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\analyticsmanager.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\analyticstelemetry.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\balloon_safe_annotation.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\browserhost.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\browserplugin.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\icon_complete.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\icon_failed.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\icon_laptop.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\installer.exeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jquery-1.9.0.min.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\l10n.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\logicmodule.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\logicscripts.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\main_close_large.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mcafeecerts.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mcafee_pc_install_icon.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mcafee_pc_install_icon2.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mfw-mwb.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mfw-nps.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mfw-webadvisor.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mfw.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\poppins-light.ttfJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\poppins-regular.ttfJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\poppins-semibold.ttfJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\progress_check.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\progress_error.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\resource.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\resourcedll.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\servicehost.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\settingmanager.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\taskmanager.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\uihost.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\uimanager.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\uninstaller.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\updater.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-common.cssJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-core.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-install.cssJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-install.htmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-ui-install.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-utils.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_check.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_check2.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_close.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_close2.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_close3.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_error.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_icon.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_logo.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_logo2.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_logo3.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\webadvisor.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\webadvisor.icoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wssdep.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslangJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-cs-CZ.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-da-DK.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-de-DE.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-el-GR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-en-US.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-es-ES.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-es-MX.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fi-FI.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fr-CA.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fr-FR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-hr-HR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-hu-HU.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-it-IT.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ja-JP.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ko-KR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-nb-NO.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-nl-NL.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pl-PL.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pt-BR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pt-PT.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ru-RU.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sk-SK.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sr-Latn-CS.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sv-SE.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-tr-TR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-zh-CN.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-zh-TW.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-cs-CZ.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-da-DK.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-de-DE.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-el-GR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-en-US.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-es-ES.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-es-MX.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-fi-FI.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-fr-CA.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-fr-FR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-hr-HR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-hu-HU.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-it-IT.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-ja-JP.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-ko-KR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-nb-NO.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-nl-NL.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-pl-PL.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-pt-BR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-pt-PT.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-ru-RU.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-sk-SK.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-sr-Latn-CS.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-sv-SE.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-tr-TR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-zh-CN.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-zh-TW.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-cs-CZ.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-da-DK.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-de-DE.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-el-GR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-en-US.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-es-ES.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-es-MX.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-fi-FI.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-fr-CA.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-fr-FR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-hr-HR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-hu-HU.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-it-IT.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-ja-JP.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-ko-KR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-nb-NO.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-nl-NL.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-pl-PL.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-pt-BR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-pt-PT.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-ru-RU.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-sk-SK.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-sr-Latn-CS.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-sv-SE.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-tr-TR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-zh-CN.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-zh-TW.jsJump to behavior
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\resource.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor.ico
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\win32\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\win32\wssdep.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\auxiliary\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\auxiliary\reset_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\uihost.exe
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\class.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\servicehost.exe
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\dkjson.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\browserhost.exe
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\updater.exe
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\clipboard.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\info-16.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\npshandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\mwbhandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\wa-controller-nps-checklist.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\x64\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\x64\wssdep.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\balloon-arrow-right.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\aj_logic.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\wa-nps-checklist.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\handlers.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\stop-video-alert-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\balloon-arrow.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\base_provider.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\init.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\card_bg_image.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\wa-controller-mwb-checklist.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\edge_onboarding.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\json.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\close_icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\logger.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\ff_monitor.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\wa-mwb-checklist.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\dialog-balloon-logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\postinit.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\logic_loader.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\wb-rocket-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-en-US.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\edge_close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\priorityqueue.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\miscutils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\enable_ext_guide_ss.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_business_logic.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\triggeracceptor.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\uiarbitratorhelper.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\providers_selector.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\enable_ext_guide_wa.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\uihandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\ss_logic.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\uithreadexithandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\enable_sideloaded_ext_guide.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\win32helper.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\tests_logic.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\keep_changes_guide.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\type_tag_utils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\browserutils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\usage_calculation.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\logomark_white.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\affid_monitor.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\common_utils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mc-logo-tm-bottom.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\oem_util.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo-1.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\packageutils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\oem_utils_wps.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo-2024.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\settingsdb.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\oem_utils_wss.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\edge.com.mcafee.webadvisor.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\open_sideloaded_ext_alert_guide.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\stringutils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\oem_util_selector.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\edge.com.mcafee.webadvisor_v2.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\green_check.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor.mcafee.chrome.extension.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\providers\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\providers\bing.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\progress_tooltip_1.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\icn_mshield.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor.mcafee.firefox.extension.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\progress_tooltip_2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\providers\yahoo.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-pt-PT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor_v2.mcafee.chrome.extension.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\installer_background.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\progress_tooltip_3.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-ru-RU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor_v2.mcafee.firefox.extension.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\smart_toast_config_manager.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\jquery-1.9.0.min.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\toggle_ext_on_guide.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-sk-SK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-sr-Latn-CS.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\toggle_off.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\smart_toast_config_selector.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-sv-SE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\toggle_on.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\selectors\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\selectors\smart_toast_search_setting.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-tr-TR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\tooltip_img_1_3.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\selectors\smart_toast_template.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\loading-spinner.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\tooltip_img_2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-zh-CN.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\selectors\smart_toast_trigger.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-zh-TW.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-oem-ss-toast-variants-step1.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\main_close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-oem-ss-toast-variants-step2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo-lg.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-oem-ss-toast-variants-woman.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-bg.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafeeicon.ico
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-en-US.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-checkbox-checked.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-checkbox-unchecked.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee_pc_install_icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-green-pc.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee_pc_install_icon2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\minimize.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-window.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\msac.ico
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-sstoast-toggle-rebranding-grass-lg.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-sstoast-toggle-rebranding-grass.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-sstoast-toggle-rebranding-step1.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\spinner_large.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-sstoast-toggle-rebranding-step2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-checklist.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_logo_upsell.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_logo_upsell2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_score_logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-common.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\edge_search\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\edge_search\edge_search_events.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-pt-PT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-core.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\about-icon-selected.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-ru-RU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\about-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ui-checklist.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-sk-SK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\amazon_upsell_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ui-dialog.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\checklisthandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-sr-Latn-CS.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-uninstall-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\chrome_extension_push_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-sv-SE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-utils.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\cryptojack-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-tr-TR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_check.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-zh-CN.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\ext_install_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_check2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\facebook.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-zh-TW.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\inst-noxup.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_close2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\inst-top.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_error.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\inst-warningbackground.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-overlay.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_logo2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-overlay.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_check.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-en-US.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-overlay.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_downchevron.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_exclamation.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-toasts.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_questionmark.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-toasts.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_timer.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-toasts.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new_tab_main_logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\overlay_ui_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\securesearchhandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\settings-close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\settings-icon-selected.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\settings-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\switch_off.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\switch_on.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\toast_impact_close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-pt-PT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\twitter.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-ru-RU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\upsell_toast_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-sk-SK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-amazon-upsell-logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-sr-Latn-CS.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-sv-SE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-amazon-upsell.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-tr-TR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-amazon-upsell.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-zh-CN.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-amazon-upsell.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-zh-TW.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ch-store-overlay-ui.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ch-store-overlay-ui.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ch-store-overlay-ui.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-checklist-risk.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-checklist-status.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-en-US.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-checklist.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-controller-checklist.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-dialog-balloon.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-dialog-balloon.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-dwtoast.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-dwtoast.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ext-install-toast.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ext-install-toast.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ext-install-toast.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ext-install-toast.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-options.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-options.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-overlay-ui.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-overlay-ui.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-overlay-ui.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-pt-PT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding-bing.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-ru-RU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-sk-SK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-sr-Latn-CS.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-sv-SE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-tr-TR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-zh-CN.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding-bing.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-zh-TW.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding-bing.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-variants.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-variants.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-variants.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-sstoast-toggle.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-sstoast-toggle.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-sstoast-toggle.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ui-dialog-balloon.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ui-dwtoast.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ui-options.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast-danger.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast-risk.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast-wss.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\warning-icon-toast.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages_web_view\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages_web_view\builtin\
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer\opera_installer_20241227050958717.logJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer\opera_installer_20241227051000410.logJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-cs-CZ.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-da-DK.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-de-DE.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-el-GR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-en-US.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-es-ES.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-es-MX.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fi-FI.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fr-CA.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fr-FR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-hr-HR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-hu-HU.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-it-IT.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ja-JP.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ko-KR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-nb-NO.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-nl-NL.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pl-PL.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pt-BR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pt-PT.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ru-RU.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sk-SK.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sr-Latn-CS.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sv-SE.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-tr-TR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-zh-CN.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-zh-TW.txtJump to behavior
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: certificate valid
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: c:\jenkins\workspace\WebAdvisor-accesslib-caller_main@2\Build\x64\Release\caller_dll.pdb source: installer.exe, 0000000C.00000000.3350639234.00007FF75CE33000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\McAfee\Development\Native\WebAdvisor-ISGIS\build\x64\Release\Installer.pdb source: installer.exe, 0000000B.00000000.3327079155.00007FF69726B000.00000002.00000001.01000000.00000014.sdmp, installer.exe, 0000000B.00000002.3536742481.00007FF69726B000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: c:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\Win32\Release\SaBsi.pdb source: saBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\LogicModule.pdb source: installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: installer.exe.pdb source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000000.2597665117.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3927249090.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000007.00000000.2600464595.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000007.00000002.3925811129.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608185157.0000000000188000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000000.2605558688.0000000000188000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000002.3926419813.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000000.2609337845.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000002.3926659240.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612280312.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: installer_lib.dll.pdb source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\AnalyticsManager.pdb source: installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\McAfee\Development\Native\WebAdvisor-ISGIS\build\x64\Release\Installer.pdb$ source: installer.exe, 0000000B.00000000.3327079155.00007FF69726B000.00000002.00000001.01000000.00000014.sdmp, installer.exe, 0000000B.00000002.3536742481.00007FF69726B000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\Win32\Release\Resource.pdb source: installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3425873206.0000000010300000.00000004.00001000.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423798817.00000174524FF000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392910751.00000174523A4000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\SettingManager.pdb source: installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\ServiceHost.pdb source: installer.exe, 0000000C.00000003.3394810418.00000174523A8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\Updater.pdb source: installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\Uninstaller.pdb source: installer.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: installer_lib.dll.pdb@ source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: C:\Source\Repos\DS-Platform\CppInstaller\CppSetup\bin\Win32\Release\CppSetup.pdb source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000000.2053199277.0000000000E29000.00000002.00000001.01000000.00000003.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\Win32\Release\Resource.pdbGCTL source: installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3425873206.0000000010300000.00000004.00001000.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423798817.00000174524FF000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392910751.00000174523A4000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\Installer.pdb source: installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\UIManager.pdb source: installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\TaskManager.pdb source: installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\ServiceHost.pdbw source: installer.exe, 0000000C.00000003.3394810418.00000174523A8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\BrowserHost.pdb source: installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DA9BF0 FindFirstFileExW,4_2_00DA9BF0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00F98D20 FindFirstFileW,5_2_00F98D20
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FBFEEB FindFirstFileExW,5_2_00FBFEEB
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\userJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppData\Local\TempJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppDataJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppData\Local\Temp\ISVD440.tmpJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI.zipJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
Source: Joe Sandbox ViewIP Address: 151.101.1.91 151.101.1.91
Source: Joe Sandbox ViewIP Address: 151.101.2.133 151.101.2.133
Source: Joe Sandbox ViewIP Address: 151.101.2.133 151.101.2.133
Source: setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: c. Facebook Messenger: A messaging service provided by Facebook, Inc., Meta Platforms Ireland Ltd. or related companies, depending on where you are accessing their services. Terms of use are available at https://www.facebook.com/legal/terms; and equals www.facebook.com (Facebook)
Source: installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://%u.%u.%u.%uhttps://%%=?=?&/
Source: installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://127.0.0.1%
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://autoupdate-staging.services.ams.osa/netinstallervwindows?&One
Source: saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664250220.0000000005BBD000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3610848174.0000000005BBA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootC
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3326051243.0000000005B66000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005B6D000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323665043.0000000005BEE000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664390048.0000000005E8B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538264048.0000000005BA0000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324757012.0000000005B68000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: installer.exe, 0000000C.00000003.3402561296.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402618649.0000017451B23000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeSt
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3326051243.0000000005B66000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664390048.0000000005E8B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324757012.0000000005B68000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3326051243.0000000005B66000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005B6D000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664390048.0000000005E8B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538264048.0000000005BA0000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324757012.0000000005B68000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2598109377.00000000011D1000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: saBSI.exe, saBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmp, installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394810418.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://clients2.google.com/service/update2/crx
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://clients2.google.com/service/update2/crxB
Source: installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3357550656.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3391293935.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3404549998.0000017451B14000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3356381187.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390853934.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374034271.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3400006266.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407930300.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394039242.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3370695746.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394110637.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3352535766.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3365140827.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379057315.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3416848825.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374902158.0000017451B15000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/codesigningrootr4
Source: saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406264526.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392606092.0000017451B49000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405799403.0000017451B30000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373264766.0000017451B21000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402226912.0000017451B27000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401305311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374831464.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423091087.0000017451BA5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412607815.0000017451B2D000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406671547.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409058583.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3386385785.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3396160078.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3393127453.0000017451B38000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U
Source: installer.exe, 0000000C.00000003.3416848825.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3416882436.0000017451B23000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/gsgccr45
Source: installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3357550656.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3391293935.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3404549998.0000017451B14000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3356381187.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390853934.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374034271.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3400006266.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407930300.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394039242.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3370695746.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394110637.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3352535766.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3365140827.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379057315.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3416848825.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374902158.0000017451B15000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca20
Source: saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406264526.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3395443115.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405799403.0000017451B30000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373264766.0000017451B21000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402226912.0000017451B27000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401305311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423091087.0000017451BA5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412607815.0000017451B2D000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390818727.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406671547.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384701338.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412695309.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0
Source: installer.exe, 0000000C.00000003.3424943877.00000174529CC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.di
Source: saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digi
Source: installer.exe, 0000000C.00000003.3407930300.0000017451B13000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiC
Source: saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664250220.0000000005BBD000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3610848174.0000000005BBA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssured
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3326051243.0000000005B66000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005B6D000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323665043.0000000005BEE000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664390048.0000000005E8B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538264048.0000000005BA0000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324757012.0000000005B68000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3326051243.0000000005B66000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664390048.0000000005E8B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324757012.0000000005B68000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, installer.exe, 0000000C.00000003.3406264526.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392606092.0000017451B49000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3395443115.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405799403.0000017451B30000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373264766.0000017451B21000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402226912.0000017451B27000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374831464.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423091087.0000017451BA5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412607815.0000017451B2D000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390818727.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406671547.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384701338.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394435633.0000017451B3E000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3357452076.0000017451B32000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3375704851.0000017451B2A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409058583.0000017451B38000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: saBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://home.mcafee.com/
Source: installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://home.mcafee.com/SaveEulaTrackingDetailsContent-Type:
Source: installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmpString found in binary or memory: http://home.mcafee.com/SaveEulaTrackingDetailsNot
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://localhost:3001api/prefs/?product=$1&version=$2..
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://ocsp.digicert.com0
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3326051243.0000000005B66000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005B6D000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664390048.0000000005E8B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538264048.0000000005BA0000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324757012.0000000005B68000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2598109377.00000000011D1000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://ocsp.digicert.com0A
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3326051243.0000000005B66000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005B6D000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323665043.0000000005BEE000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664390048.0000000005E8B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538264048.0000000005BA0000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324757012.0000000005B68000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmpString found in binary or memory: http://ocsp.digicert.com0C
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3326051243.0000000005B66000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664390048.0000000005E8B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324757012.0000000005B68000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmpString found in binary or memory: http://ocsp.digicert.com0X
Source: saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324974429.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3664250220.0000000005BBD000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324719149.0000000005B87000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324773349.0000000005BEC000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3610848174.0000000005BBA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.coma
Source: installer.exe, 0000000C.00000003.3356381187.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3352535766.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3356986865.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354113977.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3353090288.0000017451B0A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.glob_;.
Source: installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3357550656.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3391293935.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3404549998.0000017451B14000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3356381187.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390853934.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374034271.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3400006266.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407930300.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394039242.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3370695746.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394110637.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3352535766.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3365140827.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379057315.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3416848825.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374902158.0000017451B15000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.globalsign.c
Source: saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406264526.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392606092.0000017451B49000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405799403.0000017451B30000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373264766.0000017451B21000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402226912.0000017451B27000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401305311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374831464.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423091087.0000017451BA5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412607815.0000017451B2D000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406671547.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409058583.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3386385785.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3396160078.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3393127453.0000017451B38000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F
Source: saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406264526.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3395443115.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405799403.0000017451B30000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373264766.0000017451B21000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402226912.0000017451B27000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401305311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423091087.0000017451BA5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412607815.0000017451B2D000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390818727.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406671547.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384701338.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412695309.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U
Source: installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/s:EnvelopeContextTypeeulaTrackingRequestInfoxmlnshttp://hom
Source: installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3357550656.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3391293935.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3404549998.0000017451B14000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3356381187.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390853934.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374034271.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3400006266.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407930300.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394039242.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3370695746.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394110637.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3352535766.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3365140827.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379057315.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3416848825.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374902158.0000017451B15000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.cd
Source: saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406264526.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392606092.0000017451B49000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405799403.0000017451B30000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373264766.0000017451B21000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402226912.0000017451B27000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401305311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374831464.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423091087.0000017451BA5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412607815.0000017451B2D000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406671547.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409058583.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3386385785.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3396160078.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3393127453.0000017451B38000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
Source: installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3357550656.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3391293935.0000017451B16000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3404549998.0000017451B14000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3356381187.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390853934.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374034271.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3400006266.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407930300.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394039242.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3370695746.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394110637.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3352535766.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3365140827.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379057315.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3416848825.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374902158.0000017451B15000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://secure.globalsign.com/cacert/gs
Source: saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406264526.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3395443115.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405799403.0000017451B30000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373264766.0000017451B21000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402226912.0000017451B27000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401305311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423091087.0000017451BA5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412607815.0000017451B2D000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390818727.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406671547.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384701338.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412695309.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3379829141.0000017451B16000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0?
Source: saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://secure.globalsign.com:80/cacert/codesigningrootr45.crt
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://www.digicert.com/CPS0
Source: installer.exe, 0000000C.00000003.3372982747.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374996788.0000017451B29000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3371268864.0000017451B2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.mcafee.com
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2584306611.00000000045D6000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594462509.0000000004290000.00000004.00001000.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, OperaSetup.exe, 00000005.00000003.2594327141.0000000004110000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2603139442.0000000002A83000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: http://www.opera.com0
Source: installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.siteadvisor.com/favicon.ico
Source: installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.siteadvisor.com/favicon.icoF59B2EC8-1D34-435D-B539-435BA415D1B6
Source: installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.siteadvisor.com/favicon.icoMcAfee
Source: installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.siteadvisor.com/favicon.icoMcAfeemfffpogegjflfpflabcdkioaeobkgjikmfehgcgbbipciphmccgaenji
Source: installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.winimage.com/zLibDll
Source: installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.winimage.com/zLibDll1.3.1
Source: installer.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://.servicebus.windows.net/&se=&skn=Failed
Source: installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://127.0.0.1%
Source: setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://addons.opera.com/en/extensions/details/dify-cashback/
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://addons.opera.com/extensions/download/be76331b95dfc399cd776d2fc68021e0db03cc4f.opera.com
Source: setup.exe, 00000006.00000002.3943921040.000000005D230000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://addons.opera.com/extensions/download/be76331b95dfc399cd776d2fc68021e0db03cc4fC:
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.apis.mcafee.com
Source: saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.apis.mcafee.com/
Source: saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.apis.mcafee.com/N
Source: saBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663969719.0000000005B00000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2624924490.00000000034B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.apis.mcafee.com/mosaic/2.0/product-web/am/v1/record
Source: saBSI.exe, 00000004.00000002.3663969719.0000000005B00000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.apis.mcafee.com/mosaic/2.0/product-web/am/v1/recorder
Source: saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.apis.mcafee.com:443/mosaic/2.0/product-web/am/v1/record
Source: installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.apis.mcafee.comContent-Type:
Source: saBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpString found in binary or memory: https://analytics.apis.mcafee.comhttps://analytics.qa.apis.mcafee.com/mosaic/2.0/product-web/am/v1/r
Source: installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.apis.mcafee.comhttps://analytics.qa.apis.mcafee.comPOSTContent-Type:
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.qa.apis.mcafee.com
Source: installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.qa.apis.mcafee.comQuerying
Source: installer.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.qa.apis.mcafee.comhttps://analytics.apis.mcafee.comContent-Type:
Source: installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmpString found in binary or memory: https://analytics.qa.apis.mcafee.comhttps://analytics.apis.mcafee.comhttps://.servicebus.windows.net
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://assets.razerzone.com/downloads/software/Razer
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://assets.razerzone.com/downloads/software/RazerEndUserLicenseAgreement.pdf
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2628553746.00000000010FE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2628553746.00000000010F4000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://autoupdate.geo.opera.com/
Source: setup.exe, 00000006.00000003.2628553746.00000000010F4000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://autoupdate.geo.opera.com/f(
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://autoupdate.geo.opera.com/https://autoupdate.opera.com/me/OperaDesktophttps://crashstats-coll
Source: setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://autoupdate.geo.opera.com/v5/netinstaller/opera/Stable/windows/x64
Source: setup.exe, 00000006.00000003.2628553746.00000000010FE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652662729.00000000010FC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2628553746.00000000010F4000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://autoupdate.geo.opera.com/v5/netinstaller/opera/Stable/windows/x64C
Source: setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://autoupdate.geo.opera.com/v5/netinstaller/opera/Stable/windows/x64E
Source: setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://autoupdate.geo.opera.com/v5/netinstaller/opera/Stable/windows/x64p
Source: setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://autoupdate.opera.com/
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000003.2628553746.00000000010F4000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000006.00000002.3930648945.000000000108B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://autoupdate.opera.com/me/
Source: setup.exe, 00000006.00000002.3930648945.000000000108B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://autoupdate.opera.com/me/cefr7
Source: installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore/detail/mcafee%C2%AE-secure-search/enppghjcblldgigemljohkgpcompnjg
Source: installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore/detail/mcafee%C2%AE-webadvisor/fheoggkfdfchfphceeifdbepaooicaho?u
Source: installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://clients2.googleusercontent.com/.
Source: saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://confluence.int.mcafee.com/pages/viewpage.action?pageId=35264328
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://crashpad.chromium.org/
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://crashpad.chromium.org/bug/new
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://crashpad.chromium.org/https://crashpad.chromium.org/bug/new
Source: setup.exe, 0000000A.00000002.3938804118.0000000045CA4000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 0000000A.00000002.3925532515.00000000007F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://crashstats-collector-2.opera.com/
Source: setup.exe, 00000007.00000002.3932994416.0000000038614000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000007.00000002.3929329433.000000000143B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 0000000A.00000002.3931006274.0000000000FFB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 0000000A.00000002.3935540141.0000000045C14000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://crashstats-collector-2.opera.com/--annotation=channel=Stable--annotation=plat=Win32--annotat
Source: setup.exe, 00000007.00000002.3934604871.00000000386A4000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 0000000A.00000002.3938804118.0000000045CA4000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://crashstats-collector-2.opera.com/--crash-count-file=C:
Source: setup.exe, 00000007.00000002.3934604871.00000000386A4000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 0000000A.00000002.3938804118.0000000045CA4000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://crashstats-collector-2.opera.com/--database=C:
Source: setup.exe, 00000007.00000002.3933874231.000000003866C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://crashstats-collector-2.opera.com//
Source: setup.exe, 00000007.00000002.3933874231.000000003866C000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 0000000A.00000002.3937504080.0000000045C64000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://crashstats-collector-2.opera.com/32--url=https://crashstats-collector-2.opera.com/
Source: setup.exe, 0000000A.00000002.3937504080.0000000045C64000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://crashstats-collector-2.opera.com/yT
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cu1pehnswad01.servicebus.windows.net/wadp32h02/messages?timeout=60&api-version=2014-01
Source: setup.exe, 00000006.00000003.2900155539.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/
Source: setup.exe, 00000006.00000002.3931552019.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2900155539.0000000001126000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/8
Source: setup.exe, 00000006.00000003.2628553746.00000000010F4000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/?2
Source: setup.exe, 00000006.00000002.3931552019.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2900155539.0000000001126000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/C
Source: setup.exe, 00000006.00000002.3931729601.0000000001140000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/T
Source: setup.exe, 00000006.00000002.3930648945.000000000108B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2900155539.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681384823.0000000001140000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3941252634.0000000004780000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binary
Source: setup.exe, 00000006.00000003.2681384823.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binary$
Source: setup.exe, 00000006.00000003.2681384823.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binary7
Source: setup.exe, 00000006.00000002.3930648945.000000000108B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binary?
Source: setup.exe, 00000006.00000002.3941252634.0000000004780000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binaryMicrosoft
Source: setup.exe, 00000006.00000002.3931729601.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binarya
Source: setup.exe, 00000006.00000002.3941252634.0000000004780000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binaryeoperacdn.com
Source: setup.exe, 00000006.00000002.3941252634.0000000004780000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binaryera.software914163
Source: setup.exe, 00000006.00000002.3931552019.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2900155539.0000000001126000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://desktop-netinstaller-sub.osp.opera.software/v1/binaryh
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000000.2053199277.0000000000E29000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/f/
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625823950.0000000001647000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625740985.0000000001641000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739185827.0000000001649000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/f/Q
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000000.2053199277.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/o
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625823950.0000000001647000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625740985.0000000001641000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739185827.0000000001649000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/og?
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000000.2053199277.0000000000E29000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/ohttps://di7e1j5f1plfo.cloudfront.net/zbdhttps://di7e1j5f1plfo.
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624369883.0000000006486000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2740490720.000000000648D000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624178696.000000000647E000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000000.2053199277.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/zbd
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/zbd(L
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739164057.0000000001645000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625740985.0000000001641000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/zbd595
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net/zbdEL
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2136988628.00000000016DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://di7e1j5f1plfo.cloudfront.net:443/zbd
Source: setup.exe, 00000006.00000003.2647303162.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652491492.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681384823.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download.opera.com/
Source: setup.exe, 00000006.00000002.3944941294.000000005D27C000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3945137379.000000005D28C000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2628377422.0000000001140000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3942640378.000000005D207000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652662729.000000000110D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2628553746.000000000110D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2628377422.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download.opera.com/download/get/?id=67939&autoupdate=1&ni=1
Source: setup.exe, 00000006.00000002.3944941294.000000005D27C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://download.opera.com/download/get/?id=67939&autoupdate=1&ni=1https://autoupdate.opera.com/me/
Source: setup.exe, 00000006.00000002.3943921040.000000005D230000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://download.opera.com/download/get/?id=69300&autoupdate=1&ni=1&stream=stable&utm_campaign=opera
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://download.opera.com/download/get/?partner=www&opsys=Windows&utm_source=netinstaller
Source: setup.exe, 00000006.00000003.2652491492.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931552019.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681384823.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2900155539.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download3.operacdn.com/
Source: setup.exe, 00000006.00000003.2652491492.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download3.operacdn.com/$
Source: setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download3.operacdn.com/6
Source: setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download3.operacdn.com/PS
Source: setup.exe, 00000006.00000003.2652491492.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681384823.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.000000000115C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download3.operacdn.com/_
Source: setup.exe, 00000006.00000003.2681493723.000000000479D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.0000000001140000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.000000000111B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681384823.0000000001140000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download3.operacdn.com/ftp/pub/opera/desktop/115.0.5322.119/win/Opera_115.0.5322.119_Autoupd
Source: setup.exe, 00000006.00000003.2681384823.0000000001140000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://features.opera-api2.com/
Source: setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://features.opera-api2.com/api/v2/features?country=%s&language=%s&uuid=%s&product=%s&channel=%s
Source: setup.exe, 00000006.00000003.2647303162.0000000001140000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3946258123.000000005D2EC000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://features.opera-api2.com/api/v2/features?country=US&language=en-GB&uuid=1234646e-fa64-4454-98
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://gamemaker.io
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://gamemaker.io)
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://gamemaker.io/en/education.
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://gamemaker.io/en/get.
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2136988628.00000000016F1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://grand-theft-auto-5-theme.en.softonic.com&Filename=gta5.zip
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2136988628.00000000016F1000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739395872.00000000016F1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gsf-fl.softonic.com/be2/c95/e3281fb415bd02f206c89cebb2443a9bef/gta5.zip?Expires=1735335096&S
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hello.softo
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hello.softonic.com/privacy-policy
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624514532.00000000016DF000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739395872.00000000016E0000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.00000000016DC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hello.softonic.com/terms-of-use
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://help.instagram.com/581066165581870;
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://help.opera.com/latest/
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://home.mcafee.com/Root/AboutU
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://home.mcafee.com/Root/AboutUs.aspx?id=eula
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://home.mcafee.com/Root/AboutUs.aspx?id=eulanet
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://images.sftcdn.net/im#b
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://images.sftcdn.net/images/t_app-icon-m/p/2b4bea10-a4d4-11e6-aeb6-00163ed833e7/3083527615/gran
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://legal.opera.com/eula/computers
Source: setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://legal.opera.com/privacy
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://legal.opera.com/privacy.
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://legal.opera.com/terms
Source: setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://legal.opera.com/terms.
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://opera.com/privacy
Source: installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?.
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://policies.google.com/terms;
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2136988628.00000000016DE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reasonlabs.c
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reasonlabs.com/policies
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reasonlabs.com/rav_online_security_policies
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://redir.opera.com/uninstallsurvey/
Source: setup.exe, 00000006.00000002.3945137379.000000005D28C000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3942640378.000000005D207000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2628553746.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://redir.opera.com/www.opera.com/firstrun/?utm_campaign=opera_new_b&utm_medium=apb&utm_source=a
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739164057.0000000001645000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625740985.0000000001641000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000000.2053199277.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739858556.0000000005AD2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://rise-platforms.com/privacy/
Source: saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/
Source: saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/Z
Source: saBSI.exe, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/
Source: saBSI.exe, 00000004.00000003.3323687182.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003511000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676251289.000000000350A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676226000.0000000003515000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/Win/binary/3.7.2/update_bsi_product.xml
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/Win/binary/3.7.2/update_bsi_product.xml/
Source: saBSI.exe, 00000004.00000003.3323687182.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003511000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676251289.000000000350A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/Win/binary/4.1.0/update_bsi_self.xml
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/Win/binary/4.1.0/update_bsi_self.xml/
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698655552.000000000352B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636620204.0000000003532000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_DistributionRules.xml
Source: saBSI.exe, 00000004.00000003.2699456813.0000000005B00000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699210949.0000000005B00000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_DistributionRules.xml/
Source: saBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676226000.0000000003515000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_PaidDistribution.xml
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_PaidDistribution.xml/
Source: saBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_PaidDistribution.xmlN
Source: saBSI.exe, 00000004.00000003.3323687182.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003511000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676251289.000000000350A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676226000.0000000003515000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_PartnerDistribution.xml
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_PartnerDistribution.xml/
Source: saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636620204.0000000003532000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_abtest.xml
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636510952.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636287551.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_abtest.xml/
Source: saBSI.exe, saBSI.exe, 00000004.00000003.2676297523.00000000034BA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003536000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676361087.00000000034B1000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2651066038.00000000034BA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676361087.0000000003496000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_main.xml
Source: saBSI.exe, 00000004.00000003.3323687182.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003511000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676251289.000000000350A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_vars.xml
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/BSI/bsi_vars.xml/
Source: saBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/UPDATER_VERSIONaffidosplatSELF_UPDATE_ALLOWEDMAIN_XMLSTORE
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/Win/xpi/webadvisor/update.json
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/Win/xpi/webadvisor/update.jsonD;.VBS;
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/Win/xpi/webadvisor/update.jsonXh
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/Win/xpi/webadvisor/update.jsonYh
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/bsi
Source: saBSI.exe, 00000004.00000003.3636510952.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636287551.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/bsi/
Source: saBSI.exe, 00000004.00000003.3323687182.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003511000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676251289.000000000350A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676226000.0000000003515000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003536000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636620204.0000000003532000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/bsi/4.1.1/install.xml
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/bsi/4.1.1/install.xml/
Source: saBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/bsi/4.1.1/install.xmlR
Source: saBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/bsi/binary
Source: saBSI.exe, 00000004.00000002.3663969719.0000000005AF0000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/installer/4.1.1/995/
Source: saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/installer/4.1.1/995/64/installer.exeexeWS
Source: saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/pc/partner_c
Source: saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/pc/partner_custom_bsi.xml
Source: saBSI.exe, 00000004.00000002.3663969719.0000000005AF0000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.000000000349C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663969719.0000000005B00000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/update/post_install.xml
Source: saBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/SA/v1/update/post_install.xmle
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/sa
Source: saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/sa/bsi/win/binary
Source: saBSI.exe, 00000004.00000003.3636510952.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636287551.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/sa/bsi/win/binary/
Source: saBSI.exe, 00000004.00000003.2886174381.0000000005B64000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/sa/v1/pc/partner_custom_vars.xml
Source: installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/sa/v1/update/entry.xmlFailed
Source: saBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/saUPDATER_URLupdater.exeWebAdvisor_Updaterheron_hostthreat.ap
Source: installer.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmp, installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394810418.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/products/saupdater.exeWebAdvisor_Updaterthreat.api.mcafee.comheron_tok
Source: saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com/t
Source: saBSI.exe, 00000004.00000003.2676361087.00000000034B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com:443/products/SA/BSI/bsi_main.xmlttps://analytics.apis.mcafee.com/mosai
Source: saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sadownload.mcafee.com:443/products/SA/v1/installer/4.1.1/995/64/installer.exe
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://shield.reasonsecurity.com/rsStubActivator.exe
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://sourcecode.opera.com
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://telegram.org/tos/
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://twitter.com/en/tos;
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2136988628.00000000016DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/eu
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/eula
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/eula-avast-consumer-prod
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/eula-avast-consumer-products
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/eula-avast-consumer-products)
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/p
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/privacy
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/privacy-policy
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avast.com/privacy-policyEHc
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avg.com/ww-en/eula
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avg.com/ww-en/eulai
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avg.com/ww-en/privacy
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.avg.com/ww-en/privacyexeA69D9EBc4
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ccleaner.com/about/privacy-policy
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ccleaner.com/legal/end-user-license-agreement
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ccleaner.com/legal/end-user-license-agreement?
Source: installer.exe, 0000000C.00000003.3406792738.0000017451B23000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.globalsign.com/repos
Source: saBSI.exe, 00000004.00000003.3538264048.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3325936489.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3406264526.0000017451B38000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392606092.0000017451B49000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3395443115.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3384830926.0000017451B0A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3378921430.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405799403.0000017451B30000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373264766.0000017451B21000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3364585622.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401699621.0000017451B15000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3402226912.0000017451B27000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401305311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3374831464.0000017451AE2000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423091087.0000017451BA5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3412607815.0000017451B2D000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3390818727.0000017451B23000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.globalsign.com/repository/0
Source: installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/favicon.ico
Source: installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?q=%sSoftware
Source: installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?q=%ssuper_mac
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/e
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-us/polic
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3375941324.00000174523A4000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3376228638.0000017451B27000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-us/policy/global/legal.html
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-us/policy/global/legal.html$
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625210062.0000000005B5D000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739858556.0000000005AD2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-us/policy/legal.html
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-us/policy/legal.html6
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739858556.0000000005AD2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-us/policy/legal.html8
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-us/policy/legal.htmlH
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2136988628.00000000016DE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624514532.00000000016DF000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.00000000016DC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/en-us/policy/legal.htmlr_Soft
Source: installer.exe, 0000000B.00000003.3349764919.000001D149A17000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/nl-nl/policy/legal.html
Source: saBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmp, installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394810418.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/v/wa-how.html
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/consumer/v/wa-how.htmlp
Source: installer.exe, 0000000B.00000003.3349764919.000001D149A17000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mcafee.com/legal
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.opera.cga
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://www.opera.com
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://www.opera.com..
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://www.opera.com/
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://www.opera.com/download/
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.00000000016C5000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.opera.com/he/eula/computers
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.opera.com/he/privacy
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739858556.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.opera.com/he/privacyovidertc
Source: setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://www.opera.com/privacy
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.razer.com/legal/customer-priv
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.razer.com/legal/customer-privacy-policy
Source: installer.exe, 0000000C.00000003.3407804311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407563186.000001745246C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.siteadvisor.com
Source: installer.exe, 0000000C.00000003.3373583575.00000174523AB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3373716235.0000017451B41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.siteadvisor.com/ff/install
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpString found in binary or memory: https://www.whatsapp.com/legal;
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeFile created: C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C5C8CC0A7FE31816B4641D0465402560Jump to dropped file

Spam, unwanted Advertisements and Ransom Demands

barindex
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile dropped: C:\Program Files\McAfee\Temp2744101987\jslang\eula-en-US.txt -> encryption key for your account secure because without them you may lose access to your data. you are solely responsible and liable for any activity that occurs under your account, including by anyone who uses your account. if there is any unauthorized use or access to your account, you must let us know immediately. we are not responsible for any loss caused by unauthorized use of or access to your account; however, you may be liable for any losses we or others suffer because of the unauthorized use. we do not have access to master passwords and cannot recover your encrypted data if you forget the master password for any password management feature or product. we offer both free and premium versions of our password and identity management software, and the free versions limit the maximum number of unique accounts (such as a website or application login) that you can store. if you have downloaded a premium version of the software at no cost during a promotion, then when the promotional period ends you will notJump to dropped file
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile created: C:\Users\user\Downloads\grand-theft-auto-5-theme-1-installer.exe entropy: 7.99998755488Jump to dropped file
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI.zip entropy: 7.99597518735Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeFile created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe entropy: 7.99064522414Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\analyticsmanager.cab entropy: 7.99965056224Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\browserhost.cab entropy: 7.99969064067Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\browserplugin.cab entropy: 7.9992046707Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\logicmodule.cab entropy: 7.99971035479Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\mfw-webadvisor.cab entropy: 7.99497056268Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\mfw.cab entropy: 7.99645912817Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\servicehost.cab entropy: 7.99845734638Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\settingmanager.cab entropy: 7.99959252091Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\taskmanager.cab entropy: 7.99988705726Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\uihost.cab entropy: 7.99874187266Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\uimanager.cab entropy: 7.99966733883Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\uninstaller.cab entropy: 7.99958655854Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\updater.cab entropy: 7.99956639709Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\wssdep.cab entropy: 7.99928309708Jump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi entropy: 7.99707344308Jump to dropped file

System Summary

barindex
Source: grand-theft-auto-5-theme-1-installer.exe.0.drZip Entry: encrypted
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D26220: GetCurrentProcessId,GetCurrentThreadId,CryptAcquireContextW,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext,DeviceIoControl,DeviceIoControl,4_2_00D26220
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D28FB04_2_00D28FB0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D24F504_2_00D24F50
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D251104_2_00D25110
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D5D5404_2_00D5D540
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D618404_2_00D61840
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D270D94_2_00D270D9
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D2F1104_2_00D2F110
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D473B04_2_00D473B0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D43AC04_2_00D43AC0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D5FFE04_2_00D5FFE0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D581904_2_00D58190
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DAC1104_2_00DAC110
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D683A04_2_00D683A0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D706604_2_00D70660
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DA86094_2_00DA8609
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D647C04_2_00D647C0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DB09924_2_00DB0992
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D909194_2_00D90919
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DB0AB24_2_00DB0AB2
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D90B4B4_2_00D90B4B
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D90DB04_2_00D90DB0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D38EA04_2_00D38EA0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D0CF404_2_00D0CF40
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D4D2C04_2_00D4D2C0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D9933A4_2_00D9933A
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DA14AF4_2_00DA14AF
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D054004_2_00D05400
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DAD8E04_2_00DAD8E0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D5A5404_2_00D5A540
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D0A6104_2_00D0A610
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DB68E04_2_00DB68E0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D628A04_2_00D628A0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D02B004_2_00D02B00
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D8ADD04_2_00D8ADD0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D66D434_2_00D66D43
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D5F1504_2_00D5F150
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D9B3404_2_00D9B340
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D6B4F04_2_00D6B4F0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D676024_2_00D67602
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D0F8304_2_00D0F830
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D939A44_2_00D939A4
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D63A304_2_00D63A30
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D3FB404_2_00D3FB40
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D2BCB04_2_00D2BCB0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D33C504_2_00D33C50
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D07D104_2_00D07D10
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FAEE575_2_00FAEE57
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00F9F0395_2_00F9F039
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00F9115B5_2_00F9115B
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00F9E24E5_2_00F9E24E
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00F955BB5_2_00F955BB
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FC555C5_2_00FC555C
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00F946065_2_00F94606
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FC2BCD5_2_00FC2BCD
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BC6C8E06_2_6BC6C8E0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BCA00206_2_6BCA0020
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BC7AE206_2_6BC7AE20
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BC6CC406_2_6BC6CC40
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BCDEBC06_2_6BCDEBC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD61BC06_2_6BD61BC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BCBCB506_2_6BCBCB50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD65B1C6_2_6BD65B1C
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD8BABA6_2_6BD8BABA
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD89A396_2_6BD89A39
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BCFBF606_2_6BCFBF60
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BCA0E506_2_6BCA0E50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD98DC06_2_6BD98DC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD69CD06_2_6BD69CD0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B5F00207_2_6B5F0020
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B5BC8E07_2_6B5BC8E0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B5CAE207_2_6B5CAE20
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B5BCC407_2_6B5BCC40
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B60A4807_2_6B60A480
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B60CB507_2_6B60CB50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6B5B1C7_2_6B6B5B1C
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B63C3E07_2_6B63C3E0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B62EBC07_2_6B62EBC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6B1BC07_2_6B6B1BC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6D9A397_2_6B6D9A39
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6DBABA7_2_6B6DBABA
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B50F9007_2_6B50F900
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B61D1E07_2_6B61D1E0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B63E0707_2_6B63E070
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6248107_2_6B624810
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6220C07_2_6B6220C0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B64BF607_2_6B64BF60
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6B67AD7_2_6B6B67AD
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B5F0E507_2_6B5F0E50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6BA6547_2_6B6BA654
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B61ED507_2_6B61ED50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6E8DC07_2_6B6E8DC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6B9CD07_2_6B6B9CD0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B0B00209_2_6B0B0020
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B07C8E09_2_6B07C8E0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B08AE209_2_6B08AE20
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B07CC409_2_6B07CC40
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B175B1C9_2_6B175B1C
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B0CCB509_2_6B0CCB50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B0EEBC09_2_6B0EEBC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B171BC09_2_6B171BC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B199A399_2_6B199A39
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B19BABA9_2_6B19BABA
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B10BF609_2_6B10BF60
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B0B0E509_2_6B0B0E50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B1A8DC09_2_6B1A8DC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B179CD09_2_6B179CD0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AB5C8E010_2_6AB5C8E0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AB9002010_2_6AB90020
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AB6AE2010_2_6AB6AE20
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABAA48010_2_6ABAA480
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AB5CC4010_2_6AB5CC40
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC7BABA10_2_6AC7BABA
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC79A3910_2_6AC79A39
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC51BC010_2_6AC51BC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABDC3E010_2_6ABDC3E0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABCEBC010_2_6ABCEBC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC55B1C10_2_6AC55B1C
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABACB5010_2_6ABACB50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABC20C010_2_6ABC20C0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABC481010_2_6ABC4810
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABDE07010_2_6ABDE070
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABBD1E010_2_6ABBD1E0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AAAF90010_2_6AAAF900
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC5A65410_2_6AC5A654
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AB90E5010_2_6AB90E50
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC567AD10_2_6AC567AD
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABEBF6010_2_6ABEBF60
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC59CD010_2_6AC59CD0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC88DC010_2_6AC88DC0
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6ABBED5010_2_6ABBED50
Source: Joe Sandbox ViewDropped File: C:\Program Files\McAfee\Temp2744101987\installer.exe C9E3EA8126273B9FA2439F674767F420630C46D68C02A9940EE97AAD05C42872
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00D88E31 appears 83 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00DA4231 appears 31 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00D11BE0 appears 70 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00D89600 appears 60 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00D885BF appears 56 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00D48650 appears 192 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00D88375 appears 45 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00D88713 appears 374 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: String function: 00D88DFE appears 103 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: String function: 00FB13D0 appears 58 times
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: String function: 00FC9103 appears 91 times
Source: installer.exe.4.drStatic PE information: Resource name: PAYLOAD type: Microsoft Cabinet archive data, many, 23003272 bytes, 135 files, at 0x2c +A "analyticsmanager.cab" +A "analyticstelemetry.cab", number 1, 845 datablocks, 0x1 compression
Source: setup.exe.5.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (console) Intel 80386, for MS Windows
Source: setup.exe.6.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (console) Intel 80386, for MS Windows
Source: installer.exe.11.drStatic PE information: Resource name: DLL type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Source: resource.dll.12.drStatic PE information: No import functions for PE file found
Source: resource.dll.11.drStatic PE information: No import functions for PE file found
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2581529598.000000000649E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMsMpLics.dllj% vs grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2583675920.00000000064A0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMsMpLics.dllj% vs grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2581231055.00000000064C5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMsMpLics.dllj% vs grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2581203687.000000000649F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMsMpLics.dllj% vs grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624152836.00000000064C5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMsMpLics.dllj% vs grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624458872.00000000064CE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMsMpLics.dllj% vs grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2581604979.00000000064C1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMsMpLics.dllj% vs grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2740568034.00000000064CF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMsMpLics.dllj% vs grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeRegistry key queried: HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\118.0.1 (x64 en-US)\Main Install Directory
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeKey value queried: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon version
Source: classification engineClassification label: mal40.rans.spyw.evad.winEXE@34/1057@0/13
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B71AB50 FormatMessageW,LocalFree,GetLastError,7_2_6B71AB50
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D14C8E GetCurrentProcessId,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,4_2_00D14C8E
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D15C1E CoCreateInstance,OleRun,4_2_00D15C1E
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D35318 GetModuleHandleW,FindResourceW,LoadResource,LockResource,std::ios_base::_Ios_base_dtor,GetModuleHandleW,GetProcAddress,GetCurrentProcess,Concurrency::cancel_current_task,Concurrency::cancel_current_task,SysFreeString,SysFreeString,4_2_00D35318
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfeeJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile created: C:\Users\user\Downloads\grand-theft-auto-5-theme-1-installer.exeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeMutant created: \Sessions\1\BaseNamedObjects\Global\Opera/Installer/C:/Users/user/AppData/Local/Programs/Opera
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:7088:120:WilError_03
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeMutant created: \Sessions\1\BaseNamedObjects\Global\{48ca68e-e4ff-43ac-a993-6d162f33de7c}
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:1132:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:5744:120:WilError_03
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeMutant created: \Sessions\1\BaseNamedObjects\Global\CppSetupDLMSingleInstanceMutex
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile created: C:\Users\user\AppData\Local\Temp\ISVD440.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCommand line argument: Title5_2_00FAEE57
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCommand line argument: BeginPrompt5_2_00FAEE57
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCommand line argument: Progress5_2_00FAEE57
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCommand line argument: yes5_2_00FAEE57
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCommand line argument: RunProgram5_2_00FAEE57
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCommand line argument: ExecuteFile5_2_00FAEE57
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCommand line argument: InstallPath5_2_00FAEE57
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCommand line argument: %%T5_2_00FAEE57
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : Select ParentProcessId from Win32_Process where name=&apos;browserhost.exe&apos; and SessionId=1 and commandline like &apos;%fheoggkfdfchfphceeifdbepaooicaho%&apos;
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : Select ParentProcessId from Win32_Process where name=&apos;browserhost.exe&apos; and SessionId=1 and commandline like &apos;%klekeajafkkpokaofllcadenjdckhinm%&apos;
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : Select ParentProcessId from Win32_Process where name=&apos;browserhost.exe&apos; and SessionId=1 and commandline like &apos;%{4ED1F68A-5463-4931-9384-8FFF5ED91D92}%&apos;
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : Select ParentProcessId from Win32_Process where name=&apos;browserhost.exe&apos; and SessionId=1 and commandline like &apos;%{4ED1F68A-5463-4931-9384-8FFF5ED91D92}%&apos;
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : Select ParentProcessId from Win32_Process where name=&apos;browserhost.exe&apos; and SessionId=1 and commandline like &apos;%{4ED1F68A-5463-4931-9384-8FFF5ED91D92}%&apos;
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : Select ParentProcessId from Win32_Process where name=&apos;browserhost.exe&apos; and SessionId=1 and commandline like &apos;%{4ED1F68A-5463-4931-9384-8FFF5ED91D92}%&apos;
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : Select ParentProcessId from Win32_Process where name=&apos;browserhost.exe&apos; and SessionId=1 and commandline like &apos;%{4ED1F68A-5463-4931-9384-8FFF5ED91D92}%&apos;
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : Select ParentProcessId from Win32_Process where name=&apos;browserhost.exe&apos; and SessionId=1 and commandline like &apos;%fdhgeoginicibhagdmblfikbgbkahibd%&apos;
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE ParentChild(ID INT, Name VARCHAR(255), ParentID INT);
Source: installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: INSERT INTO ParentChild VALUES(?, ?, ?);
Source: installer.exe, 0000000C.00000003.3361259058.00000174523A3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3398141444.00000174523AE000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.00000174526A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE Settings SET SettingName = ? WHERE ParentID = ? AND SettingName = ?; A
Source: installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE ParentChild SET Name = ? WHERE ParentID = ? AND Name = ?;`@
Source: installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE Settings(ParentID INT, SettingName VARCHAR(40), SettingType INT, Setting BLOB);INSERT INTO Settings VALUES(?, ?, ?, ?);@
Source: installer.exe, 0000000C.00000003.3361259058.00000174523A3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3398141444.00000174523AE000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.00000174526A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
Source: installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT * FROM ParentChild;SELECT * FROM Settings;Settings_INDEX_PID_NAMESettingsCREATE INDEX Settings_INDEX_PID_NAME ON Settings (ParentID ASC, SettingName ASC);
Source: installer.exeString found in binary or memory: wa-install.html
Source: installer.exeString found in binary or memory: wa-install.css
Source: installer.exeString found in binary or memory: wa-ui-install.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-hr-HR.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-it-IT.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-hu-HU.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-ja-JP.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-nb-NO.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-ko-KR.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-es-ES.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-es-MX.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-fr-CA.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-fi-FI.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-fr-FR.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-cs-CZ.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-da-DK.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-de-DE.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-en-US.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-el-GR.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-zh-TW.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-sk-SK.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-sv-SE.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-sr-Latn-CS.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-tr-TR.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-zh-CN.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-nl-NL.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-pl-PL.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-pt-PT.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-pt-BR.js
Source: installer.exeString found in binary or memory: jslang\wa-res-install-ru-RU.js
Source: unknownProcess created: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe "C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe"
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe" /affid 91088 PaidDistribution=true CountryCode=US
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe" --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b --server-tracking-blob=NDg5MmM0M2NiZmYxOTc2MjY3ZDE3MGIyMzA3NGYyODVjNDZhOGNmNjg5YTA1ZDg5NTRhNThiN2MxZWIzZDk4OTp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijoib3BlcmEiLCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInRpbWVzdGFtcCI6IjE3MzUwMzgwMTIuNzc0NSIsInVzZXJhZ2VudCI6InB5dGhvbi1yZXF1ZXN0cy8yLjMyLjMiLCJ1dG0iOnt9LCJ1dWlkIjoiYWFmNjZmNDQtNWMyYy00ZmJmLTg0YmQtN2Y2OTE0MGY0MGRiIn0=
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x32c,0x330,0x334,0x308,0x340,0x6bef9d44,0x6bef9d50,0x6bef9d5c
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe "C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --version
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe "C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\user\AppData\Local\Programs\Opera" --profile-folder --language=en-GB --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=1408 --package-dir-prefix="C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20241227050959" --session-guid=878fa370-40e0-48bb-911a-de2b24f3f5ca --server-tracking-blob="MTZmNWMzYjllYmU1ODE2ZGQ1N2E1NWMxYWU1OTAyMTkyMDM2ZjNhNmZmZmE4NmM3ZGJhNTQ2Yjk2MzU4Y2FmMjp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInN5c3RlbSI6eyJwbGF0Zm9ybSI6eyJhcmNoIjoieDg2XzY0Iiwib3BzeXMiOiJXaW5kb3dzIiwib3BzeXMtdmVyc2lvbiI6IjEwIiwicGFja2FnZSI6IkVYRSJ9fSwidGltZXN0YW1wIjoiMTczNTAzODAxMi43NzQ1IiwidXNlcmFnZW50IjoicHl0aG9uLXJlcXVlc3RzLzIuMzIuMyIsInV0bSI6eyJjYW1wYWlnbiI6Im9wZXJhX25ld19iIiwibWVkaXVtIjoiYXBiIiwic291cmNlIjoiYWlzIn0sInV1aWQiOiJhYWY2NmY0NC01YzJjLTRmYmYtODRiZC03ZjY5MTQwZjQwZGIifQ== " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=F005000000000000
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x320,0x324,0x328,0x2fc,0x338,0x6b309d44,0x6b309d50,0x6b309d5c
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\\installer.exe" /setOem:Affid=91088 /s /thirdparty /upgrade
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeProcess created: C:\Program Files\McAfee\Temp2744101987\installer.exe "C:\Program Files\McAfee\Temp2744101987\installer.exe" /setOem:Affid=91088 /s /thirdparty /upgrade
Source: unknownProcess created: C:\Program Files\McAfee\WebAdvisor\servicehost.exe "C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe"
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess created: C:\Program Files\McAfee\WebAdvisor\uihost.exe "C:\Program Files\McAfee\WebAdvisor\UIHost.exe"
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess created: C:\Program Files\McAfee\WebAdvisor\updater.exe "C:\Program Files\McAfee\WebAdvisor\updater.exe"
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c dir "C:\Program Files (x86)\McAfee Security Scan" 2>nul
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c IF EXIST "C:\Program Files\McAfee\WebAdvisor\Download" ( DEL "C:\Program Files\McAfee\WebAdvisor\Download\*.bak" )
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c DEL "C:\Program Files\McAfee\WebAdvisor\*.tmp"
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe" /affid 91088 PaidDistribution=true CountryCode=USJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe" --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_bJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe "C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\\installer.exe" /setOem:Affid=91088 /s /thirdparty /upgrade Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b --server-tracking-blob=NDg5MmM0M2NiZmYxOTc2MjY3ZDE3MGIyMzA3NGYyODVjNDZhOGNmNjg5YTA1ZDg5NTRhNThiN2MxZWIzZDk4OTp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijoib3BlcmEiLCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInRpbWVzdGFtcCI6IjE3MzUwMzgwMTIuNzc0NSIsInVzZXJhZ2VudCI6InB5dGhvbi1yZXF1ZXN0cy8yLjMyLjMiLCJ1dG0iOnt9LCJ1dWlkIjoiYWFmNjZmNDQtNWMyYy00ZmJmLTg0YmQtN2Y2OTE0MGY0MGRiIn0=Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x32c,0x330,0x334,0x308,0x340,0x6bef9d44,0x6bef9d50,0x6bef9d5cJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe "C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --versionJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe "C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\user\AppData\Local\Programs\Opera" --profile-folder --language=en-GB --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=1408 --package-dir-prefix="C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20241227050959" --session-guid=878fa370-40e0-48bb-911a-de2b24f3f5ca --server-tracking-blob="MTZmNWMzYjllYmU1ODE2ZGQ1N2E1NWMxYWU1OTAyMTkyMDM2ZjNhNmZmZmE4NmM3ZGJhNTQ2Yjk2MzU4Y2FmMjp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInN5c3RlbSI6eyJwbGF0Zm9ybSI6eyJhcmNoIjoieDg2XzY0Iiwib3BzeXMiOiJXaW5kb3dzIiwib3BzeXMtdmVyc2lvbiI6IjEwIiwicGFja2FnZSI6IkVYRSJ9fSwidGltZXN0YW1wIjoiMTczNTAzODAxMi43NzQ1IiwidXNlcmFnZW50IjoicHl0aG9uLXJlcXVlc3RzLzIuMzIuMyIsInV0bSI6eyJjYW1wYWlnbiI6Im9wZXJhX25ld19iIiwibWVkaXVtIjoiYXBiIiwic291cmNlIjoiYWlzIn0sInV1aWQiOiJhYWY2NmY0NC01YzJjLTRmYmYtODRiZC03ZjY5MTQwZjQwZGIifQ== " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=F005000000000000Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x320,0x324,0x328,0x2fc,0x338,0x6b309d44,0x6b309d50,0x6b309d5cJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeProcess created: C:\Program Files\McAfee\Temp2744101987\installer.exe "C:\Program Files\McAfee\Temp2744101987\installer.exe" /setOem:Affid=91088 /s /thirdparty /upgrade Jump to behavior
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess created: C:\Program Files\McAfee\WebAdvisor\uihost.exe "C:\Program Files\McAfee\WebAdvisor\UIHost.exe"
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess created: C:\Program Files\McAfee\WebAdvisor\updater.exe "C:\Program Files\McAfee\WebAdvisor\updater.exe"
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c dir "C:\Program Files (x86)\McAfee Security Scan" 2>nul
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c IF EXIST "C:\Program Files\McAfee\WebAdvisor\Download" ( DEL "C:\Program Files\McAfee\WebAdvisor\Download\*.bak" )
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c DEL "C:\Program Files\McAfee\WebAdvisor\*.tmp"
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: oledlg.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: riched32.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: dhcpcsvc6.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: dhcpcsvc.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: webio.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: zipfldr.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: windows.fileexplorer.common.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: shdocvw.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: slc.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeSection loaded: ntvdm64.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: acgenral.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: msacm32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: sfc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: webio.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: dhcpcsvc6.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: dhcpcsvc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeSection loaded: cryptnet.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: acgenral.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msacm32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: acgenral.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msacm32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: acgenral.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: msacm32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: acgenral.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msacm32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: acgenral.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msacm32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: apphelp.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: winhttp.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: userenv.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: windows.storage.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: wldp.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: profapi.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: winsta.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: msasn1.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: cryptsp.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: rsaenh.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: cryptbase.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: uxtheme.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: cabinet.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: gpapi.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: webio.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: mswsock.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: winnsi.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: sspicli.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: dnsapi.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: rasadhlp.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: fwpuclnt.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: schannel.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: mskeyprotect.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: ntasn1.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: ncrypt.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: ncryptsslp.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeSection loaded: dpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: apphelp.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: windows.storage.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: wldp.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: profapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: winsta.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: msasn1.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: cryptsp.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: rsaenh.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: cryptbase.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: gpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: winhttp.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: cabinet.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: version.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: chakra.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: icuuc.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: icuin.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: icu.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: iertutil.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: iertutil.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: userenv.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: dhcpcsvc6.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: dhcpcsvc.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: webio.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: mswsock.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: winnsi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: sspicli.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: dnsapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: rasadhlp.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: fwpuclnt.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: schannel.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: mdmregistration.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: omadmapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: powrprof.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: dmcmnutils.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: iri.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: umpdc.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: wbemcomn.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: amsi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: mskeyprotect.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: ntasn1.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: ncrypt.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: ncryptsslp.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: dpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: apphelp.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: windows.storage.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: wldp.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: profapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: winsta.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: msasn1.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: cryptsp.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: rsaenh.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: cryptbase.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: gpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: winhttp.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: version.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: wkscli.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: netutils.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: netapi32.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: dsreg.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: oleacc.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: windowscodecs.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: msimg32.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: userenv.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: uxtheme.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: wbemcomn.dll
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeSection loaded: amsi.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: apphelp.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: windows.storage.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: wldp.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: profapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: wtsapi32.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: winsta.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: winhttp.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: cryptbase.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: dhcpcsvc6.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: dhcpcsvc.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: webio.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: mswsock.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: winnsi.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: sspicli.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: dnsapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: rasadhlp.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: fwpuclnt.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: schannel.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: mskeyprotect.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: ntasn1.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: ncrypt.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: ncryptsslp.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: msasn1.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: cryptsp.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: rsaenh.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: gpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: dpapi.dll
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Accept
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Accept
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Accept
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Accept
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Accept
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Accept
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Accept
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Accept
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeAutomated click: Next
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Windows\SysWOW64\RICHED32.DLLJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeWindow detected: Grand Theft Auto 5 ThemeAcceptDeclineSkip AllWhen you click "Accept" you agree to the installation of "McAfee WebAdvisor" and that you have read the <a href="https://www.mcafee.com/consumer/en-us/policy/legal.html">Privacy Policy</a> and agree to the terms of its <a href="https://www.mcafee.com/consumer/en-us/policy/legal.html">End User License Agreement</a>. Check "Add/Remove Programs" to uninstall.
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeWindow detected: Number of UI elements: 15
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfeeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\analyticsmanager.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\analyticstelemetry.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\balloon_safe_annotation.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\browserhost.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\browserplugin.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\icon_complete.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\icon_failed.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\icon_laptop.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\installer.exeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jquery-1.9.0.min.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\l10n.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\logicmodule.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\logicscripts.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\main_close_large.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mcafeecerts.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mcafee_pc_install_icon.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mcafee_pc_install_icon2.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mfw-mwb.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mfw-nps.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mfw-webadvisor.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\mfw.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\poppins-light.ttfJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\poppins-regular.ttfJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\poppins-semibold.ttfJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\progress_check.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\progress_error.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\resource.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\resourcedll.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\servicehost.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\settingmanager.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\taskmanager.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\uihost.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\uimanager.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\uninstaller.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\updater.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-common.cssJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-core.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-install.cssJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-install.htmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-ui-install.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa-utils.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_check.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_check2.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_close.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_close2.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_close3.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_error.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_install_icon.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_logo.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_logo2.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wa_logo3.pngJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\webadvisor.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\webadvisor.icoJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\wssdep.cabJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslangJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-cs-CZ.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-da-DK.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-de-DE.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-el-GR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-en-US.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-es-ES.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-es-MX.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fi-FI.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fr-CA.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fr-FR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-hr-HR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-hu-HU.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-it-IT.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ja-JP.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ko-KR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-nb-NO.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-nl-NL.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pl-PL.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pt-BR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pt-PT.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ru-RU.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sk-SK.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sr-Latn-CS.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sv-SE.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-tr-TR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-zh-CN.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-zh-TW.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-cs-CZ.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-da-DK.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-de-DE.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-el-GR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-en-US.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-es-ES.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-es-MX.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-fi-FI.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-fr-CA.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-fr-FR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-hr-HR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-hu-HU.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-it-IT.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-ja-JP.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-ko-KR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-nb-NO.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-nl-NL.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-pl-PL.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-pt-BR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-pt-PT.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-ru-RU.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-sk-SK.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-sr-Latn-CS.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-sv-SE.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-tr-TR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-zh-CN.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-install-zh-TW.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-cs-CZ.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-da-DK.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-de-DE.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-el-GR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-en-US.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-es-ES.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-es-MX.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-fi-FI.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-fr-CA.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-fr-FR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-hr-HR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-hu-HU.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-it-IT.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-ja-JP.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-ko-KR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-nb-NO.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-nl-NL.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-pl-PL.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-pt-BR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-pt-PT.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-ru-RU.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-sk-SK.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-sr-Latn-CS.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-sv-SE.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-tr-TR.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-zh-CN.jsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDirectory created: C:\Program Files\McAfee\Temp2744101987\jslang\wa-res-shared-zh-TW.jsJump to behavior
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\resource.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor.ico
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\win32\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\win32\wssdep.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\auxiliary\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\auxiliary\reset_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\uihost.exe
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\class.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\servicehost.exe
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\dkjson.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\browserhost.exe
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\updater.exe
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\clipboard.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\info-16.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\npshandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\mwbhandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\wa-controller-nps-checklist.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\x64\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\x64\wssdep.dll
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\balloon-arrow-right.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\aj_logic.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\nps\wa-nps-checklist.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\handlers.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\stop-video-alert-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\balloon-arrow.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\base_provider.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\init.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\card_bg_image.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\wa-controller-mwb-checklist.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\edge_onboarding.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\json.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\close_icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\logger.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\ff_monitor.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\wa-mwb-checklist.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\dialog-balloon-logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\postinit.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\logic_loader.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\mwb\wb-rocket-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-en-US.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\edge_close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\priorityqueue.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\miscutils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\enable_ext_guide_ss.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_business_logic.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\triggeracceptor.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\uiarbitratorhelper.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\providers_selector.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\enable_ext_guide_wa.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\uihandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\ss_logic.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\uithreadexithandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\enable_sideloaded_ext_guide.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\win32helper.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\tests_logic.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\keep_changes_guide.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\type_tag_utils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\browserutils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\usage_calculation.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\logomark_white.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\affid_monitor.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\common_utils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mc-logo-tm-bottom.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\oem_util.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo-1.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\packageutils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\oem_utils_wps.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo-2024.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\settingsdb.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\oem_utils_wss.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\edge.com.mcafee.webadvisor.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\open_sideloaded_ext_alert_guide.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\core\utils\stringutils.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\oem_utils\oem_util_selector.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\edge.com.mcafee.webadvisor_v2.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\green_check.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor.mcafee.chrome.extension.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\providers\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\providers\bing.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\progress_tooltip_1.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\icn_mshield.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor.mcafee.firefox.extension.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\progress_tooltip_2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\providers\yahoo.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-pt-PT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor_v2.mcafee.chrome.extension.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\installer_background.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\progress_tooltip_3.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-ru-RU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\webadvisor_v2.mcafee.firefox.extension.json
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\smart_toast_config_manager.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\jquery-1.9.0.min.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\toggle_ext_on_guide.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-sk-SK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-sr-Latn-CS.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\toggle_off.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\smart_toast_config_selector.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-sv-SE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\toggle_on.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\selectors\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\selectors\smart_toast_search_setting.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-tr-TR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\tooltip_img_1_3.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\selectors\smart_toast_template.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\loading-spinner.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\tooltip_img_2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-zh-CN.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\logic\smart_toasting\selectors\smart_toast_trigger.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\new-tab-res-toast-zh-TW.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-oem-ss-toast-variants-step1.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\main_close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-oem-ss-toast-variants-step2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo-lg.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-oem-ss-toast-variants-woman.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee-logo2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-bg.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafeeicon.ico
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-en-US.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-checkbox-checked.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-checkbox-unchecked.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee_pc_install_icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-green-pc.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\mcafee_pc_install_icon2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\minimize.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ss-toast-variants-window.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\msac.ico
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-sstoast-toggle-rebranding-grass-lg.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-sstoast-toggle-rebranding-grass.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-sstoast-toggle-rebranding-step1.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\spinner_large.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-sstoast-toggle-rebranding-step2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-checklist.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_logo_upsell.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_logo_upsell2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_score_logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-common.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\edge_search\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\edge_search\edge_search_events.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-pt-PT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-core.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\about-icon-selected.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-ru-RU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\about-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ui-checklist.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-sk-SK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\amazon_upsell_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-ui-dialog.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\checklisthandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-sr-Latn-CS.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-uninstall-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\chrome_extension_push_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-sv-SE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa-utils.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\cryptojack-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-tr-TR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_check.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-zh-CN.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\ext_install_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_check2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\facebook.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-checklist-zh-TW.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\inst-noxup.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_close2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\inst-top.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_install_error.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\inst-warningbackground.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-overlay.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\wa_logo2.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-overlay.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_check.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-en-US.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-overlay.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_downchevron.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_exclamation.gif
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-toasts.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_questionmark.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-toasts.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\builtin\white_timer.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new-tab-toasts.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\new_tab_main_logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\overlay_ui_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\securesearchhandler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\settings-close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\settings-icon-selected.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\settings-icon.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\switch_off.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\switch_on.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\toast_impact_close.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-pt-PT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\twitter.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-ru-RU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\upsell_toast_handler.luc
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-sk-SK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-amazon-upsell-logo.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-sr-Latn-CS.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-sv-SE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-amazon-upsell.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-tr-TR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-amazon-upsell.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-zh-CN.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-amazon-upsell.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-dialog-balloon-zh-TW.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ch-store-overlay-ui.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ch-store-overlay-ui.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ch-store-overlay-ui.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-checklist-risk.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-checklist-status.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-en-US.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-checklist.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-controller-checklist.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-dialog-balloon.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-dialog-balloon.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-dwtoast.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-dwtoast.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ext-install-toast.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ext-install-toast.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ext-install-toast.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ext-install-toast.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-options.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-options.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-overlay-ui.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-overlay-ui.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-overlay-ui.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-pt-PT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding-bing.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-ru-RU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-sk-SK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-sr-Latn-CS.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-sv-SE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-tr-TR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-zh-CN.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding-bing.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-ext-install-toast-zh-TW.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding-bing.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-cs-CZ.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-da-DK.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-de-DE.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-el-GR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-rebranding.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-es-ES.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-variants.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-variants.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-es-MX.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ss-toast-variants.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-fi-FI.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-sstoast-toggle.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-fr-CA.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-sstoast-toggle.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-fr-FR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-sstoast-toggle.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ui-dialog-balloon.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-hr-HR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ui-dwtoast.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-hu-HU.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-ui-options.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-it-IT.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast-danger.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-ja-JP.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast-risk.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-ko-KR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast-wss.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-nb-NO.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast.css
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast.html
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-nl-NL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\wa-upsell-toast.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-pl-PL.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages\webadvisor\warning-icon-toast.png
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\jslang\wa-res-oem-ss-toast-variants-pt-BR.js
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages_web_view\
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDirectory created: C:\Program Files\McAfee\WebAdvisor\MFW\packages_web_view\builtin\
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: certificate valid
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic file information: File size 4547440 > 1048576
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x217c00
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x17a800
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: More than 200 imports for USER32.dll
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: c:\jenkins\workspace\WebAdvisor-accesslib-caller_main@2\Build\x64\Release\caller_dll.pdb source: installer.exe, 0000000C.00000000.3350639234.00007FF75CE33000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\McAfee\Development\Native\WebAdvisor-ISGIS\build\x64\Release\Installer.pdb source: installer.exe, 0000000B.00000000.3327079155.00007FF69726B000.00000002.00000001.01000000.00000014.sdmp, installer.exe, 0000000B.00000002.3536742481.00007FF69726B000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: c:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\Win32\Release\SaBsi.pdb source: saBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\LogicModule.pdb source: installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: installer.exe.pdb source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000000.2597665117.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3927249090.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000007.00000000.2600464595.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000007.00000002.3925811129.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608185157.0000000000188000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000000.2605558688.0000000000188000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000002.3926419813.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000000.2609337845.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000002.3926659240.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612280312.0000000000A78000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: installer_lib.dll.pdb source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\AnalyticsManager.pdb source: installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\McAfee\Development\Native\WebAdvisor-ISGIS\build\x64\Release\Installer.pdb$ source: installer.exe, 0000000B.00000000.3327079155.00007FF69726B000.00000002.00000001.01000000.00000014.sdmp, installer.exe, 0000000B.00000002.3536742481.00007FF69726B000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\Win32\Release\Resource.pdb source: installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3425873206.0000000010300000.00000004.00001000.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423798817.00000174524FF000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392910751.00000174523A4000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\SettingManager.pdb source: installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\ServiceHost.pdb source: installer.exe, 0000000C.00000003.3394810418.00000174523A8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\Updater.pdb source: installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\Uninstaller.pdb source: installer.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: installer_lib.dll.pdb@ source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: C:\Source\Repos\DS-Platform\CppInstaller\CppSetup\bin\Win32\Release\CppSetup.pdb source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000000.2053199277.0000000000E29000.00000002.00000001.01000000.00000003.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\Win32\Release\Resource.pdbGCTL source: installer.exe, 0000000C.00000003.3392995020.00000174502E3000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3425873206.0000000010300000.00000004.00001000.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3423798817.00000174524FF000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3392910751.00000174523A4000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\Installer.pdb source: installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\UIManager.pdb source: installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\TaskManager.pdb source: installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\ServiceHost.pdbw source: installer.exe, 0000000C.00000003.3394810418.00000174523A8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\x64\Release\BrowserHost.pdb source: installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D52B30 LoadLibraryW,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,FreeLibrary,GetLastError,4_2_00D52B30
Source: OperaSetup.exe.0.drStatic PE information: real checksum: 0x224a11 should be: 0x227f95
Source: mwaCEE7.tmp.12.drStatic PE information: real checksum: 0x0 should be: 0x3208b
Source: saBSI.exe.0.drStatic PE information: section name: .didat
Source: installer.exe.4.drStatic PE information: section name: _RDATA
Source: Opera_installer_2412271009583111408.dll.6.drStatic PE information: section name: .rodata
Source: Opera_installer_2412271009583111408.dll.6.drStatic PE information: section name: CPADinfo
Source: Opera_installer_2412271009583111408.dll.6.drStatic PE information: section name: malloc_h
Source: Opera_installer_2412271009585916556.dll.7.drStatic PE information: section name: .rodata
Source: Opera_installer_2412271009585916556.dll.7.drStatic PE information: section name: CPADinfo
Source: Opera_installer_2412271009585916556.dll.7.drStatic PE information: section name: malloc_h
Source: Opera_installer_2412271009591074984.dll.8.drStatic PE information: section name: .rodata
Source: Opera_installer_2412271009591074984.dll.8.drStatic PE information: section name: CPADinfo
Source: Opera_installer_2412271009591074984.dll.8.drStatic PE information: section name: malloc_h
Source: Opera_installer_2412271009594732232.dll.9.drStatic PE information: section name: .rodata
Source: Opera_installer_2412271009594732232.dll.9.drStatic PE information: section name: CPADinfo
Source: Opera_installer_2412271009594732232.dll.9.drStatic PE information: section name: malloc_h
Source: Opera_installer_2412271010001346324.dll.10.drStatic PE information: section name: .rodata
Source: Opera_installer_2412271010001346324.dll.10.drStatic PE information: section name: CPADinfo
Source: Opera_installer_2412271010001346324.dll.10.drStatic PE information: section name: malloc_h
Source: installer.exe.11.drStatic PE information: section name: .didat
Source: installer.exe.11.drStatic PE information: section name: _RDATA
Source: browserhost.exe.12.drStatic PE information: section name: .didat
Source: browserhost.exe.12.drStatic PE information: section name: _RDATA
Source: uninstaller.exe.12.drStatic PE information: section name: .didat
Source: uninstaller.exe.12.drStatic PE information: section name: _RDATA
Source: logicmodule.dll.12.drStatic PE information: section name: .didat
Source: logicmodule.dll.12.drStatic PE information: section name: _RDATA
Source: analyticsmanager.dll.12.drStatic PE information: section name: .didat
Source: analyticsmanager.dll.12.drStatic PE information: section name: _RDATA
Source: settingmanager.dll.12.drStatic PE information: section name: .didat
Source: settingmanager.dll.12.drStatic PE information: section name: _RDATA
Source: uimanager.dll.12.drStatic PE information: section name: .didat
Source: uimanager.dll.12.drStatic PE information: section name: _RDATA
Source: taskmanager.dll.12.drStatic PE information: section name: .didat
Source: taskmanager.dll.12.drStatic PE information: section name: _RDATA
Source: servicehost.exe.12.drStatic PE information: section name: .didat
Source: servicehost.exe.12.drStatic PE information: section name: _RDATA
Source: updater.exe.12.drStatic PE information: section name: .didat
Source: updater.exe.12.drStatic PE information: section name: _RDATA
Source: uihost.exe.12.drStatic PE information: section name: .didat
Source: uihost.exe.12.drStatic PE information: section name: _RDATA
Source: wssdep.dll0.12.drStatic PE information: section name: _RDATA
Source: mwaCEE7.tmp.12.drStatic PE information: section name: _RDATA
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeCode function: 0_2_00DDCE0D push ecx; ret 0_2_00DDCE20
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D88DDB push ecx; ret 4_2_00D88DEE
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DB7CFD push ecx; ret 4_2_00DB7D12
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FC90E0 push ecx; ret 5_2_00FC90F3
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FC96C8 push ecx; ret 5_2_00FC96DD
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD60CCB push ecx; ret 6_2_6BD60CDE
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6B0CCB push ecx; ret 7_2_6B6B0CDE
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B170CCB push ecx; ret 9_2_6B170CDE
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC50CCB push ecx; ret 10_2_6AC50CDE

Persistence and Installation Behavior

barindex
Source: c:\program files\mcafee\webadvisor\x64\wssdep.dllCOM Object registered for dropped file: hkey_local_machine\software\classes\clsid\{21cbfec0-e728-420c-b4a4-a58ad2089aba}\inprocserver32
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271010001346324.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009583111408.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\analyticsmanager.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeFile created: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009591074984.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\servicehost.exeJump to dropped file
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\uninstaller.exeJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\taskmanager.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\settingmanager.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeFile created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeFile created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009594732232.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\resource.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\win32\wssdep.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\updater.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\installer.exeJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\uimanager.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\resource.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\microsoftedgewebview2setup.exeJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\logicmodule.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\x64\wssdep.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\uihost.exeJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Program Files\McAfee\WebAdvisor\browserhost.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009585916556.dllJump to dropped file
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile created: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeFile created: C:\Users\user\AppData\Local\Temp\mwaCEE7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer\opera_installer_20241227050958717.logJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile created: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer\opera_installer_20241227051000410.logJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-cs-CZ.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-da-DK.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-de-DE.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-el-GR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-en-US.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-es-ES.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-es-MX.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fi-FI.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fr-CA.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-fr-FR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-hr-HR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-hu-HU.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-it-IT.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ja-JP.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ko-KR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-nb-NO.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-nl-NL.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pl-PL.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pt-BR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-pt-PT.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-ru-RU.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sk-SK.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sr-Latn-CS.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-sv-SE.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-tr-TR.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-zh-CN.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeFile created: C:\Program Files\McAfee\Temp2744101987\jslang\eula-zh-TW.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D40540 EnterCriticalSection,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,LeaveCriticalSection,4_2_00D40540
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EFC31460C619ECAE59C1BCE2C008036D94C84B8 BlobJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeProcess information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_PhysicalMemory
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_DiskDrive
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_PhysicalMemory
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_LogicalDisk
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_LogicalDisk
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_VideoController
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_VideoController
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6B3420000 memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6B3660000 memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6B3680000 memory commit | memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6B3B50000 memory commit | memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6B3B90000 memory commit | memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6C4570000 memory commit | memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6C4670000 memory commit | memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6C46F0000 memory commit | memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6C4730000 memory commit | memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6C4870000 memory commit | memory reserve | memory write watch
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeMemory allocated: 2A6B3BF0000 memory commit | memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B61FB60 rdtsc 7_2_6B61FB60
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D14C8E GetCurrentProcessId,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,4_2_00D14C8E
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\x64\wssdep.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\browserhost.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009585916556.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271010001346324.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\analyticsmanager.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009583111408.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009591074984.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\uninstaller.exeJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\taskmanager.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\settingmanager.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009594732232.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\Temp2744101987\resource.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mwaCEE7.tmpJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\win32\wssdep.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\resource.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\uimanager.dllJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\microsoftedgewebview2setup.exeJump to dropped file
Source: C:\Program Files\McAfee\Temp2744101987\installer.exeDropped PE file which has not been started: C:\Program Files\McAfee\WebAdvisor\logicmodule.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeEvasive API call chain: GetLocalTime,DecisionNodes
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeAPI coverage: 8.6 %
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeAPI coverage: 8.6 %
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe TID: 4592Thread sleep time: -30000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe TID: 4592Thread sleep time: -30000s >= -30000sJump to behavior
Source: C:\Program Files\McAfee\Temp2744101987\installer.exe TID: 7140Thread sleep time: -30000s >= -30000s
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exe TID: 3128Thread sleep time: -30000s >= -30000s
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exe TID: 3128Thread sleep time: -30000s >= -30000s
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_ComputerSystem
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_ComputerSystemProduct
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeWMI Queries: IWbemServices::ExecQuery - Root\CIMV2 : SELECT * FROM Win32_Processor
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile Volume queried: C:\Users\user\AppData\Local\Temp\ISVD440.tmp FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile Volume queried: C:\Users\user\AppData\Local\Temp\ISVD440.tmp FullSizeInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile Volume queried: C:\Users\user\AppData\Local\Temp\7zS4664E5C2 FullSizeInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeFile Volume queried: C:\Users\user\AppData\Local\Temp\7zS4664E5C2 FullSizeInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DA9BF0 FindFirstFileExW,4_2_00DA9BF0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00F98D20 FindFirstFileW,5_2_00F98D20
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FBFEEB FindFirstFileExW,5_2_00FBFEEB
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D72782 VirtualQuery,GetSystemInfo,4_2_00D72782
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\userJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppData\Local\TempJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppDataJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppData\Local\Temp\ISVD440.tmpJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI.zipJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
Source: saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW@vL
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739858556.0000000005B07000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ntivirus","Reason\\Reason Antivirus","ReasonLabs\\EPP","Microsoft\\Windows\\CurrentVersion\\Uninstall\\ReasonLabs-EPP","VMware, Inc."],"rvd":["HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Environment\\PROCESSOR_ARCHITE
Source: updater.exe, 0000000F.00000003.3735014309.0000025BB7491000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: <SETVAR Key="Exclude_Domain_List" Value="^(((acer|adobe|amazon|andi|aol|apn|apple|applied|ask|asus|att|baidu|biglobe|bing|brave|broadcom|checkpoint|cisco|costco|crowdstrike|cyberark|deepmind|dell|designveloper|devotechnology|doubleclick|duckduckgo|duosecurity|fitbit|fortinet|fujitsu|google|hp|ibm|infinitum|intel|jpmorgan|komo|leadqual|lenovo|lg|looker|mandiant|mcafee|medion|microsoft|mozilla|naver|nest|norton|nortonlifelock|officedepot|officemax|onespan|paloaltonetworks|phind|pingidentity|proofpoint|qtnet|razer|rsasecurity|sailpoint|sentinelone|sophos|staples|symantec|tenable|t-mobile|trellix|trendmicro|verizon|walmart|waze|wix|yahoo|yandex|yep|you|youtube|acronis|ahnlab|avast|avg|avira|av-test|bitdefender|bkav|blackberry|bullguard|comodo|cybereason|deepinstinct|drweb|emsisoft|enigmasoftware|escanav|eset|f-secure|gdata-software|heimdalsecurity|k7computing|k7computing|kaspersky|lavasoft|malwarebytes|netsecurity|northguard|openai|pandasecurity|pcmatic|quickheal|rapid7|sangfor|senseon|seqrite|sparkcognition|surfshark|broadcom|threattrack|totalav|totaldefense|vipre|vmware|watchguard|webroot|withsecure|xcitium|virustotal)\.com)|(abc\.xyz)|((archive|ecosia|av-comparatives)\.org)|(bell\.ca)|(elcorteingles\.es)|((elkjop|infinitum)\.no)|(fusionauth\.io)|(perplexity\.ai)|(360\.cn)|(elastic\.co)|(npav\.net))$"/>
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739858556.0000000005AD2000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676297523.00000000034BA000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2624924490.00000000034B1000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2651066038.00000000034BA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.000000000110D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: s-EPP","VMware, Inc."],"rvd":["HKLM\\SYSTEM\\Cur
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: te\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\brand\\PRUI"],"cp":"https://www.avast.com/privacy","ctu":"https://www.avast.com/eula","ov":61,"cbfo":true,"pv":"1.32","v":3}},{"ad":{"n":"","f":"ZB_RAV_Cross_Solo_Soft","o":"RAV_Cross"},"ps":{"i":"RAV/images/ZB_RAV_Bisli_Logo_bcg_V2/DOTPS-588/EN.png","dn":"RAV Antivirus","u":"https://shield.reasonsecurity.com/rsStubActivator.exe","p":"-ip:\"dui={userid}&dit={sessionid}&is_silent=true&oc={of}&p={pubid}&a=100&b={ispb}&se=true\" -i","r":["ReasonUP","RAVAntivirus","Reason\\Reason Antivirus","ReasonLabs\\EPP","Microsoft\\Windows\\CurrentVersion\\Uninstall\\ReasonLabs-EPP","VMware, Inc."],"rvd":["HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Environment\\PROCESSOR_ARCHITE
Source: grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2136988628.00000000016DE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624514532.00000000016DF000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739395872.00000000016E0000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.00000000016DC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWL
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B61FB60 rdtsc 7_2_6B61FB60
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeCode function: 0_2_00DEF22E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00DEF22E
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D25110 RegOpenKeyExW,RegQueryValueExW,SetLastError,RegCloseKey,RegCloseKey,GetLastError,OutputDebugStringW,OutputDebugStringW,OutputDebugStringW,LoadLibraryExW,GetLastError,4_2_00D25110
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D14C8E GetCurrentProcessId,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,4_2_00D14C8E
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DB7BC0 VirtualProtect ?,-00000001,00000104,?,?,?,0000001C4_2_00DB7BC0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D52B30 LoadLibraryW,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,FreeLibrary,GetLastError,4_2_00D52B30
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D9E8FE mov eax, dword ptr fs:[00000030h]4_2_00D9E8FE
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DA7CF2 mov eax, dword ptr fs:[00000030h]4_2_00DA7CF2
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DA7CAE mov eax, dword ptr fs:[00000030h]4_2_00DA7CAE
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DA7C6A mov eax, dword ptr fs:[00000030h]4_2_00DA7C6A
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00DA7D23 mov eax, dword ptr fs:[00000030h]4_2_00DA7D23
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D1463F GetProcessHeap,4_2_00D1463F
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeCode function: 0_2_00DEF22E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00DEF22E
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeCode function: 0_2_00DDD12B SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00DDD12B
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D89018 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,4_2_00D89018
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D893F2 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_00D893F2
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D8D453 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_00D8D453
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D89586 SetUnhandledExceptionFilter,4_2_00D89586
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FB16E8 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,5_2_00FB16E8
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FB67CB IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,5_2_00FB67CB
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FB17B7 SetUnhandledExceptionFilter,5_2_00FB17B7
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00FB0D2C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,5_2_00FB0D2C
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD730C4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_6BD730C4
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD60588 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_6BD60588
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6C30C4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,7_2_6B6C30C4
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 7_2_6B6B0588 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,7_2_6B6B0588
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B1830C4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,9_2_6B1830C4
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 9_2_6B170588 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,9_2_6B170588
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC630C4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,10_2_6AC630C4
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 10_2_6AC50588 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,10_2_6AC50588
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x32c,0x330,0x334,0x308,0x340,0x6bef9d44,0x6bef9d50,0x6bef9d5cJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe "C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\user\AppData\Local\Programs\Opera" --profile-folder --language=en-GB --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=1408 --package-dir-prefix="C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20241227050959" --session-guid=878fa370-40e0-48bb-911a-de2b24f3f5ca --server-tracking-blob="MTZmNWMzYjllYmU1ODE2ZGQ1N2E1NWMxYWU1OTAyMTkyMDM2ZjNhNmZmZmE4NmM3ZGJhNTQ2Yjk2MzU4Y2FmMjp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInN5c3RlbSI6eyJwbGF0Zm9ybSI6eyJhcmNoIjoieDg2XzY0Iiwib3BzeXMiOiJXaW5kb3dzIiwib3BzeXMtdmVyc2lvbiI6IjEwIiwicGFja2FnZSI6IkVYRSJ9fSwidGltZXN0YW1wIjoiMTczNTAzODAxMi43NzQ1IiwidXNlcmFnZW50IjoicHl0aG9uLXJlcXVlc3RzLzIuMzIuMyIsInV0bSI6eyJjYW1wYWlnbiI6Im9wZXJhX25ld19iIiwibWVkaXVtIjoiYXBiIiwic291cmNlIjoiYWlzIn0sInV1aWQiOiJhYWY2NmY0NC01YzJjLTRmYmYtODRiZC03ZjY5MTQwZjQwZGIifQ== " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=F005000000000000Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x320,0x324,0x328,0x2fc,0x338,0x6b309d44,0x6b309d50,0x6b309d5cJump to behavior
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c dir "C:\Program Files (x86)\McAfee Security Scan" 2>nul
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c IF EXIST "C:\Program Files\McAfee\WebAdvisor\Download" ( DEL "C:\Program Files\McAfee\WebAdvisor\Download\*.bak" )
Source: C:\Program Files\McAfee\WebAdvisor\updater.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c DEL "C:\Program Files\McAfee\WebAdvisor\*.tmp"
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe c:\users\user\appdata\local\temp\7zs4664e5c2\setup.exe --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b --server-tracking-blob=ndg5mmm0m2nizmyxotc2mjy3zde3mgiymza3ngyyodvjndzhognmnjg5yta1zdg5ntrhnthin2mxzwizzdk4otp7imnvdw50cnkioijvuyisimluc3rhbgxlcl9uyw1lijoit3blcmftzxr1cc5leguilcjwcm9kdwn0ijoib3blcmeilcjxdwvyesi6ii9vcgvyys9zdgfibguvd2luzg93cyisinrpbwvzdgftcci6ije3mzuwmzgwmtiunzc0nsisinvzzxjhz2vudci6inb5dghvbi1yzxf1zxn0cy8yljmyljmilcj1dg0iont9lcj1dwlkijoiywfmnjzmndqtnwmyyy00zmjmltg0ymqtn2y2ote0mgy0mgriin0=
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe c:\users\user\appdata\local\temp\7zs4664e5c2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=c:\users\user\appdata\roaming\opera software\opera stable\crash reports" "--crash-count-file=c:\users\user\appdata\roaming\opera software\opera stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=stable --annotation=plat=win32 --annotation=prod=operadesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x32c,0x330,0x334,0x308,0x340,0x6bef9d44,0x6bef9d50,0x6bef9d5c
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe "c:\users\user\appdata\local\temp\7zs4664e5c2\setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=1 --showunbox=0 --installfolder="c:\users\user\appdata\local\programs\opera" --profile-folder --language=en-gb --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=1408 --package-dir-prefix="c:\users\user\appdata\local\temp\.opera\opera installer temp\opera_package_20241227050959" --session-guid=878fa370-40e0-48bb-911a-de2b24f3f5ca --server-tracking-blob="mtzmnwmzyjllymu1ode2zgq1n2e1nwmxywu1otaymtkymdm2zjnhnmzmzme4nmm3zgjhntq2yjk2mzu4y2fmmjp7imnvdw50cnkioijvuyisimluc3rhbgxlcl9uyw1lijoit3blcmftzxr1cc5leguilcjwcm9kdwn0ijp7im5hbwuioijvcgvyysj9lcjxdwvyesi6ii9vcgvyys9zdgfibguvd2luzg93cyisinn5c3rlbsi6eyjwbgf0zm9ybsi6eyjhcmnoijoiedg2xzy0iiwib3bzexmioijxaw5kb3dziiwib3bzexmtdmvyc2lvbii6ijewiiwicgfja2fnzsi6ikvyrsj9fswidgltzxn0yw1wijoimtczntazodaxmi43nzq1iiwidxnlcmfnzw50ijoichl0ag9ulxjlcxvlc3rzlziumziumyisinv0bsi6eyjjyw1wywlnbii6im9wzxjhx25ld19iiiwibwvkaxvtijoiyxbiiiwic291cmnlijoiywlzin0sinv1awqioijhywy2nmy0nc01yzjjltrmymytodrizc03zjy5mtqwzjqwzgiifq== " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=f005000000000000
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe c:\users\user\appdata\local\temp\7zs4664e5c2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=c:\users\user\appdata\roaming\opera software\opera stable\crash reports" "--crash-count-file=c:\users\user\appdata\roaming\opera software\opera stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=stable --annotation=plat=win32 --annotation=prod=operadesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x320,0x324,0x328,0x2fc,0x338,0x6b309d44,0x6b309d50,0x6b309d5c
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe c:\users\user\appdata\local\temp\7zs4664e5c2\setup.exe --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b --server-tracking-blob=ndg5mmm0m2nizmyxotc2mjy3zde3mgiymza3ngyyodvjndzhognmnjg5yta1zdg5ntrhnthin2mxzwizzdk4otp7imnvdw50cnkioijvuyisimluc3rhbgxlcl9uyw1lijoit3blcmftzxr1cc5leguilcjwcm9kdwn0ijoib3blcmeilcjxdwvyesi6ii9vcgvyys9zdgfibguvd2luzg93cyisinrpbwvzdgftcci6ije3mzuwmzgwmtiunzc0nsisinvzzxjhz2vudci6inb5dghvbi1yzxf1zxn0cy8yljmyljmilcj1dg0iont9lcj1dwlkijoiywfmnjzmndqtnwmyyy00zmjmltg0ymqtn2y2ote0mgy0mgriin0=Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe c:\users\user\appdata\local\temp\7zs4664e5c2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=c:\users\user\appdata\roaming\opera software\opera stable\crash reports" "--crash-count-file=c:\users\user\appdata\roaming\opera software\opera stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=stable --annotation=plat=win32 --annotation=prod=operadesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x32c,0x330,0x334,0x308,0x340,0x6bef9d44,0x6bef9d50,0x6bef9d5cJump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe "c:\users\user\appdata\local\temp\7zs4664e5c2\setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=1 --showunbox=0 --installfolder="c:\users\user\appdata\local\programs\opera" --profile-folder --language=en-gb --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=1408 --package-dir-prefix="c:\users\user\appdata\local\temp\.opera\opera installer temp\opera_package_20241227050959" --session-guid=878fa370-40e0-48bb-911a-de2b24f3f5ca --server-tracking-blob="mtzmnwmzyjllymu1ode2zgq1n2e1nwmxywu1otaymtkymdm2zjnhnmzmzme4nmm3zgjhntq2yjk2mzu4y2fmmjp7imnvdw50cnkioijvuyisimluc3rhbgxlcl9uyw1lijoit3blcmftzxr1cc5leguilcjwcm9kdwn0ijp7im5hbwuioijvcgvyysj9lcjxdwvyesi6ii9vcgvyys9zdgfibguvd2luzg93cyisinn5c3rlbsi6eyjwbgf0zm9ybsi6eyjhcmnoijoiedg2xzy0iiwib3bzexmioijxaw5kb3dziiwib3bzexmtdmvyc2lvbii6ijewiiwicgfja2fnzsi6ikvyrsj9fswidgltzxn0yw1wijoimtczntazodaxmi43nzq1iiwidxnlcmfnzw50ijoichl0ag9ulxjlcxvlc3rzlziumziumyisinv0bsi6eyjjyw1wywlnbii6im9wzxjhx25ld19iiiwibwvkaxvtijoiyxbiiiwic291cmnlijoiywlzin0sinv1awqioijhywy2nmy0nc01yzjjltrmymytodrizc03zjy5mtqwzjqwzgiifq== " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=f005000000000000Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe c:\users\user\appdata\local\temp\7zs4664e5c2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=c:\users\user\appdata\roaming\opera software\opera stable\crash reports" "--crash-count-file=c:\users\user\appdata\roaming\opera software\opera stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=stable --annotation=plat=win32 --annotation=prod=operadesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x320,0x324,0x328,0x2fc,0x338,0x6b309d44,0x6b309d50,0x6b309d5cJump to behavior
Source: setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: kCannot get the size of file version infoNo file version in the package\StringFileInfo\000004B0\ProductVersionNo product version value in the packageReceived an invalid version: \StringFileInfo\000004B0\ContinuousVersionReceived an invalid continuous build number: Cannot acquire internal version from the full version: \StringFileInfo\000004B0\StreamNo stream value in the packageCannot get exe output: version..\..\opera\desktop\windows\installer\common\file_version_utils_impl.ccInvalid version from exe: Cannot get exe output: streamCannot get app output Failed to run the elevated process: Failed wait for the elevated process: Unexpected result when waiting for elevated process: Shortcut element - no correct interface...\..\opera\desktop\windows\installer\common\pin_automator.ccDoneCannot get native menu handle.Cannot get desktop rect.Cannot find pin menu element.No rectangleCould not activate the menu item.ProgmanSysListView324
Source: OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmpBinary or memory string: Cannot get the size of file version infoNo file version in the package\StringFileInfo\000004B0\ProductVersionNo product version value in the packageReceived an invalid version: \StringFileInfo\000004B0\ContinuousVersionReceived an invalid continuous build number: Cannot acquire internal version from the full version: \StringFileInfo\000004B0\StreamNo stream value in the packageCannot get exe output: version..\..\opera\desktop\windows\installer\common\file_version_utils_impl.ccInvalid version from exe: Cannot get exe output: streamCannot get app output Failed to run the elevated process: Failed wait for the elevated process: Unexpected result when waiting for elevated process: Shortcut element - no correct interface...\..\opera\desktop\windows\installer\common\pin_automator.ccDoneCannot get native menu handle.Cannot get desktop rect.Cannot find pin menu element.No rectangleCould not activate the menu item.ProgmanSysListView324
Source: setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmpBinary or memory string: jCannot get the size of file version infoNo file version in the package\StringFileInfo\000004B0\ProductVersionNo product version value in the packageReceived an invalid version: \StringFileInfo\000004B0\ContinuousVersionReceived an invalid continuous build number: Cannot acquire internal version from the full version: \StringFileInfo\000004B0\StreamNo stream value in the packageCannot get exe output: version..\..\opera\desktop\windows\installer\common\file_version_utils_impl.ccInvalid version from exe: Cannot get exe output: streamCannot get app output Failed to run the elevated process: Failed wait for the elevated process: Unexpected result when waiting for elevated process: Shortcut element - no correct interface...\..\opera\desktop\windows\installer\common\pin_automator.ccDoneCannot get native menu handle.Cannot get desktop rect.Cannot find pin menu element.No rectangleCould not activate the menu item.ProgmanSysListView324
Source: setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmpBinary or memory string: Vk~VkFVkCannot get the size of file version infoNo file version in the package\StringFileInfo\000004B0\ProductVersionNo product version value in the packageReceived an invalid version: \StringFileInfo\000004B0\ContinuousVersionReceived an invalid continuous build number: Cannot acquire internal version from the full version: \StringFileInfo\000004B0\StreamNo stream value in the packageCannot get exe output: version..\..\opera\desktop\windows\installer\common\file_version_utils_impl.ccInvalid version from exe: Cannot get exe output: streamCannot get app output Failed to run the elevated process: Failed wait for the elevated process: Unexpected result when waiting for elevated process: Shortcut element - no correct interface...\..\opera\desktop\windows\installer\common\pin_automator.ccDoneCannot get native menu handle.Cannot get desktop rect.Cannot find pin menu element.No rectangleCould not activate the menu item.ProgmanSysListView324
Source: setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmpBinary or memory string: VTk~VTkFVTkCannot get the size of file version infoNo file version in the package\StringFileInfo\000004B0\ProductVersionNo product version value in the packageReceived an invalid version: \StringFileInfo\000004B0\ContinuousVersionReceived an invalid continuous build number: Cannot acquire internal version from the full version: \StringFileInfo\000004B0\StreamNo stream value in the packageCannot get exe output: version..\..\opera\desktop\windows\installer\common\file_version_utils_impl.ccInvalid version from exe: Cannot get exe output: streamCannot get app output Failed to run the elevated process: Failed wait for the elevated process: Unexpected result when waiting for elevated process: Shortcut element - no correct interface...\..\opera\desktop\windows\installer\common\pin_automator.ccDoneCannot get native menu handle.Cannot get desktop rect.Cannot find pin menu element.No rectangleCould not activate the menu item.ProgmanSysListView324
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: 4_2_00D89215 cpuid 4_2_00D89215
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: GetLocaleInfoW,4_2_00DA45DA
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: GetACP,IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW,4_2_00DAC65F
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: EnumSystemLocalesW,4_2_00DAC9ED
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: EnumSystemLocalesW,4_2_00DAC952
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: EnumSystemLocalesW,4_2_00DAC907
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,4_2_00DACA80
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: GetLocaleInfoW,4_2_00DACCE0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,4_2_00DACE06
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,4_2_00DACFDB
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: GetLocaleInfoW,4_2_00DACF0C
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: GetLocaleInfoEx,4_2_00D87E28
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeCode function: EnumSystemLocalesW,4_2_00DA3F6D
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: GetACP,IsValidCodePage,GetLocaleInfoW,5_2_00FC3117
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: EnumSystemLocalesW,5_2_00FC33C3
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: GetLocaleInfoEx,FormatMessageA,5_2_00FB239E
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: EnumSystemLocalesW,5_2_00FC34A9
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: EnumSystemLocalesW,5_2_00FC340E
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,5_2_00FC3534
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: GetLocaleInfoW,5_2_00FC3787
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,5_2_00FC38B0
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: GetLocaleInfoW,5_2_00FC39B6
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,5_2_00FC3A8C
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: EnumSystemLocalesW,5_2_00FBCA14
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: GetLocaleInfoW,5_2_00FBCF23
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,6_2_6BD84260
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,6_2_6BD801DC
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,6_2_6BD841B8
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,6_2_6BD847ED
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,6_2_6BD83F67
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,6_2_6BD8071D
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,6_2_6BD846E7
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,6_2_6BD84640
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,6_2_6BD845F5
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,6_2_6BD84520
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,6_2_6BD844B3
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,7_2_6B6D4260
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,7_2_6B6D01DC
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,7_2_6B6D41B8
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,7_2_6B6D3F67
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,7_2_6B6D071D
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,7_2_6B6D47ED
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,7_2_6B6D4640
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,7_2_6B6D46E7
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,7_2_6B6D4520
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,7_2_6B6D45F5
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,7_2_6B6D44B3
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,9_2_6B194260
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,9_2_6B1941B8
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,9_2_6B1901DC
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,9_2_6B19071D
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,9_2_6B193F67
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,9_2_6B1947ED
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,9_2_6B194640
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,9_2_6B1946E7
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,9_2_6B194520
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,9_2_6B1945F5
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,9_2_6B1944B3
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,10_2_6AC74260
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,10_2_6AC701DC
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,10_2_6AC741B8
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,10_2_6AC746E7
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,10_2_6AC74640
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,10_2_6AC747ED
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,10_2_6AC73F67
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,10_2_6AC7071D
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,10_2_6AC744B3
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: EnumSystemLocalesW,10_2_6AC745F5
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: GetLocaleInfoW,10_2_6AC74520
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeQueries volume information: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup.zip VolumeInformationJump to behavior
Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeCode function: 0_2_00DDD534 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00DDD534
Source: C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exeCode function: 6_2_6BD7714C GetTimeZoneInformation,6_2_6BD7714C
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exeCode function: 5_2_00F91C57 GetVersion,GetModuleHandleW,GetProcAddress,GetSystemDirectoryW,LoadLibraryExW,5_2_00F91C57
Source: C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
Source: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EFC31460C619ECAE59C1BCE2C008036D94C84B8 BlobJump to behavior

Stealing of Sensitive Information

barindex
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.js
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release
Source: C:\Program Files\McAfee\WebAdvisor\servicehost.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Source: C:\Program Files\McAfee\WebAdvisor\uihost.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
1
Software
Acquire InfrastructureValid Accounts521
Windows Management Instrumentation
1
DLL Side-Loading
1
DLL Side-Loading
2
Disable or Modify Tools
1
OS Credential Dumping
2
System Time Discovery
Remote Services1
Archive Collected Data
2
Encrypted Channel
Exfiltration Over Other Network Medium1
Data Encrypted for Impact
CredentialsDomainsDefault Accounts2
Native API
1
DLL Search Order Hijacking
1
DLL Search Order Hijacking
1
Deobfuscate/Decode Files or Information
LSASS Memory3
File and Directory Discovery
Remote Desktop Protocol1
Browser Session Hijacking
Junk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts13
Command and Scripting Interpreter
1
Component Object Model Hijacking
1
Component Object Model Hijacking
2
Obfuscated Files or Information
Security Account Manager147
System Information Discovery
SMB/Windows Admin Shares1
Data from Local System
SteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook12
Process Injection
1
DLL Side-Loading
NTDS1
Query Registry
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Search Order Hijacking
LSA Secrets571
Security Software Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
Masquerading
Cached Domain Credentials34
Virtualization/Sandbox Evasion
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
Modify Registry
DCSync3
Process Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job34
Virtualization/Sandbox Evasion
Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt12
Process Injection
/etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1581319 Sample: grand-theft-auto-5-theme-1-... Startdate: 27/12/2024 Architecture: WINDOWS Score: 40 121 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 2->121 123 Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines) 2->123 125 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 2->125 127 5 other signatures 2->127 9 grand-theft-auto-5-theme-1-installer_qb8W-j1.exe 3 12 2->9         started        14 servicehost.exe 2->14         started        process3 dnsIp4 111 151.101.1.91 FASTLYUS United States 9->111 113 13.226.4.21 AMAZON-02US United States 9->113 65 C:\Users\user\AppData\Local\...\saBSI.exe, PE32 9->65 dropped 67 grand-theft-auto-5-theme-1-installer.exe, Zip 9->67 dropped 69 C:\Users\user\AppData\Local\...\saBSI.zip, Zip 9->69 dropped 71 C:\Users\user\AppData\...\OperaSetup.exe, PE32 9->71 dropped 133 Writes many files with high entropy 9->133 16 saBSI.exe 11 8 9->16         started        21 OperaSetup.exe 2 9->21         started        115 2.19.198.75 AKAMAI-ASUS European Union 14->115 135 Tries to harvest and steal browser information (history, passwords, etc) 14->135 23 uihost.exe 14->23         started        25 updater.exe 14->25         started        27 cmd.exe 14->27         started        file5 signatures6 process7 dnsIp8 99 23.32.238.105 XO-AS15US United States 16->99 101 151.101.2.133 FASTLYUS United States 16->101 103 52.43.6.209 AMAZON-02US United States 16->103 59 C:\Users\user\AppData\Local\...\installer.exe, PE32+ 16->59 dropped 129 Writes many files with high entropy 16->129 29 installer.exe 141 16->29         started        61 C:\Users\user\AppData\Local\...\setup.exe, PE32 21->61 dropped 33 setup.exe 32 21->33         started        131 Tries to harvest and steal browser information (history, passwords, etc) 23->131 36 cmd.exe 25->36         started        38 cmd.exe 25->38         started        40 conhost.exe 27->40         started        file9 signatures10 process11 dnsIp12 87 C:\Program Files\McAfee\...\installer.exe, PE32+ 29->87 dropped 89 C:\Program Files\McAfee\...\wssdep.cab, Microsoft 29->89 dropped 91 C:\Program Files\McAfee\...\updater.cab, Microsoft 29->91 dropped 97 14 other files (13 malicious) 29->97 dropped 137 Writes a notice file (html or txt) to demand a ransom 29->137 139 Writes many files with high entropy 29->139 42 installer.exe 29->42         started        105 107.167.110.211 OPERASOFTWAREUS United States 33->105 107 107.167.125.189 OPERASOFTWAREUS United States 33->107 109 3 other IPs or domains 33->109 93 Opera_installer_2412271009583111408.dll, PE32 33->93 dropped 95 C:\Users\user\AppData\Local\...\setup.exe, PE32 33->95 dropped 46 setup.exe 1 6 33->46         started        48 setup.exe 5 33->48         started        50 setup.exe 1 33->50         started        52 conhost.exe 36->52         started        54 conhost.exe 38->54         started        file13 signatures14 process15 dnsIp16 117 44.236.142.208 AMAZON-02US United States 42->117 119 184.85.182.130 AKAMAI-ASN1EU United States 42->119 73 C:\Program Files\McAfee\...\wssdep.dll, PE32+ 42->73 dropped 75 C:\Program Files\McAfee\...\uihost.exe, PE32+ 42->75 dropped 77 C:\Program Files\McAfee\...\servicehost.exe, PE32+ 42->77 dropped 85 13 other files (1 malicious) 42->85 dropped 79 Opera_installer_2412271009594732232.dll, PE32 46->79 dropped 56 setup.exe 4 46->56         started        81 Opera_installer_2412271009585916556.dll, PE32 48->81 dropped 83 Opera_installer_2412271009591074984.dll, PE32 50->83 dropped file17 process18 file19 63 Opera_installer_2412271010001346324.dll, PE32 56->63 dropped

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
grand-theft-auto-5-theme-1-installer_qb8W-j1.exe6%VirustotalBrowse
grand-theft-auto-5-theme-1-installer_qb8W-j1.exe8%ReversingLabs
SourceDetectionScannerLabelLink
C:\Program Files\McAfee\Temp2744101987\installer.exe0%ReversingLabs
C:\Program Files\McAfee\Temp2744101987\resource.dll0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\analyticsmanager.dll0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\browserhost.exe0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\logicmodule.dll0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\microsoftedgewebview2setup.exe0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\resource.dll0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\servicehost.exe0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\settingmanager.dll0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\taskmanager.dll0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\uihost.exe0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\uimanager.dll0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\uninstaller.exe0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\updater.exe0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\win32\wssdep.dll0%ReversingLabs
C:\Program Files\McAfee\WebAdvisor\x64\wssdep.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe0%ReversingLabs
C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe0%ReversingLabs
C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe0%ReversingLabs
C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe0%ReversingLabs
C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe0%ReversingLabs
C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009583111408.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009585916556.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009591074984.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\Opera_installer_2412271009594732232.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\Opera_installer_2412271010001346324.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\mwaCEE7.tmp0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://di7e1j5f1plfo.cloudfront.net/f/0%Avira URL Cloudsafe
https://analytics.apis.mcafee.com/mosaic/2.0/product-web/am/v1/recorder0%Avira URL Cloudsafe
https://www.mcafee.com/consumer/en-0%Avira URL Cloudsafe
https://sadownload.mcafee.com/Z0%Avira URL Cloudsafe
https://sadownload.mcafee.com/t0%Avira URL Cloudsafe
https://home.mcafee.com/Root/AboutUs.aspx?id=eulanet0%Avira URL Cloudsafe
https://di7e1j5f1plfo.cloudfront.net/zbd5950%Avira URL Cloudsafe
https://www.opera.cga0%Avira URL Cloudsafe
http://autoupdate-staging.services.ams.osa/netinstallervwindows?&One0%Avira URL Cloudsafe
https://reasonlabs.c0%Avira URL Cloudsafe
https://www.mcafee.com/consumer/v/wa-how.htmlp0%Avira URL Cloudsafe
https://di7e1j5f1plfo.cloudfront.net/zbdEL0%Avira URL Cloudsafe
http://127.0.0.1%0%Avira URL Cloudsafe
https://sadownload.mcafee.com/products/sa/v1/update/entry.xmlFailed0%Avira URL Cloudsafe
http://ocsp.glob_;.0%Avira URL Cloudsafe
https://di7e1j5f1plfo.cloudfront.net/f/Q0%Avira URL Cloudsafe
https://www.mcafee.com/consumer/en-us/policy/global/legal.html$0%Avira URL Cloudsafe
https://www.mcafee.com/consumer/en-us/policy/legal.html60%Avira URL Cloudsafe
https://www.mcafee.com/consumer/en-us/policy/legal.html80%Avira URL Cloudsafe
https://sadownload.mcafee.com/products/SA/v1/installer/4.1.1/995/0%Avira URL Cloudsafe
https://analytics.qa.apis.mcafee.comhttps://analytics.apis.mcafee.comhttps://.servicebus.windows.net0%Avira URL Cloudsafe
https://hello.softonic.com/privacy-policy0%Avira URL Cloudsafe
https://.servicebus.windows.net/&se=&skn=Failed0%Avira URL Cloudsafe
https://www.mcafee.com/consumer/en-us/policy/legal.htmlH0%Avira URL Cloudsafe
https://www.mcafee.com/consumer/e0%Avira URL Cloudsafe
http://home.mcafee.com/SaveEulaTrackingDetailsNot0%Avira URL Cloudsafe
https://analytics.qa.apis.mcafee.comhttps://analytics.apis.mcafee.comContent-Type:0%Avira URL Cloudsafe
https://analytics.qa.apis.mcafee.comQuerying0%Avira URL Cloudsafe
https://analytics.apis.mcafee.com/N0%Avira URL Cloudsafe
https://analytics.apis.mcafee.comhttps://analytics.qa.apis.mcafee.comPOSTContent-Type:0%Avira URL Cloudsafe
https://sadownload.mcafee.com/products/saupdater.exeWebAdvisor_Updaterthreat.api.mcafee.comheron_tok0%Avira URL Cloudsafe
https://127.0.0.1%0%Avira URL Cloudsafe
https://sadownload.mcafee.com:443/products/SA/BSI/bsi_main.xmlttps://analytics.apis.mcafee.com/mosai0%Avira URL Cloudsafe
https://sadownload.mcafee.com:443/products/SA/v1/installer/4.1.1/995/64/installer.exe0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://www.avg.com/ww-en/privacyexeA69D9EBc4grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
    high
    https://sadownload.mcafee.com/tsaBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://di7e1j5f1plfo.cloudfront.net/f/grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000000.2053199277.0000000000E29000.00000002.00000001.01000000.00000003.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://legal.opera.com/termsOperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
      high
      https://di7e1j5f1plfo.cloudfront.net/zbd595grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739164057.0000000001645000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625740985.0000000001641000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://crl3.diinstaller.exe, 0000000C.00000003.3424943877.00000174529CC000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        https://home.mcafee.com/Root/AboutUs.aspx?id=eulagrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
          high
          https://sadownload.mcafee.com/products/SA/BSI/bsi_DistributionRules.xml/saBSI.exe, 00000004.00000003.2699456813.0000000005B00000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699210949.0000000005B00000.00000004.00000020.00020000.00000000.sdmpfalse
            high
            https://help.opera.com/latest/OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
              high
              https://www.opera.cgagrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://policies.google.com/terms;OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                high
                https://autoupdate.opera.com/me/cefr7setup.exe, 00000006.00000002.3930648945.000000000108B000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  https://home.mcafee.com/Root/AboutUs.aspx?id=eulanetgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://localhost:3001api/prefs/?product=$1&version=$2..OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                    high
                    https://crashpad.chromium.org/https://crashpad.chromium.org/bug/newOperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                      high
                      https://download3.operacdn.com/PSsetup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        https://www.opera.com/download/OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                          high
                          https://analytics.apis.mcafee.com/mosaic/2.0/product-web/am/v1/recordersaBSI.exe, 00000004.00000002.3663969719.0000000005B00000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://download3.operacdn.com/_setup.exe, 00000006.00000003.2652491492.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681384823.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.000000000115C000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            https://sadownload.mcafee.com/ZsaBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://sadownload.mcafee.com/products/sa/bsi/win/binary/saBSI.exe, 00000004.00000003.3636510952.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636287551.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              https://www.mcafee.com/consumer/en-grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://reasonlabs.cgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2136988628.00000000016DE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://desktop-netinstaller-sub.osp.opera.software/Tsetup.exe, 00000006.00000002.3931729601.0000000001140000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                https://sadownload.mcafee.com/products/SA/BSI/bsi_abtest.xmlsaBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636620204.0000000003532000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://crashstats-collector-2.opera.com/32--url=https://crashstats-collector-2.opera.com/setup.exe, 00000007.00000002.3933874231.000000003866C000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 0000000A.00000002.3937504080.0000000045C64000.00000004.00001000.00020000.00000000.sdmpfalse
                                    high
                                    http://autoupdate-staging.services.ams.osa/netinstallervwindows?&OneOperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://sadownload.mcafee.com/products/sa/v1/update/entry.xmlFailedinstaller.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://download3.operacdn.com/setup.exe, 00000006.00000003.2652491492.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931552019.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681384823.000000000115C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2900155539.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.000000000115C000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://clients2.googleusercontent.com/.installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        https://crashstats-collector-2.opera.com/setup.exe, 0000000A.00000002.3938804118.0000000045CA4000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 0000000A.00000002.3925532515.00000000007F0000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          https://desktop-netinstaller-sub.osp.opera.software/Csetup.exe, 00000006.00000002.3931552019.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2900155539.0000000001126000.00000004.00000020.00020000.00000000.sdmpfalse
                                            high
                                            https://www.avast.com/privacy-policyEHcgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                                              high
                                              https://autoupdate.geo.opera.com/https://autoupdate.opera.com/me/OperaDesktophttps://crashstats-collOperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                high
                                                https://crashstats-collector-2.opera.com/yTsetup.exe, 0000000A.00000002.3937504080.0000000045C64000.00000004.00001000.00020000.00000000.sdmpfalse
                                                  high
                                                  https://download3.operacdn.com/ftp/pub/opera/desktop/115.0.5322.119/win/Opera_115.0.5322.119_Autoupdsetup.exe, 00000006.00000003.2681493723.000000000479D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3931729601.0000000001140000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.000000000111B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2681384823.0000000001140000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    high
                                                    https://desktop-netinstaller-sub.osp.opera.software/v1/binaryMicrosoftsetup.exe, 00000006.00000002.3941252634.0000000004780000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      high
                                                      https://sadownload.mcafee.com/products/SA/BSI/bsi_PartnerDistribution.xmlsaBSI.exe, 00000004.00000003.3323687182.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003511000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676251289.000000000350A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676226000.0000000003515000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        high
                                                        https://crashpad.chromium.org/OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                          high
                                                          https://addons.opera.com/en/extensions/details/dify-cashback/setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                            high
                                                            https://www.ccleaner.com/legal/end-user-license-agreementgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                                                              high
                                                              https://download3.operacdn.com/$setup.exe, 00000006.00000003.2652491492.000000000115C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                high
                                                                https://redir.opera.com/www.opera.com/firstrun/?utm_campaign=opera_new_b&utm_medium=apb&utm_source=asetup.exe, 00000006.00000002.3945137379.000000005D28C000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3942640378.000000005D207000.00000004.00001000.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2628553746.000000000110D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  high
                                                                  https://www.mcafee.com/consumer/v/wa-how.htmlpsaBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://di7e1j5f1plfo.cloudfront.net/zbdELgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624226875.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  http://127.0.0.1%installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://opera.com/privacyOperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                                    high
                                                                    https://www.opera.com/he/eula/computersgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.00000000016C5000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                      high
                                                                      https://gamemaker.io)OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                                        high
                                                                        https://images.sftcdn.net/im#bgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          high
                                                                          https://www.google.com/favicon.icoinstaller.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                            high
                                                                            http://ocsp.glob_;.installer.exe, 0000000C.00000003.3356381187.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3352535766.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3356986865.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354113977.0000017451B13000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3353090288.0000017451B0A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://analytics.apis.mcafee.comhttps://analytics.qa.apis.mcafee.com/mosaic/2.0/product-web/am/v1/rsaBSI.exe, 00000004.00000000.2582082032.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmp, saBSI.exe, 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpfalse
                                                                              high
                                                                              https://sadownload.mcafee.com/products/SA/BSI/bsi_PartnerDistribution.xml/saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                high
                                                                                https://www.mcafee.com/consumer/en-us/policy/legal.html6grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                • Avira URL Cloud: safe
                                                                                unknown
                                                                                https://di7e1j5f1plfo.cloudfront.net/f/Qgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625823950.0000000001647000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2625740985.0000000001641000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739185827.0000000001649000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                • Avira URL Cloud: safe
                                                                                unknown
                                                                                https://gamemaker.io/en/get.OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                                                  high
                                                                                  https://gamemaker.ioOperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                                                    high
                                                                                    https://www.mcafee.com/consumer/en-us/policy/global/legal.html$grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137032175.00000000016CE000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    https://www.mcafee.com/consumer/en-us/policy/legal.html8grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739858556.0000000005AD2000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://www.siteadvisor.com/favicon.icoMcAfeeinstaller.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                      high
                                                                                      https://sadownload.mcafee.com/products/SA/v1/installer/4.1.1/995/saBSI.exe, 00000004.00000002.3663969719.0000000005AF0000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                      • Avira URL Cloud: safe
                                                                                      unknown
                                                                                      https://download3.operacdn.com/6setup.exe, 00000006.00000003.2681508420.0000000001126000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000003.2652606440.0000000001127000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        https://analytics.apis.mcafee.com/saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                          high
                                                                                          https://sadownload.mcafee.com/products/SA/v1/bsisaBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            https://analytics.qa.apis.mcafee.comhttps://analytics.apis.mcafee.comhttps://.servicebus.windows.netinstaller.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmpfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://hello.softonic.com/privacy-policygrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2624883027.0000000001679000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000002.2739300972.0000000001679000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://.servicebus.windows.net/&se=&skn=Failedinstaller.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://sadownload.mcafee.com/products/sa/bsi/win/binarysaBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              https://www.mcafee.com/consumer/en-us/policy/legal.htmlHgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                              • Avira URL Cloud: safe
                                                                                              unknown
                                                                                              https://www.mcafee.com/consumer/egrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                              • Avira URL Cloud: safe
                                                                                              unknown
                                                                                              https://sadownload.mcafee.com/products/SA/BSI/Win/binary/4.1.0/update_bsi_self.xml/saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                high
                                                                                                https://crashpad.chromium.org/bug/newOperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                                                                  high
                                                                                                  https://analytics.qa.apis.mcafee.comhttps://analytics.apis.mcafee.comContent-Type:installer.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                  • Avira URL Cloud: safe
                                                                                                  unknown
                                                                                                  http://crl3.digisaBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    http://home.mcafee.com/SaveEulaTrackingDetailsNotinstaller.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmpfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://sadownload.mcafee.com/products/saupdater.exeWebAdvisor_Updaterthreat.api.mcafee.comheron_tokinstaller.exe, 0000000C.00000003.3407563186.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000000.3350271738.00007FF75CD9F000.00000002.00000001.01000000.00000015.sdmp, installer.exe, 0000000C.00000003.3398141444.000001745252B000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3394810418.00000174523A8000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3409828690.00000174523A6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://sadownload.mcafee.com:443/products/SA/BSI/bsi_main.xmlttps://analytics.apis.mcafee.com/mosaisaBSI.exe, 00000004.00000003.2676361087.00000000034B1000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://127.0.0.1%installer.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    https://reasonlabs.com/policiesgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                      high
                                                                                                      https://analytics.qa.apis.mcafee.comQueryinginstaller.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                      • Avira URL Cloud: safe
                                                                                                      unknown
                                                                                                      https://analytics.apis.mcafee.comhttps://analytics.qa.apis.mcafee.comPOSTContent-Type:installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                      • Avira URL Cloud: safe
                                                                                                      unknown
                                                                                                      https://sadownload.mcafee.com/saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                        high
                                                                                                        https://www.avast.com/pgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                          high
                                                                                                          https://assets.razerzone.com/downloads/software/RazerEndUserLicenseAgreement.pdfgrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                            high
                                                                                                            https://sadownload.mcafee.com/products/SA/BSI/bsi_PaidDistribution.xmlsaBSI.exe, 00000004.00000002.3663188086.00000000034B1000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676226000.0000000003515000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                              high
                                                                                                              https://sadownload.mcafee.com/products/SA/BSI/bsi_abtest.xml/saBSI.exe, 00000004.00000003.3538335676.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636510952.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3323687182.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3636287551.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003524000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                high
                                                                                                                https://sadownload.mcafee.com/products/sasaBSI.exe, 00000004.00000002.3663188086.000000000345E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                  high
                                                                                                                  http://www.siteadvisor.com/favicon.icoinstaller.exe, 0000000C.00000003.3372548069.0000017452512000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3361259058.0000017452497000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3354713173.00000174523A5000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3401133970.000001745278A000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3405604975.0000017452606000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                    high
                                                                                                                    https://desktop-netinstaller-sub.osp.opera.software/v1/binaryeoperacdn.comsetup.exe, 00000006.00000002.3941252634.0000000004780000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                      high
                                                                                                                      https://www.avast.com/eulagrand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005ADE000.00000004.00000020.00020000.00000000.sdmp, grand-theft-auto-5-theme-1-installer_qb8W-j1.exe, 00000000.00000003.2137074904.0000000005B07000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                        high
                                                                                                                        https://sadownload.mcafee.com/products/SA/BSI/Win/binary/4.1.0/update_bsi_self.xmlsaBSI.exe, 00000004.00000003.3323687182.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2699390350.0000000003511000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676251289.000000000350A000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2698371929.0000000003510000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3324825753.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2886296022.000000000350C000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3304241140.000000000350B000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2815880117.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.2676271658.000000000350F000.00000004.00000020.00020000.00000000.sdmp, saBSI.exe, 00000004.00000003.3538335676.000000000350B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                          high
                                                                                                                          https://legal.opera.com/eula/computersOperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000008.00000001.2606348634.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                                                                                            high
                                                                                                                            https://analytics.apis.mcafee.com/NsaBSI.exe, 00000004.00000002.3663188086.0000000003506000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                            • Avira URL Cloud: safe
                                                                                                                            unknown
                                                                                                                            https://sadownload.mcafee.com:443/products/SA/v1/installer/4.1.1/995/64/installer.exesaBSI.exe, 00000004.00000003.3304241140.0000000003524000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                            • Avira URL Cloud: safe
                                                                                                                            unknown
                                                                                                                            https://download.opera.com/download/get/?id=69300&autoupdate=1&ni=1&stream=stable&utm_campaign=operasetup.exe, 00000006.00000002.3943921040.000000005D230000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                              high
                                                                                                                              https://www.siteadvisor.cominstaller.exe, 0000000C.00000003.3407804311.00000174502DB000.00000004.00000020.00020000.00000000.sdmp, installer.exe, 0000000C.00000003.3407563186.000001745246C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                high
                                                                                                                                https://features.opera-api2.com/api/v2/features?country=US&language=en-GB&uuid=1234646e-fa64-4454-98setup.exe, 00000006.00000003.2647303162.0000000001140000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3930648945.00000000010E0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3946258123.000000005D2EC000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  https://www.opera.com..OperaSetup.exe, 00000005.00000003.2594496731.0000000003602000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000006.00000002.3927505086.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000006.00000002.3933586816.0000000003040000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000006.00000002.3948474288.000000006BE57000.00000002.00000001.01000000.0000000D.sdmp, setup.exe, 00000007.00000002.3938686287.000000006B7A7000.00000002.00000001.01000000.0000000E.sdmp, setup.exe, 00000007.00000002.3926213298.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000008.00000002.2608229543.000000000019A000.00000002.00000001.01000000.0000000F.sdmp, setup.exe, 00000009.00000002.3932754111.0000000003220000.00000002.00000001.00040000.0000000C.sdmp, setup.exe, 00000009.00000000.2609373441.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmp, setup.exe, 00000009.00000002.3946002140.000000006B267000.00000002.00000001.01000000.00000012.sdmp, setup.exe, 0000000A.00000002.3944942740.000000006AD47000.00000002.00000001.01000000.00000013.sdmp, setup.exe, 0000000A.00000000.2612335847.0000000000A8A000.00000002.00000001.01000000.0000000C.sdmpfalse
                                                                                                                                    high
                                                                                                                                    https://sadownload.mcafee.com/products/SA/v1/pc/partner_custom_bsi.xmlsaBSI.exe, 00000004.00000003.2815962655.0000000005B2A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                      high
                                                                                                                                      • No. of IPs < 25%
                                                                                                                                      • 25% < No. of IPs < 50%
                                                                                                                                      • 50% < No. of IPs < 75%
                                                                                                                                      • 75% < No. of IPs
                                                                                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                      52.43.6.209
                                                                                                                                      unknownUnited States
                                                                                                                                      16509AMAZON-02USfalse
                                                                                                                                      107.167.96.37
                                                                                                                                      unknownUnited States
                                                                                                                                      53755IOFLOODUSfalse
                                                                                                                                      107.167.96.38
                                                                                                                                      unknownUnited States
                                                                                                                                      53755IOFLOODUSfalse
                                                                                                                                      151.101.1.91
                                                                                                                                      unknownUnited States
                                                                                                                                      54113FASTLYUSfalse
                                                                                                                                      184.85.182.130
                                                                                                                                      unknownUnited States
                                                                                                                                      20940AKAMAI-ASN1EUfalse
                                                                                                                                      23.32.238.105
                                                                                                                                      unknownUnited States
                                                                                                                                      2828XO-AS15USfalse
                                                                                                                                      13.226.4.21
                                                                                                                                      unknownUnited States
                                                                                                                                      16509AMAZON-02USfalse
                                                                                                                                      151.101.2.133
                                                                                                                                      unknownUnited States
                                                                                                                                      54113FASTLYUSfalse
                                                                                                                                      2.19.198.75
                                                                                                                                      unknownEuropean Union
                                                                                                                                      16625AKAMAI-ASUSfalse
                                                                                                                                      95.100.135.104
                                                                                                                                      unknownEuropean Union
                                                                                                                                      16625AKAMAI-ASUSfalse
                                                                                                                                      107.167.110.211
                                                                                                                                      unknownUnited States
                                                                                                                                      21837OPERASOFTWAREUSfalse
                                                                                                                                      107.167.125.189
                                                                                                                                      unknownUnited States
                                                                                                                                      21837OPERASOFTWAREUSfalse
                                                                                                                                      44.236.142.208
                                                                                                                                      unknownUnited States
                                                                                                                                      16509AMAZON-02USfalse
                                                                                                                                      Joe Sandbox version:41.0.0 Charoite
                                                                                                                                      Analysis ID:1581319
                                                                                                                                      Start date and time:2024-12-27 11:08:11 +01:00
                                                                                                                                      Joe Sandbox product:CloudBasic
                                                                                                                                      Overall analysis duration:0h 13m 11s
                                                                                                                                      Hypervisor based Inspection enabled:false
                                                                                                                                      Report type:full
                                                                                                                                      Cookbook file name:default.jbs
                                                                                                                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                      Run name:Run with higher sleep bypass
                                                                                                                                      Number of analysed new started processes analysed:22
                                                                                                                                      Number of new started drivers analysed:0
                                                                                                                                      Number of existing processes analysed:0
                                                                                                                                      Number of existing drivers analysed:0
                                                                                                                                      Number of injected processes analysed:0
                                                                                                                                      Technologies:
                                                                                                                                      • HCA enabled
                                                                                                                                      • EGA enabled
                                                                                                                                      • AMSI enabled
                                                                                                                                      Analysis Mode:default
                                                                                                                                      Sample name:grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                      Detection:MAL
                                                                                                                                      Classification:mal40.rans.spyw.evad.winEXE@34/1057@0/13
                                                                                                                                      EGA Information:
                                                                                                                                      • Successful, ratio: 77.8%
                                                                                                                                      HCA Information:Failed
                                                                                                                                      Cookbook Comments:
                                                                                                                                      • Found application associated with file extension: .exe
                                                                                                                                      • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
                                                                                                                                      • Sleep loops longer than 100000000ms are bypassed. Single calls with delay of 100000000ms and higher are ignored
                                                                                                                                      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                                                                                                                      • Execution Graph export aborted for target installer.exe, PID 6984 because there are no executed function
                                                                                                                                      • Execution Graph export aborted for target setup.exe, PID 4984 because there are no executed function
                                                                                                                                      • Not all processes where analyzed, report is missing behavior information
                                                                                                                                      • Report creation exceeded maximum time and may have missing disassembly code information.
                                                                                                                                      • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                      • Report size exceeded maximum capacity and may have missing disassembly code.
                                                                                                                                      • Report size getting too big, too many NtCreateKey calls found.
                                                                                                                                      • Report size getting too big, too many NtEnumerateKey calls found.
                                                                                                                                      • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                                      • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                      • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                      • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                      • Skipping network analysis since amount of network traffic is too extensive
                                                                                                                                      No simulations
                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                      151.101.2.133file.exeGet hashmaliciousLummaC, Glupteba, PureLog Stealer, RisePro Stealer, SmokeLoader, Stealc, zgRATBrowse
                                                                                                                                      • linktr.ee/phpmyadmin/
                                                                                                                                      RESPUEALPROCDONVINCPDF4689002 RESPUEALPROCDONVINCPDF4689004.exeGet hashmaliciousUnknownBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      Banking details.exeGet hashmaliciousUnknownBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      Halkbank_Ekstre_20210302_075312_783075.pdf.exeGet hashmaliciousUnknownBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      REQUEST FOR QUOTATION 4675674665.exeGet hashmaliciousSnake KeyloggerBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      PO#BC210243_pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      hfLfKDTosA.exeGet hashmaliciousAzorultBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      e0YQRfcpqS.exeGet hashmaliciousAzorultBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      Doc7656.xlsxGet hashmaliciousFormBookBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      Zahlungskopie.exeGet hashmaliciousAgentTeslaBrowse
                                                                                                                                      • www.chelseafc.com/
                                                                                                                                      107.167.96.38Revo.Uninstaller.Pro.v5.3.4.exeGet hashmaliciousUnknownBrowse
                                                                                                                                        Revo.Uninstaller.Pro.v5.3.4.exeGet hashmaliciousUnknownBrowse
                                                                                                                                          151.101.1.91gTU8ed4669.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                            gTU8ed4669.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                              do.ps1Get hashmaliciousUnknownBrowse
                                                                                                                                                P0HV8mjHS1.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                  mdPov8VTwi.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                    nmy4mJXEaz.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                      file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                        file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                          file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                            file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                              184.85.182.130Canvas of Kings_N6xC-S2.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                Violated Heroine_91zbZ-1.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                  23.32.238.105qkfI7LuPTEGet hashmaliciousUnknownBrowse
                                                                                                                                                                    No context
                                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                    AMAZON-02USSpace.arm6.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                    • 54.217.10.153
                                                                                                                                                                    https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                                                                                                                                                                    • 52.53.112.200
                                                                                                                                                                    https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                                                                                                                                                                    • 52.53.112.200
                                                                                                                                                                    https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                                                                                                                                                                    • 52.53.112.200
                                                                                                                                                                    https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                                                                                                                                                                    • 52.53.112.200
                                                                                                                                                                    sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                                                                                                                                    • 54.171.230.55
                                                                                                                                                                    db0fa4b8db0333367e9bda3ab68b8042.i686.elfGet hashmaliciousMirai, GafgytBrowse
                                                                                                                                                                    • 35.73.111.15
                                                                                                                                                                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                                                                                                                                    • 54.171.230.55
                                                                                                                                                                    5935c1f1a7da8e42028da77013b80635afdd605866569.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                    • 18.167.52.240
                                                                                                                                                                    aD7D9fkpII.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                    • 18.238.49.124
                                                                                                                                                                    IOFLOODUSarmv5l.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                    • 107.178.118.71
                                                                                                                                                                    powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                                                                                                    • 107.167.90.100
                                                                                                                                                                    arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                                                                                                    • 148.163.112.79
                                                                                                                                                                    isWLAjve0K.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    QhR8Zp6fZs.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    CNUXJvLcgw.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    xWpAZpLw47.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    nnn.exeGet hashmaliciousAgentTeslaBrowse
                                                                                                                                                                    • 107.178.108.41
                                                                                                                                                                    ssd.exeGet hashmaliciousAgentTeslaBrowse
                                                                                                                                                                    • 107.178.108.41
                                                                                                                                                                    SqWzv6g2gV.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    IOFLOODUSarmv5l.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                    • 107.178.118.71
                                                                                                                                                                    powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                                                                                                    • 107.167.90.100
                                                                                                                                                                    arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                                                                                                    • 148.163.112.79
                                                                                                                                                                    isWLAjve0K.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    QhR8Zp6fZs.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    CNUXJvLcgw.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    xWpAZpLw47.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    nnn.exeGet hashmaliciousAgentTeslaBrowse
                                                                                                                                                                    • 107.178.108.41
                                                                                                                                                                    ssd.exeGet hashmaliciousAgentTeslaBrowse
                                                                                                                                                                    • 107.178.108.41
                                                                                                                                                                    SqWzv6g2gV.exeGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                    • 104.161.43.18
                                                                                                                                                                    No context
                                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                    C:\Program Files\McAfee\Temp2744101987\installer.exeCanvas of Kings_N6xC-S2.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                      Violated Heroine_91zbZ-1.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                        C:\Program Files\McAfee\Temp2744101987\resource.dllCanvas of Kings_N6xC-S2.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                          Violated Heroine_91zbZ-1.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1873389 bytes, 2 files, at 0x44 +A "\analyticsmanager.dll" +A "\analyticsmanager.manifest", flags 0x4, number 1, extra bytes 20 in head, 167 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1884085
                                                                                                                                                                            Entropy (8bit):7.9996505622372345
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:49152:LlNi5UxPyveWv1Kq0bsw2m0ynXCuTDEU9t3DupTUrhGB/34WSID:BNi58y2qK7CynBTcp2s3pSID
                                                                                                                                                                            MD5:D879D97ACF98B6EC553731A91D9FCD1C
                                                                                                                                                                            SHA1:B001BA483BDB22E75069BE626946C9BE06AEA9F5
                                                                                                                                                                            SHA-256:D5D6D579965CB2E231AF81A2BF60A39A1955EC3782F27D9B1B8177F87B202C94
                                                                                                                                                                            SHA-512:0514F7F80D7D2D05F949621B80166602096130DB5F18C6099C35A0EE18DF8EAAF056557F24DE1D2B7C5C4817056B4CDDDA42231243FA35B64BD1853558FE4236
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF...........D...............................)....................S........YBq .\analyticsmanager.dll.......S....YLq .\analyticsmanager.manifest.i....+..[...3 x...@..$"....ZN..2\X.$.H.....JfBF.VPA..@&l R6...9E..#@.6....D..-.$.Ho...L...`.S.Df..j....y....{u.g9..x...H.3._.&^..!.?..V...sX...S.{V/...j>..Nn.Y.Nv$....c.\.].X..p...p.k...J=..A1.j.` (..|...CHH.b@...........PU.A.9........I.u:.n.h h..bD.......sXK.F0.u.K..^\.....(L.Z....`.f...T;.3...b..j.......m.N.;....m......w.7.In.....o....r.^...n.Y...T.........._>.1.^{..6...)..m...h...T..f.rw^c..uEW.7w}...5I%m..k...?<n...f..6....C.?..?.oV...6.{{..7W...s......k9..I...g5..PG.....\c...m.^..P...TS?.hv.Bz.....w.|.......G.]...k....?vM.,...@.g......Xol.."...{...).t../MY(;..&.....e...q.Z.R.[w.3h=7.|_..;._g.v8k..{l...3~........uK...k;....O=>.C.;....n..Iup..?...0.&.\.r..m...........:F.n...O....1.._..t....g.5Q..{.l....A.....0...}.5.0..xz.L.]U..@..y.:...7..H.....+..n..k......}bbW..6.2..Wo......._..Gcp$.vG....oA...
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 39734 bytes, 56 files, at 0x44 +A "\analyticstelemetry.manifest" +A "\context\analyticscontextconfig.luc", flags 0x4, number 1, extra bytes 20 in head, 4 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):50430
                                                                                                                                                                            Entropy (8bit):7.941471101884989
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:Hd16nLMR3pD1CrhfSYKhdrFo5h3rzmXDQ8nDx7/c9yI46JKwF2PsS2EF:HT6nIhp4rI1diL+D71zhXw7SL
                                                                                                                                                                            MD5:A15CF0E1FEA6C857CD90A27073009053
                                                                                                                                                                            SHA1:0C5735098A552EF00F0E3E406A0D8887F296C7B7
                                                                                                                                                                            SHA-256:63B731A170F3EEC34F4EEDFC1727F9C6343C0AE2F981783873C638F9A8F16EBF
                                                                                                                                                                            SHA-512:851765E13AF4444AF9DDECBF48E4D11A83B8E8494CE6795C97855A90F7F24163F6E4548C4FDE451E45FC1B17BCC54618FCC780B9263D223961E02CAB355E1D9C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:MSCF....6.......D...........8...............6....)..........T.......Z..........YWq .\analyticstelemetry.manifest.....Z......Y.l .\context\analyticscontextconfig.luc.....g......Y.l .\context\analyticswpssetting.luc.....+......Y.l .\context\analyticswsswps.luc.....G$.....Y.l .\context\browserinformation.luc......7.....Y.l .\context\browserversion.luc......;.....Y.l .\context\contexthandler.luc.....d=.....Y.l .\context\externalutilityfunction.luc.J....@.....Y.l .\context\featuretrackingfeature.luc...../^.....Y.l .\context\hashedmachineid.luc......`.....Y.l .\context\msspstatus.luc.O....g.....Y.l .\context\samrecoverable.luc.....7k.....Y.l .\context\sequencenumber.luc.....?m.....Y.l .\context\smarttoasting.luc.R....q.....Y.l .\context\subscriptionexpirydate.luc.R...]s.....Y.l .\context\subscriptionstatus.luc......w.....Y.l .\context\subscriptiontype.luc.Y....y.....Y.l .\context\suitestatus.luc....."}.....Y.l .\context\wpssubscriptionexpirydate.luc.F....~.....Y.l .\context\wpssubscriptionst
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3166
                                                                                                                                                                            Entropy (8bit):7.890916051269147
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:b/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODx7FspC:bSDZ/I09Da01l+gmkyTt6Hk8nT3KC
                                                                                                                                                                            MD5:2048DF489A12C4C9E2341BEF42883205
                                                                                                                                                                            SHA1:281863D9F8B8D4D0DAD62E66E35F5C96CA0155FD
                                                                                                                                                                            SHA-256:DDA74B071B5869A22B327633D9641F1340EC5B913359BB389C34C44A6DB579A5
                                                                                                                                                                            SHA-512:815FC1E3A2E623FEA3B13AA2BCB3895FF9DDB2A7A05E1633C83D3F647EC4A4050AF0670ED01CABA47F02A920BF6AD84191B0B03EAD1E45105DD20D302D00CCE2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR................a....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1302240 bytes, 8 files, at 0x44 +A "\browserhost.exe" +A "\browserhost.manifest", flags 0x4, number 1, extra bytes 20 in head, 121 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1312936
                                                                                                                                                                            Entropy (8bit):7.9996906406741735
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:24576:YKpc0IfBMQK252fl8b2Rd6cTiIYF3wiXNuBERjpvRKxrOoCxX2htEPh3hDr:YK8jK25GKb2R6IYFAeNuqDvKCmDEp3h/
                                                                                                                                                                            MD5:F81CD9F1599139C5DE0CCD3B13285927
                                                                                                                                                                            SHA1:59E7C8CF872C2F781BB1DD8A735E5610535F4C43
                                                                                                                                                                            SHA-256:808E5DFBAF55691037A992E719F1FBF5BF5FB40F8D6440D0706F27D4E7FB9CE2
                                                                                                                                                                            SHA-512:167E42368002C5CF233D4F8A39C3E5FDF0BA952DE024E1AE4951AD2C7F0E989AC615A0A57E006E653A77F971E73C708A8EF6E26C6049BD76096D28B764C4CCD6
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF............D................................)..............y.....;........YLq .\browserhost.exe..-....;....YTq .\browserhost.manifest.f....)<....Y"k .\edge.com.mcafee.webadvisor.json.e....+<....Y"k .\edge.com.mcafee.webadvisor_v2.json......,<....Y"k .\webadvisor.mcafee.chrome.extension.json.L...%/<....Y"k .\webadvisor.mcafee.firefox.extension.json.....q0<....Y"k .\webadvisor_v2.mcafee.chrome.extension.json.K....3<....Y"k .\webadvisor_v2.mcafee.firefox.extension.json.6...~...[...G .C...@..4.....j..Tj}ZYjY.T.X.QE;uF...Q..#..:G..nlwgT.X3*h...5.....F..........v........\..7....Zg..........U.! @........&-s.*..-f....u....58u..j......B3.G...M.Q.R.JS.n*pI........>!..KB...................B5S4VVVE........VlP.<.H9.L.......q..X.Zc+.[.......O.(..q...j...1n.w._;._e..l../.C}op..q.........Q./...w..{.=....[....!.x`...r...on3.U....<......{....F.o.......|.....r...wy..i.\[:...g/.w.~...=V#^....<2.................}O=..../K....v.y.......`.6..a....?.5W.|.i.=......#o.w....q..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 5067323 bytes, 2 files, at 0x44 +A "\browserplugin.manifest" +A "\e10ssaffplg.xpi", flags 0x4, number 1, extra bytes 20 in head, 183 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5078019
                                                                                                                                                                            Entropy (8bit):7.999204670703307
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:98304:rPTtx20xoUoRYyKXJT6me+cU7Zd94YoMVvtvQNUznnFu5U3z:rX+cyKXRbe/U7ZgYNV1vMULFdj
                                                                                                                                                                            MD5:AFA82B1222D9A93CE2EC0279DC025671
                                                                                                                                                                            SHA1:C9297D806D299DA095F9D1979DB9C5B54BAF237F
                                                                                                                                                                            SHA-256:FFA9CE39C49A226732E75BC8B5558FFC9DB3C12A7984FF4D99C9CE5E8BF214B6
                                                                                                                                                                            SHA-512:65B63AD867F922F1053E51420B98B46BB6C5E05FD7A7E01E52F89914E206704D28FACB8C426558290034A212E6FF4B75A68FCE2E1E7D41A97539F96360F1AB5C
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF....;RM.....D...........................;RM..)..................u..........YUq .\browserplugin.manifest.xU[.u......Y.p .\e10ssaffplg.xpi...A.[..[.....pj........*.D..]..qwwwwwpw.P.....\p.].....U.........6j...V..<M^$... .#,.a...OS........Z./O.@..O2..1.....i.)%M[..8p.u.`v7...&.Z.BGy.....A.."......7..$.N.6p.N..3..A...@..(..55...~?.c...l.K.c..LM......-.4..))..!...P..=...,+.....k.CG..+...i'.m+...L.* ...XgbZ^X.\.Ww..._.X\\[.i_.`..[.a.....}jn.......K8X.o....L.........1o.f._&......_.5..:....:k*....b>Z.r...?..f......sOp....L.8j...=...........f........_... .ZfZdd.X."....._...{.O[S.._.....e.[..}9*b..5.,5.......7..V}...Y...Wt(....../.Y...cm...._....5/..I..\:..v....~.6.~.../S......5......q?\..E.......4........'......U...Y.x.~.:..P..w...>..>6..,....1RZ..q.I.23...:;.....Sj]d]`Yffc._#.2......C.........}C.D.......?.n..V..Uf.k]Xn.i......E..L.....MF..}_..G......R....I...;...j.....[.E.....9.ai_q.........`..{o.c.....:........c....>LG...j.g......o.a^....E...G...R.......
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3219
                                                                                                                                                                            Entropy (8bit):7.7127647052020425
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:ek20QaOtG6FvySCYWm8yAxvU+LblYFv2tct:eQQaOwhS8m8yH+flLtct
                                                                                                                                                                            MD5:4A09448B224F83F4E6D36AEC9FF4DA1E
                                                                                                                                                                            SHA1:CC42250CAF610210EFF2904B1A08630A0888AB2F
                                                                                                                                                                            SHA-256:911215D1ADA8D78A33F6ED9A3740A0652BE74EFA34ED22AE569D143F9B3B5040
                                                                                                                                                                            SHA-512:390587FA96D17112CA7EC1ADFE2BA103FE39E980A35A2D4C7A3B6BCF4DE9E95B200DDCEE3C4B6C34899DE51F20F9635D41259558C77CF24279D26264DA953E2B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...d...d.....p.T....tEXtSoftware.Adobe ImageReadyq.e<...(iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c014 79.156797, 2014/08/20-09:53:02 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2014 (Macintosh)" xmpMM:InstanceID="xmp.iid:013EDEF9F71C11E4981AC0D7455F8258" xmpMM:DocumentID="xmp.did:013EDEFAF71C11E4981AC0D7455F8258"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:013EDEF7F71C11E4981AC0D7455F8258" stRef:documentID="xmp.did:013EDEF8F71C11E4981AC0D7455F8258"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>d.8.....IDATx..kL.W.....Z(....h5>J....T,...4U...h.I..&~...`..hc......"h.. X.....m...Q....%...........'..ta.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3390
                                                                                                                                                                            Entropy (8bit):7.74331289225542
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:ek2J8fBtCIc5eJXe1TDiotN45Myx7n6v9+j0ZH:e98fB8vcJqVUtx+9+j0p
                                                                                                                                                                            MD5:AEE9C26A50511C3E4196C28662BCE665
                                                                                                                                                                            SHA1:ADF6DA6EE3EAAD88E8EF1C9C07505AEFFDE89B57
                                                                                                                                                                            SHA-256:0E2904A557F79BCE71A47BFB03E49FA9C5B54C7855017B54143EA2214501BFE6
                                                                                                                                                                            SHA-512:F90AA520FD9308C502B857C4425BF6CF6E12C401EA4B538534E58655448232CF797AA9A9BA60B0932DBAFC28EE925D22BED6740DF82BB02C5C99EF851389F783
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...d...d.....p.T....tEXtSoftware.Adobe ImageReadyq.e<...(iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c014 79.156797, 2014/08/20-09:53:02 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2014 (Macintosh)" xmpMM:InstanceID="xmp.iid:013EDEFDF71C11E4981AC0D7455F8258" xmpMM:DocumentID="xmp.did:013EDEFEF71C11E4981AC0D7455F8258"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:013EDEFBF71C11E4981AC0D7455F8258" stRef:documentID="xmp.did:013EDEFCF71C11E4981AC0D7455F8258"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>..*.....IDATx..klTU...v..--/5.<.J...."F.aD.HQ4..(...j.P.a...?T ..F...........5..... ..jU..Q#.V(.]g...w.g.n.$.m
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 100 x 73, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1511
                                                                                                                                                                            Entropy (8bit):7.072392857408681
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:YQ1hepWwjx82lY2T3JbVvdgqud1oUUyJ3Vnf//XPtGiLBVa470GoqF0ynT6/at8a:YuccNn2Vw7znJ3BvPtnLW5qF0yTUa6fC
                                                                                                                                                                            MD5:4D3A0258CF71A406CB7669FBE3FBEB2E
                                                                                                                                                                            SHA1:0811273369EADF2604DB3C53426F85FE74B785E4
                                                                                                                                                                            SHA-256:C156050A5D788BAD7D8F36482072B44A23F502F23C5F9198F6EB1EB066765DEE
                                                                                                                                                                            SHA-512:837A275BC63DD19F5F8553E056C5EAF257D530A54E0EC386BB28B0A515CA58929E3464612C30D9E7034ACF7473119E03B00EBAB26B220391330FEF12BC087973
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...d...I............tEXtSoftware.Adobe ImageReadyq.e<...(iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c014 79.156797, 2014/08/20-09:53:02 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2014 (Macintosh)" xmpMM:InstanceID="xmp.iid:3EBDD818F71C11E4981AC0D7455F8258" xmpMM:DocumentID="xmp.did:3EBDD819F71C11E4981AC0D7455F8258"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:013EDEFFF71C11E4981AC0D7455F8258" stRef:documentID="xmp.did:013EDF00F71C11E4981AC0D7455F8258"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>..}....UIDATx..K.Q..sj-HT...X..t.Z.P.A$...v...._.-]DAkG....#.B....dr.(..@.*......-y.......<H.......{..^.\NA|h..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3079968
                                                                                                                                                                            Entropy (8bit):6.4924663136231695
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:x4h9JG7wvcPOowb0j5LjY58nbwsMB/KLGVwazuZbQH8:49/cPOoG0j5LjYObU/SKuZi8
                                                                                                                                                                            MD5:9B6FDFBC11B51E810F01598730A002F4
                                                                                                                                                                            SHA1:E93BBC426BE5BA4D4E9A8FE6C59404C9C693223F
                                                                                                                                                                            SHA-256:C9E3EA8126273B9FA2439F674767F420630C46D68C02A9940EE97AAD05C42872
                                                                                                                                                                            SHA-512:9D6E8C635FABDF71E4E0EB694CED5348445B69F7DB0F3DE83348B441DF2B4A24282C56C5E7AC1703060C5A106C28E9F06B71AABECD62DC67EFF944B057B8DA95
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Joe Sandbox View:
                                                                                                                                                                            • Filename: Canvas of Kings_N6xC-S2.exe, Detection: malicious, Browse
                                                                                                                                                                            • Filename: Violated Heroine_91zbZ-1.exe, Detection: malicious, Browse
                                                                                                                                                                            Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$.........&f.{H5.{H5.{H5..K4.{H5..M42{H5O.L4.{H5O.K4.{H5O.M4.{H5,.M4.{H5..M4.{H5..L4.{H5..I4.{H5.{H5.{H5!.L4.{H5.{I5.yH5..A4l{H5..H4.{H5...5.{H5.{.5.{H5..J4.{H5Rich.{H5........................PE..d...TYWg.........."....$............P..........@............................../......./...`.........................................0.".$...T."......@&.8h....$..c...l.. ...../.h2... .p..................... .(....h..@....................."......................text............................... ..`.rdata..............................@..@.data...4.....".......".............@....pdata...c....$..d...f#.............@..@.didat....... &.......$.............@..._RDATA..\....0&.......$.............@..@.rsrc...8h...@&..j....$.............@..@.reloc..h2..../..4...8..............@..B........................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (32132), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):93205
                                                                                                                                                                            Entropy (8bit):5.288377247760317
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:fYcvR3VhH37Ha7EmakRhIHASkCDy08otU6myJXXxMZyYk0AjrzCqlKDo9YhnaTdf:fY8MaW2c+UELKUqnAdiG
                                                                                                                                                                            MD5:A75A7E75DE7E95D0CF44254B591A0EAD
                                                                                                                                                                            SHA1:A495F1544144C935F83A30E025265E3314E19078
                                                                                                                                                                            SHA-256:E88147A2742CA1378EAB2E0E684C0898FE156DDDBCDBE142CBF8A8C1FE25BEB6
                                                                                                                                                                            SHA-512:4CF67506E0C6E6A0D44A9C796092C09D99D834F9A5C94352A87880099BED1CA99086EED502B9604B64753E4BA56C5F15FDD1E47B2AF6CAEF9EA1B7F02A55EE06
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! jQuery v1.9.0 | (c) 2005, 2012 jQuery Foundation, Inc. | jquery.org/license */(function(e,t){"use strict";function n(e){var t=e.length,n=st.type(e);return st.isWindow(e)?!1:1===e.nodeType&&t?!0:"array"===n||"function"!==n&&(0===t||"number"==typeof t&&t>0&&t-1 in e)}function r(e){var t=Tt[e]={};return st.each(e.match(lt)||[],function(e,n){t[n]=!0}),t}function i(e,n,r,i){if(st.acceptData(e)){var o,a,s=st.expando,u="string"==typeof n,l=e.nodeType,c=l?st.cache:e,f=l?e[s]:e[s]&&s;if(f&&c[f]&&(i||c[f].data)||!u||r!==t)return f||(l?e[s]=f=K.pop()||st.guid++:f=s),c[f]||(c[f]={},l||(c[f].toJSON=st.noop)),("object"==typeof n||"function"==typeof n)&&(i?c[f]=st.extend(c[f],n):c[f].data=st.extend(c[f].data,n)),o=c[f],i||(o.data||(o.data={}),o=o.data),r!==t&&(o[st.camelCase(n)]=r),u?(a=o[n],null==a&&(a=o[st.camelCase(n)])):a=o,a}}function o(e,t,n){if(st.acceptData(e)){var r,i,o,a=e.nodeType,u=a?st.cache:e,l=a?e[st.expando]:st.expando;if(u[l]){if(t&&(r=n?u[l]:u[l].data)){st.isArray(t)?t=t.concat(
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2374), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):74892
                                                                                                                                                                            Entropy (8bit):3.8109048145074778
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:MtrgKi7KxT98/9UIBtIFbxb6EFNBRV25JWavzs87n37ebyUDfIjGB:hs91bzNx0JWGsiUDwI
                                                                                                                                                                            MD5:EF03E8660898846DA8DAAE5F63A6D510
                                                                                                                                                                            SHA1:3131A93875E49EBA659D56EC9264DF716FBA7196
                                                                                                                                                                            SHA-256:B2F89F5F2FDCD42E4DABC6967CAB68FCF5B0A9F2DD935F0F8D079D4014CD2430
                                                                                                                                                                            SHA-512:0D2233C2648A7CFA4E977490E0DB00FFA7AA32E2058B66376CB4D5C2EFB40D6BA4CC4D5519C3B76EDBB0AD122B08BD3721EED48C00BCA0046A5EF011F33221FE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..L.i.c.e.n...n... .s.m.l.o.u.v.a. .n.a. .b.e.z.p.e...n.o.s.t.n... .s.o.f.t.w.a.r.e. .I.n.t.e.l.........D...k.u.j.e.m.e. .z.a. .v.y.u.~.i.t... .b.e.z.p.e...n.o.s.t.n...h.o. .s.o.f.t.w.a.r.u. .a. .s.l.u.~.e.b. .s.p.o.l.e...n.o.s.t.i. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n. .(.d...l.e. .j.e.n. .. S.o.f.t.w.a.r.e.. ).,. .k.t.e.r... .p.o.s.k.y.t.u.j.e. .j.e.j... .s.t.o.p.r.o.c.e.n.t.n... .v.l.a.s.t.n...n... .d.c.e.Y.i.n... .s.p.o.l.e...n.o.s.t. .M.c.A.f.e.e... .T.o.t.o. .j.e. .p.r...v.n... .u.j.e.d.n...n... .m.e.z.i. .v...m.i. .a. .n.a.a... .s.p.o.l.e...n.o.s.t..... .I.n.s.t.a.l.a.c... .n.e.b.o. .p.o.u.~.i.t...m. .S.o.f.t.w.a.r.u. .v.y.j.a.d.Y.u.j.e.t.e. .s.o.u.h.l.a.s. .s. .p.o.d.m...n.k.a.m.i. .u.j.e.d.n...n...,. .p.r.o.t.o. .s.i. .j.e. .p.e...l.i.v... .p.Y.e...t...t.e... .........T.a.t.o. .s.m.l.o.u.v.a. .n.a. .b.e.z.p.e...n.o.s.t.n... .S.o.f.t.w.a.r.e. .I.n.t.e.l. .(.d...l.e. .j.e.n. .. S.m.l.o.u.v.a.. ). .u.p.r.a.v.u.j.e. .v.a.a.e. .p.r...v.a. .k. .p.o.u.~.i.t... .S.o.f.t.w.a.r.u.,. .j.e.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2582), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):91776
                                                                                                                                                                            Entropy (8bit):3.4531006440869785
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:nVNCGgfhrLJT5kmiYjC8DZ9p7WmTg5MSItM7Q1cTm/diaa8mwQUIqetIHi7M6X65:nVNCGgfhpTziY2Ol7FtD0aa8mWe9+PL
                                                                                                                                                                            MD5:E7B24B072397487B19385511F573B992
                                                                                                                                                                            SHA1:CD88B156249AAA968CCBC12BF54F5149DA2BAEBA
                                                                                                                                                                            SHA-256:E8013A95BF7632B1F129F7DAEBFF48A742EEFAE9729B2BDD9F2B0920688A4BC0
                                                                                                                                                                            SHA-512:174DCF163649A3355B36A1A8E948EC85588CD29A2B57DE60DA861195EEFAB6909134CE26445160E26088EC2CB9575480154859DE4D7DD32C53D7CD7855CAD0A8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..L.i.c.e.n.s.a.f.t.a.l.e. .f.o.r. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........T.a.k.,. .f.o.r.d.i. .d.u. .b.r.u.g.e.r. .I.n.t.e.l. .S.e.c.u.r.i.t.y.s. .s.o.f.t.w.a.r.e. .o.g. .t.j.e.n.e.s.t.e.r. .(.".S.o.f.t.w.a.r.e.n.".).,. .d.e.r. .l.e.v.e.r.e.s. .a.f. .M.c.A.f.e.e.,. .s.o.m. .e.r. .e.t. .h.e.l.e.j.e.t. .d.a.t.t.e.r.s.e.l.s.k.a.b. .a.f. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .D.e.t.t.e. .e.r. .e.n. .j.u.r.i.d.i.s.k. .a.f.t.a.l.e. .m.e.l.l.e.m. .o.s. .. .i.n.s.t.a.l.l.a.t.i.o.n. .e.l.l.e.r. .o.p.r.e.t.t.e.l.s.e. .a.f. .a.d.g.a.n.g. .t.i.l. .v.o.r.e.s. .S.o.f.t.w.a.r.e. .b.e.t.y.d.e.r.,. .a.t. .d.u. .a.c.c.e.p.t.e.r.e.r. .d.i.s.s.e. .v.i.l.k...r.,. .s... .d.u. .b.e.d.e.s. .l...s.e. .d.e.m. .o.m.h.y.g.g.e.l.i.g.t... .........I. .d.e.n.n.e. .l.i.c.e.n.s.a.f.t.a.l.e. .f.r.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.".A.f.t.a.l.e.n.".). .g.e.n.n.e.m.g...s. .d.i.n.e. .r.e.t.t.i.g.h.e.d.e.r. .t.i.l. .a.t. .b.r.u.g.e. .S.o.f.t.w.a.r.e.n.,. .b.e.g.r...n.s.n.i.n.g.e.r. .f.o.r. .d.e.n.n.e. .b.r.u.g.,. .v.o.r.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (3216), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):104206
                                                                                                                                                                            Entropy (8bit):3.4917892348426625
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:Sw8jufxOksgk9WB2s9JIEwSKjKmDwwy0U6QVMsaXSTLgaP3FGb:FahQVS
                                                                                                                                                                            MD5:2358F282F57F60EEEF57A981D52E34EF
                                                                                                                                                                            SHA1:85F899EC06E3276222EF630715E982522D15CC73
                                                                                                                                                                            SHA-256:C5E6541AB7B449EAC82BA40CBF58BE36DF771636AFB8A377927DDEF846D63A17
                                                                                                                                                                            SHA-512:5482E0D53F82EB52F837F391E1B2D8FD6C7D12CFD67A97BF2DE54EDCF849A7C760DDAE2537B122D8A4EE723349F2E0F1DABC08441A9D38A60F8B5704A760D770
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y. .L.i.z.e.n.z.v.e.r.t.r.a.g.........V.i.e.l.e.n. .D.a.n.k.,. .d.a.s.s. .S.i.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .S.o.f.t.w.a.r.e. .u.n.d. .D.i.e.n.s.t.e. .(.. S.o.f.t.w.a.r.e.. ). .n.u.t.z.e.n.,. .d.i.e. .v.o.n. .M.c.A.f.e.e.,. .e.i.n.e.r. .h.u.n.d.e.r.t.p.r.o.z.e.n.t.i.g.e.n. .T.o.c.h.t.e.r.g.e.s.e.l.l.s.c.h.a.f.t. .v.o.n. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n.,. .b.e.r.e.i.t.g.e.s.t.e.l.l.t. .w.e.r.d.e.n... .D.i.e.s. .i.s.t. .e.i.n. .r.e.c.h.t.s.k.r...f.t.i.g.e.r. .V.e.r.t.r.a.g. .z.w.i.s.c.h.e.n. .u.n.s.. m.i.t. .d.e.r. .I.n.s.t.a.l.l.a.t.i.o.n. .o.d.e.r. .d.e.m. .Z.u.g.r.i.f.f. .a.u.f. .u.n.s.e.r.e. .S.o.f.t.w.a.r.e. .s.t.i.m.m.e.n. .S.i.e. .d.i.e.s.e.n. .B.e.d.i.n.g.u.n.g.e.n. .z.u... .L.e.s.e.n. .S.i.e. .s.i.e. .d.e.s.h.a.l.b. .b.i.t.t.e. .a.u.f.m.e.r.k.s.a.m. .d.u.r.c.h... .........D.i.e.s.e.r. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .L.i.z.e.n.z.v.e.r.t.r.a.g. .(.. V.e.r.t.r.a.g.. ). .u.m.f.a.s.s.t. .I.h.r.e. .R.e.c.h.t.e. .z.u.r. .N.u.t.z.u.n.g. .d.e.r. .S.o.f.t.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2776), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):103714
                                                                                                                                                                            Entropy (8bit):4.054402888023057
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:7NPKnckk7Va7/ZYluLyBO/mw5rMpNVjX7MYeFz8cX:lKB5rMdX4/H
                                                                                                                                                                            MD5:07550B71611D249AD061DC876AB53C6C
                                                                                                                                                                            SHA1:D2C9A88A2830DA9103D20392DFFD2A637586B276
                                                                                                                                                                            SHA-256:F922665E3947D8555D96607A1CAF20A1C3CA650C4A42F518EA9765502FF01062
                                                                                                                                                                            SHA-512:BAAF338E1FE444B38EBB015802D40D3402E541C2C42202A534C59034187A0D7B5C681FB135B732B596CD8679B7900CEDD47882EE2CA605EA76CC5415F7DEDE26
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:................ ............. ............. ..................... ....... ................... .I.n.t.e.l. .S.e.c.u.r.i.t.y............... ......................... ....... ............................. ................... ....... ................... .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. ................... ).,. ....... ............... ... .M.c.A.f.e.e.,. ....... ....................... ..................... ................... ....... .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... ... ............... ................. ....... ............. ................. ............... ..... ......... ....... .......... .. ....................... ... ..................... ....... ..................... ....... ....................... ....... ..................... ..... ......... ................. ...........,. ................. ....... ....................... ..... ......... ................... ....................... ........... ............... ............... ............. ............. .....................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2456), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):85990
                                                                                                                                                                            Entropy (8bit):3.453112144507336
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:/F7Fw4sT8hXmsqSrobeIT6f9BMaR4EYtI7F56:aoK
                                                                                                                                                                            MD5:01BD6FB66DC6D58D2B1722D83FE26440
                                                                                                                                                                            SHA1:B2766FF537D2883630EE3FB148E6A159EFB8383E
                                                                                                                                                                            SHA-256:9A97854186CD17584C9649FEC8B77C2BB059B5ADA7AF9D128092E6EC30A377E5
                                                                                                                                                                            SHA-512:578E5267FFC67F81D8B0782071033C9622CF9D8199B9118FA1CE80CB8D3F0AC101D0D81AF8B0A0B64ADB9A0FB69C7EC237632F0C02200D8655F9C071ADA6129A
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y. .L.i.c.e.n.s.e. .A.g.r.e.e.m.e.n.t.........T.h.a.n.k. .y.o.u. .f.o.r. .u.s.i.n.g. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .s.o.f.t.w.a.r.e. .a.n.d. .s.e.r.v.i.c.e.s. .(.. S.o.f.t.w.a.r.e.. ).,. .p.r.o.v.i.d.e.d. .b.y. .M.c.A.f.e.e.,. .a. .w.h.o.l.l.y. .o.w.n.e.d. .s.u.b.s.i.d.i.a.r.y. .o.f. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .T.h.i.s. .i.s. .a. .l.e.g.a.l. .a.g.r.e.e.m.e.n.t. .b.e.t.w.e.e.n. .u.s.. i.n.s.t.a.l.l.i.n.g. .o.r. .a.c.c.e.s.s.i.n.g. .o.u.r. .S.o.f.t.w.a.r.e. .m.e.a.n.s. .y.o.u. .a.r.e. .a.g.r.e.e.i.n.g. .t.o. .t.h.e.s.e. .t.e.r.m.s.,. .s.o. .p.l.e.a.s.e. .r.e.a.d. .t.h.e.m. .c.a.r.e.f.u.l.l.y... .........T.h.i.s. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .L.i.c.e.n.s.e. .A.g.r.e.e.m.e.n.t. .(.. A.g.r.e.e.m.e.n.t.. ). .c.o.v.e.r.s. .y.o.u.r. .r.i.g.h.t.s. .t.o. .u.s.e. .t.h.e. .S.o.f.t.w.a.r.e.,. .r.e.s.t.r.i.c.t.i.o.n.s. .o.n. .t.h.a.t. .u.s.e.,. .o.u.r. .r.i.g.h.t. .t.o. .a.u.t.o.m.a.t.i.c.a.l.l.y. .r.e.n.e.w. .a.n.d. .c.h.a.r.g.e. .y.o.u. .f.o.r. .p.a.i.d. .v.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2904), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):100834
                                                                                                                                                                            Entropy (8bit):3.4283040020854774
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:JgO+5MfF+qvVWjB19FUUl2whazC7vT/yFjaX5Q9+5SYALxacixm44ri7qYdZ+vQm:Jg/5R9WPzzC3cix5kzYdZ+vQNQOW
                                                                                                                                                                            MD5:EE9BC03D94335360BE94CFE2ED38F2E7
                                                                                                                                                                            SHA1:D79ADFD3CBF5FB2BAA048DCD577FB82B02759F7C
                                                                                                                                                                            SHA-256:2B6CBEA00317FDFF876880A2EB2590A06D79A9EBA05B72A08F7AF674C3441AE0
                                                                                                                                                                            SHA-512:CC65C061A107DF5A19FE3077A31417A75DD6798A17D30CC4CE08DF1724D849538BC8589FF6D561368BEB1B70060AD344DE37D0C4ABC5471CC3BEA1A14D847007
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..A.c.u.e.r.d.o. .d.e. .l.i.c.e.n.c.i.a. .d.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........G.r.a.c.i.a.s. .p.o.r. .u.t.i.l.i.z.a.r. .l.o.s. .s.e.r.v.i.c.i.o.s. .y. .e.l. .s.o.f.t.w.a.r.e. .d.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. S.o.f.t.w.a.r.e.. ).,. .s.u.m.i.n.i.s.t.r.a.d.o.s. .p.o.r. .M.c.A.f.e.e.,. .u.n.a. .f.i.l.i.a.l. .p.a.r.t.i.c.i.p.a.d.a. .p.l.e.n.a.m.e.n.t.e. .p.o.r. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .E.s.t.e. .e.s. .u.n. .a.c.u.e.r.d.o. .l.e.g.a.l. .e.n.t.r.e. .n.o.s.o.t.r.o.s... .A.l. .i.n.s.t.a.l.a.r. .o. .a.c.c.e.d.e.r. .a. .n.u.e.s.t.r.o. .S.o.f.t.w.a.r.e. .i.n.d.i.c.a. .u.s.t.e.d. .q.u.e. .a.c.e.p.t.a. .l.o.s. .p.r.e.s.e.n.t.e.s. .t...r.m.i.n.o.s.,. .p.o.r. .l.o. .t.a.n.t.o.,. .l.e. .r.o.g.a.m.o.s. .q.u.e. .l.o.s. .l.e.a. .c.o.n. .a.t.e.n.c.i...n... .........E.l. .p.r.e.s.e.n.t.e. .A.c.u.e.r.d.o. .d.e. .l.i.c.e.n.c.i.a. .d.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.e.l. . .. A.c.u.e.r.d.o.. ). .e.s.t.a.b.l.e.c.e. .c.u...l.e.s. .s.o.n. .s.u.s. .d.e.r.e.c.h.o.s. .d.e. .u.s.o. .d.e.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2904), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):100834
                                                                                                                                                                            Entropy (8bit):3.428277035149879
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:JgO+5MfF+qvVWjB19FUUl2whazC7vT/yFjaX5Q9+5SYALxacixm44ri7qYdZ+vQH:Jg/5R9WPzzC3cix5kzYdZ+vQNQO3
                                                                                                                                                                            MD5:C3BF812E539D6533C1835F2750E2576E
                                                                                                                                                                            SHA1:DA5D515CAD63E95762BAFFF2610D9E9C80D35EB9
                                                                                                                                                                            SHA-256:F181CA55AF444B171A8360B33A3521AB9118B9F36F944BF687D43EE0563C0C9C
                                                                                                                                                                            SHA-512:26F23774F7D665AEB550C5BFE5FA012FE08CCE2ECD7A6EA246F8A2233FAA7329A1D52F50CD1171089B473BCB49B96858B8CAA90C6E882FB8FB4BA3682BD25747
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..A.c.u.e.r.d.o. .d.e. .l.i.c.e.n.c.i.a. .d.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........G.r.a.c.i.a.s. .p.o.r. .u.t.i.l.i.z.a.r. .l.o.s. .s.e.r.v.i.c.i.o.s. .y. .e.l. .s.o.f.t.w.a.r.e. .d.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. S.o.f.t.w.a.r.e.. ).,. .s.u.m.i.n.i.s.t.r.a.d.o.s. .p.o.r. .M.c.A.f.e.e.,. .u.n.a. .f.i.l.i.a.l. .p.a.r.t.i.c.i.p.a.d.a. .p.l.e.n.a.m.e.n.t.e. .p.o.r. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .E.s.t.e. .e.s. .u.n. .a.c.u.e.r.d.o. .l.e.g.a.l. .e.n.t.r.e. .n.o.s.o.t.r.o.s... .A.l. .i.n.s.t.a.l.a.r. .o. .a.c.c.e.d.e.r. .a. .n.u.e.s.t.r.o. .S.o.f.t.w.a.r.e. .i.n.d.i.c.a. .u.s.t.e.d. .q.u.e. .a.c.e.p.t.a. .l.o.s. .p.r.e.s.e.n.t.e.s. .t...r.m.i.n.o.s.,. .p.o.r. .l.o. .t.a.n.t.o.,. .l.e. .r.o.g.a.m.o.s. .q.u.e. .l.o.s. .l.e.a. .c.o.n. .a.t.e.n.c.i...n... .........E.l. .p.r.e.s.e.n.t.e. .A.c.u.e.r.d.o. .d.e. .l.i.c.e.n.c.i.a. .d.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.e.l. . .. A.c.u.e.r.d.o.. ). .e.s.t.a.b.l.e.c.e. .c.u...l.e.s. .s.o.n. .s.u.s. .d.e.r.e.c.h.o.s. .d.e. .u.s.o. .d.e.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2621), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):90558
                                                                                                                                                                            Entropy (8bit):3.4500679413514117
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:HE2oXLv8VtIG4O4mPf5lC66AlB1Fd+NlLVlbH2ZuWUh/U:Hl4gtI24cf5c6J7l8vWUhc
                                                                                                                                                                            MD5:678A39502230D029CC22AB42787EC4EF
                                                                                                                                                                            SHA1:7314F42A6412DF9ADC98261EBF674C417A9E2437
                                                                                                                                                                            SHA-256:73CCA4EF648544FAF7B4E20B7F54D7D4B2761674D61ADE0CB0943CB98BC22897
                                                                                                                                                                            SHA-512:B00BF94EBFA427A2B669F18F963640E9C6442137BC7647F0EBE75A1D00E2D8D0696A10A49A238962014F17E26E6946861EFB5BD4931D5D6157AEB29EFB4C9C9D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y.n. .k...y.t.t...o.i.k.e.u.s.s.o.p.i.m.u.s.........K.i.i.t.o.s.,. .e.t.t... .v.a.l.i.t.s.i.t. .I.n.t.e.l. .S.e.c.u.r.i.t.y.n. .o.h.j.e.l.m.i.s.t.o.n. .j.a. .p.a.l.v.e.l.u.t. .(.. o.h.j.e.l.m.i.s.t.o.. ).,. .j.o.t.k.a. .t.a.r.j.o.a.a. .M.c.A.f.e.e.,. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n.i.n. .k.o.k.o.n.a.a.n. .o.m.i.s.t.a.m.a. .t.y.t...r.y.h.t.i..... .T...m... .o.n. .l.a.i.l.l.i.n.e.n. .s.o.p.i.m.u.s. .m.e.i.d...n. .j.a. .k...y.t.t...j...n. .v...l.i.l.l..... .A.s.e.n.t.a.m.a.l.l.a. .t.a.i. .k...y.t.t...m...l.l... .o.h.j.e.l.m.i.s.t.o.a.m.m.e. .s.i.t.o.u.d.u.t. .n...i.h.i.n. .e.h.t.o.i.h.i.n.,. .j.o.t.e.n. .o.n. .t...r.k.e.....,. .e.t.t... .l.u.e.t. .n.e. .h.u.o.l.e.l.l.i.s.e.s.t.i... .........T...m... .I.n.t.e.l. .S.e.c.u.r.i.t.y.n. .k...y.t.t...o.i.k.e.u.s.s.o.p.i.m.u.s. .(.. s.o.p.i.m.u.s.. ). .p.i.t..... .s.i.s...l.l.....n. .k...y.t.t...j...n. .o.i.k.e.u.d.e.t. .o.h.j.e.l.m.i.s.t.o.n. .k...y.t.t.....n.,. .t...t... .k...y.t.t..... .k.o.s.k.e.v.a.t. .r.a.j.o.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2833), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):100074
                                                                                                                                                                            Entropy (8bit):3.4570958714075197
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:YUojrJ1ucLHrQIvVQXrsE2Kd6kPu1dTNjOy+psORpT6koBWT7qO6H5U8mSwE9Neu:YwrsE2KdYmfwqjlK2BZVqCChcw0c
                                                                                                                                                                            MD5:11FB5D919E8D4CA8E251B8316C0D9FDD
                                                                                                                                                                            SHA1:844E3895654A12291557A08C0B8EDDEB931CA55B
                                                                                                                                                                            SHA-256:9D13797690BB4B88C62A53CB602249BEBCF6604931241EC7481CB4B132863B11
                                                                                                                                                                            SHA-512:2BC3C24A5F696589A075AB3BA64E823056EA53E1773B1183B4FCF06E5E17A21ED3C521639C29FE8E4F5CA1FD51F8FE496A22A1B84DC7DF34FEF63D6E6825F16A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..C.o.n.t.r.a.t. .d.e. .l.i.c.e.n.c.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........M.e.r.c.i. .d.'.u.t.i.l.i.s.e.r. .l.e. .l.o.g.i.c.i.e.l. .e.t. .l.e.s. .s.e.r.v.i.c.e.s. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.....L.o.g.i.c.i.e.l.....). .f.o.u.r.n.i.s. .p.a.r. .M.c.A.f.e.e.,. .u.n.e. .f.i.l.i.a.l.e. .e.n. .p.r.o.p.r.i...t... .e.x.c.l.u.s.i.v.e. .d.'.I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .L.e. .p.r...s.e.n.t. .d.o.c.u.m.e.n.t. .e.s.t. .u.n. .a.c.c.o.r.d. .j.u.r.i.d.i.q.u.e. .c.o.n.c.l.u. .e.n.t.r.e. .v.o.u.s. .e.t. .n.o.u.s... .E.n. .i.n.s.t.a.l.l.a.n.t. .o.u. .e.n. .a.c.c...d.a.n.t. ... .n.o.t.r.e. .L.o.g.i.c.i.e.l.,. .v.o.u.s. .a.c.c.e.p.t.e.z. .l.e.s. .p.r...s.e.n.t.e.s. .c.o.n.d.i.t.i.o.n.s... .V.e.u.i.l.l.e.z. .d.o.n.c. .l.e.s. .l.i.r.e. .a.t.t.e.n.t.i.v.e.m.e.n.t... .........L.e. .p.r...s.e.n.t. .C.o.n.t.r.a.t. .d.e. .L.i.c.e.n.c.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.....C.o.n.t.r.a.t.....). .p.o.r.t.e. .s.u.r. .v.o.s. .d.r.o.i.t.s. .d.'.u.t.i.l.i.s.e.r. .l.e. .L.o.g.i.c.i.e.l.,. .l.e.s. .r.e.s.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2833), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):100074
                                                                                                                                                                            Entropy (8bit):3.4566889314561657
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:YUojrJ1ucLHrQIvVQXrsE2Kd6kPu1dTNjOy+psORpT6koBWT7qO6H5U8mSwE9Nec:YwrsE2KdYmfwqjlK2BZVqCChcw0a
                                                                                                                                                                            MD5:32C0E5CC752C2F76FF6AA79B9D7E4F58
                                                                                                                                                                            SHA1:A4C7E48D029A4951B43D2948B20A8B12FFCF619F
                                                                                                                                                                            SHA-256:B003840DF4B91DD867552137E01BE0BD601EAAFB74E9974F83144FDC9EE9BF0C
                                                                                                                                                                            SHA-512:B1F61FF518D1A972574E9FD2AC763BF82BEB985AACA7661164AFCB28AF75709F539A837A8A7347F677FCEBC034EB96498E7F1A121967A8D5A0F807683618A2C5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..C.o.n.t.r.a.t. .d.e. .l.i.c.e.n.c.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........M.e.r.c.i. .d.'.u.t.i.l.i.s.e.r. .l.e. .l.o.g.i.c.i.e.l. .e.t. .l.e.s. .s.e.r.v.i.c.e.s. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.....L.o.g.i.c.i.e.l.....). .f.o.u.r.n.i.s. .p.a.r. .M.c.A.f.e.e.,. .u.n.e. .f.i.l.i.a.l.e. .e.n. .p.r.o.p.r.i...t... .e.x.c.l.u.s.i.v.e. .d.'.I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .L.e. .p.r...s.e.n.t. .d.o.c.u.m.e.n.t. .e.s.t. .u.n. .a.c.c.o.r.d. .j.u.r.i.d.i.q.u.e. .c.o.n.c.l.u. .e.n.t.r.e. .v.o.u.s. .e.t. .n.o.u.s... .E.n. .i.n.s.t.a.l.l.a.n.t. .o.u. .e.n. .a.c.c...d.a.n.t. ... .n.o.t.r.e. .L.o.g.i.c.i.e.l.,. .v.o.u.s. .a.c.c.e.p.t.e.z. .l.e.s. .p.r...s.e.n.t.e.s. .c.o.n.d.i.t.i.o.n.s... .V.e.u.i.l.l.e.z. .d.o.n.c. .l.e.s. .l.i.r.e. .a.t.t.e.n.t.i.v.e.m.e.n.t... .........L.e. .p.r...s.e.n.t. .C.o.n.t.r.a.t. .d.e. .L.i.c.e.n.c.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.....C.o.n.t.r.a.t.....). .p.o.r.t.e. .s.u.r. .v.o.s. .d.r.o.i.t.s. .d.'.u.t.i.l.i.s.e.r. .l.e. .L.o.g.i.c.i.e.l.,. .l.e.s. .r.e.s.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2677), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):87744
                                                                                                                                                                            Entropy (8bit):3.5874191528402934
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:4D5AY14mQom+cQuoy8H5Zo3ij63ydrXxYM+gDUC5lBvt4UgmsiyePIOA:3jelDB1vm
                                                                                                                                                                            MD5:5CC370E61A37DF91B7D6C966805A5926
                                                                                                                                                                            SHA1:8CE489F5074986D14A1735B7D276265A61BAAAF2
                                                                                                                                                                            SHA-256:82C092D77335642F2968FA74C0F50079EC2A2A81A3E3A8A0636C1219DCC10FD7
                                                                                                                                                                            SHA-512:4CDB0FF15716FF82843CC0AC6F3DC2F07C16EEBC62E1377F6F951211F0984A98322F8F71824F6C859C1D4D779A11D947A2784454B8D12CF7EC2297E5415CBDBB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..L.i.c.e.n.c.n.i. .u.g.o.v.o.r. .z.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........H.v.a.l.a. .a.t.o. .k.o.r.i.s.t.i.t.e. .s.o.f.t.v.e.r. .i. .u.s.l.u.g.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.".S.o.f.t.v.e.r.".).,. .k.o.j.i. .i.s.p.o.r.u...u.j.e. .M.c.A.f.e.e.,. .p.o.d.r.u.~.n.i.c.a. .u. .p.o.t.p.u.n.o.m. .v.l.a.s.n.i.a.t.v.u. .t.v.r.t.k.e. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .O.v.o. .j.e. .p.r.a.v.n.i. .u.g.o.v.o.r. .i.z.m.e...u. .n.a.s.. i.n.s.t.a.l.i.r.a.n.j.e. .i.l.i. .p.r.i.s.t.u.p. .n.a.a.e.m. .S.o.f.t.v.e.r.u. .z.n.a...i. .d.a. .s.e. .s.l.a.~.e.t.e. .s. .n.j.e.g.o.v.i.m. .u.v.j.e.t.i.m.a.,. .p.a. .v.a.s. .m.o.l.i.m.o. .d.a. .i.h. .p.a.~.l.j.i.v.o. .p.r.o...i.t.a.t.e... .........O.v.a.j. .L.i.c.e.n.c.n.i. .u.g.o.v.o.r. .z.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.".U.g.o.v.o.r.".). .o.b.u.h.v.a...a. .v.a.a.e. .p.r.a.v.o. .n.a. .k.o.r.i.a.t.e.n.j.e. .S.o.f.t.v.e.r.a.,. .o.g.r.a.n.i...e.n.j.a. .u. .n.j.e.g.o.v.o.m. .k.o.r.i.a.t.e.n.j.u.,. .n.a.a.e. .p.r.a.v.o. .n.a. .a.u.t.o.m.a.t.s.k.o. .o.b.n.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2782), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):98690
                                                                                                                                                                            Entropy (8bit):3.685619337213005
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:3+Y5qMxXdv62/0ojFC0hQY+eUbM5wbg6u+sWOvm1SeWN3CBw4bZKMoBwAbCxpI1t:zsGDmMeI
                                                                                                                                                                            MD5:747D979803169F76FFB0694E906515EC
                                                                                                                                                                            SHA1:88615D66D8601DBB4F647BBEF9F33BC09F139CB8
                                                                                                                                                                            SHA-256:4DD8DEEA7EF8DB214D5C9E8A524EE0FD1BEF58937623945BB17DE69CD8C4125A
                                                                                                                                                                            SHA-512:3F33985624C3FF4989A9C37350EFFD4E07CF70195F4F462E4359EF3215DECFE1DF0772ECE2201EA620BE3B5CA1650F87D2F10CA08BA9926F799BDC77324DB3BE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y. .l.i.c.e.n.c.s.z.e.r.z.Q.d...s.........K...s.z...n.j...k.,. .h.o.g.y. .a.z. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n. .t.e.l.j.e.s. .t.u.l.a.j.d.o.n... .l.e...n.y.v...l.l.a.l.a.t.a.,. .a. .M.c.A.f.e.e. ...l.t.a.l. .k...n...l.t. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .s.z.o.f.t.v.e.r.t. ...s. .s.z.o.l.g...l.t.a.t...s.o.k.a.t. .(.. S.z.o.f.t.v.e.r.. ). .h.a.s.z.n...l.j.a... .E.z. .a. .l.i.c.e.n.c.s.z.e.r.z.Q.d...s. .e.g.y. .k...z...t.t...n.k. .l...t.r.e.j...t.t. .j.o.g.i. .m.e.g...l.l.a.p.o.d...s. .. .a. .S.z.o.f.t.v.e.r...n.k. .t.e.l.e.p...t...s.e. .v.a.g.y. .a. .S.z.o.f.t.v.e.r...n.k.h...z. .v.a.l... .h.o.z.z...f...r...s. .a.z.t. .j.e.l.e.n.t.i.,. .h.o.g.y. ...n. .e.g.y.e.t...r.t. .a. .s.z.e.r.z.Q.d...s.b.e.n. .f.o.g.l.a.l.t. .f.e.l.t...t.e.l.e.k.k.e.l.,. .e.z...r.t. .o.l.v.a.s.s.a. .e.l. .f.i.g.y.e.l.m.e.s.e.n. .a.z.o.k.a.t... .........A.z. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .l.i.c.e.n.c.s.z.e.r.z.Q.d...s. .(.. S.z.e.r.z.Q.d...s.. ). .a. .S.z.o.f.t.v.e.r. .h.a.s.z.n...l.a.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2974), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):103642
                                                                                                                                                                            Entropy (8bit):3.410756917907654
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:D+piF3I9T9qL1rEINLBC7LcfZJJSMqHDYCebssNKlU8rmjVHJkItVdM1OrzjW:6/c16yjdM1OS
                                                                                                                                                                            MD5:D9AFC6FA5E620BA21FC7AAE5EEA075A1
                                                                                                                                                                            SHA1:722FAFD586D555E67868847BE2D590728211F968
                                                                                                                                                                            SHA-256:D87E62812B503E53398140F0FA7F334647D1F44AE8A7BA8F070FC783F1BA9730
                                                                                                                                                                            SHA-512:4537A9755CB3B960EECA97E7E3DD415E206628E1426563F982EE7FF957B1784F4FFEA825635447F43F6043E1FADD7B8643F3FB7ADBB7B95B80E86D35986866D4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..C.o.n.t.r.a.t.t.o. .d.i. .l.i.c.e.n.z.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........G.r.a.z.i.e. .p.e.r. .a.v.e.r. .s.c.e.l.t.o. .d.i. .u.t.i.l.i.z.z.a.r.e. .i. .s.o.f.t.w.a.r.e. .e. .i. .s.e.r.v.i.z.i. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.".S.o.f.t.w.a.r.e.".). .f.o.r.n.i.t.i. .d.a. .M.c.A.f.e.e.,. .c.o.n.s.o.c.i.a.t.a. .i.n.t.e.r.a.m.e.n.t.e. .c.o.n.t.r.o.l.l.a.t.a. .d.i. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .I.l. .p.r.e.s.e.n.t.e. .d.o.c.u.m.e.n.t.o. .c.o.s.t.i.t.u.i.s.c.e. .u.n. .c.o.n.t.r.a.t.t.o. .l.e.g.a.l.e. .t.r.a. .n.o.i. .e. .l.'.u.t.e.n.t.e... .L.'.i.n.s.t.a.l.l.a.z.i.o.n.e. .o. .l.'.a.c.c.e.s.s.o. .a.i. .n.o.s.t.r.i. .S.o.f.t.w.a.r.e. .i.m.p.l.i.c.a. .l.'.a.c.c.e.t.t.a.z.i.o.n.e. .d.i. .q.u.e.s.t.i. .t.e.r.m.i.n.i. .d.a. .p.a.r.t.e. .d.e.l.l.'.u.t.e.n.t.e.,. .c.h.e. .p.e.r.t.a.n.t.o. ... .t.e.n.u.t.o. .a. .l.e.g.g.e.r.l.i. .c.o.n. .a.t.t.e.n.z.i.o.n.e... .........I.l. .p.r.e.s.e.n.t.e. .c.o.n.t.r.a.t.t.o. .d.i. .l.i.c.e.n.z.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.".C.o.n.t.r.a.t.t.o.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (1234), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):41412
                                                                                                                                                                            Entropy (8bit):5.772085659974916
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:8bY257pwJE0xJUhghf/3Gkojyef4ktbfR/KSCDpKIb5MhON:8E257OJE0ighfSyKtbfxapV
                                                                                                                                                                            MD5:98E639EF30DAC59ECA90EEB00D0E43E6
                                                                                                                                                                            SHA1:31AC8D540EA3A0202797CB3B3B370128B4D17D81
                                                                                                                                                                            SHA-256:CC3A2E0426012943EB51B2A2568F06F0273F0CE5403ACA4A906278186126E5A9
                                                                                                                                                                            SHA-512:29201C2D4A8E465BB045FF8F415BC43834B4E6D55C3A561B2039580291B21472F54A092E551F8A2DA2B7EBF7EA65CDED46993BF287B6D89E1BE0CEB801E61E51
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y. ..O(u1...QY.}........I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n. .n0hQM..Q.P[.O>yg0B0.0 .M.c.A.f.e.e.L0.c.OY0.0 .I.n.t.e.l. .S.e.c.u.r.i.t.y. ..0.0.0.0.0.0J0.0s0.0.0.0.0...0.0.0.0.0.0.0.0...0)R(uD0_0`0M0B0.0L0h0F0T0V0D0~0Y0.0 .,gQY.}o0J0.[.ih0S_>yh0n0..k0.}P}U0.0.0.l.vj0QY.}g0Y0.0J0.[.io0.0S_>yn0.0.0.0.0.0.0.0.0.0.0.0.0.0~0_0o0]0.0k0.0.0.0.0Y0.0S0h0k0.0.0.0,gQY.}n0ag.Nk0.T.aW0_0h0.0j0U0.0~0Y0n0g0.0,gQY.}.0.0O0J0...0O0`0U0D0.0 .........S0n0 .I.n.t.e.l. .S.e.c.u.r.i.t.y. ..O(u1...QY.}.f...0,gQY.}.0..o0.0J0.[.in0.0.0.0.0.0.0.O(u)j.0.O(u6RP..0.0.0.0.0.0.0n0.g.Q.0.0.0.0.0~0_0o0_j...0..R.vk0.f.eJ0.0s0...Y0.0S_>yn0)j)R.0J0.0s0S_>yh0J0.[.in0..k0zv.uY0.0.S..'`n0B0.0.}.Nn0.N..k0.[Y0.0J0.[.in0.T.ak0d0D0f0....W0f0D0~0Y0.0 ....j0.0,gQY.}h0h0.0k0J0.[.ik0i.(uU0.0.0.0S_>yn0.0.0.0.0.0.0k0..Y0.0.X.f..h.t.t.p.s.:././.w.w.w...m.c.a.f.e.e...c.o.m./.c.o.m.m.o.n./.p.r.i.v.a.c.y./.j.a.p.a.n.e.s.e./.i.n.d.e.x...h.t.m....0+T.0...Rag.Nx0n0.0.0.0L0+T~0.0f0D0~0Y0.0 ..T.Vyr.gn0ag.No0,gQY.}
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (1439), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):46328
                                                                                                                                                                            Entropy (8bit):5.58543674296238
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:iLBTRAz/+e7qDm/7QgTt2Bk6baOLFureI5mIxFRlKi3lu:iLnAz/+e+DmzQgZ2BdblJsSi3lu
                                                                                                                                                                            MD5:F890FFDF8BBEB7A877F1DA8978AFC5CB
                                                                                                                                                                            SHA1:1920F72796976EB486C3AB9B2BBA34530DE4CC84
                                                                                                                                                                            SHA-256:6522E4325DBA7429F941B435FDC5F79281582D4F04BF13C3708ECA24385A7F96
                                                                                                                                                                            SHA-512:50EA45A40A907FE41FF0F15AB1A36311053C76703E0AB07407FB6554954F2A7F96363E8FB46DBD6E401D9F6B7D03175016243C0C0D54BA86A241844EB8289FE7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y. .|.t. ... ..}.........I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n.X. ...a. .... .....x. .M.c.A.f.e.e..... .....X.. .I.n.t.e.l. .S.e.c.u.r.i.t.y. ......... ... ...D...(.t.X. .. ......... ).|. .....t. ...T... .....i..... .t..@. .....@. ...... ...t.X. ..... ..}...... .....X. .........|. .$.X.X.p... .a.8...X.. ...@. .t. ..}. .}..... ..X.X.. ...t...\.,. .}...D. ...X. .J... .}.<...0. ......... .........t. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .|.t. ... ..}.(.t.X. .. .}.. ).@. ......... ..... .....,. ......... .....X. ...\. .p.t.,. .........X. . .. .....t.. .0..... ...t. ....<.\. ..}.D. .1...X.. ......... ...a.D. ...l.`. ... .... .....X. .....,. ...... .....@. ...... ...t... .....`. ... .... .....X. ...... ...\. ...X.X. ..X. .....D. ........ .t. .8...... ...X.... ........ .t. ..... ..}.D. .l.1.X.. .\. .....x. ....\. ..... ..}. .}...(...:. ...x.......8. .H..8.,. .(.h.t.t.p.s.:././.w.w.w...m.c.a.f.e.e...c.o.m./.c.o.m.m.o.n./.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2743), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):84476
                                                                                                                                                                            Entropy (8bit):3.446843354798183
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:fvk22xFWKEjm1iM70NJnqNiGAsX0MRKQ/s+p6jdIuRMPNGZJq7ALa/jcuqqRp5QV:fvk22xFWKEjm1iM70NJnqNiGAsX0MRKL
                                                                                                                                                                            MD5:0FC2D0F93151C10CE5332B318B34749B
                                                                                                                                                                            SHA1:0CE5DA03AC3F9833A04C528510AA7E93308E9832
                                                                                                                                                                            SHA-256:84BA9DE6406BE526CA526BAF01EC1A4704AD65333AA15873418455CAC7DB77D7
                                                                                                                                                                            SHA-512:88F023C2A1DE1647BB64D48EDD5E57C245A183701B750BF6868EA844F1B26EB93877F66A07F798049D3A67C02B5223ABD6C2B853980F58542E744C7D4C910D80
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..L.i.s.e.n.s.a.v.t.a.l.e. .f.o.r. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........T.a.k.k. .f.o.r. .a.t. .d.u. .b.r.u.k.e.r. .I.n.t.e.l. .S.e.c.u.r.i.t.y.s. .p.r.o.g.r.a.m.v.a.r.e. .o.g. .t.j.e.n.e.s.t.e.r. .(.".p.r.o.g.r.a.m.m.e.t.).,. .l.e.v.e.r.t. .a.v. .M.c.A.f.e.e.,. .e.t. .h.e.l.e.i.d. .d.a.t.t.e.r.s.e.l.s.k.a.p. .a.v. .I.n.t.e.r. .C.o.r.p.o.r.a.t.i.o.n... .D.e.t.t.e. .e.r. .e.n. .j.u.r.i.d.i.s.k. .a.v.t.a.l.e. .m.e.l.l.o.m. .o.s.s. .. .i.n.s.t.a.l.l.a.s.j.o.n. .e.l.l.e.r. .b.r.u.k. .a.v. .v...r. .p.r.o.g.r.a.m.v.a.r.e. .b.e.t.y.r. .a.t. .d.u. .g.o.d.t.a.r. .d.i.s.s.e. .v.i.l.k...r.e.n.e.,. .s... .l.e.s. .d.e.m. .n...y.e... .........D.e.n.n.e. .l.i.s.e.n.s.a.v.t.a.l.e.n. .f.o.r. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.".a.v.t.a.l.e.n.".). .d.e.k.k.e.r. .d.i.n. .r.e.t.t. .t.i.l. ... .b.e.n.y.t.t.e. .p.r.o.g.r.a.m.v.a.r.e.n.,. .b.e.g.r.e.n.s.n.i.n.g.e.r. .p... .d.e.n.n.e. .b.r.u.k.e.n.,. .v...r. .r.e.t.t. .t.i.l. .a.u.t.o.m.a.t.i.s.k. .f.o.r.n.y.e.l.s.e. .o.g. .t.a. .b.e.t.a.l.t. .f.o.r. .b.e.t.a.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2801), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):100578
                                                                                                                                                                            Entropy (8bit):3.442006366072733
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:OQ/9KbnOOfNlk/R5OVUR5Oh/RKe/HEUnOZVOsf6jzytJpjIzGeQRV22n3sT58jQM:B
                                                                                                                                                                            MD5:8F101B5AF8CB0A1F5783173B125DCD47
                                                                                                                                                                            SHA1:6CD517E2565B326CCBD900C67D668EA2D2D899A4
                                                                                                                                                                            SHA-256:CB5A555248A9C01D9C9967790CDD7F616D147E1C1E7B737F13641F5E2842AE1B
                                                                                                                                                                            SHA-512:D08432ACB958D5CC878819C00DEFF27E02EEE3A48F544DC7A097AD98D64C11DB3AB2C79831D546900EF9BAF4B121722330D1AA31AE8A2D9887B399BCE0425CBD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..L.i.c.e.n.t.i.e.o.v.e.r.e.e.n.k.o.m.s.t. .v.a.n. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........D.a.n.k. .u. .v.o.o.r. .h.e.t. .g.e.b.r.u.i.k. .v.a.n. .I.n.t.e.l. .S.e.c.u.r.i.t.y.-.s.o.f.t.w.a.r.e. .e.n. .-.d.i.e.n.s.t.e.n. .(.'.S.o.f.t.w.a.r.e.'.).,. .a.a.n.g.e.b.o.d.e.n. .d.o.o.r. .M.c.A.f.e.e.,. .e.e.n. .v.o.l.l.e.d.i.g.e. .d.o.c.h.t.e.r.o.n.d.e.r.n.e.m.i.n.g. .v.a.n. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .D.i.t. .i.s. .e.e.n. .j.u.r.i.d.i.s.c.h.e. .o.v.e.r.e.e.n.k.o.m.s.t. .t.u.s.s.e.n. .o.n.s... .D.o.o.r. .o.n.z.e. .S.o.f.t.w.a.r.e. .t.e. .i.n.s.t.a.l.l.e.r.e.n. .e.n. .t.e. .o.p.e.n.e.n.,. .g.e.e.f.t. .u. .a.a.n. .d.a.t. .u. .a.k.k.o.o.r.d. .g.a.a.t. .m.e.t. .d.e.z.e. .v.o.o.r.w.a.a.r.d.e.n... .L.e.e.s. .z.e. .d.u.s. .z.o.r.g.v.u.l.d.i.g... .........D.e.z.e. .L.i.c.e.n.t.i.e.o.v.e.r.e.e.n.k.o.m.s.t. .v.a.n. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.'.O.v.e.r.e.e.n.k.o.m.s.t.'.). .b.e.s.c.h.r.i.j.f.t. .u.w. .r.e.c.h.t.e.n. .o.m. .d.e. .S.o.f.t.w.a.r.e. .t.e. .g.e.b.r.u.i.k.e.n.,. .d.e. .b.e.p.e.r.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2967), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):101850
                                                                                                                                                                            Entropy (8bit):3.7337427670871493
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:dnEmLzXswPaPfzO8liJQIKQ42HzLMH7scwS3/80GIrKQ+Qp:ayXeV
                                                                                                                                                                            MD5:DD278C4F855195B67D66D697BDB8F909
                                                                                                                                                                            SHA1:F00413B9D2D51C36524011D43AFC93B4813AB4F5
                                                                                                                                                                            SHA-256:07420FBC165BB9E0D85C9B4634185DB361A6AEA7A2921A204A453F9446A24ACF
                                                                                                                                                                            SHA-512:01959DB09243CD80FA821E9808BE2386B63FA09DE7E8416CD4B2C8558CD3511309E1CAF7AC3D9ECD6550A66E5BC5DE9BFA990B12055F2E9885095C2F8F0743B8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..U.m.o.w.a. .l.i.c.e.n.c.y.j.n.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........D.z.i...k.u.j.e.m.y. .z.a. .k.o.r.z.y.s.t.a.n.i.e. .z. .o.p.r.o.g.r.a.m.o.w.a.n.i.a. .i. .u.s.B.u.g. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.z.w.a.n.y.c.h. .d.a.l.e.j. .. O.p.r.o.g.r.a.m.o.w.a.n.i.e.m.. ). .o.f.e.r.o.w.a.n.y.c.h. .p.r.z.e.z. .M.c.A.f.e.e.,. .s.p...B.k... .z.a.l.e.|.n...,. .k.t...r.e.j. .w.y.B...c.z.n.y.m. .w.B.a.[.c.i.c.i.e.l.e.m. .j.e.s.t. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .N.i.n.i.e.j.s.z.y. .d.o.k.u.m.e.n.t. .s.t.a.n.o.w.i. .u.m.o.w... .p.r.a.w.n... .m.i...d.z.y. .n.a.m.i. .a. .U.|.y.t.k.o.w.n.i.k.i.e.m. .. .z.a.i.n.s.t.a.l.o.w.a.n.i.e. .n.a.s.z.e.g.o. .O.p.r.o.g.r.a.m.o.w.a.n.i.a. .l.u.b. .u.z.y.s.k.a.n.i.e. .d.o. .n.i.e.g.o. .d.o.s.t...p.u. .j.e.s.t. .r...w.n.o.z.n.a.c.z.n.e. .z. .z.a.a.k.c.e.p.t.o.w.a.n.i.e.m. .n.i.n.i.e.j.s.z.y.c.h. .w.a.r.u.n.k...w.,. .w. .z.w.i...z.k.u. .z. .c.z.y.m. .p.r.o.s.i.m.y. .o. .u.w.a.|.n.e. .z.a.p.o.z.n.a.n.i.e. .s.i... .z. .t.r.e.[.c.i... .d.o.k.u.m.e.n.t.u... ...
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2603), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):91306
                                                                                                                                                                            Entropy (8bit):3.4652957363909573
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:f8Wc1lp2b6cXQJ6rHcTCGXPF3zzhTOJpy0WlLyd5S+tKIbTw3ZurbNlar+wHmCY8:f7HceS+3bTrb/R6mdyZ
                                                                                                                                                                            MD5:53E6AB1DBC04F90855A804EB0FDE8BD6
                                                                                                                                                                            SHA1:670903185FE8323A590E521B37CF053FB493DD2D
                                                                                                                                                                            SHA-256:DF12D8D8C608B9C97637F8B40D34AAE67B828A6647DC96D866921EA2A8FEE557
                                                                                                                                                                            SHA-512:3917E69341F37DA4F56772CC0CB1B9B0A5507B3A147036081CD474887442DEFE25AB2972C1E21142F16EADFB29D0F9F72053EF532CC54410ED6552F1E4DA5F7C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..C.o.n.t.r.a.t.o. .d.e. .L.i.c.e.n...a. .d.o. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........A.g.r.a.d.e.c.e.m.o.s. .p.o.r. .u.t.i.l.i.z.a.r. .o. .s.o.f.t.w.a.r.e. .e. .o.s. .s.e.r.v.i...o.s. .d.o. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.".S.o.f.t.w.a.r.e.".).,. .f.o.r.n.e.c.i.d.o. .p.e.l.a. .M.c.A.f.e.e.,. .u.m.a. .s.u.b.s.i.d.i...r.i.a. .i.n.t.e.g.r.a.l. .d.a. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .E.s.t.e. ... .u.m. .c.o.n.t.r.a.t.o. .l.e.g.a.l. .e.n.t.r.e. .n...s.:. .a.o. .i.n.s.t.a.l.a.r. .o.u. .a.c.e.s.s.a.r. .n.o.s.s.o. .S.o.f.t.w.a.r.e.,. .s.i.g.n.i.f.i.c.a. .a. .s.u.a. .c.o.n.c.o.r.d...n.c.i.a. .c.o.m. .e.s.t.e.s. .t.e.r.m.o.s.,. .d.e. .f.o.r.m.a. .q.u.e. .v.o.c... .d.e.v.e. .l...-.l.o.s. .c.o.m. .a. .m...x.i.m.a. .a.t.e.n.....o... .........E.s.t.e. .C.o.n.t.r.a.t.o. .d.e. .L.i.c.e.n...a. .d.o. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.".C.o.n.t.r.a.t.o.".). .c.o.b.r.e. .s.e.u.s. .d.i.r.e.i.t.o.s. .d.e. .u.t.i.l.i.z.a.....o. .d.o. .S.o.f.t.w.a.r.e.,. .r.e.s.t.r.i.....e.s. .a. .e.s.s.e. .u.s.o.,. .o. .
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2536), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):96486
                                                                                                                                                                            Entropy (8bit):3.474385310343869
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:GfDawY1TqufUqhbQGb0jiATGoeQmiBKTVIsFdf:2DetR
                                                                                                                                                                            MD5:95C81C2F7BE9EC7FB3AFBFDFF70D14B3
                                                                                                                                                                            SHA1:A50B146F43C5E0F716B0E40D5F21BBDCD70C4E27
                                                                                                                                                                            SHA-256:9E74B00324D9A91001B43D72EC2BD8C8D3310200B201A8155FABF20CA91BCF7C
                                                                                                                                                                            SHA-512:42E9DC893BEB007184B0BAC34108AD7D8EA04CE155093195CB56FF6CF52FE9364109ABBD2A9FF820CCE673FE73F86B577499C89B798AC889CD4CE76B1FB45A2E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..C.o.n.t.r.a.t.o. .d.e. .L.i.c.e.n...a. .d.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........O.b.r.i.g.a.d.o. .p.o.r. .u.t.i.l.i.z.a.r. .o. .s.o.f.t.w.a.r.e. .e. .o.s. .s.e.r.v.i...o.s. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. S.o.f.t.w.a.r.e.. ). .f.o.r.n.e.c.i.d.o.s. .p.e.l.a. .M.c.A.f.e.e.,. .u.m.a. .s.u.b.s.i.d.i...r.i.a. .t.o.t.a.l.m.e.n.t.e. .d.e.t.i.d.a. .p.e.l.a. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .E.s.t.e. .d.o.c.u.m.e.n.t.o. .c.o.n.s.i.s.t.e. .n.u.m. .c.o.n.t.r.a.t.o. .l.e.g.a.l. .e.n.t.r.e. .a.m.b.a.s. .a.s. .p.a.r.t.e.s.. a.o. .i.n.s.t.a.l.a.r. .o.u. .a.o. .a.c.e.d.e.r. .a.o. .n.o.s.s.o. .S.o.f.t.w.a.r.e. .e.s.t... .a. .c.o.n.c.o.r.d.a.r. .c.o.m. .o.s. .p.r.e.s.e.n.t.e.s. .t.e.r.m.o.s.,. .p.o.r. .i.s.s.o.,. .l.e.i.a.-.o.s. .a.t.e.n.t.a.m.e.n.t.e... .........O. .p.r.e.s.e.n.t.e. .C.o.n.t.r.a.t.o. .d.e. .L.i.c.e.n...a. .d.o. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. C.o.n.t.r.a.t.o.. ). .i.n.c.l.u.i. .o.s. .s.e.u.s. .d.i.r.e.i.t.o.s. .d.e. .u.t.i.l.i.z.a.....o. .d.o. .S.o.f.t.w.a.r.e.,. .r.e.s.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2934), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):105274
                                                                                                                                                                            Entropy (8bit):3.9253511414203475
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:Zrlkl/OV57V/gTNKukdeCNCaM2sJCX7Zh7Ft7yvFsknxFFNZ6AJTaFkke2bnMBqV:JfRpOEZhc8LSQ0PnmEw
                                                                                                                                                                            MD5:6C84B834B887139049C5504670366472
                                                                                                                                                                            SHA1:25BBF94DFD8C58DB8B5BF7B4FECDB71C9FBC5FDF
                                                                                                                                                                            SHA-256:AA6A72816341C265F4A0EA77349E16AB8BDCADCD94DEAFA2D3DE6B36EB0B7CD9
                                                                                                                                                                            SHA-512:224CD295FCA574AFAA21233BE5488F35C8F509D608E0A3F87B9A8E1B62F740CDCC248855102D1F04E51136E1C6A227466DA2DC7064CFF7C0DD8065F639F24C53
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:....8.F.5.=.7.8.>.=.=.>.5. .A.>.3.;.0.H.5.=.8.5. .4.;.O. .?.@.>.3.@.0.<.<.=.>.3.>. .>.1.5.A.?.5.G.5.=.8.O. .I.n.t.e.l. .S.e.c.u.r.i.t.y...........;.0.3.>.4.0.@.8.<. ...0.A. .7.0. .8.A.?.>.;.L.7.>.2.0.=.8.5. .?.@.>.3.@.0.<.<.=.>.3.>. .>.1.5.A.?.5.G.5.=.8.O. .8. .A.;.C.6.1. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(."...@.>.3.@.0.<.<.=.>.5. .>.1.5.A.?.5.G.5.=.8.5.".).,. .?.@.5.4.>.A.B.0.2.;.O.5.<.K.E. .:.>.<.?.0.=.8.5.9. .M.c.A.f.e.e. .. .4.>.G.5.@.=.5.9. .:.>.<.?.0.=.8.5.9.,. .=.0.E.>.4.O.I.5.9.A.O. .2. .?.>.;.=.>.9. .A.>.1.A.B.2.5.=.=.>.A.B.8. .:.>.@.?.>.@.0.F.8.8. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... ...0.=.=.K.9. .4.>.:.C.<.5.=.B. .?.@.5.4.A.B.0.2.;.O.5.B. .N.@.8.4.8.G.5.A.:.>.5. .A.>.3.;.0.H.5.=.8.5. .<.5.6.4.C. .=.0.<.8... .#.A.B.0.=.>.2.:.0. .8.;.8. .4.>.A.B.C.?. .:. .=.0.H.5.<.C. ...@.>.3.@.0.<.<.=.>.<.C. .>.1.5.A.?.5.G.5.=.8.N. .>.1.>.7.=.0.G.0.N.B. ...0.H.5. .A.>.3.;.0.A.8.5. .A. .C.A.;.>.2.8.O.<.8. .M.B.>.3.>. .A.>.3.;.0.H.5.=.8.O.,. .?.>.M.B.>.<.C. .2.=.8.<.0.B.5.;.L.=.>. .>.7.=.0.:.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2701), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):89572
                                                                                                                                                                            Entropy (8bit):3.733984219681676
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:plH9miYwq9hpeKK283X97rpcvXctx1qDQDupSMeylm5Wq0FGQueLS9FpSzvFgxS6:pPfqU7AcD1/DmDqOrS9FpkXvaGOtdx
                                                                                                                                                                            MD5:D70C08567DD28293CF26FC845C86A8DE
                                                                                                                                                                            SHA1:D30264B5DAE3D20F09E13BFEE306BBF10699A9FA
                                                                                                                                                                            SHA-256:B1594471911399202D2F1993F38ADC97C6E4F2B4645DAC1AE12E7574A56F4CD7
                                                                                                                                                                            SHA-512:E7665ADFEB32A03F83736A5E49DA876C898F8B8E5A023FA36141E105E49D0D23F7319EAACD6D53367FFCA023BF5D32215A50D954799CF8B9350BA0AB64EBB054
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..L.i.c.e.n...n... .z.m.l.u.v.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y...........a.k.u.j.e.m.e. .v...m. .z.a. .p.o.u.~...v.a.n.i.e. .s.o.f.t.v...r.u. .a. .s.l.u.~.i.e.b. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. S.o.f.t.v...r.. ).,. .p.o.s.k.y.t.o.v.a.n...c.h. .s.p.o.l.o...n.o.s.e.o.u. .M.c.A.f.e.e.,. .k.t.o.r... .j.e. .d.c...r.s.k.o.u. .s.p.o.l.o...n.o.s.e.o.u. ...p.l.n.e. .v.l.a.s.t.n.e.n.o.u. .s.p.o.l.o...n.o.s.e.o.u. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .T.o.t.o. .j.e. .p.r...v.n.a. .z.m.l.u.v.a. .m.e.d.z.i. .n.a.m.i. .. .i.n.a.t.a.l...c.i.o.u. .a.l.e.b.o. .p.r...s.t.u.p.o.v.a.n...m. .k. .n...a.m.u. .S.o.f.t.v...r.u. .s...h.l.a.s...t.e. .s. .t...m.i.t.o. .p.o.d.m.i.e.n.k.a.m.i.,. .t.a.k.~.e. .s.i. .i.c.h.,. .p.r.o.s...m.,. .p.o.z.o.r.n.e. .p.r.e.....t.a.j.t.e... .........T...t.o. .L.i.c.e.n...n... .z.m.l.u.v.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(...a.l.e.j. .l.e.n. .. Z.m.l.u.v.a.. ). .s.a. .v.z.e.a.h.u.j.e. .n.a. .v.a.a.e. .p.r...v.a. .n.a. .p.o.u.~...v.a.n.i.e. .S.o.f.t.v...r.u.,. .o.b.m.e.d.z.e.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2634), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):88356
                                                                                                                                                                            Entropy (8bit):3.578074617368606
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:1PXzqxuAlAEnb93roW/JxeTYZ9/sn7/87/FXoQEHVX/Z0S/ja:dWVkTmR1b
                                                                                                                                                                            MD5:59FC5F3BD9A87AE9413F2FE477EC3FDE
                                                                                                                                                                            SHA1:BFC3646E09C23F6DA7A28FDE78B76931BB1A97BA
                                                                                                                                                                            SHA-256:A9CC5B406D73552009F63842964E73E3A614F0A777B8403BA0D55BE85A8129C3
                                                                                                                                                                            SHA-512:E1494204F3D87892886422919F3CEAAA708981649E69910082353601BCD9CB58D3367DB8CA291D27486B6C467EA71B36E98BE468A43005DAFD5DC7F34EF917FD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..U.g.o.v.o.r. .o. .l.i.c.e.n.c.i.r.a.n.j.u. .k.o.m.p.a.n.i.j.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........H.v.a.l.a. .v.a.m. .a.t.o. .k.o.r.i.s.t.i.t.e. .s.o.f.t.v.e.r. .i. .u.s.l.u.g.e. .k.o.m.p.a.n.i.j.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. S.o.f.t.v.e.r.. ).,. .k.o.j.i. .o.b.e.z.b.e...u.j.e. .k.o.m.p.a.n.i.j.a. .M.c.A.f.e.e.,. .p.o.d.r.u.~.n.i.c.a. .u. .p.o.t.p.u.n.o.m. .v.l.a.s.n.i.a.t.v.u. .k.o.m.p.a.n.i.j.e. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .O.v.o. .j.e. .p.r.a.v.n.i. .u.g.o.v.o.r. .i.z.m.e...u. .n.a.s. .. .i.n.s.t.a.l.i.r.a.n.j.e. .n.a.a.e.g. .S.o.f.t.v.e.r.a. .i.l.i. .p.r.i.s.t.u.p.a.n.j.e. .n.j.e.m.u. .z.n.a...i. .d.a. .p.r.i.h.v.a.t.a.t.e. .o.v.e. .u.s.l.o.v.e.,. .p.a. .i.h. .s.t.o.g.a. .p.a.~.l.j.i.v.o. .p.r.o...i.t.a.j.t.e... .........O.v.a.j. .U.g.o.v.o.r. .o. .l.i.c.e.n.c.i.r.a.n.j.u. .k.o.m.p.a.n.i.j.e. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. U.g.o.v.o.r.. ). .p.o.k.r.i.v.a. .v.a.a.a. .p.r.a.v.a. .d.a. .k.o.r.i.s.t.i.t.e. .S.o.f.t.v.e.r.,. .o.g.r.a.n.i...e.n.j.a. .t.o.g. .k.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2632), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):89704
                                                                                                                                                                            Entropy (8bit):3.503772885574125
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:dcFeHhjwanoMWVOjxKI+psB/YgpnuIbVGml:WFCwKWsQgp1
                                                                                                                                                                            MD5:A94B5016A1C36889003DCB74084BE0E8
                                                                                                                                                                            SHA1:E0E6FA59216BE5F45EB1633D566A1BA10C2AD340
                                                                                                                                                                            SHA-256:5E51ADC76C5CBAAC85C47732B15FA9D15435F6EC8A865E1B84D670149D752F58
                                                                                                                                                                            SHA-512:0897F2C7F7719D3A71552B8F1303DB8A00FD45A32CDC5E26AED1CEDDD5F18F302B8D09F781F8D5C45E9F170CEB4B060CFE11636FB3F513121BED02CCE76AD41A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..L.i.c.e.n.s.a.v.t.a.l. .f...r. .I.n.t.e.l. .S.e.c.u.r.i.t.y.........T.a.c.k. .f...r. .a.t.t. .d.u. .a.n.v...n.d.e.r. .p.r.o.g.r.a.m.v.a.r.a.n. .o.c.h. .t.j...n.s.t.e.r.n.a. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. P.r.o.g.r.a.m.v.a.r.a.n.. ). .f.r...n. .M.c.A.f.e.e.,. .e.t.t. .h.e.l...g.t. .d.o.t.t.e.r.b.o.l.a.g. .t.i.l.l. .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n... .N...r. .d.u. .i.n.s.t.a.l.l.e.r.a.r. .e.l.l.e.r. .a.n.v...n.d.e.r. .P.r.o.g.r.a.m.v.a.r.a.n. .g.o.d.k...n.n.e.r. .d.u. .a.u.t.o.m.a.t.i.s.k.t. .v.i.l.l.k.o.r.e.n.,. .s... .l...s. .n.o.g.a. .i.g.e.n.o.m. .d.e.m. .f...r.s.t... .D.e.t.t.a. ...r. .e.t.t. .b.i.n.d.a.n.d.e. .j.u.r.i.d.i.s.k.t. .a.v.t.a.l. .o.s.s. .e.m.e.l.l.a.n... .........D.e.t.t.a. .L.i.c.e.n.s.a.v.t.a.l. .f...r. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .(.. A.v.t.a.l.e.t.. ). .r.e.g.l.e.r.a.r. .d.i.n.a. .r...t.t.i.g.h.e.t.e.r. .i. .s.a.m.b.a.n.d. .m.e.d. .a.n.v...n.d.n.i.n.g. .a.v. .P.r.o.g.r.a.m.v.a.r.a.n.,. .e.v.e.n.t.u.e.l.l.a. .b.e.g.r...n.s.n.i.n.g.a.r. .i. .a.n.v...n.d.n.i.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (2527), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):89572
                                                                                                                                                                            Entropy (8bit):3.761887651307163
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:U4WLetFwU8STnnWH0I9fkl7+JaRtbJHGdnC2vJfPI9n9AkllkhZBYziG/xJd8oSc:UjLetFwbSTnnWH0IdkN+JaRt0dnC2xI1
                                                                                                                                                                            MD5:91C06A443F143BAE210CF6BA678B2813
                                                                                                                                                                            SHA1:829A9B675F5D12E6C9BCB9751A8B2167A701B610
                                                                                                                                                                            SHA-256:D454E9D22FA1413F35EF41BEE944300FE3776EE55CD8A41BFE588FC1A86A36F6
                                                                                                                                                                            SHA-512:7C014F1AC0AA7BC2EC7124BF5C5DC13168EEE98EBE2C3A387C67E318798EB58A09817753956E8F6206505AFEB0C63AD759AD31E6F977874B97F237D72F433454
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y. .L.i.s.a.n.s. .S...z.l.e._.m.e.s.i.........I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n.. 1.n. .y...z.d.e. .y...z. .i._.t.i.r.a.k.i. .o.l.a.n. .M.c.A.f.e.e. .t.a.r.a.f.1.n.d.a.n. .s.a...l.a.n.a.n. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .y.a.z.1.l.1.m.1. .v.e. .h.i.z.m.e.t.l.e.r.i.n.i. .(.. Y.a.z.1.l.1.m.. ). .k.u.l.l.a.n.d.1...1.n.1.z. .i...i.n. .t.e._.e.k.k...r. .e.d.e.r.i.z... .Y.a.z.1.l.1.m.1.m.1.z.1.n. .k.u.r.m.a.n.1.z. .v.e.y.a. .Y.a.z.1.l.1.m.1.m.1.z.a. .e.r.i._.i.m. .s.a...l.a.m.a.n.1.z. .a.r.a.m.1.z.d.a.k.i. .b.u. .y.a.s.a.l. .s...z.l.e._.m.e.n.i.n. .i.l.g.i.l.i. .h...k...m.l.e.r.i.n.i. .k.a.b.u.l. .e.t.t.i...i.n.i.z. .a.n.l.a.m.1.n.a. .g.e.l.e.c.e...i.n.d.e.n.,. .l...t.f.e.n. .b.u.n.l.a.r.1. .d.i.k.k.a.t.l.i.c.e. .o.k.u.y.u.n... .........0._.b.u. .I.n.t.e.l. .S.e.c.u.r.i.t.y. .L.i.s.a.n.s. .S...z.l.e._.m.e.s.i. .(.. S...z.l.e._.m.e.. ). .Y.a.z.1.l.1.m.1.n. .k.u.l.l.a.n.1.l.m.a.s.1.n.a. .i.l.i._.k.i.n. .h.a.k.l.a.r.1.n.1.z.1.,. .s...z. .k.o.n.u.s.u. .k.u.l.l.a.n.1.m.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (873), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):27048
                                                                                                                                                                            Entropy (8bit):6.7933720259471135
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:dGlhiqpYn3S6kZ5pZsM1SDo9P0VSpjzjW+EpgLDR5CCaGdYQ:dWDuIVZsM19DjzjW+EpgLN5qvQ
                                                                                                                                                                            MD5:E40ED8A73802CBA2C7E94C103AF9B29E
                                                                                                                                                                            SHA1:CD42A5567397259E1F59D2739C7E7F65CCA2B13B
                                                                                                                                                                            SHA-256:6C6A08446A815E7595100C3A6BAC95DE406057CFCD32856378EEC0828F60D4D3
                                                                                                                                                                            SHA-512:B24F225F71F0641CD0E71508144821C6E4BA8F7DE6D5CE8990953B74236EA22F53CCCA5BC52A5B9CB40DEC07158222982993D07467AF459EC279C08CB73C853D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y. ....SOS...........a"..`.O(u1u .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n. ..vhQD.P[lQ.S .M.c.A.f.e.e. ..c.O.v .I.n.t.e.l. .S.e.c.u.r.i.t.y. .o..N.T.g.R... o..N. ...0 ../f.`.N.b.NKN...v.l._OS.....[..b....b.N.v. o..N. ..sSh.:y.`.T.a..Nag>k...Vdk...N.~.....0 .........,g .I.n.t.e.l. .S.e.c.u.r.i.t.y. ....SOS..... OS... ...m.v.`.O(u. o..N. .vCg)R.0.O(uP.6R.0.b.N.R.~..v^1\. o..N. .v.N9.Hr,g.b.R...T.`6e9..vCg)R...N.S.`.T.a....N...Q.b.NKN...S...N.u.v.NUO.N...0 .,gOS...S+T.b.N.v...y.X.fI{D..Rag>k.v...c .(.h.t.t.p.s.:././.w.w.w...m.c.a.f.e.e...c.o.m./.c.o.m.m.o.n./.p.r.i.v.a.c.y./.c.h.i.n.e.s.e.-.s.i.m.p.l.i.f.i.e.d./.i.n.d.e.x...h.t.m.).....Nag>k._.....v^qQ.T.g.b..(u.N.`.v,g.l._OS...0 ..V.[/.0W:Syr.[.vag>kMO.NOS...v.g.T.Nag.0 ..........Y.g.`*g.n .1.8. ..\...l.g.`.v6r.k.b.v.b.N...N.N._{.HQ.c.S,gOS..v^.Nh..`.{.t. o..N. ...v.T.a...`.N._.O(u. o..N. .b.T.b.N.c.O.`.v*N.N.Oo`.0 .........1......c.S,gOS...T.O9e .. .US.Q. .c.S. .c...b.[.. o..N. ..sSh.:y.`.eag.N.T.a.S,g
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with very long lines (904), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):27300
                                                                                                                                                                            Entropy (8bit):6.852328782163936
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:RLcNdFNy9pQbexWBTeP5s8FmxoFfEgQSPsxFHMOKQZgTmLL/ytmq/V:Rcf6w3BKx/hagQSPsxtKjTmY
                                                                                                                                                                            MD5:992019F123EDA3E9D332E2B974ED1809
                                                                                                                                                                            SHA1:5A307D4BCB62D6EE451B29B31C8A4B6BBCF8606C
                                                                                                                                                                            SHA-256:52D00E90DFA554AE761BC820D5CC119A56963CFF95266194C80E4BBE0FC2CC18
                                                                                                                                                                            SHA-512:5198EDD5ADB84D60CC39D26BE1169B6F21115CD5791FA98909EC5FFEA5AC0D54E8CDC2D67D6F04F8FF14471188F0E2459E946DD7A2CDA069BCD6A7EBDAF42ABF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:..I.n.t.e.l. .S.e.c.u.r.i.t.y. ..c.k.T.}.........a...`.O(u1u .I.n.t.e.l. .C.o.r.p.o.r.a.t.i.o.n. .hs.P[lQ.S .M.c.A.f.e.e. ..c.O.v .I.n.t.e.l. .S.e.c.u.r.i.t.y. ......g.R...0...0...0 .../f.`...b.PKN...v.l._.T.} .. ..[..bX[.S.b.P.v.0...0..sSh.:y.`.T.a...N.h>k...Vdk..N0}.....0 .........,g .I.n.t.e.l. .S.e.c.u.r.i.t.y. ..c.k.T.}...0.T.}.0...m..`.O(u.0...0.v.k)R.0.O(uP.6R.0.b.P..R.~..&N1\.0...0.v.N..Hr,g.b.R...T.`6e...v.k)R...N.S.`.T.a..N..N...zl.b.PKN...S.."u.u.v.NUO-rp..0 ..b.P.].S.b.b.P.v...y.kr..fI{D..R.h>k.v#.P} .(.h.t.t.p.s.:././.w.w.w...m.c.a.f.e.e...c.o.m./.c.o.m.m.o.n./.p.r.i.v.a.c.y./.c.h.i.n.e.s.e.-.t.r.a.d.i.t.i.o.n.a.l./.i.n.d.e.x...h.t.m.)......N.h>k._.....&NqQ.T.i.bi.(u.e.`.v,g.l._.T.}.0 ..W.[/.0W@Syr.[.v.h>kMO.e.T.}.v.g._.N.h.0 ..........Y.g.`*g.n .1.8. .rk...l.g.`.v6r.k.b.vw..N...N.P._..HQ.c.S,g.T.}&N.Nh..`.{.t.0...0...v.T.a...`.N..AQ1..O(u.0...0.b.T.b.P.c.O.`.v.P.N....0 .........1......c.S,g.T.}.T.O9e .. ..c.N.0.c.S.0.c...b.[..0...0..sSh.:y.`!q.h
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3039
                                                                                                                                                                            Entropy (8bit):5.584549435681096
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3HNBDTH2dKcmPEG445Y1I8knQ5l6GGAlpfkPlC0XnslNE0wJZGl31KzEImtumzcc:3tuKJsG4450I8ksl6IlpfUlC0XslNE7I
                                                                                                                                                                            MD5:F3A5029C7AF82837AC07608AF5AB874E
                                                                                                                                                                            SHA1:5D2DCA52BB24BAF4BA244CF0774A39B5D32F45DF
                                                                                                                                                                            SHA-256:E38D92D43EC339994C92CA684C687600BFDB3DF89A6892C11883E7B56FB9C5E7
                                                                                                                                                                            SHA-512:F157BD3C10A7C6F9AAEE73998670DF683A795451799C498EB4B3D179EA048A35422AE716DD2D0E737051111097A4B0D02129683524ABE047C15BE4B2C94F42AE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Licen.n. smlouva",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "P.e.etl(a) jsem si licen.n. smlouvu a souhlas.m s n..",.. //{0} - Company name.. THANK_YOU: "D.kujeme, .e jste si vybrali {0}",.. INSTALL: "Instalovat",.. CANCEL: "Zru.it",.. RETRY: "Zkusit znovu",.. DONE: "Hotovo",.. //{0} - Product name.. PROGRESS_TITLE: "Produkt {0} je v.. osobn. bezpe.nostn. poradce p.i proch.zen. internetu.",.. PROGRESS_SUBTITLE: "Instalace...",.. COMPLETE_TITLE: "V.born.! Dokon.ili jsme instalaci osobn.ho online poradce.",.. COMPLETE_SUBTITLE: "V.e p.ipraveno",.. COMPLETE_LAUNCH: "Otev..t prohl..e.",.. ERROR_OS_REQUIREMENTS: "V instalaci nen. mo.n. pokra.ovat, proto.e v.. opera.n. syst.m nespl.uje minim.ln. syst.mov. po.adavky. Prove.te aktualizaci a zkuste to znovu.",.. ERROR_BROWSER_REQUIREMENTS: "V instalaci nen. mo.n. pokra.ovat, proto.e v.. prohl..e. nespl
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2750
                                                                                                                                                                            Entropy (8bit):5.30356527863537
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3blK55gOog4oCwdO1nE4Zx7eOIcvKV+VvKVHQfHbd+LnoEnE/jshVcKV+v2hQOsX:3blSgwhsx6OI6Pzfp+dErsM2kL/zMVsb
                                                                                                                                                                            MD5:470EDE85B44EBF458DDBE6F9F7BB2B5B
                                                                                                                                                                            SHA1:4B0064A1E3D3A4ECB724D76005A2FAC29CA98BEC
                                                                                                                                                                            SHA-256:BE64067C90C5F001065ED8BB8EFFF5ADCD4E1F51FB68D836C7B006CFD2EE1231
                                                                                                                                                                            SHA-512:66278668B6420352FF1BAB40C10F8B11C427B52B90C39039CE3F621C1D20EFAB85FC7945021A2D6C1885EA469377323310573E90832DDAED66C95A2BC2C4A8BB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "licensaftale",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Jeg har l.st og accepterer licensaftalen",.. //{0} - Company name.. THANK_YOU: "Tak, fordi du valgte {0}",.. INSTALL: "Installer",.. CANCEL: "Annuller",.. RETRY: "Pr.v igen",.. DONE: "F.rdig",.. //{0} - Product name.. PROGRESS_TITLE: "{0} er din personlige sikkerhedsr.dgiver, uanset hvad du foretager dig online.",.. PROGRESS_SUBTITLE: "installerer ...",.. COMPLETE_TITLE: "Super! Din personlige onliner.dgiver er blevet installeret.",.. COMPLETE_SUBTITLE: "Klar til brug",.. COMPLETE_LAUNCH: ".bn browser",.. ERROR_OS_REQUIREMENTS: "Installationen kan ikke forts.tte, fordi dit operativsystem ikke opfylder minimumskravene. Opdater det, og pr.v igen.",.. ERROR_BROWSER_REQUIREMENTS: "Installationen kan ikke forts.tte, fordi din browser ikke opfylder minimumskravene. Opdater din browser, og pr.v igen.",.. ERROR_VERSION: "Der er allerede e
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3119
                                                                                                                                                                            Entropy (8bit):5.263823184445253
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:36u+Npa+LIkjy9uRfJZHgf3hz0i2kTCyuyt0pWUOt:36Dpam3e6J9gvhz0i2PygOt
                                                                                                                                                                            MD5:CF761E54EEB153F8D82C500A4769E2AC
                                                                                                                                                                            SHA1:E7F4B6ED0EC302F5D7307F374CDC1963169AD847
                                                                                                                                                                            SHA-256:91E289DF7673C8055F98A1097CC2EB4B7AB243095FFB0D6D775C80718B449EA7
                                                                                                                                                                            SHA-512:E08535F7729CEAC31D940B8FCB7DADFE1B522596D0DA1295586290F916CDB377B945D85120CE9110F700E918C9878E664C95F33AA9427B6DDA9FA636B9F8EBF6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Lizenzvertrag",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Ich habe den Lizenzvertrag gelesen und stimme ihm zu.",.. //{0} - Company name.. THANK_YOU: "Vielen Dank, dass Sie sich f.r {0} entschieden haben.",.. INSTALL: "Installieren",.. CANCEL: "Abbrechen",.. RETRY: "Erneut versuchen",.. DONE: "Fertig",.. //{0} - Product name.. PROGRESS_TITLE: "{0} ist Ihr pers.nlicher Berater f.r Online-Sicherheit.. zu Hause und unterwegs.",.. PROGRESS_SUBTITLE: "Installation l.uft...",.. COMPLETE_TITLE: "Wunderbar! Ihr pers.nlicher Berater f.r Online-Sicherheit ist installiert.",.. COMPLETE_SUBTITLE: "Fertig",.. COMPLETE_LAUNCH: "Meinen Browser .ffnen",.. ERROR_OS_REQUIREMENTS: "Ihre Installation kann nicht fortgesetzt werden, da Ihr Betriebssystem nicht die Mindestsystemanforderungen erf.llt. Bitte aktualisieren Sie es, und versuchen Sie es erneut.",.. ERROR_BROWSER_REQUIREMENTS: "Ihre Installation kann
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4568
                                                                                                                                                                            Entropy (8bit):4.938030579645634
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:3CL8S9mqS51CrYI1avgbfflo3uSAmQiRdjzkrMBGrmyyeyZUf:3Q9u51CrYmavg7flMdjzkry2my7yZQ
                                                                                                                                                                            MD5:790E186D6F2DEF3CA6EA55392DF0655E
                                                                                                                                                                            SHA1:42ACA36E1416CDAE2463DC0E47714592F57A7697
                                                                                                                                                                            SHA-256:AC37E16D3FCE1598D6321143CBF733EC472B2D0663031C6BB51150D4735E9630
                                                                                                                                                                            SHA-512:D3E641D4484F430B3E5C1421A7F093EE1CF2558E264CC7A9EBC5FE1EAEDFB29B42B70828F4579682218DDF756A263E56FFE8A4F07416A3B6A6666A4A5571EC4B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "........ ...... ......",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "... ........ ... .......... .. ........ ...... ......",.. //{0} - Company name.. THANK_YOU: "... ............ ... ......... {0}",.. INSTALL: "...........",.. CANCEL: ".......",.. RETRY: "......... ....",.. DONE: ".....",.. //{0} - Product name.. PROGRESS_TITLE: ".. {0} ..... . .......... ... ......... ......... .... .. .. ......... ... ..........",.. PROGRESS_SUBTITLE: ".......... ..............",.. COMPLETE_TITLE: "......! ...... ............ ... ......... ... ........... .........",.. COMPLETE_SUBTITLE: "......",.. COMPLETE_LAUNCH: "....... ... ...
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2642
                                                                                                                                                                            Entropy (8bit):5.26126673440905
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3TmE5KCrHEAvhhIDX6uSBf15aN+conkQt52fEZhozWZIMJJZ1G1gPWJjm7VJ5ZNz:33NIAphIzqfE+c6bZhozqxJZXtbNz
                                                                                                                                                                            MD5:2ECA66E2E06EB81CB19B754D062422EE
                                                                                                                                                                            SHA1:247B9A7EEB7B53DF79DC2EEB1D436F4A7FA3C21D
                                                                                                                                                                            SHA-256:AC9A2B4DFC0C1D8BF9804B677383281586D590B47B92BB114E2DCF70FEF418D6
                                                                                                                                                                            SHA-512:D36E793F7DEA8A6C1B29E1578604E0E56FD5CBC74A1E9BE312F5A45D5E02011DED191F38C4A74F5926008ABFB42A48ECB0CB477EAE2238F3E0B3C6EBCC1C3839
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "License Agreement",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "I have read and agree to the License Agreement",.. //{0} - Company name.. THANK_YOU: "Thank you for choosing {0}",.. INSTALL: "Install",.. CANCEL: "Cancel",.. RETRY: "Try Again",.. DONE: "Done",.. //{0} - Product name.. PROGRESS_TITLE: "{0} is your personal safety advisor wherever you go online.",.. PROGRESS_SUBTITLE: "Installing...",.. COMPLETE_TITLE: "Great! We've installed your personal online advisor.",.. COMPLETE_SUBTITLE: "Ready to go",.. COMPLETE_LAUNCH: "Open my browser",.. ERROR_OS_REQUIREMENTS: "Your installation cannot continue because your operating system does not meet the minimum system requirements. Please update it and try again.",.. ERROR_BROWSER_REQUIREMENTS: "Your installation cannot continue because your browser does not meet our minimum system requirements. Please update your browser and try again.",.. ERROR_VERSIO
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2710
                                                                                                                                                                            Entropy (8bit):5.245237571526594
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3Vu7DIIaj1E01NIsNIwfQ6+YHPCEfgDy5zxIhJoPlZ8RyJF4WmHnw:3Vq8IR01NIszfQ6+ObfgDizxOJoPlmRk
                                                                                                                                                                            MD5:89D30F4BD6DC4040FE6E7D2DAECF82C5
                                                                                                                                                                            SHA1:EA2FFB4EE0F55D156C2C2061C8059FA294070C8F
                                                                                                                                                                            SHA-256:9C1FB5137870E54808DCCE19310B012CC0FBEAD46E5529F3D7649030101126C3
                                                                                                                                                                            SHA-512:381763224AEC521DD5F0DFB7D28E4CD208E5FE5777F666E07803D6E81B6BD0EE1D82E24E2A8010FB5DE4786F446F182DD73C79E623A4ADEF84D7BA11DAA02F7C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Contrato de Licencia",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "He le.do y acepto el Contrato de Licencia",.. //{0} - Company name.. THANK_YOU: "Gracias por elegir {0}.",.. INSTALL: "Instalar",.. CANCEL: "Cancelar",.. RETRY: "Reintentar",.. DONE: "Listo",.. //{0} - Product name.. PROGRESS_TITLE: "{0} es tu asesor personal de seguridad vayas donde vayas en Internet.",.. PROGRESS_SUBTITLE: "Instalando... ",.. COMPLETE_TITLE: ".Genial! Hemos instalado tu asesor personal online.",.. COMPLETE_SUBTITLE: "Listo para empezar",.. COMPLETE_LAUNCH: "Abrir mi navegador",.. ERROR_OS_REQUIREMENTS: "Tu instalaci.n no puede continuar porque tu sistema operativo no cumple los requisitos m.nimos del sistema. Actual.zalo e int.ntalo de nuevo.",.. ERROR_BROWSER_REQUIREMENTS: "Tu instalaci.n no puede continuar porque tu navegador no cumple nuestros requisitos m.nimos del sistema. Actualiza tu navegador e int.n
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2723
                                                                                                                                                                            Entropy (8bit):5.254671238185329
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3Vu7DI4aj1EpJJNIsNIwfQQ2jlHPHEq7gDJLzxIhJoPlZ8RyJF4WmfliAHHg:3Vq84RnJNIszfQQ2B8q7gDJLzxOJoPll
                                                                                                                                                                            MD5:8E00965B8F656729F6BB69F9DB20BA30
                                                                                                                                                                            SHA1:DE6C861649D8D1A272293D12F8355F8801DFF903
                                                                                                                                                                            SHA-256:957389B3314E56E86C0F0187AB6380EE5D7658992875754EEB9374D5C3A0868E
                                                                                                                                                                            SHA-512:CB7A70DB64A456CBD1D8BDA77E562C2704309A5D469D22729858F66EA6B1C5D995975155C047559FF2E1D3B4826B0C95B7980A2E2A3E76621B3A10A7319C3402
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Contrato de Licencia",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "He le.do y acepto el Contrato de Licencia",.. //{0} - Company name.. THANK_YOU: "Gracias por elegir {0}.",.. INSTALL: "Instalar",.. CANCEL: "Cancelar",.. RETRY: "Intentarlo de nuevo",.. DONE: "Listo",.. //{0} - Product name.. PROGRESS_TITLE: "{0} es tu asesor personal de seguridad vayas donde vayas en Internet.",.. PROGRESS_SUBTITLE: "Instalando...",.. COMPLETE_TITLE: ".Excelente! Hemos instalado tu asesor personal en l.nea.",.. COMPLETE_SUBTITLE: "Listo para empezar",.. COMPLETE_LAUNCH: "Abrir mi navegador",.. ERROR_OS_REQUIREMENTS: "Tu instalaci.n no puede continuar porque tu sistema operativo no cumple los requisitos m.nimos del sistema. Actual.zalo e int.ntalo de nuevo.",.. ERROR_BROWSER_REQUIREMENTS: "Tu instalaci.n no puede continuar porque tu navegador no cumple nuestros requisitos m.nimos del sistema. Actualiza tu nave
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2740
                                                                                                                                                                            Entropy (8bit):5.308093679067159
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3O056PfLCRVyEaXqPs9IYxDT8iwKxp8iElfoKMV7xXTDbtDM57LzTsB1DUozuTI/:3oWvTkqP4IYxHXxZIfXIjC5vUbzzuTCX
                                                                                                                                                                            MD5:1C5D948F5088E01097CB94B6BE3989D4
                                                                                                                                                                            SHA1:34714E6BBDF90CA78F4B2130FEBA690223ED2A4A
                                                                                                                                                                            SHA-256:EE036B98E8935B09A98A4971CC1EA00EB379273F8B75611FBCD403A18D2DB0DE
                                                                                                                                                                            SHA-512:C373659C5DEC792EFD62A9C1F10A0F409F0D48E2D62A398154F1B7F3EF4B06816AA10D6DFB5581181AB2C8097DCE5333BC81AAAE4C36E7CC678A122285C5A176
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "lisenssisopimuksen",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Olen lukenut lisenssisopimuksen ja hyv.ksyn sen",.. //{0} - Company name.. THANK_YOU: "Kiitos, ett. valintasi oli {0}",.. INSTALL: "Asenna",.. CANCEL: "Peruuta",.. RETRY: "Yrit. uudelleen",.. DONE: "Valmis",.. //{0} - Product name.. PROGRESS_TITLE: "{0} on henkil.kohtainen turvallisuusneuvojasi aina, kun olet verkossa.",.. PROGRESS_SUBTITLE: "Asennetaan.",.. COMPLETE_TITLE: "Loistavaa! Olemme asentaneet henkil.kohtaisen verkkoneuvojasi.",.. COMPLETE_SUBTITLE: "Valmis",.. COMPLETE_LAUNCH: "Avaa selain",.. ERROR_OS_REQUIREMENTS: "Asennusta ei voi jatkaa, koska k.ytt.j.rjestelm.si ei t.yt. j.rjestelm.n v.himm.isvaatimuksia. P.ivit. se ja yrit. uudelleen.",.. ERROR_BROWSER_REQUIREMENTS: "Asennusta ei voi jatkaa, koska selaimesi ei t.yt. j.rjestelm.n v.himm.isvaatimuksia. P.ivit. selain ja yrit. uudelleen.",..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2957
                                                                                                                                                                            Entropy (8bit):5.29084273603639
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3TtTOo+8f2FWuEqdv5G8I5ybT1IG82ybSTIG8Cfjvz75B8zq5DVMk7LrqbkbGErr:3TCCyWfSv5G8I5WTK2WScCfjvz1mzkKy
                                                                                                                                                                            MD5:A36FADC66327107E12C725A415539CBF
                                                                                                                                                                            SHA1:3C3381D7EAC7D6EC38793044D1ACCBA8C9094BC8
                                                                                                                                                                            SHA-256:5705F5857F4E8BF384F270A56BF32A1F8ECCD99630D2289504797270530973CD
                                                                                                                                                                            SHA-512:97974E495E6C6990112FBA80C11900B6B782DFA48C8112759FC1D7469D7EB525F114047B100C666757E690901E3ACD7E35C23E38113144154E99D9DF40E49B88
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "contrat de licence",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "J'ai lu et j'accepte le contrat de licence",.. //{0} - Company name.. THANK_YOU: "Merci d'avoir choisi {0}",.. INSTALL: "Installer",.. CANCEL: "Annuler",.. RETRY: "R.essayer",.. DONE: "Termin.",.. //{0} - Product name.. PROGRESS_TITLE: "{0} est votre conseiller personnel en mati.re de s.curit., o. que vous alliez en ligne.",.. PROGRESS_SUBTITLE: "Installation...",.. COMPLETE_TITLE: "Parfait! Nous avons install. votre conseiller personnel en ligne.",.. COMPLETE_SUBTITLE: "Pr.t . d.marrer",.. COMPLETE_LAUNCH: "Ouvrir mon navigateur",.. ERROR_OS_REQUIREMENTS: "Votre installation ne peut pas se poursuivre, car votre syst.me d'exploitation ne r.pond pas . la configuration minimale requise. Veuillez le mettre . jour et r.essayer.",.. ERROR_BROWSER_REQUIREMENTS: "Votre installation ne peut pas se poursuivre, car votre navigateur
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2953
                                                                                                                                                                            Entropy (8bit):5.295545771935365
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3TtTOo+8f2FWuEqLv5G8I5ybT1IG82ybSTIG8Cfjvz75B8zq5DVMk7OxqbkbGErD:3TCCyWfYv5G8I5WTK2WScCfjvz1mzkK7
                                                                                                                                                                            MD5:8B60FCE0D6FD3962E148686F21AB4E9A
                                                                                                                                                                            SHA1:FFE7DAEFF6A7420BA6E5CAC2D6B2539182799948
                                                                                                                                                                            SHA-256:2FAE4BB5432E67F6B47BF2C3E2C5B44CFA56104468602047DE2A19C96923D7DF
                                                                                                                                                                            SHA-512:95330E44C94A221CB9B1A25932810259D1DBEA535FE5D5ABAF43BFC8BF65C0625FEF730F78EE9BDCF5F5E1E2C7084C5A54DB5A381A5598D98DB8CD85FA11D89D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "contrat de licence",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "J'ai lu et j'accepte le contrat de licence",.. //{0} - Company name.. THANK_YOU: "Merci d'avoir choisi {0}",.. INSTALL: "Installer",.. CANCEL: "Annuler",.. RETRY: "R.essayer",.. DONE: "Termin.",.. //{0} - Product name.. PROGRESS_TITLE: "{0} est votre conseiller personnel en mati.re de s.curit., o. que vous alliez en ligne.",.. PROGRESS_SUBTITLE: "Installation...",.. COMPLETE_TITLE: "Parfait.! Nous avons install. votre conseiller personnel en ligne.",.. COMPLETE_SUBTITLE: "Pr.t . d.marrer",.. COMPLETE_LAUNCH: "Ouvrir mon navigateur",.. ERROR_OS_REQUIREMENTS: "Votre installation ne peut pas se poursuivre, car votre syst.me d'exploitation ne r.pond pas . la configuration minimale requise. Veuillez le mettre . jour et r.essayer.",.. ERROR_BROWSER_REQUIREMENTS: "Votre installation ne peut pas se poursuivre, car votre navigateu
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2827
                                                                                                                                                                            Entropy (8bit):5.347421387804527
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3vFCs47Qs1rDlEjihC7nRIoYwPabwfefNMcLRMGbm6+IN6I1GeRJ2lz1aIIJC5iH:3v8Nd1OjQgRIoYAaMfaNMcLreINJ3fwG
                                                                                                                                                                            MD5:C22CF0B54F76C868382282AE594FA364
                                                                                                                                                                            SHA1:45E2EC3E57496EB2FC4E1136423DA44BAA044461
                                                                                                                                                                            SHA-256:8EB9809593BA4B5248D1FBF0DB7DC5E22F040AC469D882B78EB4CE4A5668725A
                                                                                                                                                                            SHA-512:7754AF022340B47763205FAAF3395DA6EA93D0E69B67696EDA8197677977D8D46493A27639E4D2EF2AA06AFB846510ECFD0A070C9C326340A1EDB78970FFBB33
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Licencni ugovor",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Pro.itao/la sam Licencni ugovor i saglasan/na sam s njim",.. //{0} - Company name.. THANK_YOU: "Zahvaljujemo .to ste odabrali {0}.",.. INSTALL: "Instaliraj",.. CANCEL: "Odustani",.. RETRY: "Poku.aj ponovo",.. DONE: "Gotovo",.. //{0} - Product name.. PROGRESS_TITLE: "{0} je va. osobni savjetnik za sigurnost na svakom mjestu na mre.i.",.. PROGRESS_SUBTITLE: "Instaliranje...",.. COMPLETE_TITLE: "Sjajno! Instalirali smo va.eg osobnog savjetnika na mre.i.",.. COMPLETE_SUBTITLE: "Spremno za pokretanje",.. COMPLETE_LAUNCH: "Otvori moj preglednik",.. ERROR_OS_REQUIREMENTS: "Va.a instalacija se ne mo.e nastaviti jer va. operativni sustav ne zadovoljava minimalne zahtjeve sustava. A.urirajte ga i poku.ajte ponovno.",.. ERROR_BROWSER_REQUIREMENTS: "Va.a instalacija se ne mo.e nastaviti jer va. preglednik ne zadovoljava minimalne zahtjev
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3020
                                                                                                                                                                            Entropy (8bit):5.501193888773686
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3tTcztb3AE5sBQIkQfa4xR9X+MK+ReCoPMre6Q/sIzqjIaLej1uh9JQh/aS:3otzN5sBQIkQfa4xR1+MKPkreb/tzeBY
                                                                                                                                                                            MD5:86A072B9B0E5BDB616874C39BD0F0264
                                                                                                                                                                            SHA1:D3524BD363AFFEACA8079B2C9C24BE445BDFDC98
                                                                                                                                                                            SHA-256:DCC631D88F305B8E71691C6852E3E8425244E38C90905FB78B47EF23102E6FCA
                                                                                                                                                                            SHA-512:F50CAC2DA38082AEBB97C8DD2D1D69F62A4152616EF3710247C5C00E691475C52DDC52FD0A4CEC22AB9B7DB920CD3FD4DF2F10F6F8259CE4F6C0613D4920BFE4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Licencmeg.llapod.s",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Elolvastam .s elfogadom a Licencmeg.llapod.st",.. //{0} - Company name.. THANK_YOU: "K.sz.nj.k, hogy a {0} term.k.t v.lasztotta",.. INSTALL: "Telep.t.s",.. CANCEL: "M.gse",.. RETRY: "Pr.b.lkozzon .jra",.. DONE: "K.sz",.. //{0} - Product name.. PROGRESS_TITLE: "A {0} az .n szem.lyes biztons.gi tan.csad.ja, amely mindenhova .nnel tart online.",.. PROGRESS_SUBTITLE: "Telep.t.s...",.. COMPLETE_TITLE: "Rendben! Telep.tett.k a szem.lyes biztons.gi tan.csad.j.t.",.. COMPLETE_SUBTITLE: "K.szen .ll",.. COMPLETE_LAUNCH: "B.ng.sz. megnyit.sa",.. ERROR_OS_REQUIREMENTS: "A telep.t.s nem folytathat., mert az oper.ci.s rendszer nem tesz eleget a minim.lis rendszerk.vetelm.nyeknek. Friss.tse, majd pr.b.lkozzon .jra.",.. ERROR_BROWSER_REQUIREMENTS: "A telep.t.s nem folytathat., mert a b.ng.sz. nem
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2654
                                                                                                                                                                            Entropy (8bit):5.273633144698911
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:30WhiWDdQoG5DJItZEqRU0TMNIbpJ5WpGKf/w+roo5Ng5wZpEY854U6hgz9+IR17:39q51529MNI75JKf7rDm5f6hgzIG1u0R
                                                                                                                                                                            MD5:6ADAA4FF9AFC5B3A70191C7778893813
                                                                                                                                                                            SHA1:5F639C9E8E626D160A9832674AF8BEBCC4C324DE
                                                                                                                                                                            SHA-256:8AA0EB04D5149925AD51ADC06D3F6468A4F2062F9A64BB80F85CAFCDA8BEA353
                                                                                                                                                                            SHA-512:BA1433C4EF8EB91C90A5578FF81A276507E9A94D624C6D0BEDF6069F5F7A41D00F49DC2C4B23F5D481400245270E3B56236193198B1A98DAE2576E7BD9CB69B7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Contratto di Licenza",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Ho letto e accetto il Contratto di Licenza",.. //{0} - Company name.. THANK_YOU: "Grazie per aver scelto {0}",.. INSTALL: "Installa",.. CANCEL: "Annulla",.. RETRY: "Riprova",.. DONE: "Fine",.. //{0} - Product name.. PROGRESS_TITLE: "{0} . il tuo consulente personale per la sicurezza ovunque tu vada online.",.. PROGRESS_SUBTITLE: "Installazione in corso...",.. COMPLETE_TITLE: "Ottimo. Abbiamo installato il tuo consulente online personale.",.. COMPLETE_SUBTITLE: "Pronti a partire",.. COMPLETE_LAUNCH: "Apri il browser",.. ERROR_OS_REQUIREMENTS: "L'installazione non pu. continuare. Il sistema operativo non soddisfa i requisiti minimi del sistema. Aggiornalo e riprova.",.. ERROR_BROWSER_REQUIREMENTS: "L'installazione non pu. continuare. Il browser non soddisfa i requisiti minimi del sistema. Aggiorna il browser e riprova.",.. ERROR_VE
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3621
                                                                                                                                                                            Entropy (8bit):5.5881432753526985
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:3wpT6KUHA0ZV0Ikw0nofKxypVqml/MiXzYGDpvvSDruthk:3w8Hg0sUKgpYZiXzYGDpXaKthk
                                                                                                                                                                            MD5:B3B9671F29B88CF708C23FAA154F3AF2
                                                                                                                                                                            SHA1:B0C26292029AE7A19A635761FAE1B137C75E6BCB
                                                                                                                                                                            SHA-256:9AC130DCF86390701CC3A6C3551DD925360173CD59AC5ACE698BDEAB98309A67
                                                                                                                                                                            SHA-512:1A46ABD016A1A7F3061E293FF0DED137509F6036C4363430D17107D9E26F8914D84DBA4634B3B0CB4A112D5E23594FB8670C2E8E0D0CFF4BA002AEEA32748FB6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "......",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "................",.. //{0} - Company name.. THANK_YOU: "{0}....................",.. INSTALL: "......",.. CANCEL: ".....",.. RETRY: "...",.. DONE: "..",.. //{0} - Product name.. PROGRESS_TITLE: "{0}......................... .........",.. PROGRESS_SUBTITLE: "..........",.. COMPLETE_TITLE: "................ ..... ..................",.. COMPLETE_SUBTITLE: ".......",.. COMPLETE_LAUNCH: "........",.. ERROR_OS_REQUIREMENTS: "........ .....................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2982
                                                                                                                                                                            Entropy (8bit):5.847345330966997
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:34HjWMme4EaOYIc1TK1adfNDmI6DugabURx8B9HU5KzpJI6iUs/JAgPiX5NKt:346M3FadIc1+1cfRyDFfRqBRU5KzpJpy
                                                                                                                                                                            MD5:39F3D2B27B66D5E6956963328124B8D3
                                                                                                                                                                            SHA1:D85D5BFB9BF91E7AF751803F092E8F416D921EA9
                                                                                                                                                                            SHA-256:7C4AFC7091B859A02BAE6084CC2A3D1D2EFAB4CE39A544E0417136082EAB0203
                                                                                                                                                                            SHA-512:BB5550C76BBD499B7B9073EF2BA066D71F65E1B8BD834C57B7F431A4ADF5C4E723625DA1246598A37BF106CB4CE043FC2EBB819B0A941917366397D55A7627D0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: ".... ..",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: ".... ... .. .....",.. //{0} - Company name.. THANK_YOU: "{0}.(.) ... ... .....",.. INSTALL: "..",.. CANCEL: "..",.. RETRY: ".. ..",.. DONE: "..",.. //{0} - Product name.. PROGRESS_TITLE: "{0}.(.) .. .... .. .. .. ... .......",.. PROGRESS_SUBTITLE: ".. ....",.. COMPLETE_TITLE: "....! .. ... .... .......",.. COMPLETE_SUBTITLE: ".. ..",.. COMPLETE_LAUNCH: ". .... ..",.. ERROR_OS_REQUIREMENTS: ".. ... .. ... .. ... .... .. ... ... . ..... ...... .. ......",.. ERROR_BROWSER_REQUIREMENTS: "..... .. ... .. ... .... .. ... .
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2722
                                                                                                                                                                            Entropy (8bit):5.303037907360488
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3795wot+OdOcWOEYoIOtl9IcBVF/qFSfE88QIwUueoIJhGduaT+G9hykWYYrzr9g:37Z+OZSFJNIaVFCFSfE2IwS885ZrzrKX
                                                                                                                                                                            MD5:325FDF0453BC217006C5EBD8E937EF2E
                                                                                                                                                                            SHA1:690B0339939946FC8A66E7BC3888B47132012E2D
                                                                                                                                                                            SHA-256:AE6C759B42D34C6900489EA3B5FCD57692737B522F7126BE814B576FB55B37CD
                                                                                                                                                                            SHA-512:12A146E232D234843A59404C287D78E1F9CCDFBC6A6BDA982E705EA9AAEAAC847A9C8CBA6FBC6ACA13AF16EC643F14D3A9E852B1AA25E6ED95879D3110B64703
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Lisensavtale",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Jeg har lest og godtar lisensavtalen",.. //{0} - Company name.. THANK_YOU: "Takk for at du valgte {0}.",.. INSTALL: "Installer",.. CANCEL: "Avbryt",.. RETRY: "Pr.v p. nytt",.. DONE: "Ferdig",.. //{0} - Product name.. PROGRESS_TITLE: "{0} er din personlige sikkerhetsr.dgiver uansett hvor du g.r p. nettet.",.. PROGRESS_SUBTITLE: "Installerer ...",.. COMPLETE_TITLE: "Flott! Vi har installert din personlige nettr.dgiver",.. COMPLETE_SUBTITLE: "Du er klar",.. COMPLETE_LAUNCH: ".pne nettleseren min",.. ERROR_OS_REQUIREMENTS: "Installasjonen kan ikke fortsette fordi operativsystemet ikke oppfyller minimum systemkrav. Oppdater det, og pr.v p. nytt.",.. ERROR_BROWSER_REQUIREMENTS: "Installasjonen kan ikke fortsette fordi nettleseren ikke oppfyller minimum systemkrav. Oppdater nettleseren, og pr.v p. nytt.",.. ERROR_VERSION: "Du har allere
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2834
                                                                                                                                                                            Entropy (8bit):5.221829835796673
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:34+VvRiGOx7kopCe4I2RjEY5n40w7TI3k7+WxXDk7+xIXrf24+5N7XR7lnw2IuXU:3nVSw7tRAOjiI3WrxXDWmIXrfw5VhnBk
                                                                                                                                                                            MD5:D406EAF5B9CBBB2546618F3D626A2970
                                                                                                                                                                            SHA1:D149C8916B9820AF6256E57FA6521DA63A063418
                                                                                                                                                                            SHA-256:AB6A945EDDBD05644903E5465FAC344C675DCFF1BF749FD02D4D134C2FDD643E
                                                                                                                                                                            SHA-512:E8C6A03DD0A2C6DCCF28C34EC9E6D6C66F06524F6FC554600C99C68AA75E70A06C0CBB650A88B6DA2ED753B7F7F05FE63A4AA69C2D6A3DE94ACDE8E2B422ED5F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "licentieovereenkomst",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Ik heb de licentieovereenkomst gelezen en ga ermee akkoord.",.. //{0} - Company name.. THANK_YOU: "Bedankt dat u hebt gekozen voor {0}",.. INSTALL: "Installeren",.. CANCEL: "Annuleren",.. RETRY: "Opnieuw proberen",.. DONE: "Klaar",.. //{0} - Product name.. PROGRESS_TITLE: "{0} is uw persoonlijke veiligheidsadviseur, waar u ook online bent.",.. PROGRESS_SUBTITLE: "Installeren...",.. COMPLETE_TITLE: "Fantastisch! Wij hebben uw persoonlijke online adviseur ge.nstalleerd.",.. COMPLETE_SUBTITLE: "Klaar om aan de slag te gaan",.. COMPLETE_LAUNCH: "Open mijn browser",.. ERROR_OS_REQUIREMENTS: "Uw installatie kan niet doorgaan omdat uw besturingssysteem niet voldoet aan de minimale systeemvereisten. Werk het bij en probeer het opnieuw.",.. ERROR_BROWSER_REQUIREMENTS: "Uw installatie kan niet doorgaan omdat uw browser niet voldoet aan onze min
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2823
                                                                                                                                                                            Entropy (8bit):5.563972162117738
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3dGFMW2pQHsBEbkZoNIGzxS5zXwWfeZOrma+1FKHZZ8ziDwThXiQLN3VzlzI77R5:3dGc+HbwZQIySBwWfeGmV8HZchyUNFzu
                                                                                                                                                                            MD5:609E78D49DA067E287FC7252C23C27A7
                                                                                                                                                                            SHA1:721E3387F38D84C1438FF57D2EC7C9BAC7A317B4
                                                                                                                                                                            SHA-256:FE7EB51C80968E5C1F92336EF132EC12AB27FECCD3BF0DC4AB87E80268334A97
                                                                                                                                                                            SHA-512:EB856F23E0152D43A411CC45A1CD4B56E84D5D8016C1EB549FC90D43C1668C005A191C7710ACF61DB2A32B2D341A4629BD3663A0538361281049D2228079D6FC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Umow. licencyjn.",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Znam i akceptuj. Umow. licencyjn.",.. //{0} - Company name.. THANK_YOU: "Dzi.kujemy za wybranie produktu {0}",.. INSTALL: "Zainstaluj",.. CANCEL: "Anuluj",.. RETRY: "Spr.buj ponownie",.. DONE: "Gotowe",.. //{0} - Product name.. PROGRESS_TITLE: "{0} to Tw.j osobisty doradca ds. bezpiecze.stwa w Internecie.",.. PROGRESS_SUBTITLE: "Instalowanie...",.. COMPLETE_TITLE: ".wietnie! Zainstalowali.my Twojego osobistego doradc. w Internecie.",.. COMPLETE_SUBTITLE: "Gotowe",.. COMPLETE_LAUNCH: "Otw.rz przegl.dark.",.. ERROR_OS_REQUIREMENTS: "Nie mo.na kontynuowa. instalacji, bo system operacyjny nie spe.nia minimalnych wymaga. systemowych. Uaktualnij go i spr.buj ponownie.",.. ERROR_BROWSER_REQUIREMENTS: "Nie mo.na kontynuowa. instalacji, bo przegl.darka nie spe.nia minimalnych wymaga. systemowych. Uaktualnij j. i spr.buj p
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2789
                                                                                                                                                                            Entropy (8bit):5.3016062340489984
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3wJinI7w56E8GjaIrKc2NfOe6zLZIlS+LuV5eEHHW6zFVI1rJqPTZ6XJfaoMym4D:3y7a1jaIrOfJgLzPHHHW6z3aJqPd6ZS6
                                                                                                                                                                            MD5:775D02E62D343C8AF21F50328C759CC7
                                                                                                                                                                            SHA1:1F976C75FB8425AB61CF1D66527C34E41019CB71
                                                                                                                                                                            SHA-256:072785166431B8CFD6744F1583A8D0ECF275854EC4EBDE6B851DD8AAF19371CE
                                                                                                                                                                            SHA-512:AFF7467FF93B4DF13519DEA1E2363D84B90C427F1DED6F6D43AA4C6123B33C88CAAB8999AA6A6709DCBC7B7550BAB368D3B190E425B6DAEC0FA5647CFFE9BD41
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Contrato de licen.a",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Eu li e concordo com o Contrato de licen.a",.. //{0} - Company name.. THANK_YOU: "Agradecemos por escolher o {0}",.. INSTALL: "Instalar",.. CANCEL: "Cancelar",.. RETRY: "Tentar novamente",.. DONE: "Conclu.do",.. //{0} - Product name.. PROGRESS_TITLE: "{0} . seu assessor pessoal de seguran.a sempre que estiver online.",.. PROGRESS_SUBTITLE: "Instalando...",.. COMPLETE_TITLE: "Excelente! Seu assessor pessoal online est. instalado.",.. COMPLETE_SUBTITLE: "Pronto para come.ar",.. COMPLETE_LAUNCH: "Abrir meu navegador",.. ERROR_OS_REQUIREMENTS: "N.o . poss.vel continuar a instala..o porque o sistema operacional n.o atende aos requisitos m.nimos de sistema. Atualize-o e tente novamente.",.. ERROR_BROWSER_REQUIREMENTS: "N.o . poss.vel continuar a instala..o porque o navegador n.o atende aos nossos requisitos m.nimos de sis
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2834
                                                                                                                                                                            Entropy (8bit):5.285322036631864
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3T1cnI7wb1EbiIvQdKVvNfwSe6GfIeTnL+LdbeEsa5cztlI1rJqPFqWruD6NnqBL:3TZ7IubiIvQdUlfKFiHsa5czPaJqPFqf
                                                                                                                                                                            MD5:C7052BCD40A05D0A3C7F0EE4B23D4420
                                                                                                                                                                            SHA1:109A90360C15D73BFC1F1830419EBCBFA070E8D4
                                                                                                                                                                            SHA-256:DEDE2191F3B5936FC69D10FDF61C0D71B22486055BC68E5B4F7655025B19BFAA
                                                                                                                                                                            SHA-512:E9D0A62C150920F2BDFD7E1E7D18875D9E85A90D24CC01FA961EDAA57893450A67A5F866D5626F8F5FE9767A59E0FA48E22D8FBB482CB94C57FC0B9DE7E79146
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "contrato de licen.a",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Li e aceito o contrato de licen.a",.. //{0} - Company name.. THANK_YOU: "Agradecemos por escolher a {0}",.. INSTALL: "Instalar",.. CANCEL: "Cancelar",.. RETRY: "Tentar novamente",.. DONE: "Conclu.do",.. //{0} - Product name.. PROGRESS_TITLE: "{0} . o seu consultor de seguran.a pessoal onde quer que navegue online.",.. PROGRESS_SUBTITLE: "A instalar...",.. COMPLETE_TITLE: ".timo! Instal.mos o seu consultor pessoal online.",.. COMPLETE_SUBTITLE: "Pronto para come.ar",.. COMPLETE_LAUNCH: "Abrir o meu browser",.. ERROR_OS_REQUIREMENTS: "N.o . poss.vel continuar a instala..o porque o seu sistema operativo n.o cumpre os requisitos m.nimos do sistema. Atualize-o e tente novamente.",.. ERROR_BROWSER_REQUIREMENTS: "N.o . poss.vel continuar a instala..o porque o seu browser n.o cumpre os nossos requisitos m.nimos do sistema.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4105
                                                                                                                                                                            Entropy (8bit):4.975608303898123
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:30u/iNM+4IOq/knqwkXf2EAaKOTLvl8szDmSXyD+X2h:30u/2MNjLnUP2Zb2GszDmSXyCXg
                                                                                                                                                                            MD5:4DD96DA7415A652A5E484DC6239782CF
                                                                                                                                                                            SHA1:6208329EDEEC28D151D9E5800115A3F81BA816A2
                                                                                                                                                                            SHA-256:66A056646393A313C24FB488886376E7B361407CD348C2E7B1EE8254CF2576BB
                                                                                                                                                                            SHA-512:685EDA453DBD36C9A6120B80AF39D0B7EBDDA81A9BCBABDEE52AD6650F830AA6E235FE31ED4A61FD8B20E9BE25BBDB90AC39766C608EB3ADADEEE679664FAD6C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "............ ..........",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: ". ........(.) . ........ ............ ..........",.. //{0} - Company name.. THANK_YOU: ".......... .. ..... {0}",.. INSTALL: "..........",.. CANCEL: "......",.. RETRY: "......... .......",.. DONE: "......",.. //{0} - Product name.. PROGRESS_TITLE: "{0} . ... ... ...... ........ .. ............ . ..........",.. PROGRESS_SUBTITLE: "............",.. COMPLETE_TITLE: ".......! .. .......... ...... ........ .. .............",.. COMPLETE_SUBTITLE: "... ......",.. COMPLETE_LAUNCH: "....... .......",.. ERROR_OS_REQUIREMENTS: "......... .. ..... .... .........., ... ... .
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2909
                                                                                                                                                                            Entropy (8bit):5.626133730858778
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3KUWqz7ZZceEHrdNIzNUAuvAKf+EGAzo+93L08AwF7ERm4502zLzIPJicLhqaX4U:3K/AZeH3IzNUAuvAKf+EGAs+JL08AIwO
                                                                                                                                                                            MD5:9F16073EC6F27264D8157CA0C6BAC3FF
                                                                                                                                                                            SHA1:02A8694638AA2DDA4E30848821E175479C4E7588
                                                                                                                                                                            SHA-256:4AEDFE6AF187A36A25F824C5C3819D6FED03AF76C4B722AF4772F90BACF1FF86
                                                                                                                                                                            SHA-512:E852A1F712DA32FB30CC79FE0D33CE57430B4CA59936824D55A2F2FE1167959774FDC9634EE7BEC7C84965F68495CCE24DCAA1BB6D85D2B90406782D1285CA7C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Licen.n. zmluva",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Pre..tal(-a) som si dokument Licen.n. zmluva a.s.hlas.m.s n.m",.. //{0} - Company name.. THANK_YOU: ".akujeme, .e ste si vybrali {0}.",.. INSTALL: "In.talova.",.. CANCEL: "Zru.i.",.. RETRY: "Sk.si. znova",.. DONE: "Hotovo",.. //{0} - Product name.. PROGRESS_TITLE: "{0} je va..m osobn.m poradcom v oblasti bezpe.nosti, kdeko.vek sa pripoj.te na web.",.. PROGRESS_SUBTITLE: "In.taluje sa...",.. COMPLETE_TITLE: "V.borne! Nain.talovali sme v..ho osobn.ho online poradcu.",.. COMPLETE_SUBTITLE: "M..ete za.a.",.. COMPLETE_LAUNCH: "Otvori. m.j prehliada.",.. ERROR_OS_REQUIREMENTS: "Va.a in.tal.cia nem..e pokra.ova., lebo v.. opera.n. syst.m nesp..a minim.lne syst.mov. po.iadavky. Aktualizujte ho a sk.ste to znova.",.. ERROR_BROWSER_REQUIREMENTS: "Va.a in.tal.cia nem..e pokra.ova., lebo v
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2792
                                                                                                                                                                            Entropy (8bit):5.357366308263878
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:31hpQU1rGGEji4oL8BI7J2wEfD/f6zRlce+ISDO4MERSeXlzd5iLIXQ5T7H5OWQj:35b1WjBACI7ItfD/fojmIKYENVzd566v
                                                                                                                                                                            MD5:D7BCA954858CFDD077B87175B015B529
                                                                                                                                                                            SHA1:C2209D10757A7646B21951981A4DD1ADE40CBE7B
                                                                                                                                                                            SHA-256:21CA8FC0D87338E407A5BF3966F0385979993BBE4F42390201BC1366E6E07EA9
                                                                                                                                                                            SHA-512:B02BE531DD0D55261969C95EDDEB2FB431E1C5D302A8BEB692DBB36933904383F48EE08FA0CAE66AB521ADEEC541777327865D67FFA2DA7C76E4056E0462DCA6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Ugovor o licenciranju",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Pro.itao sam i saglsan sam s Ugovorom o licenciranju",.. //{0} - Company name.. THANK_YOU: "Hvala .to ste izabrali {0}",.. INSTALL: "Instaliraj",.. CANCEL: "Otka.i",.. RETRY: "Poku.aj ponovo",.. DONE: "Gotovo",.. //{0} - Product name.. PROGRESS_TITLE: "{0} je va. li.ni savetnik za bezbednost gde god da ste na mre.i.",.. PROGRESS_SUBTITLE: "Instaliranje...",.. COMPLETE_TITLE: "Odli.no! Instaliran je va. li.ni savetnik za bezbednost",.. COMPLETE_SUBTITLE: "Spreman je",.. COMPLETE_LAUNCH: "Otvori pregleda.",.. ERROR_OS_REQUIREMENTS: "Instalacija se ne mo.e nastaviti jer operativni sistem ne ispunjava na.e minimalne sistemske zahteve. A.urirajte ga i poku.ajte ponovo.",.. ERROR_BROWSER_REQUIREMENTS: "Instalacija se ne mo.e nastaviti jer operativni sistem ne ispunjava na.e minimalne sistemske zahteve. A.urirajte pregled
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2700
                                                                                                                                                                            Entropy (8bit):5.360820792263823
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3pdCODtNYC/mqEYcQdE9IcaF8kFFafEoGyIucFI4Xc3+NqYk7svff0ozg2IfGETU:3JROLieInFhFafEojIvn3fvzrCRZNsrJ
                                                                                                                                                                            MD5:B553D7133C80C6AB93BF33A7DB0E65CA
                                                                                                                                                                            SHA1:0670C14B53E7D362EF19F35C18095D43258E23E2
                                                                                                                                                                            SHA-256:4D9CD0727E42F367AC9720FF1BEA9EA32062D09294C973B54B57050C05E4FFD5
                                                                                                                                                                            SHA-512:D06743CEDD5CDB6E98F1768DBC425550110D858A904828231591AB71EA9A2C6728EE75239CC7E2C411F2E993337F5C69B1FA33D82D5395DC24753915702E3622
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "licensavtalet",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Jag har l.st och godk.nner licensavtalet",.. //{0} - Company name.. THANK_YOU: "Tack f.r att du v.ljer {0}",.. INSTALL: "Installera",.. CANCEL: "Avbryt",.. RETRY: "F.rs.k igen",.. DONE: "Klart",.. //{0} - Product name.. PROGRESS_TITLE: "{0} .r din personliga s.kerhetsr.dgivare var du .n kopplar upp dig.",.. PROGRESS_SUBTITLE: "Installerar ...",.. COMPLETE_TITLE: "Toppen! Vi har installerat din personliga internetr.dgivare.",.. COMPLETE_SUBTITLE: "Allt .r redo",.. COMPLETE_LAUNCH: ".ppna i webbl.saren",.. ERROR_OS_REQUIREMENTS: "Installationen kan inte forts.tta eftersom operativsystemet inte uppfyller systemkraven. Uppdatera det och f.rs.k igen.",.. ERROR_BROWSER_REQUIREMENTS: "Installationen kan inte forts.tta eftersom webbl.saren inte uppfyller systemkraven. Uppdatera webbl.saren och f.rs.k igen.",.. ERROR_VERSION:
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2936
                                                                                                                                                                            Entropy (8bit):5.4922221769296184
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3DdrZpFTox8fYCPZEpdhp0IW+AVJBn+AWuzfNLFnsZFfB9mpFA8lLgMs/U4oXMoN:3JZToKnKpdheIWtr+uzfvsTfTGacLXz5
                                                                                                                                                                            MD5:18A69E3CA3CA0156A63A1DFBE77D4F29
                                                                                                                                                                            SHA1:ECA17161D2AD2642AC9103107009275945113340
                                                                                                                                                                            SHA-256:A931E05C2614D3739472F9DD6F252A860BD8EFF5C65476427D3FFB388BCFBB7C
                                                                                                                                                                            SHA-512:175C2C45C6E178C034D8419DA14BD77F4878ACD0B242F74BB5AA8B4FAF3D8A25B854E7E1C6ACF8D71573D23FBBB8899B13FED05B2A47C7598E51DEC6340B4FE3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "Lisans S.zle.mesi",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: "Lisans S.zle.mesini okudum ve kabul ediyorum",.. //{0} - Company name.. THANK_YOU: "{0} .r.n.n. tercih etti.iniz i.in te.ekk.r ederiz",.. INSTALL: "Y.kle",.. CANCEL: ".ptal",.. RETRY: "Tekrar Deneyin",.. DONE: "Bitti",.. //{0} - Product name.. PROGRESS_TITLE: "{0}, .evrimi.i oldu.unuz her yerde ki.isel g.venlik dan..man.n.zd.r.",.. PROGRESS_SUBTITLE: "Y.kleniyor...",.. COMPLETE_TITLE: "M.kemmel! Ki.isel .evrimi.i dan..man.n.z. y.kledik.",.. COMPLETE_SUBTITLE: "Haz.r",.. COMPLETE_LAUNCH: "Taray.c.m. a.",.. ERROR_OS_REQUIREMENTS: "..letim sisteminiz minimum sistem gereksinimlerini kar..lamad... i.in kurulumunuz devam edemiyor. L.tfen g.ncelleyin ve tekrar deneyin.",.. ERROR_BROWSER_REQUIREMENTS: "Taray.c.n.z minimum sistem gereksinimlerimizi kar..lamad... i.in kurulumunuz devam edem
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2349
                                                                                                                                                                            Entropy (8bit):6.290274114517677
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3oWfvFbBReTE4anI7mO8VDfA9lwVooJy17QGYDV5zzIG+b7jyW1XoUW:3oWHrR34anI7mO8VDfA9lMTocGu7zzzN
                                                                                                                                                                            MD5:2CCA1854019AAD327B3FABE1000E9BEF
                                                                                                                                                                            SHA1:59A26CCDD6327DDDC4C02650171177A27E771452
                                                                                                                                                                            SHA-256:4E07338BAAA7C846DA5FECB9680BFF445E7701B143BD2025A55A04F58EA0379F
                                                                                                                                                                            SHA-512:731086276C68E129023B444192F151855158B84E0542F112849082F911D58F6E632C32E147507D25C60E003D5564EFA2E3EBA1FFD18DEF475F64BDCBDAF8F2B5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "....",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: ".............",.. //{0} - Company name.. THANK_YOU: ".....{0}",.. INSTALL: "..",.. CANCEL: "..",.. RETRY: "..",.. DONE: "..",.. //{0} - Product name.. PROGRESS_TITLE: "{0}............",.. PROGRESS_SUBTITLE: ".....",.. COMPLETE_TITLE: "....................",.. COMPLETE_SUBTITLE: "....",.. COMPLETE_LAUNCH: ".......",.. ERROR_OS_REQUIREMENTS: "................................",.. ERROR_BROWSER_REQUIREMENTS: "................................",.. ERROR_VERSION: "..................",.. ERROR_FAIL: ".............
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2522
                                                                                                                                                                            Entropy (8bit):6.318470816194378
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3wPuvnWuIBAezE3esIo5M++fI/lYjfGFsjL7F9f9tz3JIeqWaGUnfAr5hTD:3wUwAv3FIL++fI/l0f7F9f7z5jqWofA3
                                                                                                                                                                            MD5:306CB62C14A658C9E25B72926B0585D7
                                                                                                                                                                            SHA1:B97A542503E581BA545574FA0C0A5B1CE658F9D8
                                                                                                                                                                            SHA-256:42E2F61873BD8A7F6A03B76C68955A3D0D701313AD773B32AF802240968872BF
                                                                                                                                                                            SHA-512:EFD763788B1D991A7ECEC1B77353C1455EB9376A0D961D4069968C6D5471612329FF88E052806FEB42DD09A01BF7CD82701E010EFABAA53149DC0BDB1957A55A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrInstall_ = {.. EULA_TITLE: "....",.. EULA_CONTENT: "",.. EULA_TERMS_AGREE: ".............",.. //{0} - Company name.. THANK_YOU: "..... {0}",.. INSTALL: "..",.. CANCEL: "..",.. RETRY: "....",.. DONE: "..",.. //{0} - Product name.. PROGRESS_TITLE: "{0} .....................",.. PROGRESS_SUBTITLE: ".....",.. COMPLETE_TITLE: "..................",.. COMPLETE_SUBTITLE: "....",.. COMPLETE_LAUNCH: ".....",.. ERROR_OS_REQUIREMENTS: "................................",.. ERROR_BROWSER_REQUIREMENTS: "...............................",.. ERROR_VERSION: "................",.. ERROR_FAIL: ".........
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):716
                                                                                                                                                                            Entropy (8bit):5.6123995105579825
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfx6v9LuO4biqra6fMocbkLwT5zxjAHo8+9wuRToEwCWHmlva:7e9SlNLiaf4v9KO4zG6fMocWIOHo8+9G
                                                                                                                                                                            MD5:00F4E38B48072F3869B60E0D95C2A9B6
                                                                                                                                                                            SHA1:C8CE5CA8F175008CCBEC78275E757F62FE9C635A
                                                                                                                                                                            SHA-256:C2D22278512E32727CB434EA10F23C86AE9C08CAF0AE4DAB02F02FCB1041BB99
                                                                                                                                                                            SHA-512:64429F44AD0594E529C1C4CE9FFB87981790E67BAAF4CA3E704FE13C2BAE720E602E9ED2D74F3E9664A91EC6B3C1524070137732798EB8B4E830996379C3C16D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verze",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Prohl..en. o ochran. osobn.ch .daj.",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Hotovo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//7915940C39986F4880E6A2FBC9737543635F5A1D110ED6E3AFFDAFAB149C5AFF1703FFC9466951316626F1FBB58178AEBD100D0078DABFC21D0714D0CEEA119F++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):728
                                                                                                                                                                            Entropy (8bit):5.552900854514872
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4biUvzbkLwT5zxjAHo8wN9wuRTo6NHMxracRckCdXt:7e9SlNLiafLYFv9KO4Z7WIOHo8wN9ZR/
                                                                                                                                                                            MD5:B2C903C076A41A1737DB816018633A98
                                                                                                                                                                            SHA1:FAD0008D1C2D4713239C3D9058685919F656B7AD
                                                                                                                                                                            SHA-256:F525F6EAF3880731B179D85B090C0632DA0D913FC84E5E3F98071AF276259F55
                                                                                                                                                                            SHA-512:95283B3B641A234A122386A6E7D1D8358FD5AC67F1F72262E53B028A5927B12EAF501A2D4E4B45A14014D96CAE69C0E514540CEA80686F1696901E609E14E805
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "meddelelse om beskyttelse af personlige oplysninger",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "F.rdig",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//514C43E98B794D2AC98CC2A39D1794688A93B8FE872BF50CB063364579F1BEA8C13AEB945A186AC919AC0B33B114C4CDF8877E143AD3B5EDF237023A807AE010++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):695
                                                                                                                                                                            Entropy (8bit):5.549081746702864
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4bi+p3ibkLwT5zxjAHo8+N9wuRToEKQw/Fht:7e9SlNLiafLYFv9KO4pSWIOHo8+N9ZRQ
                                                                                                                                                                            MD5:D758E0A6DA482AE0EEB46E0B8A65C9CD
                                                                                                                                                                            SHA1:7945EA60F5AFC84819283037B2FF493CB8224C5E
                                                                                                                                                                            SHA-256:14F8DB188A0130B264D3A34D0ADD757FD1BE3C5A5E02E581BC0A9D578F736B87
                                                                                                                                                                            SHA-512:E93EB661D24C40DD2375B521B256EE9F3CAE01868E261B2F4ECA39CF8BE37C7C0120097DAA365B8F5503D0388FA70E8E26E1F795E27E0BA903BC5444FEF2E55E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Datenschutzhinweise",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Fertig",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//9F9083EA4FDED455F3A23B016952128F280E9BB91D2498BDFC250400DD82FD928136390AEA869B7A1C014FE3C0760121E9800361A5837B39456C1EDC9746BEF2++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):750
                                                                                                                                                                            Entropy (8bit):5.77117399690753
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kft6v9LuO4bi7XKfRWkGmbkLwT5zxjAHo8JP9wuRTol6VFB:7e9SlNLiafEv9KO4mXCWkHWIOHo8JP9t
                                                                                                                                                                            MD5:1C8FFEDEC34AB60D998C996AC7D55462
                                                                                                                                                                            SHA1:58B78A462590B78A421024E70D4CF89434AA7BC1
                                                                                                                                                                            SHA-256:CBCB9411E7947D6483DF5E05D967C9531AAAA0CA3F233E86994247818540CA5E
                                                                                                                                                                            SHA-512:83A500DDD5064EC74808E28A1544862D47FA42188E0AD57B22E0241529147261DA4AF60017EFF000ADBF88E307A6FA56C78963D73AC9A6B2536E2FD2B9D81D56
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "......",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "...... ............ .... .........",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: ".....",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//D7F2DA34F1B7920CDF501DA892A6EF4E0F0482D5B374A1842AA59B4D81D84459C21E6F05926E192B86431EBB5037EB33BDA11B0E22308710E9627D7E7BBDD102++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):688
                                                                                                                                                                            Entropy (8bit):5.487912643529434
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4biqkCbkLwT5zxjmT9wuRTo/upmkI2uDiSRgC:7e9SlNLiafLYFv9KO4zkCWIoT9ZRRIk8
                                                                                                                                                                            MD5:CC46B4069EB88FCA4183A1802345E488
                                                                                                                                                                            SHA1:06D6CABDCD0E67EBE402C81E12963AA00E04E799
                                                                                                                                                                            SHA-256:ADF2EC9276CD96BAA46E217DCE9586664C7DFFA22986B26596AC985D3E0C3903
                                                                                                                                                                            SHA-512:1DD44483C0ACF7442FE1DAADF0FD3256C1099EBF63265984CEC610F8811CEAE867A1081D8BB8B9B801E08BDE0E8D7E265BA4A36536B0E47FC000E262F23B8848
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Privacy Notice",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Done",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//93ECAFC6B6FA905461032E6E8DB4729D2263C0306E689F6F2ED8EBDE9DEEB34B003A93CD10F9DA8B1526F7017FC0F77DFDA6CAA0F0FEE67BE1F16FE012A4EE93++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):700
                                                                                                                                                                            Entropy (8bit):5.5223212774827966
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfri6v9LuO4bicmuXnbkLwT5zxjcglP9wuRTo2XZwfIuN1gC:7e9SlNLiafrFv9KO40AnWIqgV9ZRFQf
                                                                                                                                                                            MD5:54A4EB2032797DD5698E222029700740
                                                                                                                                                                            SHA1:2F7E07CEB0295F3239CE8F12E8A9D40277CDD301
                                                                                                                                                                            SHA-256:30055D95C0B902C93AA58EDB2743B19D928212C2F7549148E79EFAA99E263BF9
                                                                                                                                                                            SHA-512:C05E874A388172D7CD8921F4C1F9D61AC8F03D0EB53EC4CDB0ECB530461264A948560B949FE6416BEA2077440AA44F0B60F0BB0C19A986F042433E2C141CE8C6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versi.n",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Aviso de Privacidad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Aceptar",.. DONE: "Listo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//D637B12E35A4ABAF510C98358FC89098EE8C5F537636E86A2E74A59998CBCCEADD062E0D121A282C7F190C2006C9FEF1A0F154606AF95776592B825C8C802D02++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):700
                                                                                                                                                                            Entropy (8bit):5.537604554770778
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfri6v9LuO4bicmuXnbkLwT5zxjcglP9wuRTo6mVa4V9ncmIv:7e9SlNLiafrFv9KO40AnWIqgV9ZR1QfA
                                                                                                                                                                            MD5:AB2324AA7C6A311DC97B36ADA22046CF
                                                                                                                                                                            SHA1:5932FD81A2126A13F7C03910E68744C7F41DE394
                                                                                                                                                                            SHA-256:A7D4654BAE3D149D345A887A7892962793D061C9E755F251A7D19C2F564B939B
                                                                                                                                                                            SHA-512:E538DACA1AED4E6B3273DD1388B7A0FA576CD3ABDF156DCF6C3D816F14B7516711724C77E1C98E2B672981E32558CB7DFE4E4850A634F6C021BFE84BEF1EC267
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versi.n",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Aviso de Privacidad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Aceptar",.. DONE: "Listo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//1496EF941B55F4BF4FF8C580A2561563C6BC322E226844D8B8F8BACF0FBFDA7F6BA401BFB844DE187768CB4BE50BA3807F79D92D3D499CA70EB86A09479E101D++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):694
                                                                                                                                                                            Entropy (8bit):5.5173328903737
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfft6v9LuO4biO6EGbkLwT5zxjAHo88WN9wuRTo8M9DEXW+A29dC:7e9SlNLiafsv9KO43GWIOHo8Z9ZRnS+Q
                                                                                                                                                                            MD5:2EFAA2FE73F61AAA9575F06A7EE25AAA
                                                                                                                                                                            SHA1:28DB2864BC91CFEC0F615800C7C48D0954F8DE61
                                                                                                                                                                            SHA-256:3D65ACAD9615F07267279B3C6EF547C033D37B1F55E9F393BA5F07149BF158ED
                                                                                                                                                                            SHA-512:57D8821F7C5EFA9B630E3CB0A9CFB51E0A1BC81D8FBCECB0595FA2373B3B8AC488717516EDBE4DF07E83D372E73341BD04A3907745D7AB5C08100FE9141B5E67
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versio",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "tietosuojaselosteen",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Valmis",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//592438C477D7D5A0FCDE0A4ABEEC1E61160F3ADB96ED593D2336CB7F85A5D7ED20530ED0297802AE44966CA63AEC0B0D86E87CCF49CB09DA32283990C5157737++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):710
                                                                                                                                                                            Entropy (8bit):5.571075904252609
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4bieQdbkLwT5zxjAHo8g9wuRToHcONXKvL+u9vFJ:7e9SlNLiafLYFv9KO4wdWIOHo8g9ZR2Y
                                                                                                                                                                            MD5:B1FEF06E6DB7C7840355CFDC9E66DFA9
                                                                                                                                                                            SHA1:1A72F5525215F467F2687052C1C107143BFBC497
                                                                                                                                                                            SHA-256:CA51CECD55303BF09C0F9E0E8285419EED57BB2E457E906FDC06763F1AABE64A
                                                                                                                                                                            SHA-512:0D3A8FC6D51795EBD7116CF30FE7371A01ABAC64D898045EA8BF1E22C975E2E805B9ABF2B51BCD9B12A10CC56941320869E63A818DBAEAA72764010251757171
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "d.claration de confidentialit.",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Termin.",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//E31462AD7B349988780C04B0BC7C8C4421A8A65C2B0267E5BA72FC3F8BB7278C1889AB97283D655440681525FC18608C9BF44C79B9E6B01A384AB197AD90FD4C++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):710
                                                                                                                                                                            Entropy (8bit):5.544187033409281
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4bieQdbkLwT5zxjAHo8g9wuRTompOE6pzxcgRg:7e9SlNLiafLYFv9KO4wdWIOHo8g9ZRHN
                                                                                                                                                                            MD5:81FF80E529C769AECE9D98592D14A500
                                                                                                                                                                            SHA1:88D9EC34A3852BB8577FDC4ED89AD71A79862F5C
                                                                                                                                                                            SHA-256:98DDF02B185AC2036F8EBBB6ADF9C7B4FA14FC8CA9FBD19B7FFBFEA3770977F4
                                                                                                                                                                            SHA-512:24C932AD5D51E1B014E8BBB5371104884EC3A20530F8D6653F28D6F52F2571A2ACDF70D803EF12FA7D974DD3907632676F0BEBA0CB679D46E46D3AB7B9B3CCE7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "d.claration de confidentialit.",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Termin.",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//6272E90B87E22993E4A9C7AFBD1EA5F6E826D3D603124F3F6DA42CB6FD6A7CA04857CE3220935E918503D17C26ED9CE2AD48B2A2C83030EBCF9BE923DD91B71E++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):703
                                                                                                                                                                            Entropy (8bit):5.5270598050887205
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfv66v9LuO4biaBzcbkLwT5zxjHT9wuRTo4jRF4zOAkE4XG0:7e9SlNLiaflv9KO43BoWIVT9ZR774zhK
                                                                                                                                                                            MD5:7AAE3B6206C930CD459C11C26F120447
                                                                                                                                                                            SHA1:9B5AE66FBDE3B0E7AD58C1D69A7DAF40AACEDC67
                                                                                                                                                                            SHA-256:8DCD9C2FB5873BB4F522C9E8209A0CD93242C1B1B47EC53166E2E03355668E1D
                                                                                                                                                                            SHA-512:47977AC2A48626E4500E7E8A84E9843FF2C7CF5CC403AC58629B13D0DFA288BE320A48436332D0AC2FEF97D7959F14BE2DDFBB50FA35516C03070E56A694DDA3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verzija",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Obavijest o privatnosti",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "U redu",.. DONE: "Gotovo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//C5921FB8FE54F0C9BADA85486599B32A165D30DEEA2DDBC8609E4045DAA88AD032F6AB1D073C3AEC92DB86343CB0733C39A62CA3F84D756E6E086481CE8F7AAF++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):699
                                                                                                                                                                            Entropy (8bit):5.578115457562142
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfQdU6v9LuO4bihIHmdcbkLwT5zxjAHo8Kwv9wuRToXaaMM:7e9SlNLiafQd7v9KO4k6ocWIOHo8Kwvw
                                                                                                                                                                            MD5:BEB5960C719B090AA684968F630B674F
                                                                                                                                                                            SHA1:30F3214BFE12A27A84BDC14446F4F57AF96E46B9
                                                                                                                                                                            SHA-256:3851B97C8DBCFE1A9E85AB1B712E3F4B8388BFD7EC665211C83D66A59C5A8772
                                                                                                                                                                            SHA-512:33E3874AF7AD6186532F1B5EC90156287C3D73837183EE4934D7919AA8A43145DFC6413840782E759E8B65211673AE3A8794DA424EC9B565875CEA709D6AD17F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verzi.",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Adatv.delmi k.zlem.ny",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "K.sz",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//0D63EE19641986D9D825A8C5134A9CE24F11402D1E1B0E33B2454ACB50E4A62EF5E0C8E59D2ABEA7BF41C597CE801D9CE9A00D9E4A4FFA823C7789863F9BE63C++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):697
                                                                                                                                                                            Entropy (8bit):5.505876168763784
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfy6v9LuO4biNp7mbkLwT5zxjm79wuRToSj0hWSWzpp+8:7e9SlNLiafVv9KO4apKWIo79ZRXPzpg8
                                                                                                                                                                            MD5:A14208DB73B39365C4D6C838776981D9
                                                                                                                                                                            SHA1:FEB20B19EF9C58C6CC10914A9E139ECC617D91A1
                                                                                                                                                                            SHA-256:E13248A02CC9BF468A097DBAFF0BEED57176284BD10E431E4005C525B91C8618
                                                                                                                                                                            SHA-512:53A3E81DB1AD91A64D281AE089C8AB4526873D7A1EBBA27C93146320CB132160EF7441DDECFC715C2F28F5901E74E9B1EC02116C247C287458AE4F7DD5899373
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versione",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Notifica sulla Privacy",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Fine",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//9D53CF31538C018BAE126DDA881FFD6C157AD09EBFB4BDBA389AED758E33FCE052A61F8F331AEC363DAE8E19DA957FBD41B0D08A44EBDA2D4CDEC8D669091087++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):808
                                                                                                                                                                            Entropy (8bit):5.7409373263357235
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7e9fLdo5ijdfA6Dlv9o4A2AWIOHo8UHv9ZR6Ued3:K9fLdICdfA49XLAWIOfUHFKdd3
                                                                                                                                                                            MD5:28B7739A421835EB9CD88B6013D4E689
                                                                                                                                                                            SHA1:DCF2CCD130415AC7F2C45E4495AAFC5EC976B058
                                                                                                                                                                            SHA-256:0C69D07D25EADA8203C4207A619F31992E1EC223D9550E645E2780C4BF3C29FA
                                                                                                                                                                            SHA-512:501684FDD4B4569C5BFB7A4F7E4C32B7FD8272E2B4961958F64B03E6B74D5767E19E17133F43A3CE5ED4DD932DE509C96C2D57F53B8C60318F03AE764A86EE0E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "..... .........",.. PRODUCT_NAME_LIVE: "..... ......... ...",.. PRODUCT_NAME_TRADEMARKED: "...... .........",.. VERSION: ".....",.. WEBADVISOR: ".........",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "........",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "..",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//26438DF7DDD1B7091ED260C5751D4A077CA382594D057744E7A18123A105135A5502DE2EC8D32B83E5301B99F1BF5EEC74B00DEF5B1B21DBF4CDBD9CC6109029++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):742
                                                                                                                                                                            Entropy (8bit):5.82878368970307
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSd6ds63i7R6ikfV/i6v9kc4biyGbkLwT5zxjsGiFW9wuRToa+g/N0u+Ho:7e9Ed13isnfVtv9kc4sWIViQ9ZR2gl4I
                                                                                                                                                                            MD5:53F240755A3E1938272249CCF8BD05D7
                                                                                                                                                                            SHA1:770F628BB772CC9461CF3D234E061EA4D810B119
                                                                                                                                                                            SHA-256:51DCD424DE086E10A9591AB85F830A8F466108F9DBBAA4B47A6DBAFB04BF2986
                                                                                                                                                                            SHA-512:54E1024EFC0B118C78C2406FB7D92E9794A241CBDE0D122957CC2C0C9628B443EE3EB7BEB916C83AD6BA7E8A706BFC8B7A78513119902A867A3728938EDE2A50
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee ......",.. PRODUCT_NAME_LIVE: "McAfee ...... ...",.. PRODUCT_NAME_TRADEMARKED: "McAfee. ......",.. VERSION: "..",.. WEBADVISOR: "......",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: ".. .. ....",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "..",.. DONE: "..",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//277BE604E32720DCF4BFF19AAA4CE10DDD8BABD440063659C78111528AE8B9281D266930182575EBEEBD256C8A040C4507A85B56B99FD882D9F3380D6FDEEA77++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):696
                                                                                                                                                                            Entropy (8bit):5.566757432761514
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kf3Hi6v9LuO4biqyNLMBHbkLwT5zxjmf9wuRToQMLVXQQgAe:7e9SlNLiaf3Fv9KO4zyNsHWIof9ZRtMA
                                                                                                                                                                            MD5:13FAE2BC4589EEB043806433697F4963
                                                                                                                                                                            SHA1:3D8CFA01762AEE740AA79236BADF9377275C8056
                                                                                                                                                                            SHA-256:F566A0C874B6497D4062F50ED554E5B997E4802E3B38AE70F59ED5787E39ACE9
                                                                                                                                                                            SHA-512:0A9DA7FA70D04D7AB53E4B7965EE8B6985BA1B2F6B2BACDFBEA92958ADAED25DC469BF6CA81B17BB75F53D3F5E39EFC3828984CC2346D1AFA6E6DAD14F364025
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versjon",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Personvernmerknad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Fullf.rt",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//E6C0634EF860473E5E1AC5DB56979665B177B654AF315AE120E64100E5693F76AC7D9890274062266625FE1B3B2BE60A8D8495F7A38F8C8C5EC99648483D6C21++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):746
                                                                                                                                                                            Entropy (8bit):5.619956078029764
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfP6v9LuO4biKGCEnbkLAWB2CT5zxjAHo8CW9AWB2CuRToJI5rcn4:7e9SlNLiafyv9KO4TGCEnWtB26OHo8Cb
                                                                                                                                                                            MD5:92F19DA62297C36C9E535BC5BF8B2F61
                                                                                                                                                                            SHA1:4BACE2C47E227ED1FEA94EF2712745FCC7F17E2D
                                                                                                                                                                            SHA-256:55CA92573C4E375DD2036798B34060BB822CB3B30396806A414539B5BF247474
                                                                                                                                                                            SHA-512:7B8F12E39550B6ED65D50606D4CA8D8D52252D0527FE62538F1653339E3FCD36E16F096391D63A1A0A2FCCA1C210F16D0E79EDC0F66008D3BB0F8F12E20A69A1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versie",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "privacyverklaring",.. PRIVACY_URL: "https://www.mcafee.com/consumer/nl-nl/policy/legal.html",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Gereed",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/consumer/nl-nl/policy/legal.html",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//85B81632B31DF611B6DB04A1F9D62E994290E36CF52C98D4DBD8811EE052DF144CC11541848F2D1C2C3DB510126DF77205BF71332EE9E5CB31D881E9C857B245++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):709
                                                                                                                                                                            Entropy (8bit):5.575958834672549
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kf6v66v9LuO4bipidGGnbkLwT5zxjmO9wuRTo/xumdtLwnVC7dTN3:7e9SlNLiaf6vtv9KO4oMGGnWIoO9ZRi/
                                                                                                                                                                            MD5:0303083C987D0942CFF17CE9D0027E93
                                                                                                                                                                            SHA1:FF1E0146514A442652002DD534A41046937B5914
                                                                                                                                                                            SHA-256:56188A2ED3326B0860D9CF76D6961CB643FC1A2F93E2FFB4DA2ABC0FF8640116
                                                                                                                                                                            SHA-512:ECC7AB3D3F27CB2383AA8C49F86F6C6BFA1027148997D4F92825D9B730641D214C95C0BE924B71575B1395A61267F34CBA6CF27D13E2F8D9EFDF753E6749C76C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Wersja",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Informacje o ochronie prywatno.ci",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Gotowe",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//2B110267F6341264500B29DC41AFD0C0D54141C5440DF4870008641509E32199642C5F03BF1696B79BA1C750119560BDEC726C2E3E852CCC3A6285FD7890EE61++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):700
                                                                                                                                                                            Entropy (8bit):5.549994684984163
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfqX6v9LuO4bicmHbkLwT5zxjAHo8kf9wuRTo12WFze9jTXEPvOun:7e9SlNLiafBv9KO40HWIOHo8K9ZR2Mt6
                                                                                                                                                                            MD5:801B89861183733EA35C952F78618985
                                                                                                                                                                            SHA1:E32C18AC6CA2B460C09759604CFC012AA030C03C
                                                                                                                                                                            SHA-256:95115CF18EE1E1A4896B08DBA7F24D012FB1B019215F86EC0FCE99141DEA9EFB
                                                                                                                                                                            SHA-512:3E0654E78080E2B6C5FF461F9DC4F85AD29D19754DD46880E80A4208E134CE2D5B6E449F9AC65592DC2BBDC2B7E44234998F0F7700CFA1E0218851FD5EEF5531
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Vers.o",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Aviso de privacidade",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Conclu.do",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//38319A37158F74349C56AE780D2FE1EA74369BCF9BF2139B6E7E1F6356EE6BF27E0781B2EC874623B3ACBC61CBD4F20A336E5563F143AC8483FE50230576700A++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):700
                                                                                                                                                                            Entropy (8bit):5.5619311609747175
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfqX6v9LuO4biHfHbkLwT5zxjmkf9wuRToePiIUngpgph8kWhuGCs:7e9SlNLiafBv9KO4ofHWIoK9ZR1BUkvt
                                                                                                                                                                            MD5:0826E1B34CD2718A14E67DB7471FEFF8
                                                                                                                                                                            SHA1:466CF995CD7E7673DF269E4DA917833DECFDEAEF
                                                                                                                                                                            SHA-256:E84BDF8D70A4D9032B2ECD3B2920DFA245E4420A1A05D2681A661D358D6804BB
                                                                                                                                                                            SHA-512:041E3F2164BA3C67A4F306855B59AF7BC516AFCEADD315FFE8E28A573CF2FE2DFD1B8F62A2C509ED85D9D24D95D56EEEB7D22D10A5CA007BF13A24F069089031
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Vers.o",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "aviso de privacidade",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Conclu.do",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//62715013ADB65289BD1425F49A9D44B5CF85BB826081DA7BECE9C3AE4217243A475EC1084D7F31910504181A52A7F7B35DA37012AB7F3002AE77CF8DF6F40CC2++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):751
                                                                                                                                                                            Entropy (8bit):5.755930371819692
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kf96v9LuO4bi4epiXbkLwT5zxjhKgE9wuRTowy3NvVknWaZpFkWc:7e9SlNLiafUv9KO4sWWISt9ZRmvVknP6
                                                                                                                                                                            MD5:CB17FD8DACE0C83B800F99F280D52A63
                                                                                                                                                                            SHA1:337B214690529E33BA2294A73E957F6D608788B0
                                                                                                                                                                            SHA-256:04271C792B07D7C0AA35385B55D51D3CD95398588C2F45D934775E669BB183AA
                                                                                                                                                                            SHA-512:6C47919977A192326E14B13C58CBF056901B12CC03B4C22B15D299E0D7538F49C21873E0A744E77924492468EA4F7F42FC42DBA610B24872DDEA397AE4539CD8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "......",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "........... . ..................",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "..",.. DONE: "......",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//88620717E9EE799EB8AA7F2E1760C2014F35B651171979FE060EC65AA5F267F05ADEDAC3569FF2A423984079CA92354D45A0F0554C8443802E3B39E48FEC628D++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):719
                                                                                                                                                                            Entropy (8bit):5.6102161711105865
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfa6v9LuO4biIAbkLwT5zxjAHo8+9wuRToS+Y4nU:7e9SlNLiafNv9KO4uWIOHo8+9ZR8Y4nU
                                                                                                                                                                            MD5:54082BF3A6B20F715D94808EF1951E71
                                                                                                                                                                            SHA1:B338216AA1F573D6F3EE14D26A514C5B9741C3EF
                                                                                                                                                                            SHA-256:C291BC36DF5BED83B96AC1A20B18B1B26A50035BF78B392A87A8205AC3EF169E
                                                                                                                                                                            SHA-512:126630161BD3266CAF11661A20AF0662EAE3263CA0D489CDF1B03796F2C732BABD865A37AE7B143ABD8EFA6AE1CFDD928710F33008058D22E8C153EFD8AF39E6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verzia",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Vyhl.senie o pou..van. osobn.ch .dajov",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Hotovo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//5624C53BCE8EA93E7C318B6470C5FD2BEA3CDF9448B5D8D70C5A88356E4684C1840F2A24BACB9BB5EC460482E3A6AD71B85856879DC16C66C82BC35A4E3EF13B++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):706
                                                                                                                                                                            Entropy (8bit):5.554327092493012
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfv66v9LuO4biagkcbkLwT5zxjHT9wuRToojRkm5e4eRgiX20qdSh:7e9SlNLiaflv9KO4cjWIVT9ZRnfeBg0X
                                                                                                                                                                            MD5:0C9AFEA80408DB59A843AAFA6C0BC23C
                                                                                                                                                                            SHA1:D9BECCE27AC0CC8ABD9DABB30EE7B23618CA7E7F
                                                                                                                                                                            SHA-256:F3ED198C41D3CDA9E9C973CE8C69650A2D66F8A496822AAC76FBBD4B23B779F9
                                                                                                                                                                            SHA-512:34C1977CEABEDA559AAD30E9162D3C4DEBCDD852EB3B79EF137739430479CDD0B6054D56973EECAA13B184596C42CB987DA26ED37D34DF34B7E7C8AF4F35D7CB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verzija",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Obave.tenje o privatnosti",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "U redu",.. DONE: "Gotovo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//1A84BCFAB89E78FD65597DBB6DEDC6ECA87B05E1F9B47ABDC62D1AD910BA86893B1F3895942A45176464D7D9FEC7BACF6A8B07D4191E028305DAD41F83806930++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):690
                                                                                                                                                                            Entropy (8bit):5.513710902007872
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4bieGbkLwT5zxjmf9wuRTofn0mzpNlBFjhoepkhn:7e9SlNLiafLYFv9KO4JGWIof9ZRcn0c+
                                                                                                                                                                            MD5:F70671A24786782017CD814AC6AC72C1
                                                                                                                                                                            SHA1:26F9AC77B1764AD13371B720A92F3A15158BEE40
                                                                                                                                                                            SHA-256:CD852B915D12B12640D3E5197CEB2D464A1B495CB78A3B6680C3F09EAD0ED91E
                                                                                                                                                                            SHA-512:AB57130DC2E669B486BE710A98AC90F37D0C27970EF2CE12D6F1ED2A544103AAD0FD166373A8D76F2E62B8A506233A4FCB5DBFBCCFFE3B4B85D7259E470C4E9F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Sekretesspolicy",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Klart",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//F9E40AAC3AB58D47F27C4E63326E01B8315CDD4E1995A9F361D05DD7B20E79F8EBE2F210A12CF91EBE35A4C492EF923C7A37BEBD67F790E5AA02D49BB75EF0EA++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):696
                                                                                                                                                                            Entropy (8bit):5.545555209314935
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfT6v9LuO4bij2VbkLwT5zxjAWoN9wuRToq8TMJ81S1oQtZvrgn:7e9SlNLiafGv9KO48QWIuv9ZR3qr
                                                                                                                                                                            MD5:6968161BAA9545B01DDA30AF5FB7A36F
                                                                                                                                                                            SHA1:7E78CE16FE43653B060C217ED37A1CD65C38CD04
                                                                                                                                                                            SHA-256:148E55B8F85C7837B17520E2100AA5C2A8F956FBEACB18E84876F7C12A98C654
                                                                                                                                                                            SHA-512:2B47FD43A6BE7701B6EB24174EEB78251E194EE8764B04F0CF53CB33C063EE08DE6D535C1CD2033FCEBF36309E3797C76139014D4A2EE5773EF076DB6DFF77BD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "S.r.m",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Gizlilik Bildirimi",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Tamam",.. DONE: "Bitti",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//8776C33924D3DE44C8ADF4713EB85340482CAC0087E39DAE7CD3D05592F58E39FD4C4D7E36F383819137D5CFB5EEA1E8CE9717243D9763F93875A3834861584A++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):719
                                                                                                                                                                            Entropy (8bit):5.935688545805366
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSuKxi7s6kfF6v9bgbi5ywbkLwT5zxjtDYv9wuRTopfLfT7XbP7:7e9uui7s/fsv9bg4ywWIv49ZRufLXbz
                                                                                                                                                                            MD5:80C3F7CF329979756A2483C61FDC94E0
                                                                                                                                                                            SHA1:4D789234D75ACF3E6876C742D7E4B2DB660E15A4
                                                                                                                                                                            SHA-256:77888F083FA21B5CFD2EB5CBE5C6407A7421BB04D76F127F49DD5BD426D1C572
                                                                                                                                                                            SHA-512:4C2C012A7D27C2C0DE54B1650D24AB7C909A871CEFF1410D1E2EB3BC9F8783F8928F812813D970AEA92D7989CF669771B7FFA18431A3132510D4CC459204D81A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: ".......",.. PRODUCT_NAME_LIVE: "..........",.. PRODUCT_NAME_TRADEMARKED: ".... ....",.. VERSION: "..",.. WEBADVISOR: "....",.. COMPANY_NAME: "...",.. PRIVACY_NOTICE: "......",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "..",.. DONE: "..",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//F6E98D5300FA7FAC3CDBD26ECC83D725DB0761530427BCE04CAF85A01F83E6368A59F8EE59AAF5009800F25844EFB5700CEED010C18D0F0F99E2C31715A94B21++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):694
                                                                                                                                                                            Entropy (8bit):5.6689804706681635
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfF6v9LuO4biP3emebkLwT5zxjgDYv9wuRToar0jJ5H91/f:7e9SlNLiafsv9KO4d1WIG49ZRhr0jP/f
                                                                                                                                                                            MD5:5BC62AD32578785B4E38CC765AD01B86
                                                                                                                                                                            SHA1:388C382BEDA295EDAA6ED522EFABF3F4F917976C
                                                                                                                                                                            SHA-256:888CB78E02C9F494C4C43B93D35379125379F52DD5EFCB9EF93B985142A2A710
                                                                                                                                                                            SHA-512:4DD4107512C06F65816C0926FA7E35BE8DEF88923C5EC14F3FEF175D579163BF1B8DFD73B3921E684F038B82B6D45D1BF43705F0BAAC266F3FF0EFAF33CAE0C5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "..",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: ".....",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "..",.. DONE: "..",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//3BFEE6F1AAA6203888EACD212AA6EA71B5BEE9F5E25B2EBFBF7067F80AE1F91149DA1C89745A5D6C58244D823622DBDAD484EB12F3CCDC2A6A8C7775DA7229D1++
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 259320 bytes, 513 files, at 0x44 +A "\l10n.manifest" +A "\jslang\new-tab-res-toast-cs-CZ.js", flags 0x4, number 1, extra bytes 20 in head, 39 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):270016
                                                                                                                                                                            Entropy (8bit):7.936612208642757
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:54vC5RltAOux9/RAVX/xTAOSOTZ42dNIoaPTCepCSVhoGIsMfhRMj8vAlx2FL/ih:2vMRl/9xMOPbsVbCepzwfEf2xiLLZ
                                                                                                                                                                            MD5:4C8E546D932FC567FA9A68C82F938E6E
                                                                                                                                                                            SHA1:498A252C3B26A6F3FF91CABA13FFEBB31AEB0298
                                                                                                                                                                            SHA-256:BC88EE7B453E250F66B4FBD42BFB76176AE98A30583742302D26477E3D422206
                                                                                                                                                                            SHA-512:B94D33BD7E2D1601C2A707014454B15BE8105C95460F9C78BEE766A0415FA30B8FE63D2B179F906B5E5C9B0BD50E70E04EEDBFCDFD1D1CA35DD1A8207C9E6860
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:MSCF............D................................)...........i..'..............YOq .\l10n.manifest.#..........Y.p .\jslang\new-tab-res-toast-cs-CZ.js.#..........Y.p .\jslang\new-tab-res-toast-da-DK.js.#..........Y.p .\jslang\new-tab-res-toast-de-DE.js.#..........Y.p .\jslang\new-tab-res-toast-el-GR.js.#...!......Y.p .\jslang\new-tab-res-toast-en-US.js.#...D......Y.p .\jslang\new-tab-res-toast-es-ES.js.#...g......Y.p .\jslang\new-tab-res-toast-es-MX.js.#..........Y.p .\jslang\new-tab-res-toast-fi-FI.js.#..........Y.p .\jslang\new-tab-res-toast-fr-CA.js.#..........Y.p .\jslang\new-tab-res-toast-fr-FR.js.#....".....Y.p .\jslang\new-tab-res-toast-hr-HR.js.#....&.....Y.p .\jslang\new-tab-res-toast-hu-HU.js.#...9).....Y.p .\jslang\new-tab-res-toast-it-IT.js.#...\,.....Y.p .\jslang\new-tab-res-toast-ja-JP.js.#..../.....Y.p .\jslang\new-tab-res-toast-ko-KR.js.#....2.....Y.p .\jslang\new-tab-res-toast-nb-NO.js.#....5.....Y.p .\jslang\new-tab-res-toast-nl-NL.js.#....8.....Y.p .\jslang\new-tab-re
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1590193 bytes, 2 files, at 0x44 +A "\logicmodule.dll" +A "\logicmodule.manifest", flags 0x4, number 1, extra bytes 20 in head, 139 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1600889
                                                                                                                                                                            Entropy (8bit):7.99971035478572
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:24576:KWXPgoXVPxkdAh2E2dwWj9Y+GA0cGtaPNxDqKchRBvLObiVPdsQI+Wn2ud:dIyPxk62dKA0cqQNfchvLvlsQI+E
                                                                                                                                                                            MD5:5CABC7883BB21C8BFF60D53E0EA36BCC
                                                                                                                                                                            SHA1:F70D4B8CBE253A7B9EC24F3763EC6FA3878EBD6F
                                                                                                                                                                            SHA-256:FDACD53DDA248588C1C33BD9292727BB489C3607155CE27362CB814C13496E9B
                                                                                                                                                                            SHA-512:009AEACAF6C57E533CCCF37BA62F8188BF183EFD6B57676A4731A001F1AA8AB657C731F0BB339D5A50EAD8D2194EF4048CD64A573BE03E230DA55BEA5098AA6F
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF.....C......D............................C...)...................LE........YLq .\logicmodule.dll......LE....YVq .\logicmodule.manifest....3(+..[...9 .....@T.5........K...u.Z.U1......4,.v..".X.C......N..h.n...6Z!.a......Y,.".D.4CeX...W.w.w...........V..R......7..rXv7...*../8vs.yc...$........qz;...*/.1Pw2.$.....u$Fo......"^.x.... ...*.H....@h...h.j......g.g.|.N..K..M .h..D}.5.+.b".p.?W..wZ....z..l...b{.,...Y.r[..0..T.{.G{.....W....W......w.._..t.j.+W.~..{j....~j..ZY.......Myzs...........o.B|..*.....x....&O.?q3..Gu....,s.H1^.[..........h..t{.$..J....X...........m....&...U.z..u6.......^.J....l.K.....j.:C.[...~.J...F.......C./.gYS.s..;.>..=k....z.l_...<{.c3w..........9.....S..;.K....c.:._..O.,.4G.W/..............V..?./....n..z....\.....7..e..&uw.N.......}.....S|...s..Z.......>.f.Hz.....g..i.Q.[5.2.-.ek...m}.'.....\On..n|}...}...........1....~......1..T[..38*...X..v.*..>;.r...5+^.|`.n......./...-..).6..*.j.K..=..pH....4. ......j..o..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 43684 bytes, 25 files, at 0x44 +A "\logicscripts.manifest" +A "\logic\aj_logic.luc", flags 0x4, number 1, extra bytes 20 in head, 6 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):54380
                                                                                                                                                                            Entropy (8bit):7.967541093183867
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:+69/cpr6gUcdL2uYcTaCRy6JT52f7gVPC2hSDXeNXJmZWP6jKoOh2Psc2EPZ:+sgUcdLuCIKTk0ML7eIlK7c1Z
                                                                                                                                                                            MD5:947535D9D40C5D9449ECD7D013DCAF9D
                                                                                                                                                                            SHA1:B3334CE8B2A03A390E4A8ACE1050909D2AB720D2
                                                                                                                                                                            SHA-256:F7B7CAE20366EBECEA2C85FDBC4414D68825351EA1863F60884CC0FB37301E87
                                                                                                                                                                            SHA-512:CEE30131D4A15ECF63B305480FD989E0B07D3BB82D25AB42D5AB408574DEE1237247A506D813432C4DABBF27629A8EDBB6433B68CE841A657AD6ECC21B77494B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:MSCF............D................................).............................YWq .\logicscripts.manifest.M..........YWq .\logic\aj_logic.luc.....9......YWq .\logic\base_provider.luc.....E......YWq .\logic\edge_onboarding.luc.v..........YWq .\logic\ff_monitor.luc.@...w;.....YWq .\logic\logic_loader.luc......F.....YWq .\logic\miscutils.luc.W&..~[.....YWq .\logic\oem_business_logic.luc.}.........YWq .\logic\providers_selector.luc.....R......YWq .\logic\ss_logic.luc.....Y......YWq .\logic\tests_logic.luc.f...P......YWq .\logic\type_tag_utils.luc...... .....YWq .\logic\usage_calculation.luc......(.....YWq .\logic\oem_utils\affid_monitor.luc.0..../.....YWq .\logic\oem_utils\oem_util.luc......1.....YWq .\logic\oem_utils\oem_utils_wps.luc.Q...KG.....YWq .\logic\oem_utils\oem_utils_wss.luc......P.....YWq .\logic\oem_utils\oem_util_selector.luc.>...<S.....YWq .\logic\providers\bing.luc..F..zi.....YWq .\logic\providers\yahoo.luc.t...[......YWq .\logic\smart_toasting\smart_toast_config_manager.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 13 x 14, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):440
                                                                                                                                                                            Entropy (8bit):7.185064395828422
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7Jmynud+EVDvBXmY5j9yEhcZxAalEbKWwz:vyGbVDvxJ5alnWwz
                                                                                                                                                                            MD5:3F33BF7A71F1A94B30AD98121F2DC31F
                                                                                                                                                                            SHA1:533B933BACBAE375164518AF202EB90086BEFC44
                                                                                                                                                                            SHA-256:4D3581315F5AB93538BEE793BA9727FC9E8444E9B09773566C4BDF0C44618828
                                                                                                                                                                            SHA-512:4E768ABACB878A5F9BE79B91E9BC77778F62AA4ACAEC4A246AB3359E86FF685250A1BA9E7765CE5174A42E5936CFAC27CB381B505F92F30EBF4B43806848899C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.....................sBIT....|.d.....pHYs...........~.....tEXtCreation Time.10/1/14........tEXtSoftware.Adobe Fireworks CS6......IDAT(...1K.a..........+ht...".96..\....M..f..9........ n....~.KK..o..~..g{8.:...I..D%...^..6V......w<K.......z.?..dk2..p.G.U.&...?..U.].m.O....L2.o.`<,.....k....|....L...Q._.<.....?(...[...lW...O.6....Z....r.q....Nr..p2.d._.w...1....F.....@..x....x.X..T./.H..w./.yrd.......IEND.B`.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 67 x 57, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2052
                                                                                                                                                                            Entropy (8bit):7.890065571351557
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CHjblGYXQQEZZyIOrNK6rC4lWVkOjKpgOojQ9dCe2LfmC:PYgNZKJKSC4YF+WjyOZ
                                                                                                                                                                            MD5:18344204EC04F1E95E086D3BC94FA0FD
                                                                                                                                                                            SHA1:87CA3ED8948774091B451F7CB2F95139E56D351B
                                                                                                                                                                            SHA-256:30ADF46FD9311E5C6DFEA8A2AB2176EBAF83E7019EE341896FC3AAA5F498D2BA
                                                                                                                                                                            SHA-512:13757DC62505D01E44523823F38001D28A2FB9CBA5ACBF9CB7D9BDD8D0F19583D814E5A47B2DB255E18CCC05C34D43A02C387B60D05D1E802F9AF527D3633C5E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...C...9.....ms......gAMA......a.....IDATh...l.........|u...4q....T$....IHK.u.h...lS..{.....i.6..h....@PX[.&...AH.&.($E.(.R..).......M..:..}.g.M.8.c3.'........{....}.``....q.. 0..b.=B..?.:t......1..P_f5.......).7\..e..Y.gA.......XPL...Hss. .ks..... ..aPx;|VO..{{{).`"...VAb....u.|..>_..#......2>V......9.g ....<Bss.T....LFI[[..+%.Y.....N...~X.!......h.q.J.l...A.s...p8,.|.K2..'.{.j..c.<.|m..<.....'.K....zF...nu..<...\.a#U.Q.a#`..ZF%`...6..=j{ta...ax.....\.<.H....<>.'...x......./n..g..'G.z.E.|.....(H~)2...U..O.?w...u.X{..j.v.D.M...z.9.|.a.......\v..f..0....0..1Xs..p&5.C.?....XY.~...K...p.._.+.*...KEF......5V.f....l.u...N..../o....t....b.......z.).....v............f......L.:.n+..s>.r0l.i..&.u...1.J)..sk0l.j0j0l.l....C.......*3Q#..7.......f.[..&).r.z..0..^Xs...z.-`....3..........{N.e...g...O..~[A.F...."....E.d|..?.8S.........}.|;.......>u..B.....Y Z.w.....W..:...Z+.r....+...7..._..b..........~.a..w..o........0.J...[.d...W..>...
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7205
                                                                                                                                                                            Entropy (8bit):7.9471260512499375
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:KS4Do1RyFyKSZ4pTSumpAO/Ap6CQU9Uw/JLO/xvifnL:F4E1RCFpWumX/Ap2UeMq/xGL
                                                                                                                                                                            MD5:F2E3045621ADE164E9DA40F294BEB00C
                                                                                                                                                                            SHA1:36E9D967C679FC898BED1FF6751A73BB863EAF79
                                                                                                                                                                            SHA-256:D820CF499FC4A9453771A23209A6C63DDD2CE3439E8B651A98DDF0C36ED2BDA5
                                                                                                                                                                            SHA-512:7E515A44BD63B33881EE86E0A911897138F2BA0A6E81925612EAF19E3EDAC5A9FDCEDE30E3AFF3E906A4BBA8AA4570E06308D75783057015C882C7E62A880928
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...`...`......w8....gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....bKGD..............pHYs.................tIME......'..l.....IDATx..y.\U..?......./.@@....E&..P..GF.Q.F.....#..T..........D4.AC....b. +![w..NuU/.....q.z!.ToI@..SIW.s..}.y..s.U..?g.D?`..._T.(..}.n.I.w"+_..r0}y,.....`&....P......8.,....n.I..c@.4._....]@.J..UL.....A...[K........[.-...A.....g.'.N........#.l`.p'.d..o.@@T.P..tQ.A..........t..q`5.=...B.(Q.).."..`1j..&..n....}..e..].....-...x]..p%d.(,............g....o.C......p.j ..W~tW.3.]mq ...H.Q.P..-...Q2...v..O(..`...8....?.4...A..}#K...m......|-.....w.2.m..lwL....Ys..y.;..\.Q ..p..e....B'p..........^@m.c\..[..Z!v....*a5...T#R..B8YH|.....iw...8......,f.v......i`..:T.!F.\....t"5....0..._..K ...M.`.8d.5.9.x.c.v.A...Ug...Va.d.?..M]B.U..E.E.....: . .B5.B.1."......>...w7.-....@.P.;.d.LUp.D.0..R..TE......k..K[.>o...?.~....i..}bu...6......Pj.g.U..~'..+.|.F'......y..t.p..0.6 ........E.).n`...3\-D.......^~6..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:XML 1.0 document, ASCII text, with very long lines (2293), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):126293
                                                                                                                                                                            Entropy (8bit):5.969613768259596
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:sY+8or+sWZ21Wzwtp31uRla7GTvfwjBobALAnr+sqDK7G3lq0lAE:dcPsjO31ui7GLjA8rPqDK7Gb
                                                                                                                                                                            MD5:D0CD30BD9B02F33B222FF8A846821D4B
                                                                                                                                                                            SHA1:DA85556707CB3FD59E08DF69017DF6BB82E52F62
                                                                                                                                                                            SHA-256:1CC3969AEF3DC3DC2330DB0386C6C27C09A58D078689D8D97D900A2B9ABE31A0
                                                                                                                                                                            SHA-512:6C1F9DE0897F02648638B26F20728C5F2E9822F8CAD232ED42ACC18F33AAE7E102C7A00E5D42B80C10E423DB937DC6AB783255342B12B0DB07B378508886C2ED
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<?xml version="1.0" encoding="UTF-8" ?>..<Package Version="1">.. <Certificates>.. <Certificate Name="McAfee Trust:0">.. <Privilege>PRIVILEGE_IOCTL</Privilege>.. <Issuer>Microsoft Root Certificate Authority</Issuer>.. <Subject>Microsoft Code Signing PCA</Subject>.. <ValidFrom>20060125</ValidFrom>.. <ValidTo>20170125</ValidTo>.. <SerialNumber>6115082700000000000C</SerialNumber>.. <PublicKeyMD5>4A171B7E5701870357585DD1BAAD752C</PublicKeyMD5>.. <SHA1Thumbprint>FDD1314ED3268A95E198603BA8316FA63CBCD82D</SHA1Thumbprint>.. <Data>MIIGgTCCBGmgAwIBAgIKYRUIJwAAAAAADDANBgkqhkiG9w0BAQUFADBfMRMwEQYKCZImiZPyLGQBGRYDY29tMRkwFwYKCZImiZPyLGQBGRYJbWljcm9zb2Z0MS0wKwYDVQQDEyRNaWNyb3NvZnQgUm9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMDYwMTI1MjMyMjMyWhcNMTcwMTI1MjMzMjMyWjB5MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3RvbjEQMA4GA1UEBxMHUmVkbW9uZDEeMBwGA1UEChMVTWljcm9zb2Z0IENvcnBvcmF0aW9uMSMwIQYDVQQDExpNaWNyb3Nv
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 10171 bytes, 6 files, at 0x44 +A "\mfw-mwb.manifest" +A "\packages\mwb\mwbhandler.luc", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):20867
                                                                                                                                                                            Entropy (8bit):7.877341631586747
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:CwziFKbAJ7q4Zolsgy3SpfLbZMeV7E96ki29d1ikEpTSJIVE8E9VF0NyOOj:CVlJOnqtCpfRMu442PsnK2ET
                                                                                                                                                                            MD5:1BF5917726859D01723B7C7D0C8E3401
                                                                                                                                                                            SHA1:983057A862D666936D66C869ACFBD36BD834381F
                                                                                                                                                                            SHA-256:FA356D5E1E483A5529B38A7AF7BA9D4E334A04154C2E4FA9DA77B1173CD238E5
                                                                                                                                                                            SHA-512:E8D9F74BC23F2625BBCBEDCBFFF2E2C613EDD83670E8C59069F3C790DA1004EB24AEA9148ACBE3BFDDD881466CAF587634219287D2C8F4A60C6BBB41BD30D44D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:MSCF.....'......D............................'...)..........m.......W..........YSq .\mfw-mwb.manifest.....W......YSq .\packages\mwb\mwbhandler.luc.3..........Y"k .\packages\mwb\stop-video-alert-icon.png..&.." .....YSq .\packages\mwb\wa-controller-mwb-checklist.js.^...%F.....YSq .\packages\mwb\wa-mwb-checklist.html......O.....Y"k .\packages\mwb\wb-rocket-icon.png...d"F&6Q[.....`...A..#..O...T.C.2...z..(QW....Z.j..$..C.;........_..|G..|..D...f........'.........K..5@....ZO...E....$.w}m9..}............5....^..Ma#..F;..[VcK=. ....... ..4#.Ef....n.n%......v....@.h@./..!....qr..8..A..,?.J@"..&n..........Q..._a5.x..`ri..8.&..P%..0...D...4tj`&z.I...#.[...D.0pG|S.3..w..".A...x....$m.A.......W.J.0B......R....&..UU.a@.? ..4....\J..{^.....'..9.eu.]2.k^..1.u.j.-....39.Ky....X.G..l.W..J[~.~..v5d...r.L.7T....y...-&....(...<....{.Y....d..&l.`...b...)p....}.....h.....=m....s.0#!...*w....sp.../..V..d.../.O...e.W....c>G.......f?=p...T~..{.y.Ec+......*... j.d......ET,.2.........9.PP$...
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 12420 bytes, 6 files, at 0x44 +A "\mfw-nps.manifest" +A "\packages\nps\clipboard.png", flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):23116
                                                                                                                                                                            Entropy (8bit):7.897449731737562
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:9VwGeUVwizXYr9+6UXn9BXBg5Tu5zTOXI6ki29d1ikA1I2SJIVE8E9VF0NyaA4LC:9IUVwiziO5i5TaS72PsP02Ef4W
                                                                                                                                                                            MD5:E7D9075EE9B4A0DDD5E37997FED5BA32
                                                                                                                                                                            SHA1:3AA715350F76B7751625121D80C5DF61625435EA
                                                                                                                                                                            SHA-256:64AF2D604765B508C310E44477543954F797CD876813D1AEDFC1308980D651AD
                                                                                                                                                                            SHA-512:586FD1EC9509206F970440B94C3EC6D7AC1A11937B6A1749D0475812473EED79ED283D3BD977073274BD02D30703A002CFE0D12D69D293F61F6EF24C82829E21
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:MSCF.....0......D............................0...)..........Z.......P..........YSq .\mfw-nps.manifest.k...P......Y"k .\packages\nps\clipboard.png.-..........Y"k .\packages\nps\info-16.png............YSq .\packages\nps\npshandler.luc..e..{/.....YSq .\packages\nps\wa-controller-nps-checklist.js............YSq .\packages\nps\wa-nps-checklist.html.....P*..[...............3.7.K... ^!.a...7...J. ^.....H.%..... !.........+.x/$....^%x.....J...My.s.[.F...'..{.p..A..................T...%.u......m.fomdl2sn..X[.....<.P....)...&.*.729......j...}..q...86.&.../B@...S.....zU...x.....jd.h.....C[;#.C/.l..g?.c.}1b!US3X.:av.?......<..>T..T..o..FA...'.7............w..|.!. .a..7-s..5...i....q....>.l..|..m.....4.;.r#Z>..#.../w.;.........7............nhW.j.}.k/.Oq...B;....4....~..9F7._~.*.Y..\.....8.._.l@.......;..?..g...E.~..3....;#...}.?.i2.m..2......._...B.....~x.]........>.N.N..7.(.7.;.......|..M.mh.h...K....../.~."...;.@;CM>L.@.|....). .@..=........... "...&?@..5.......
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 778438 bytes, 176 files, at 0x44 +A "\mfw-webadvisor.manifest" +A "\packages\auxiliary\reset_handler.luc", flags 0x4, number 1, extra bytes 20 in head, 91 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):789134
                                                                                                                                                                            Entropy (8bit):7.99497056267783
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:12288:qDvsTrmwn5S+tfRl6ZCFpbWIEQXUdMUcTZfmI4l+YonCgFRGyAytbg/QYcBeJbp+:q2pnBtfRk4FpbHGdMUo+6tFgbSb7BeJU
                                                                                                                                                                            MD5:DDA2017CC752902D620249ED1A22B205
                                                                                                                                                                            SHA1:327E24CF04B28C5EAF3DB9F2E05EB2AB9FBB8DD3
                                                                                                                                                                            SHA-256:C0B41A04E5FA665C31FB12BE474DDAD97EE2F470C3CC5633C517ADAB50BF3CAE
                                                                                                                                                                            SHA-512:CDC2226D7A12D536AFF17CEE663B11625A2C21997BC22E5270F1D996C284D6D94D7F7A2766672DBD7C60EB494ACC487EEFA5868CEE8B3E51782FC2BC89FAB865
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF............D................................)...........+..[..............YQq .\mfw-webadvisor.manifest."..........YRq .\packages\auxiliary\reset_handler.luc............Y"k .\packages\builtin\balloon-arrow-right.png............Y"k .\packages\builtin\balloon-arrow.png..5.........Y"k .\packages\builtin\card_bg_image.png.8....L.....Y"k .\packages\builtin\close_icon.png.T....N.....Y"k .\packages\builtin\dialog-balloon-logo.png.....aT.....Y"k .\packages\builtin\edge_close.png..I..ZU.....Y"k .\packages\builtin\enable_ext_guide_ss.png..R..E......Y"k .\packages\builtin\enable_ext_guide_wa.png.d4..!......Y"k .\packages\builtin\enable_sideloaded_ext_guide.png..8...&.....Y"k .\packages\builtin\keep_changes_guide.png.W...J_.....Y"k .\packages\builtin\logomark_white.png......`.....Y"k .\packages\builtin\mc-logo-tm-bottom.png......f.....Y"k .\packages\builtin\mcafee-logo-1.png......l.....Y"k .\packages\builtin\mcafee-logo-2024.png.EP..Xr.....Y"k .\packages\builtin\open_sideloaded_ext_alert_guid
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 299121 bytes, 53 files, at 0x44 +A "\mfw.manifest" +A "\core\class.luc", flags 0x4, number 1, extra bytes 20 in head, 33 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):309817
                                                                                                                                                                            Entropy (8bit):7.9964591281715425
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:6144:4PsfJaOdO7MsIVUqqDNRv2I13E7ZySrD1bHcEBa6Xc3OuV/b8W/46+T:vxE70VUXpRvB1UNySN8EBa6XMOuVj8WA
                                                                                                                                                                            MD5:E47EFBAA8572C26C8040AAE2738B246F
                                                                                                                                                                            SHA1:4DDB1AF4A2019BB459C0E71CBF493A4263FE08CA
                                                                                                                                                                            SHA-256:7FB7B0BE4FCC462DCC5FDE645B870694DE354CDA990EA4BD66B9EE8506701FA5
                                                                                                                                                                            SHA-512:171A9DBFC69ED456ABF20074696CE684B3BAB40447F90E549729AF010A6AEF0A211232F2C68BCD08D8585D3F223B254514F72E71F16EBFC245056649EA8FE2EA
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF....q.......D...........5...............q....)..............!..............YQq .\mfw.manifest............YQq .\core\class.luc..'..H......YQq .\core\dkjson.luc.....B2.....YQq .\core\handlers.luc.....M;.....YQq .\core\init.luc.2...ND.....YQq .\core\json.luc......F.....YQq .\core\logger.luc.....;I.....YQq .\core\postinit.luc......M.....YQq .\core\priorityqueue.luc......R.....YQq .\core\triggeracceptor.luc......S.....YQq .\core\uiarbitratorhelper.luc......b.....YQq .\core\uihandler.luc.u...ng.....YQq .\core\uithreadexithandler.luc.Kw...k.....YQq .\core\win32helper.luc............YQq .\core\utils\browserutils.luc.r..........YQq .\core\utils\common_utils.luc.c...S......YQq .\core\utils\packageutils.luc............YQq .\core\utils\settingsdb.luc.}..........YQq .\core\utils\stringutils.luc.^...,......Y"k .\packages\builtin\green_check.png..>.........Y"k .\packages\builtin\icn_mshield.png.....mZ.....Y"k .\packages\builtin\installer_background.png..l..At.....YQq .\packages\builtin\jquery-1.9
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:TrueType Font data, 13 tables, 1st "GDEF", 19 names, Microsoft, language 0x409
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):159892
                                                                                                                                                                            Entropy (8bit):6.727831490585094
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:Kbo6bpQgbkPJrVtnmOIwXhRsJZzTzhUUfm3ustnayEsrCjScsd6XClVMfY:ipV8rtnxZRiJ9WKm31taHsMXsqw
                                                                                                                                                                            MD5:FCC40AE9A542D001971E53EAED948410
                                                                                                                                                                            SHA1:E247A92158E112F8BF7B638C8D95381D66B00DBB
                                                                                                                                                                            SHA-256:647F014D36822EF7E0413FFBB65598AE0CB57FB798E635C63912C93D94EB356A
                                                                                                                                                                            SHA-512:01E6B5B1B4F86BB52F363D49F5A57250B1C9905D7B2FAA45DEF87EA7C2784B0288AA48D4E006B04E993B761D235632264A3DAA6C64D60D425DC5100140E74605
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:...........PGDEF.......X...@GPOS...[..#<....GSUB?....Y...&rOS/2.v........`cmap5.;.........glyf...........head..$Y... ...6hhea...L.......$hmtxG..K........loca.'.....l...Hmaxp...1....... name...+........post:.h...6..."......#.....y.............d...............d.........................!...........;_.<..................6............................................"."...y.z...}.}.........\._...g.l...s.s.....L.,.......X...K...X...^.2.G............................ITFO...........d.o.s ........"..... ......................................... .~.....#.1.7.H.[.e.~.........Y.....................(.0.3.9.E.I.M.P.^.e.o.p.r........ . . . . " & 0 : D . . . .!.!"!&!."."."."."."."."+"H"`"e%.%............ .!.......(.6.9.L.^.h.........Y.......................*.1.5.<.G.K.P.X.`.f.p.r........ . . . . & 0 9 D . . . .!.!"!&!."."."."."."."."+"H"`"d%.%............s.R.P.N.J.F.E.B.@.>...,.....l...................................9...........Q........................A...2............................8....
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:TrueType Font data, 13 tables, 1st "GDEF", 17 names, Microsoft, language 0x409
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):158240
                                                                                                                                                                            Entropy (8bit):6.749916892166723
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:iBLCaPkPJr9Q0T+GNqUESJ/8w/lF703hmTWH6lrGcRAbf9EpthYp0wf0IDh1jlG4:6LCY8zQjGfJ/AaHjxlzOk7gb3Va4J
                                                                                                                                                                            MD5:093EE89BE9EDE30383F39A899C485A82
                                                                                                                                                                            SHA1:FDD3002E7D814EE47C1C1B8487C72C6BBB3A2D00
                                                                                                                                                                            SHA-256:707FDC5C8BAB57A90061C6A8ED7B70D5FFB82FC810E994E79F90BACE890C255A
                                                                                                                                                                            SHA-512:4BE480DF0B639750483EB09229B4EDCFDCD16141EB95D92A3F28A13BF737146D7CC5DB6AD03A5CDE258F71B589E5310B6D9BC1563AC7B1D40408EEA236D96F4B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:...........PGDEF.......X...@GPOS.G!...#(....GSUB.'....Y...&tOS/2..w........`cmap5.;.........glyfQ..........head..$a... ...6hhea.u. .......$hmtxf..1........loca.#.....T...Hmaxp...,....... name............post:.h...7..."......#.....v.............d...............d.....n..................."...........S_.<..................6........)..................................."."...y.z...}.}.........\._...g.l...s.s.....S.........X...K...X...^.2.H............................ITFO...........d.o.s ........$..... ......................................... .~.....#.1.7.H.[.e.~.........Y.....................(.0.3.9.E.I.M.P.^.e.o.p.r........ . . . . " & 0 : D . . . .!.!"!&!."."."."."."."."+"H"`"e%.%............ .!.......(.6.9.L.^.h.........Y.......................*.1.5.<.G.K.P.X.`.f.p.r........ . . . . & 0 9 D . . . .!.!"!&!."."."."."."."."+"H"`"d%.%............s.R.P.N.J.F.E.B.@.>...,.....l...................................9...........Q........................A...2............................8....
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:TrueType Font data, 13 tables, 1st "GDEF", 19 names, Microsoft, language 0x409
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):155232
                                                                                                                                                                            Entropy (8bit):6.739857306155488
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:0FyHGX8bZ0eysTnqHvobJixBp0TKf3H5z8MkKURj7i8w+fW+uQ:0kHGsysUnQ3tX
                                                                                                                                                                            MD5:6F1520D107205975713BA09DF778F93F
                                                                                                                                                                            SHA1:8A4ACE9392D06BCB7F8EA2F5169B07E4C383A90D
                                                                                                                                                                            SHA-256:248C0244B350EC68880996AA6BE6D7796274B49992D5FCBBEFE251906AA4EA36
                                                                                                                                                                            SHA-512:5E40D2EBE39605ED0C2D8BE022DD716E51B018E1BB0AE0101164E1E02BCF6B7CCA5EC0DA2EBCB533D959AE766AF8863B27D62EFBBA1755E9E8D45E7BCE51FA36
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:...........PGDEF.......X...@GPOS-.....#X....GSUB=....Y...&vOS/2.z........`cmap5.;.........glyf.q>S...@....head..$n... ...6hhea.0.........$hmtx.B.$........loca.qX........Hmaxp...%....... name.. .........post:.h...70.."......#.....t.............d...............d.....8..................."........n.?/_.<..................6........C..................................."."...y.z...}.}.........\._...g.l...s.s.....b.X.......X...K...X...^.2.L............................ITFO...........d.o.s ........*..... ......................................... .~.....#.1.7.H.[.e.~.........Y.....................(.0.3.9.E.I.M.P.^.e.o.p.r........ . . . . " & 0 : D . . . .!.!"!&!."."."."."."."."+"H"`"e%.%............ .!.......(.6.9.L.^.h.........Y.......................*.1.5.<.G.K.P.X.`.f.p.r........ . . . . & 0 9 D . . . .!.!"!&!."."."."."."."."+"H"`"d%.%............s.R.P.N.J.F.E.B.@.>...,.....l...................................9...........Q........................A...2............................8....
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 98 x 97, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9635
                                                                                                                                                                            Entropy (8bit):7.971630978673207
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:eSkVYfbW3C2GLUk/EK0pL0Q+Izxgzakz5qYtUFrJopOiHicNsnXFNQO1:BkCTW3IwQEhpP+qyoYtXpOiCSeTQO1
                                                                                                                                                                            MD5:B7B4680D9A3CD75069209C711DD78AE5
                                                                                                                                                                            SHA1:8630ADF49BE5197C8BE7DE3064853B974EBCC40F
                                                                                                                                                                            SHA-256:B5A5812DA8C7E672AF1430BAE440E86D3563068934E4BBA8CBB0EAD0F963F714
                                                                                                                                                                            SHA-512:675FB67447459746699BFB35E39D6C5A48E059B1926E2DD25009B61F804E2F1404756AE73CCE5F6FC825E77FD004735F43E66A8258E85A40F980C2325A0B3DE7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...b...a.....-1t.....pHYs.................sRGB.........gAMA......a...%8IDATx..}....`dV........-.[-..3.E.!.f.............A...am..X........`cN..........l......U.ygT.._..M.*+3222#3"2..7.3..^Z..h.aA.#t:... M..z.H.Gk..BH.c......u..j.wfz.\..V8.....b.}....^..uv.@...y.\v.P....[.o.........t....C.....&8......<.....W....!|$.h........L....d[......0..G..N. ..\...Mw....l.s.....B...y_Y...N. ...S..=.f..$p..rJ.!...f.=...S.......7...._3b}=...#Fu..........O../3T..L..3.e.\....|`k.8@.$.9.7|..N!.2A.#.]..#M.R/M.7...q..o..?q.]...6e=..G.&......j.(.P+.09. .E..z....;.]... ...F.....O.@N. .*x.....[..z....o.9...~....W..r ....t....4.i".....q.3....\.>.... .Y.&.JuuR.1..'Z.z.1.U....S....Ko.S..c.o....1.jW..7y...P*5n..W.U=C.{....../;....0v6...Y.......'M..K...o....nu*.....>r_...#e."..... q..bv..?....u.cu+.....-.*..fL.E`...s..=.....G....'E.....r._u.9.|...6."T..||/...t.....q:.Zh....OBx,&..o......gv.t/......ap..y_k...........#|../.......g....kV..F.`...!.[..wH
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 97 x 97, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9167
                                                                                                                                                                            Entropy (8bit):7.966353314469126
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:LSgdj1ijBb2XcxmTaGGEWQtJO9gfSgdXl/pfywweHSZnda:+4j812XRcEBtJNtdvfg5nda
                                                                                                                                                                            MD5:8B09AF802EEF156F9466C3FBE5524BD2
                                                                                                                                                                            SHA1:B30DD8FCCC6ABE38C6215339319A61E8EE2DE6C8
                                                                                                                                                                            SHA-256:79A84DE2346F891575C8BBF2AE394492424736F2C611B3921B5B2ADBDDE5C31A
                                                                                                                                                                            SHA-512:7EB38602DE8748B3D8E722C437DB581003EF666CF32276A8D5BD7BA4C5E49C6D1861A590BAF7D4855C229F4918F147C03440FD8629DBEE068A26F494358D89B6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...a...a............pHYs.................sRGB.........gAMA......a...#dIDATx..}....p......( (.j..7p..*.dq.5`tT@0...cLt...q.d2..g..9.#*.%9....3.9.."KTD.,f|...(....w..[uou..oa.S....T..[.nu.....`......#@.Ax..c...-..`......G.....2.I...28@A.......x...{...!..`..V....}w.. .gW..|.W...uW...z...|...i.m...D......F..(a.....5k<^~....+...y...>h....U..n...n.L0f&.'?..j.(.....a....?f.>U...wP.w..%.._...Jm...W.S.W!I.@.n.....zm...7............M=`....G'adu..'...;`g.>vS.L.f..oB.Y...ol\...Sz...0}..p....7C......2n7n.I..t.*.R.....lh.....K.L.}.{]...!Mg@G\O.N..{.'.._.t.... [v.A^.[.(w]r..Q.....t.|...{.......2...~....V...g.^UB.._.M.......L....n.U.R].v5..].B!D....r.T.m.67.....O...{........A....a......^....s.Q?B..fC+.C.}.n..A........l.]u..D.Z..6.m.K+h..x..l....)G..~w.|...v)..."n...{...~..78..m6.....W....Q.6u.~<.`.#.h ...5.2.B..k......zP...~.......O....e.....=..H...q$t..<F.w..w...;v.T.;u2...>;v..;......@(.A'c:3.{.9..y...^.m..^X'v[..R..a...;wF..e
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):27336
                                                                                                                                                                            Entropy (8bit):5.57578184442293
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:UBhBT/W58RrB3M65lWHqXPDenaKb6ki29d1ikN42niSJIVE8E9VF0NyJlP:uBr3M65Kr22Psu/2ExP
                                                                                                                                                                            MD5:5E8BFBB3A3DC1E55C7D024E6C1ED51C5
                                                                                                                                                                            SHA1:5676951B6835B3426365F73A5FAF398BA705B611
                                                                                                                                                                            SHA-256:C5C3A970925D4BA60CE859F90ED37A206BD658B88F852BAC3B182BED75A9C9ED
                                                                                                                                                                            SHA-512:F14CDB2AF7B6FCAA7A3C675D512871AF019B83764E848B23EA765EB3B702BC36BF56B9D2D9B93898354F893F7819A706798B1EC3229559770159992C8E3F54FD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Joe Sandbox View:
                                                                                                                                                                            • Filename: Canvas of Kings_N6xC-S2.exe, Detection: malicious, Browse
                                                                                                                                                                            • Filename: Violated Heroine_91zbZ-1.exe, Detection: malicious, Browse
                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Q=.0S..0S..0S..O...0S..OQ..0S.Rich.0S.........PE..L....XWg...........!...$.....>...............................................`......._....@.......................................... ..\:...........@...*..............p............................................................................rdata..x...........................@..@.rsrc...\:... ...<..................@..@.............XWg........o................XWg.........................XWg........l................XWg............................................RSDS../.|.zH.?.iDv......C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\Win32\Release\Resource.pdb......................GCTL....p....rdata..p........rdata$voltmd............rdata$zzzdbg.... ..`....rsrc$01....`!.......rsrc$02....................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 27834 bytes, 3 files, at 0x44 +A "\resource.dll" +A "\resourcedll.manifest", flags 0x4, number 1, extra bytes 20 in head, 4 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):38530
                                                                                                                                                                            Entropy (8bit):7.954027041122931
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:BPTPipu6nDeFnJ8mfpiAFlRPJy5nG9hqKwIvylo2PsY2E7H:B7KEYDeFJ8mfpv5PJr9cPo7Yd
                                                                                                                                                                            MD5:B40FED403CC20AB93D2538D2CFDD1EB3
                                                                                                                                                                            SHA1:804E6C796769F113716C66F84849289ECC77CF92
                                                                                                                                                                            SHA-256:BA9DF47AD7A36C724204727E53DD3CBDACBBA3A581797345926762F99885D82D
                                                                                                                                                                            SHA-512:4ADFA6CF722544F71938F06B6559209788D2EC3780855A342569DB927E765A1EC675C935500ACF196F154FE2DE2DC23B2454656F8A818AEF9B172D4DE5A93F4B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:MSCF.....l......D............................l...)...................j.........YLq .\resource.dll......j.....YOq .\resourcedll.manifest.4....p.....Y"k .\webadvisor.ico...t..8..[.... ..q..@..$Q.P...>...m..........F.Q.]N..D.,..*....Q(.RWBT.P.@..@Ff..............N...@,.T7...a`..].RK..wC.[de.{....z....g..F.].._..).QFeq. ...d............h...l{.}.....w.I6h.&a.!.h4.h....FF...Pc.k..... ...J0..#...S..B>.....+M"o:...6......1`.!..-....g..j.1K..w....trji*@'*.8:#.........3....r.....47.6.c..j.R.. .kg.4..A.....o.M\.-D......I.7,...G../}....x..{..=......].xB.~..."...]....\.M....>.DsK......)....J..E...y...m.-w...q]2..%.}..=.'..-........}...S=.&A......6...1.k.....S.s:.K.pe.Na.OX8...(..c..Z.P|........AB...~..]kt.......x.......k.P.8ptw.q..Q..<.W..O..1o-...p].o..Z..A....Ex..q)..'{..-.\... . ..=.Z...\.a.W-M....*.........i.S#...<..@.....f.P..=Hy..c.......>\y<.x.a......d..>.y..b.-.c.$..}.x......Z....8yQ.c...D..M.@l.....,iBH.x...!... .A$..M.A.Aha....D.{.B.A
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 325651 bytes, 2 files, at 0x44 +A "\servicehost.exe" +A "\servicehost.manifest", flags 0x4, number 1, extra bytes 20 in head, 29 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):336347
                                                                                                                                                                            Entropy (8bit):7.998457346375142
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:6144:mbbCLH8RBLMUtQl5vbMTCcl3ahyMsCjR9ytMtO8tLjs8NYxkjS:k8cHMUSl5zROKhFytMtO8tk8NYxH
                                                                                                                                                                            MD5:208D8F91316603869AD394B8688FCFF0
                                                                                                                                                                            SHA1:649BB6533989CB329055C85D6AE5289911853311
                                                                                                                                                                            SHA-256:C461B03530D9417E38CA660CFEBB72AC0BC04CF02A5394A7E006711AE26C0B12
                                                                                                                                                                            SHA-512:19AE6EF1D5DB23BFED14A554D9166F55DDED95725A81EC73434D422962C09D303181658F0D33486F9646420121839248313484C6C619625D00646F929A7D3FDA
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF............D................................)...................!.........YBq .\servicehost.exe......!.....YLq .\servicehost.manifest.\......[.... .1....C.%"....)......^RY....A.JA.F..d(....h..&;..;.....&'... '?.~.=....6....M[..;.i.......^U. 3.........z?.^{.H.h...A..:'M..A.....TrWy...&.M.....A.Au|.F..v^...R@.J.2.D#.I.3.uH........... ..1...7...)............._..^.o6._.....<...?G.....W.....p.V....L...d\'.....^y....m...n......._H.].I.n....n![........j._.).........C...*.O...w......lR.=..W..v.|......v....^..*._V'.7..r.......p....m.8.WXE........m~...)....w?i.4.s....}{.....w..6....o....M._J...vw....S..l.v..\.x.x.........fk.._:........l.^......7.7......[....[2.....>^~.3.............V.|._OwW...t.S.$.-....i=...W....S...v+....xR.-......b.&.q....o.n..]....c......?>.w..$?...z-...{...Y...O.I...9....:.K.Mh..j....{..g.d.o.{..E..Z..>.i..M...5....3Nf.:.........E....f..;|...q...mc>.~..S?..M..7.)...I...o.>.<p._T.........g....../..6.mrn...x..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 792715 bytes, 2 files, at 0x44 +A "\settingmanager.dll" +A "\settingmanager.manifest", flags 0x4, number 1, extra bytes 20 in head, 61 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803411
                                                                                                                                                                            Entropy (8bit):7.99959252090515
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:12288:5m726vX8g2LmrswYCCNzEkzEtGMkkSKEZmqfzcVALFLc3nZDeg10emzCkc2w4G:5AqL1wo5EkcHE5c0qnReGmzCQw4G
                                                                                                                                                                            MD5:2EB5A010C9B9ACC0AE15E0C5480DA20F
                                                                                                                                                                            SHA1:1021994A4B7D59347A112A26F298DF0DBE694834
                                                                                                                                                                            SHA-256:9F6674151FCD2E4842247436D90AAB310F85BE8D7F7F41886A2A73DA05E103C8
                                                                                                                                                                            SHA-512:4BA98F9290D052172EEAE47DC469E91EDA2CBF92F5CFFE5ADDAB0A00A548AA706A88C095741FA5182378EAD7E32922FCE3370C7C4EAAF0886999F136EEABD8FF
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF............D................................)..............=....'.........YCq .\settingmanager.dll......'.....YNq .\settingmanager.manifest.?.......[.... x....GR.4".....~..sO...]RI..Z...d.9....WN...\j......fa.lQ..e@..f.=...5y7..;.Uxs...}...n...o.@<F..f.......{.{....w.....O.[.M..E.X8.5...X..M..8.0......q..+....sP. TZ@........#..}..P.. ..j......w..w7.....%.*f.... b..'7.]_...^...rM4........3..{[...SW..i..2........{.....}..:.7.\.O&:......?....l/_.x...|../.M.nk.>....g.o.[b.w..q....U..M...d....._O..mzm..!.N.w.v.e....t.u.n>....ry.N=.}o.e...qc...)...`.6o.......g....b....k..........>7....]$....T..?..m9..m.w..?...2....{6..{y'.hC3.....K|..'.z..o..6......>.}..,s..u..[2W.i$;...._.~....m.&...^r..m...~..........l.&.s6..ij..O{......}.......]/(...d..~w....6.....f.>.....o.W......p./.........6.........+..m.{.K......}.Q...mj.&v..<.bF.....x........N.n..w.o{<..n...%}...x|}......Y_... .w.M.7......<......~J....u...;....m...+.-w>.....=...........]...}..2....
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 3084243 bytes, 3 files, at 0x44 +A "\microsoftedgewebview2setup.exe" +A "\taskmanager.dll", flags 0x4, number 1, extra bytes 20 in head, 185 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3094939
                                                                                                                                                                            Entropy (8bit):7.999887057255646
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:49152:3y3xnx08sXqiQVLyAQ6l7xcha+PVhtnHQ02CnCaxEYC8DPPA6tjfqA5qFvNTH/:ipx08sXRzH6l7xktNQ0/nC8bDPbBfl0N
                                                                                                                                                                            MD5:911ACE2C29FF8EFF71661A1D40899F5A
                                                                                                                                                                            SHA1:45134612E4211FD9DDF096DC0FD1A23C6FD8DF7F
                                                                                                                                                                            SHA-256:D382E4573197AB894D6D89F7807CF277B78910429D136DACE3DF13F4BC89361B
                                                                                                                                                                            SHA-512:9BD6586A965673078F3B1F507E8A55638FD7C6A48F9A43A0DF3BB5BFF774DA9F40F4F4E7B0924493E84EA6211C1E998F4E135FA1D9E8F6E6CB977DDA042FBD51
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF....../.....D............................./..).................. ?.........Y.p .\microsoftedgewebview2setup.exe.8.@. ?.....YJq .\taskmanager.dll.....X.\....YNq .\taskmanager.manifest......I..[........."S`$..........XY.....$.$B9f.....0`..u$.*.V..w..g;`.......l.........d*<.*......@H..E..F..h....m.l.m...sy;3...r.....g....~.....ml..<hm.......@y.`7m66..-Vp...[Xm......b..`...Zq..7...f.....71K4..\......#.TD.U.E.{{..f..]...BeD0 d"...t@@..A....pr....B0"`Qy.rS..>a.5..@..u...*n...D....7..W+=.W.h.~.[?..SQ}o..I4....*.....vQo..w.K.O.Uj./......Q.?....T.^...l..'P........>.1....-....../...~....y=.~e....c...nVX./..U....4.o....T..O.....;..R..!..`.{l.....Cr.?.7:.Q.....+5.....>Z...,j.|.....-..L..+0.<L}..Ecc...V9s.kq..u.8.KUb...7.w..l..d?..`....K..+Kc.h.=F...~...\...\F.....j3.<.g..r.4.\zO..v.-..;..:.\..wdH&....AU...z.....0W\ X.'5W.J`>...z.......}..dr.."...*V....H.EI..[.A`.$[.fS ...z...^.Ez.....9..h..'.....6../.ut..(.c....0.b*.....'.dz0.!.`.....F~Z.....y...&.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 320923 bytes, 2 files, at 0x44 +A "\uihost.exe" +A "\uihost.manifest", flags 0x4, number 1, extra bytes 20 in head, 28 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):331619
                                                                                                                                                                            Entropy (8bit):7.998741872658551
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:6144:ZCErdbWdAgQYM+E7K1G8bi+KgrK5BkgmjP6cz2r37a+Winmk4FlDJ1BakHeW:guCdeYdTdYB5u87aimkqtJ18K
                                                                                                                                                                            MD5:4981CD63B9694AE01D847DD6062B4710
                                                                                                                                                                            SHA1:4D7DB8426680D83F00A947117F6AEA2F93F51B68
                                                                                                                                                                            SHA-256:ED3AA972B8CA5CB4D8BFBD5A64899B0E94A6774A8EAF7A07F33C042542B5B5B5
                                                                                                                                                                            SHA-512:43E8F81E26B665BC25B6DCEF5BE72D942273A51B4B246180A29A65FA536432150507BEEEB8B9BBCC1F7AF010D430B2F4C976A139AACC4181A5BAD95207060FE1
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF............D................................)..................(..........YLq .\uihost.exe.-...(......YPq .\uihost.manifest..K.<....[.... ......C.%"....i.+./-.....2..AF9....<.E...L.BG.s2L8H..1mt. .s.w....w..........M..H."}.Mv.&.2.B..........y?....]w{........2..o"T...d.u.nZwo7yW/.-....a.....Q.....^&..0$...A...O........A...5.EdPF.........A..iI.[...7.....6^_.W].Wx..6......[.4....~a6..G.'..$.....].M7.%.H..<.Q.A......2..R.%n.^....Y/.3....i..nys..6.!n.....#...a....e'.r.{.:.&.y/h......M8..c.....e.9.7.q..C.\....y7N......m.../.v.M^..k}...&..............G'.o.S5......m3..>..\2..........a.r.T...GL'...~..U......).:...zz?....t...b~J..%.$2..=.........~|CH.Yt...omd56.......w<;O......+..............&y.;.......1..S....E.q.h..%"u.!y...OI.?.oKo..&.K>.....x>}.ru............^}.m....>.=]....Y.4..xj....&.g$...s./.._.<...}pi-l..Z.....q&lc...=....:.......U...{../...~...}..6...;O..3....G.\t.U>.e>.|...9i.....C.?.=.........y..{k..o*..........q.v.*......wo
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1903517 bytes, 2 files, at 0x44 +A "\uimanager.dll" +A "\uimanager.manifest", flags 0x4, number 1, extra bytes 20 in head, 179 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1914213
                                                                                                                                                                            Entropy (8bit):7.999667338831825
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:49152:yKMiSSfA6FHbmpr7uesuCOsMtjXelk0ctCzF/B:9MiSSPHq+elnsMtj8VcczF/B
                                                                                                                                                                            MD5:ADF2753456668E23BF3E9742A3BB2005
                                                                                                                                                                            SHA1:588A8DCF581EFE21F9BB85103B7E64D5C2126E26
                                                                                                                                                                            SHA-256:18127EED598C2244A0A8BAB993047E1226A6C3AD83D2F50D1D69522F99B14BD2
                                                                                                                                                                            SHA-512:4D5CDFB9762586A725BAC4300D8616CEA846641AE73F39B7EA9216C175F819E0DA8866EACDF4BC73D22DC43B67723A93E44F50C0B7EF4C67635209C643A3BEA6
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF............D................................)..................X7Y........YLq .\uimanager.dll.)...X7Y....YPq .\uimanager.manifest.....;..[...W h`...@D.0.....[..Ve.........h.bh......Qb..1Z.^.....z........a.....E..........Df..j......=..............#..Xn..]......."g.ZEN..>...s.$.cn...,O"n\.,..N9O.#c.m...I...I.7...b..5k.....-.T...,.@...AU.@..U......".""(..".9}..W....`556/..j..Dh[....D.....h.@.X.T..n.Q..n....0.M.~.;..=`..N>.4S..."....}o\./....;...tv...x....O....t....t{..n6+..vT..*g.s.....%.r1.4..fL.E.7nV&O...Sf....u....u..Jj..K.9.,.{^.[..........^?.w.L9..W..{.....T.].....w/B...&........vf.+...^...=f.j...\..}.....J...6..^|O._......-.>z..Z.@.k,.L.m......../..07..,o;.a.z...{..G.....hE.`..G.7.....F..g......ZY.)......7...W.?.~1...9....vK..M...oFs...P.A..b...?..........%.......r........E..........=....m.j.l,..v....?L..-.}t=....a.;{.......r.o...?I._.......? .v9.,.w...@.J.]j.$.......<....r1...=e....S"ZM..f=.W.~.U2;..Y.i..4n..... Ktk....muOa..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 1060402 bytes, 5 files, at 0x44 +A "\uninstaller.exe" +A "\uninstaller.manifest", flags 0x4, number 1, extra bytes 20 in head, 93 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1071098
                                                                                                                                                                            Entropy (8bit):7.999586558542834
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:24576:t3FJD195W15hAfcyKEB2rxIoS8VvGwX8wWqIhVi15fUmB:t3Fp0BA0y9ySgOwX2hQ1Fz
                                                                                                                                                                            MD5:E50E13A73D3DBCF71FB24D60551EACE5
                                                                                                                                                                            SHA1:5C182CFBFEF403A6D6D9A08B204E981B0B7C9C7A
                                                                                                                                                                            SHA-256:73C1C4DF12FE3B41CF6C93B7386C7ABEA7A6B4B2DCA8B38F677FB0AD5638D82E
                                                                                                                                                                            SHA-512:6ED8B0F3E276E2B7055081062F65B30EC8EAB038462FD876B453B87756BDDC17D44DBBE07F6E8E614F9F3779C6EEA0F9E29A9D5F1719FD4DC46122F8E9C8666C
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF....2.......D...........................2....)..............]...0.-........YLq .\uninstaller.exe.u...0.-....YSq .\uninstaller.manifest..&....-....YSq .\wa-ui-uninstall.js.....].-....YSq .\wa-uninstall.css.....C......YSq .\wa-uninstall.html...K..)..[...! .S...@..%.....[_.l=k.m.lS.k.(rc..r{_.:._...\h.:E....Bs.+.v.Q....u..n..w.R;....D 3CuF.g`....s.{.n.g.G...W.@..uE"A..$y..u..$..M....[d...EH.....\.yy.4..;q..B.$D...iX.....t7y.Dy.+.......U..@U../(.........2+...o.s}.T.4...U..;..h..S. ....;........EU%U.K.QG.;...7.u.3.!W*.j............r...^.....r^......]s....M......B.W_l.<..g..]...Gjf.>..G..{.:b...=:....t..].S@v~.fs.<...K...5..%..&.........u..]L__C.9/.c.umR.[.*d.\.z)U.U..ZJ...Z)........Y%g.BHDCU.j..V..5<.._........P.Q.Y..+.............:../5.l..<.sew..~K.7..;..6...j...o.......v.M..`..6]..w..J_m...G..5.bV[t....-.....*.}....ySP....U...B..x.......s.4~...rb,...............tV=.u.M.a.R..;.....w..-..s.....i.7zk.]...wT....n......o_.up:*.>\.?.u...%.'..L
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 975981 bytes, 2 files, at 0x44 +A "\updater.exe" +A "\updater.manifest", flags 0x4, number 1, extra bytes 20 in head, 85 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):986677
                                                                                                                                                                            Entropy (8bit):7.99956639708756
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:24576:RBd9puI1ziTB2EmlSFYf0wqb+mrB35oxdRpE:R3uIFETmf1aadE
                                                                                                                                                                            MD5:78C722BE85852E553B64D8712469F279
                                                                                                                                                                            SHA1:B1E77B8C1D0CF642B97DEB769479B5B1204B7D39
                                                                                                                                                                            SHA-256:01FA1D5C7E9C064C8128CFD753C391D617C9781095A9A5E97B36E765ABA5DF5A
                                                                                                                                                                            SHA-512:0FF015BC2A44D4BC9B6EEBC6C666ABFF176F84F268E095DE03614CD672C3A6416E9904375D82763ECA5A697383FFB34796CD96B8E9DF81E39B88D25AA0732730
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF....m.......D...........................m....)..............U.....)........YLq .\updater.exe.......)....YSq .\updater.manifest.9....)..[.... .....@..4.......}.Z......(.....6(...b..hi...N..h...W'.v.KM....F...Fl~.R2g..ff.f......w...W....-..I..(....E....M....j.$....W|.m.$.Yg............J.. h4.....8&....".L.(2.,..~. .I0.......H....3*.3y.........Jk5.Z.v$.8......2.6...J.......J.wII5X....M..])...r.<...5...v^.duX..k...9.\o..v_.d...%..W2m..........?i.H?z...5..._u,.Wi.0......'..L..?.S.C..m....gl...?..H[........._W;..I....0y.i9g{UT)...y..MZV..*.?..>...k........Z.F/....#V......S.l..~.aG..P...+M.p..{...s.JQ.\J.x..|..$.+.g.0.g..o...`...~.m.....^.....2h....g;O...c..l ...o.o.m....?.d...K.s.vz...{\b..y......dKl._.]u..]....x......N......l+.=.`.|W.s[.s....n..M.:UN..)..]X.l]].....N..om.n........37..Z.......))..Q`y..E...+%....z...^6..E..`>......C2.....]...a......hx.....4....._.1na.....y<;N....:.....O.Y..vT{}...q...+.....T.1.......~..zP.v..*..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (33246), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):34082
                                                                                                                                                                            Entropy (8bit):6.048810099348607
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:E9DDI1HkcKGBrgXjhvgVfk4rcB7uGzQtn4rZW:E9DDI6thXjez1jtn9
                                                                                                                                                                            MD5:BED2FF23927C34F86C480203AA7F87A0
                                                                                                                                                                            SHA1:90B1B32D7A9CEECCD555D674582CB8AEE64E8909
                                                                                                                                                                            SHA-256:9D7AC9A5AE897E993C0B6BAD468F56BF3B6CEFCFEAAD6FD2307CF8370945A2C2
                                                                                                                                                                            SHA-512:6538FEDBC2DCE5EAF944CBD18F93783CDBFDC2920726A3509D0686BD062793B422AE6C6F67DFB0C344AC3E084F8B1F10425FA4636D1BA0FBD9E2ACE86EA6AE83
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Open Sans Regular */....@font-face {.. font-family: 'Open Sans';.. src: url(data:application/font-woff;charset=utf-8;base64,d09GRgABAAAAAGEsABMAAAAAsTAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAABqAAAABwAAAAcbEIkOkdERUYAAAHEAAAAHQAAAB4AJwDwR1BPUwAAAeQAAASiAAAJmCwaFlhHU1VCAAAGiAAAAIEAAACooF6Ikk9TLzIAAAcMAAAAXgAAAGCg5ZlGY21hcAAAB2wAAAGGAAAB2s9AWKBjdnQgAAAI9AAAAEYAAABGE1sNN2ZwZ20AAAk8AAABsQAAAmVTtC+nZ2FzcAAACvAAAAAIAAAACAAAABBnbHlmAAAK+AAATOAAAJGkMGdKhmhlYWQAAFfYAAAAMgAAADYJip5GaGhlYQAAWAwAAAAfAAAAJA9zBj9obXR4AABYLAAAAjcAAAOm2kNYqmxvY2EAAFpkAAABzAAAAdZ4GFVubWF4cAAAXDAAAAAgAAAAIAIHAZduYW1lAABcUAAAAgcAAASAUcWdxHBvc3QAAF5YAAAB7gAAAt15xIzucHJlcAAAYEgAAADaAAABfLpWDR93ZWJmAABhJAAAAAYAAAAG7JdVfgAAAAEAAAAA0WhVmAAAAADJNTGLAAAAANGknRZ42mNgZGBg4AFiMSBmYmAEwpdAzALmMQAADaEBGAAAAHjarZZLbFRVGMf/M51hxoKWqtH4CBoyNrUGjQ1J27GwatpaDZZpi4MOig/iAkJCY0hMExaFgbgwIQYrOTxqCkyh0FmQUpryMkxXLNzhaW3jyuVJV8QFIY6/c9sp4EjVxHz55dw597vf43/OPXMVklSpbn2qSEvru916/rOvenep5oveHTtVv+uTL3droyL4qFiU9/0316GdO3p3K+6vAiIKB2NcoXh
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):26093
                                                                                                                                                                            Entropy (8bit):4.7761022291638975
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:J+6T4vNmgN8k0+yycVCI6z0jG7RXDX43UMRmvm/A:aDIpI
                                                                                                                                                                            MD5:F43DEE507EB2DF869CB73160D95D37C0
                                                                                                                                                                            SHA1:F58C1E59B243C7A26899DAE98F5EE4A2D9BDEA0D
                                                                                                                                                                            SHA-256:BCFED78D2CF2398723A9692B56C975E69B8688878444EFA90C8189F442275BBF
                                                                                                                                                                            SHA-512:7CEFD72CC1D4867C6EADB101C0D96BB0E4F2E0B911FE91723C25BD61352F165D8ECD1440549BA08B490A97EDB59360A8F681B8341F779680DA036C4D8D189444
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Core */..(function (wa) {.. var core = wa.Core = wa.Core || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External;.... //Component.. core.Component = function (name, status, key) {.. this.name = name;.. this.status = status;.. this.key = key;.... this.isIgnored = function (key) {.. var isIgnored = false;.. var startIgnore = this.settings.get("startIgnoreDate" + (key || this.key));.. var ignoreDuration = parseInt(this.settings.get("ignoreDuration"));.... if (startIgnore && ignoreDuration) {.. var today = this.settings.getToday();.. var startIgnoreDate = startIgnore.parseBasicDate();.. isIgnored = today >= startIgnoreDate && today <= startIgnoreDate.addDays(ignoreDuration);.. }.... return isIgnored;.. };.... this.isInFixGracePeriod = function (key) {.. var inGracePeriod = false;..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (65472), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):636601
                                                                                                                                                                            Entropy (8bit):5.63060729988193
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12288:XKNvSkRBq880BAA0967ktah2IdSv5543cKNLNNVN56wOr7MdRhPEceKr1GPHte7t:628L4LItv7
                                                                                                                                                                            MD5:32190953AE1D851EBA731EB250147E34
                                                                                                                                                                            SHA1:E1D0DEB689A194648C7B88C08968F50A6581C369
                                                                                                                                                                            SHA-256:7FD09C7D1237844150EEF67CB08DBAC2E7348E45C21E815E581FDCE10F73DD73
                                                                                                                                                                            SHA-512:3F520F1D597C4875E76530EA694816245A0CB2BA48C80B8F5E439640E4BE99C24A48B464ECD335A3E2CF77163AB81C985CE874C055F1A39FC0592890776A644E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Poppins Light */..@font-face {.. font-family: 'Poppins';.. src: url(data:application/font-truetype;charset=utf-8;base64,AAEAAAANAIAAAwBQR0RFRgkWCRkAAAFYAAAAQEdQT1PuAPdbAAAjPAAAE7pHU1VCP5XTjAAAWZAAACZyT1MvMtmIduQAAAGYAAAAYGNtYXA1CTsUAAAB+AAAAtJnbHlmpQ0L6QAAgAQAAfCQaGVhZBrmJFkAAAEgAAAANmhoZWEMkgZMAAAA/AAAACRobXR4R+vvSwAAErQAABCIbG9jYYQn/AsAAApsAAAISG1heHAEpQExAAAA3AAAACBuYW1lvgkdKwAABMwAAAWecG9zdDq/aJsAADb4AAAilQABAAAEIwCXAAwAeQAGAAEAAgAeAAYAAABkAAAAAwACAAEAAAQa/qIAZAoD/fL5hQofAAEAAAAAAAAAAAAAAAAAAAQhAAEAAAAEAQYZH5g7Xw889QADA+gAAAAA2KSpuwAAAADbFjbL/fL9zAofBB0AAAAHAAIAAAAAAAAAAQAAAAwAAAAAAAAAAgAIABgAHwADACIAIgADAHkAegADAH0AfQADAJIAkgADAlwCXwADAmcCbAADAnMCcwADAAQDTAEsAAUAAAKKAlgAAABLAooCWAAAAV4AMgFHAAAAAAQAAAAAAAAAAACABwAAAAAAAAAAAAAAAElURk8AwAAA+wIEGv6iAGQEbwJzIAAAkwAAAAACIgK8AAAAIAAEAAAAAgAAAAMAAAAUAAMAAQAAABQABAK+AAAAmgCAAAYAGgAAAA0AIAB+AQcBGwEjATEBNwFIAVsBZQF+AY8BkgH9AhsCWQK8AscCyQLdA8AJAwkLCQ0JEQkUCSgJMAkzCTkJRQlJCU0JUAleCWUJbwlwCXIehR69HvMe+SANIBQgGiAeICIgJiAwIDogRCCoIKwguiC
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1223
                                                                                                                                                                            Entropy (8bit):5.186885559675722
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:csYz7A2NVMz71Mz7FMzrVMzPVMz6LVMCo7jOWwV601:3O7A2meCeiCoHOrL
                                                                                                                                                                            MD5:A48CD7866D67064133CA40332E1AEBA2
                                                                                                                                                                            SHA1:690E6F818F41E2F0C5850453471920656652120B
                                                                                                                                                                            SHA-256:FCB36430BE30A6B2CFEDBAA99D2FFBA2A294AE0EC1357D182529E3704A2BC293
                                                                                                                                                                            SHA-512:6D610D0973DE74F313489078DB0E1D407F7656ECA275EC8A8FB312791F639411D80A8C91B2F1C74F42AC987AA94253804736DEF657B13D652F73D208FFE3F4B3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:wa-install.css" />.. <script type="text/javascript" src="wacore:jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-install-#loc#.js" charset="utf-8"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js" charset="utf-8"></script>.. <script type="text/javascript" src="wacore:wa-utils.js"></script>.. <script type="text/javascript" src="wacore:wa-core.js"></script>.. <script type="text/javascript" src="wacore:wa-ui-install.js"></script>..</head>..<body onselectstart="return false">.. <div id="wa-installer">.. <div class="header">.. </div>.. <div class="content">..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):19374
                                                                                                                                                                            Entropy (8bit):3.839664034038164
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:GVtiD5/K2joI8nXfzdM5cwwrbIVWw5ujfIGNELDoXpNxx:GVYjoICvGCnvP
                                                                                                                                                                            MD5:1A7B7910DA9584DA8D5B303DAE809BEC
                                                                                                                                                                            SHA1:9D624FB44988CF08F1641DFC69B4365ACD0FEE2C
                                                                                                                                                                            SHA-256:1DFE0D8D41907999AF6B9C0757FA924B46BE1FE175DA58D68EA3B3AE364B29D5
                                                                                                                                                                            SHA-512:516CD3BC185F746DF52D9D64E81E8CC57DF1F90382934557A1B5B785919CB2E3117C19AB42D10C27B88E42B3761DB4892CB126BF3B85D41037178E7FBF8B4C80
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Installer UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _instrument = wa.Utils.Instrument,.. _lrt = wa.Utils.Lang.ResType,.. _l = wa.Utils.Lang(_lrt.INSTALL).get,.. _window = wa.Core.Window,.. _external = window.external;.... ui.Installer = function () {.. var buttonId = "wa-installer-button",.. _this = this,.. RC_INSTALL_ERROR = -1,.. RC_INSTALL_DOWNGRADE = -2,.... open = function () {.. _window.ready(function () {.. //check preconditions.. var productName = wa.Core.WebAdvisor.getProductName();.. if (!_external.CheckDoWeMeetOSRequirements()) {.. _external.SetInstallResult(RC_INSTALL_ERROR);.. _external.ShowMessageBox(_l("ERROR_TITLE_CANT_CONTINUE"),.. _l("ERROR_OS_REQUIREMENTS"));.. _instrument.log("Installer",
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):16591
                                                                                                                                                                            Entropy (8bit):4.419418555736827
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:BZwBjFVz+j5csy4h11lidEaCaNz4UcEm7damvbat2RSFZC9On/7W:WBQj5csy4DIE3oUUmMmvbaHC
                                                                                                                                                                            MD5:FD128D0E27CD53B6F4AF938B28CD9196
                                                                                                                                                                            SHA1:8A5BBCF6B9D04E3BA1C8A5B54DDC78167A8ACFF3
                                                                                                                                                                            SHA-256:01923E4F4B2E16D2A870B6B1447FC9CC95CC2DF680CBDD5DF389A067DCBD30B8
                                                                                                                                                                            SHA-512:C785D2A6BF15CD5B109AF02118F2C69E7D51B58BD025B2227168B41EEB2F10B4B711F27052EF52F247F06A9DCC7292674D84C9070E5A1F1343C3F8BE67024F87
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Utilities */..var _langResources_ = {.. checklist: (typeof _lrCheckList_ !== "undefined") && _lrCheckList_,.. options: (typeof _lrOptions_ !== "undefined") && _lrOptions_,.. shared: (typeof _lrShared_ !== "undefined") && _lrShared_,.. uninstall: (typeof _lrUninstall_ !== "undefined") && _lrUninstall_,.. sstoast: (typeof _lrSecureSearchToast_ !== "undefined") && _lrSecureSearchToast_,.. install: (typeof _lrInstall_ !== "undefined") && _lrInstall_,.. webboost: (typeof _lrWebBoost_ !== "undefined") && _lrWebBoost_,.. waiff: (typeof _lrExtensionInstall_ !== "undefined" && _lrExtensionInstall_),.. ut: (typeof _lrUpsellToast_ !== "undefined" && _lrUpsellToast_),.. overlay: (typeof _lrOverlay_ !== "undefined" && _lrOverlay_),.. newTabToast: (typeof _lrNewTabToast_ !== "undefined" && _lrNewTabToast_),.. ssToastVariants: (typeof _lrSSToastVariants_ !== "undefined" && _lrSSToastVariants_)..};....(function (wa, lr) {.. var util = wa.Utils = wa.Utils || {}
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 14 x 14, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):558
                                                                                                                                                                            Entropy (8bit):7.494810764492959
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7iIHftwTmWkW3O+xbR/GfmNFycqV7o5jNiXrj0IGDfjo/1:zT5+aVefmORm8bnGD09
                                                                                                                                                                            MD5:F8AF1796D709A69C3FBDD16822596FD6
                                                                                                                                                                            SHA1:D216CB9A49EF4223138BE20D027B3ABEEFAC7DB0
                                                                                                                                                                            SHA-256:055E07F760351C3F33E708E4720D5A34A60ABD8D13F2FE05A473DFD5ED9714C2
                                                                                                                                                                            SHA-512:FBD9C93490B818798F4614E6EEA7EF9FA05D535F50071806E763CD9EBEE478559F614EAC90720E4B5F88D803DB0AD459F1D1C67954C2C379B1BB435CCA74390A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............H-.....gAMA......a.....IDAT(.u..k.Q....1&.k..T..bO.K...DP....I..{.PRA..............QA..J/....eM.tS..7..v...y.7.7.f..R?......W.......N.....G...z.N.a._.X=.sg.5..r.k....Z...R....[..X..W....N....v...H.1x......L......R..@:v.w.....W........v.lc/F..b .C\.:.[Q.`..E`.L.J..!....<..m.q....R.&...""%F(^M.`..e.,N..q..y<.../.O:.mP..,A.QrZ}[u0..,3...S.K.\.EM5.!mH......}N.+j....p.O.E.......[..C.\x......nMi...~%.vv...|8...y.xV..v<ZZu.....y]@.1......]..).6.M.'.'.%o.T..5.Rq8..l..;...Ha......5......IEND.B`.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 14 x 14, 8-bit colormap, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):785
                                                                                                                                                                            Entropy (8bit):6.380231936591206
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:nmwBSRPy8iSvgv+aYS0NFVO/6cgDHNUPZ7SCOr2zhxNoEMBxNB:mwBSRVL4v+/jNFVO/6cgDHWhbOKHCEIj
                                                                                                                                                                            MD5:5367B11C1B0484E2B64AFFF761DB5B69
                                                                                                                                                                            SHA1:CA05EC2A55FAB6A4035920C38B6FF198044DA594
                                                                                                                                                                            SHA-256:1CAE0E0663BA559CA8FE7AD3A1E07AB23AB9E3DBADA1AA572AD9C2C5D51D5627
                                                                                                                                                                            SHA-512:322DF7AFB16185EB4D39AA4881A27E04B1D310773FCFBB77D0F1C83237A56D100F6567091E30BF0DC6A11EA29A22A52BF091B66C5863823596108C155C031588
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............(.......gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....PLTE...#..$..%..$..#..#..$..$..$..#..$..#..%..%..$..#..#..#..#..#..$..#..#..$..$..$..$..$..#..#..$..$..$..$..$..$..$..$..$..#..$..$..$..$..$..$..$..#..$..%..$..$..$..#..$..$..%..$..#..$..$..#..$..$..$..$..$..$..$..$..$..$..#..#..$..$..%..$.....p~.S...NtRNS........................T....L..........K..T...S.....JJ...O....r)1N.T......L...P.....bKGDOnfAI....pHYs.................tIME........l.-....IDAT..-.g..`.F..o.PISC.[.........|..s.@.Jr.PM.3.Ah.&....dI.01..t...v.K.h.o[?..^.....Gc.&..8....A..<..r5...QY.F..n.8..@=A.l.u.....n.C.....>.o.4...&!.KUd.&R$>.e*o..T....:...~g....%tEXtdate:create.2022-02-16T15:21:59+00:00h......%tEXtdate:modify.2022-02-16T15:21:59+00:00..x.....IEND.B`.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 12 x 12, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):327
                                                                                                                                                                            Entropy (8bit):7.1140535970703365
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPIcWn2ofLbzmoGGaKdwjXI76l4AXT8ctmzXxNuJpTqAp:6v/7DWn3btahecDAuJp1
                                                                                                                                                                            MD5:C0708D1E58F1EF1BAB621620F3B09130
                                                                                                                                                                            SHA1:0BEB49A1CC1E71F364BCF42B474890F35CB8CC3A
                                                                                                                                                                            SHA-256:834380BD8B6F9BFEF000A555541AEC2BEC01DC46C91DCB7F950D109B81BAE5C2
                                                                                                                                                                            SHA-512:241C93BC2677B1F0788C2C0DDD9A7FFCCC7A865DAD427EA8C89E437FC796FD12F80D2A962A8D02B1B2391E10CFF768F17E34BD45502A0E31D6E1C8F443C2AA34
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............Vu\.....gAMA......a.....IDAT(...On.@........=J.&....5....8A..M]{..s......Q#0.7...0.......yr).q8..s....sp.....W.u.q+..;|.5&..n{..{.............>..".^S......#q.6B...4.t....~e.[@B.&...L.o...h..8.......Q....+..b.i..MhxRaG....Y..F....,......G.E....`(....V.v.4.b.$..S.O.....Sh.B....IEND.B`.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 12 x 12, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):272
                                                                                                                                                                            Entropy (8bit):6.591404605834916
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPIcE/6TsR/nQV32e46OIoiMr6FRK7MhtCxllbp:6v/7DE/6Ts/nnPIcr6+ozCjz
                                                                                                                                                                            MD5:F79A1953A8E6CC342847B4B00DDBD736
                                                                                                                                                                            SHA1:9AC411CADB6652F4FDBD854300ADCB5C21C04BAA
                                                                                                                                                                            SHA-256:4F8EF204C1884F868866D03B4D11DF1237480C1CAA38ADEC1C13444050105B88
                                                                                                                                                                            SHA-512:DFB54D3D20FF53B867328945FE3D69B56055D5861EFCE2A069653B1792A5477AB4C3B73A3DEE82DD1377D1573099AB70C2F6C285C694DDBD0B1EE9667CFC4F2A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............Vu\.....pHYs.................sRGB.........gAMA......a.....IDATx.u.... .DW>...>.RRYJq>).>|E...!..3...t...a.?..w.!.P..../l....2....Q..ZS.%'.........y^.Q..H.T.V.D..W]..t.*X4t#9O;......=U%u0...f.......3`...[.S^..m..$..?[...{4.Y....IEND.B`.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 25 x 25, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):404
                                                                                                                                                                            Entropy (8bit):7.033473403283132
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/75/6Ts/THdCug1JmIiSJgH0Htx7n6u3GvewiSulgs7:I/6WHdVgOSJ8ivnb2vXiSulgm
                                                                                                                                                                            MD5:958DBAA93BCDEADA1D578CB7AE159E1B
                                                                                                                                                                            SHA1:15B954D2E439A725CFE04FF14D16938BB928E937
                                                                                                                                                                            SHA-256:DAA47D81BEC1A30312B994269EF408222094C826661FFB655C2CBCEE25A695C0
                                                                                                                                                                            SHA-512:DF2EF3DEEE9ABF2E1E61A00419228D66492D0E36389D01AA9E9599F9B19AC72133068ADEF5A1E1D7F2E790ADF91D057568C0091C71DC284A0A6D89206738B57F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............c....pHYs.................sRGB.........gAMA......a....)IDATx..=N.@..g..(}.JJ.%.2..::Bk.9..>.PQSRA.+.L..K..J.d9.......j<.O..f.&......OR.Y.$....k.0^y=DQ.....@...'GB.y.....L....Y].!.'....j.....y.>.8.......!C.1.-......1....u..@.@...X:..b.........i.....m.b.e...H.D....ey..5:GJ.....t....M...O..BA..Wo...?.s.\g...?..\s...O.I.t..u......W...UO.&)..E..........IEND.B`.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 14 x 14, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):428
                                                                                                                                                                            Entropy (8bit):7.367179920202989
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7iIHbGI9XbxzlcdqzUCOXC5pC38WWn9:eGIrzlcdL4CZW9
                                                                                                                                                                            MD5:0EF65600F5A2D01876B6F9EC668C9D2E
                                                                                                                                                                            SHA1:31F378D2D6BE62F3A426523B1AA3D61323B2B9AA
                                                                                                                                                                            SHA-256:17DC5C3BAA1D35CA60C7DEE7CC70B76446765769960FC5D4852E065478C871C4
                                                                                                                                                                            SHA-512:7D9EC74CECF8DF49D4F8E676053573798A029D889E8676CFE90891EB68E49A2FE9AE828F38BB99851888B25A76581EBE2B62694D3C66D193016B4446004A9271
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............H-.....gAMA......a....cIDAT(.uR.J.A..f..&Q..*....h..... ...(.........K...!Vib...B...qf..{.9....|..3C............@..........5..8.b...z`-....s.ID..G....PEQ.;?1...p.h;..z6Z..4.X..c..$E3s.b..ry.|..yVy...0.Rr..W..S.......A.1.....s./".j..g.H{l...Q....d................fE..;..'+.).j.F...J......~.s..Y./...6.v....|......,...m..[m....n......D.E.OvU.n..W<.m..=h#.O..Zm.yj..@.tums.....IEND.B`.
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 107 x 108, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4418
                                                                                                                                                                            Entropy (8bit):7.945868276745926
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:BSXpPtcN4jQ/l2TW7NCXY5VudzavDXNuN+BOokaUxV0MBhtsW:BS5Ptl7T6NUBSX8N+BOXvV0qAW
                                                                                                                                                                            MD5:85731024186630DC2090EA039BC46BAF
                                                                                                                                                                            SHA1:1AFFCA914FE3D2EDE59753D85F0F75AD88EFC1FB
                                                                                                                                                                            SHA-256:0DC43266D3BBE9D952FEAF46E816E3F3C80C3425AF795D7C41FB5647C80A2FF5
                                                                                                                                                                            SHA-512:D7FE98C43463647DEBD42F7A79128AC681F89355244546DAE5CB924123CC1EFF0B18F71D9A50EE6BE3A4903B417B63C1665E20A19CB35435CFD6B7A7671321D4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...k...l.....m.L.....pHYs.................sRGB.........gAMA......a.....IDATx..kp..u.........I).)...m....Nj.-...V..L..C.Q.O.4iBu.f.G.$..C=..d......7...+}L;.......X..t..I....x?vs...."w...P..P.....s.....&&&&&&&&&&&&&&w(...J.'..'.g........m@S....6...D. .....G.<...V....+..{......Ihx....A..1A.._..X.a\Qr.(..;.;...4.X..D.8.Y.Q..gL.3...u6.X.... ......b.e.).|...9...!......:..Z.V..,.n..T,vw.(..M....V.tz?p.[........z...]..nU.&....E.&........W..Y.:F....+..6.".3V.rZ.z.2V..X...nDs.Mz..$.h=.b..`>..^....Qo.hh..jLM.JG..).c.j..H|VQ.../j.!n042..6(*J.....|R...o...._{^.F.}..PV$'.y.z.*.Z....D..Pt..P6./..I..j.V..4.........._~.......*...0x'.%.....?...au.J.."..#.<.U.F.XP....n..eeD.P.i(....,....t...#p......NG..E...~..?(l+..%...&.....>A.h.L...?...........a..&.b...K..$[..\<.9.D3 ..Z..J..N@..P-.$.s; ..v...=..B.J....%.....i.J"..k. ....V./Z.Y.......wQ$.6.Q..B..Z#.... [...P.q#..zC7.]Y.F..s.s=(..%..T@Eb..p....J.$..B.T&........lp.B.{..2.y%i.s......
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 233 x 30, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5361
                                                                                                                                                                            Entropy (8bit):7.956335361585333
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:tXYxwio7C2guemm5poLpMmjxiN4f7DsCk7RkuxKBaKeVfGJiQmiMQ2qileA2I:toxpo9gKmsMmjwSXgyLBepQblA2I
                                                                                                                                                                            MD5:0D8F8EFEB474FC9B2C825D7F2A875471
                                                                                                                                                                            SHA1:ADBC30FD0131A01B3150753C7EBFD6EF648F0DE1
                                                                                                                                                                            SHA-256:ACC40FDA844EADDF65B9580C484F1FE2E17358B352D99BABC6865BF0C74D9B00
                                                                                                                                                                            SHA-512:90FEBC4B2165D37CBB1CF09295CF2F5B5713DD14A02CDC101318426CEB55D35B7C47B254D0F20CCB8297FC69EE77EAA5969FF98A0965D325C94AD81B6A56BA9E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............9B....gAMA......a.....IDATx...xTE....I .D..l,....(....Q.\..ftf...qA..D...?a..o.#.8..<.9:....A..."......KB...?7...M:......}7U..9..N.s.T..hZ"%$..@B...$$..@B...4!.UYY.E].Ln.%Qu.K.8....Z+I..m...m%v.6...K..]ki....W.}.y.%.O.1"dY..5...{...x.ef.X.~a..3K.u.l^.8'..?.z*#%.._.}.yT..Z..k..b..3{.{.>W_.,x,J......LM.T.>.x.....^..c.'...8^..(]...z(..._.......&..w..9..)..W.,s1.>.):.0.4.Y...nq...7....;......7)Xk.a...O...g.l...c.^..)8.%.e...h....U..7.O.'$.....]K.r0.Y5u..K....tH?.NSzwl.o..IG6...........X.(.z-.X....ju.+.Jpd.j......t.>...../?TW.0u..7........@B.. ....yYZ.iZ..:s...}_X2.O.....1kJ..3.*.9+... ].4.Y.2.....r>hM....}..-..|!d..i#U...F...Dr...5....D[..]..u._u....[.>.{5.xX...t.|L........}?........J.H?P.....M.n....-.......d......pQ....3..[...;vT.dg....5.@..0...[.c..1...U....i........a...o..[.PB.....E..^......."|........$..."V....tZ..`W...[...z.1..[~.Buu.[.........]/..x.(.`Z.A....`p...]RR.4u'u.]..u'...p..[sh..w.....g+
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 232 x 23, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2938
                                                                                                                                                                            Entropy (8bit):7.909981061900822
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:nv/69bTJ0Ji4hnEhRHzXJH3ndGzDr9zHUeqr7zpiT7efEgo3cRE0+U9sLBCYv2ZG:vSdJN7HziDr3S9i/efLQcRZ9sowGdK
                                                                                                                                                                            MD5:65938FC9439B2307513A95D515BCA1F7
                                                                                                                                                                            SHA1:DDDFE8D64ED371E973C46B6726B60BB0C0810BF9
                                                                                                                                                                            SHA-256:B2703E2E2A404B90EDAB7A67B23037C32BE2780F20CB15FFA6F6E44666B8EFB5
                                                                                                                                                                            SHA-512:93F755F5E208CA08955684D7789F6B8AF49F542DD41AFD9D678EC417CB535734C9C8182B87EC2EA8B8AA9FA502AC8BA90E383A9977F7E01BFF393AF0D1F400BA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............m......pHYs.................sRGB.........gAMA......a.....IDATx..\]R...o.T.yZ.'.8..y..f_"N.8.....`N.r... '.y...>,{..'.}....n..%[..!U.)..|.t...G..O?.. .~....@.N...a;..e.....1}.?....>.Ma...>.?..u.}L...m.N. ..8.>fe*.z..dr..u.D.1.R<.....T..J.......\.ZP..V}....M?...2..3.....)...T.yG.4...kO....t......b5...-....4F].q%c...-....v.2...O....g0...g.&R.2.n..<?P.q9.....+l3...X&T;...z."L).12..D..a.G3..OQ.Y....%..P.=.....2....%u.}4.(..N.!.)t....w...M.@.0.pt.a%..N...|.|\f+H.Rk.?..G..v.q.7.5.'..F}.....lm....rS[.4..F2..R.-..V......AU....!./.\S;...M/..K`..w...>.f'm..bf..y>..$D@......1....3.>...Cn!.:.........C*..-.PE14....$&}..?..I...._2.m.<....L.<.........92.p......jT....%.~..Q.U...6.4/.U..4L+HK.\i.z...Au.@>Z..Y.....kk...pQ..!....|..1g8...Uc$.....Y......9.....`0t..p..(...R.N....w`......\...<......M....-.95.f..W;xx>.7"..'..._z.REq.=e2..bg.S..r..VKcI.j.....\.O..T...q.>....H..6AE...{'?.....w.X.J...w.d.......O%..-%...1*.53..NPB.O.[M./.:..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:PNG image data, 170 x 19, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2441
                                                                                                                                                                            Entropy (8bit):7.882452566815817
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:g/6K2jqFIKOQuXlTw1zVYFZJ73pnzqE+RKtsMI8ZoHptP65FLdi:gStjoOQFy3p3Vf+oyp8CO5Pi
                                                                                                                                                                            MD5:71612012982B1C220E7A4BA5F6099D89
                                                                                                                                                                            SHA1:FAA7AEFFBD02AB94767039A2B2E35EF9CF3450E1
                                                                                                                                                                            SHA-256:4EB38967FF6BA50EFBCD918875A997B26776A6884AD6A04E00405414D7721B11
                                                                                                                                                                            SHA-512:AC5A5C1033BE2A9DD626DF26FAE52D4A161DF964B791A3562568ADD58AF802A9A6443BF59C9385023E20AB3A8EEC06579D88833D61FD444105E318CAF885221F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR................?....pHYs.................sRGB.........gAMA......a.....IDATx..ZMR#...j.F.... ...'....5'.8......'.9...#N....O0.c.{1z..H......j.z.Fb..B...*++.*..3l4...%c7..u`...WI....\.....2h.l..s...g.A?.z..k...<..nb..I....y..(.L..G..2.a.uj....mc..c....f..j. p...w..k.Y{.2.....w..x..iB...wwO+h....y./.Y.@..6..vw..].y.......l@.....Tt....U...v!@....rt.Q.~..S.Z.......vw..&....._.8...+th....s..I...7hc.}...(.x,k^d.1..............>............8.}.\..s.V...-..)._..g..E.......M1.C..)..3.xx...........?...B......H...%.c..e...htf6.EP.....I.C.bLGX.*...8....]..U.......m..7....r_...............o.....q.^..?Q.r.*.B.#.].>.|../^......k.@@MV.'fEP.o.s..u.#.....].q.X..C.....q\o"k..C.....|gU...&TtI..g....O....Y..p3~.W.....??..).Q4..v|.Z...g.qy@aE.x=..=0...s...J.n.....(..V.3........<....."Hk...NWb..w(....m..%z[..{^.S.J.0?y...}0Q.B..`..e.xO.........E..........W....4..B..'.."..p.......m.M%.ZT...O.a.Q.W%..9h.VJ..Q.wTF.......I....E.$<....C.[,.%l..,...Q...Z....~.mG-ya
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, single, 1223 bytes, 1 file, at 0x44 +A "\webadvisor.manifest", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):11919
                                                                                                                                                                            Entropy (8bit):7.688335463848691
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:3Dyyj6kSDnicM9Lx76iiX0in1k7IEY9x8yS35IVnEy2sE9jBF0Nyw8v0l/:P6ki29d1ikyGNGxvSJIVE8E9VF0Nyw8w
                                                                                                                                                                            MD5:0EF336BB27EE9BEAC04C8AD6A8B186A5
                                                                                                                                                                            SHA1:5FE7CA6F16DEB828B3C989EC8A127D707DCFD908
                                                                                                                                                                            SHA-256:4011B7B1DBA4EC23887B9529915E194B9DC6574D80185FD482C0320A59AD2A88
                                                                                                                                                                            SHA-512:C88BD126D08CBA3FE7CB5A59458039CF7F1981F12D875CB91CD9EE4F2D9ADFDE6703136B117B1943A1FBDE21E14EA9C04117B12F4CD18009A22F41FE520FAB3E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:MSCF............D................................)..........i..................YLq .\webadvisor.manifest.q.Q.V...[.....2Z..4.%3...f...>P(w..k.*..|......'4.4.WUr.}............D$.`V.Q.lBrC.......].."...}......0;...Wz./.].r.p....|.3...........f..N.4w.v......2./....O.?..b..x.......xZP...ES.NS.........Fq..2......i...5o|.k..xw>...qPD,....u.z.kj.N....j../!..o.........D...&.....#......X...BB....%$..F...wr.I.B4.d..g....X.3.d.G.@.e...o2..9~..1..}}...>...?..9A.XI....U...b0Z.. WH.W.br....o4.eZb..l.woigXr^....+c..v..D......2C[..v......F.|>Q'.pW.WM....T..sw}k..;!.Z..&.b7..|.O|.t/.....?:Btc....C....&.,..lPl...T-......[.s..^..t.~w.8'....r..-r.z...L...-.rw...uwYa.........7.Oy.0~....*JE...l....#U?LX.3...pbzD.._c.170..s.'.>.....M....{v......OWE../.K.m.{.....b.^N...*..*.O....*...\.g..}Y..9gWm.>zJ%H......q`.....=.,gp.*..q0.j....V..I1%6*."..>%,..y(_...N.;...h\..........bVx.QZ....4..^...P...'.\.9.q...Pp....[t;..g."..(..D......h.y...2....s............>.O....
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:MS Windows icon resource - 11 icons, 48x48, 16 colors, 4 bits/pixel, 32x32, 16 colors, 4 bits/pixel
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):99892
                                                                                                                                                                            Entropy (8bit):3.9749743269785345
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:JLBqG5eVRjB/jZRj0t4kgU1l50AIDP88+2Y:JLBh5eWgU1B8+2Y
                                                                                                                                                                            MD5:236FC5ABB597615A608DAB7BE98D5FBC
                                                                                                                                                                            SHA1:18D3D1CF56898B264A24DE24DC13E4B9B7EED768
                                                                                                                                                                            SHA-256:06ADAB20CB028B5DC61762691E8C8A6157EB1199526F7C773338B9BF51BD63C6
                                                                                                                                                                            SHA-512:155766AA5659BB9E298AEDE4064832168002EEDEE836710C2259446FC35437AD70C04454DEF2D9EB40A83A029351EA1726D65ACBDB8FE8217C016FD4986F7F4E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:......00......h....... ......................(.......00.............. ......................h...~"........ .n....'........ .(...TC..00.... ..%..|K.. .... .....$q........ .h......(...0...`...........................................................................................................p......................9Yx...................yyy9Y..................yyY.yy57...............s.....y.yy.............y9Y9Y5..9y.w.............9yyy.....................y.9qy....yy5............yyy.yqy.y.Y9yp...........y.xy....9yyY5....yY9.y.9.......yq....p....9yyqqyp......y.yy5.p...YyY9..p.......yy9Y.Y.........p..............p...Yyy.p...............p...99Yw............y9S.0...................yy..p....yY8............yyS.p...y9y.............y1......y.Y8............yYy.p...................y9yyp...................yyY.p...yyy.............y9yq....9Y.w............yyY9p...................y9yYp...................yyY9p...................y9q.....................yyYyp.......................p.............P.....
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 576083 bytes, 3 files, at 0x44 +A "\wssdep.manifest" +A "\win32\wssdep.dll", flags 0x4, number 1, extra bytes 20 in head, 45 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):586779
                                                                                                                                                                            Entropy (8bit):7.9992830970835564
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:12288:wpnTlBe5fPL2OE9X9y9KO+HWpRWHMHHe6toSDe/W4K:wTlByLmPm+2zWHMH3oae+4K
                                                                                                                                                                            MD5:AFB062D1441DF0ACB1171AF089D2050B
                                                                                                                                                                            SHA1:EBAB2B66617C5CE75A1F8737335B71894FEE47FF
                                                                                                                                                                            SHA-256:4C9B176469D7F6D987D0C6B7D9FA01AC9E894AF6C6EE88C2150786DD1DFD1505
                                                                                                                                                                            SHA-512:9DDB46E01E816366F473DEC7F01E535611AFAD1C82436BE3D3088A28B4519DF6872D9A6B279AAC5842B98838969B47A4F11BA5302C998D95FD48DFAA1285C326
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:MSCF....S.......D...........................S....)..............-...i..........YTq .\wssdep.manifest.....i......Y.p .\win32\wssdep.dll..G..I......YLq .\x64\wssdep.dll....U.8..[...8....."C`3..[....]..4(.....F*m.@k.Uj......e....ST.)i....N.}.....3.....k-.-. ...F2Y......3..2....@..~......w..g.NRN>]..tN.C..-....`..B....-(.aW./.Bv......^.F.%i..Y...%..%.....Mk@6.fw.......d..S....d@y..:....@Xf..............{.....|.7.k.Mri.*.T.:..*."QIP.2..B.(.$``..... ..@X.......5.m...Q.3.e;.....I...NZ.3&.)1..m....*..w6.>.5.2.&.....A..=m.O.....OJGK4.6...4.>_RIU...t]N.8.O.{fT....'...<*]..E...Y..l....t...p.....k..o....S..k=....?4.....4.5..E.e.B7.....I..:..-.b/"...mk.w :.H..5...>..g....3..k.t~.Y.C.=.[....h..6U.....M.L...x>c^.~.m.....Z.1.W.5*S*Q.1.$..Wp...I.P..)H.O..........o...]+uIc{...E.6..#x..G. v............k..'.e..k.....9.0.(.....*.f....^.J.I..Z.La.K.e.:..JbL..Z\R_...._...y...?..Ia..}[.......4......(.7..d.a.k...D...s......l.......C.[.L..........t.6Z..].Q.
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (1531), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1738
                                                                                                                                                                            Entropy (8bit):5.310615763879483
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:jL4Ej0KD98d7lvOKi18GDAxJxFyWLcLBoHC85QsZKwkYq1O:fQKud71OKincxJxMW08RkYq1O
                                                                                                                                                                            MD5:BF5DBDBC3BE0BEB13B8DC98C9C80AB1D
                                                                                                                                                                            SHA1:F94538C278914A6B7DE73667B59324B2E07EFAA1
                                                                                                                                                                            SHA-256:9FD4D6CA3E5428EAAFAB78196B9901DE6871A003335F3A609943904AEC510121
                                                                                                                                                                            SHA-512:42439E42E63A86D9F245CADFA42A73AD94C16892737C76DA921BF92BB7974B1FF8097709F079D2028FBB61D590FB0CEB896F9AD9D1CF96572526610F635E14BE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var aviary_client_fileVersion = "1.2.207"; ..function CreateAviaryClientHelper(){try{var a={Get:function(f){try{if(this._aviaryPlugin){var c=this._aviaryPlugin.Get(f);this._logInformation("Get: key: "+f+" value:"+JSON.stringify(c));return c}}catch(d){this._logError("Get exception: "+d.message)}return null},Set:function(c,d){if(this._aviaryPlugin){this._aviaryPlugin.Set(c,d)}},ToJsonString:function(){try{if(this._aviaryPlugin){return this._aviaryPlugin.ToJsonString()}}catch(c){this._logError("ToJsonString exception: "+c.message)}return null},GetDirtyFlag:function(d){try{if(this._aviaryPlugin){return this._aviaryPlugin.GetDirtyFlag(d)}}catch(c){this._logError("GetDirtyFlag exception: "+c.message)}return true},Setup:function(){try{if(this._aviaryPlugin){return}var f=JSONManager.getSingleton("dictionary");var c=f.data;var d=c.product_settings;this._aviaryPlugin=getPluginFactory().Create("ContextItemAviaryStore");this._aviaryPlugin.Initialize(JSON.stringify(d));g
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (14337), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):14537
                                                                                                                                                                            Entropy (8bit):5.350517802797016
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:ktu3RAn5OgUkr5oAZ0hFrBhCHzWFhBs4tdOceg+tktXSWV03w:k43RAnblghz0TqDsy+tklVH
                                                                                                                                                                            MD5:B1F49ADA2A373D0CAFCFC589F7387F38
                                                                                                                                                                            SHA1:22C7047052583C698E48510BF7A02A03ACA8B4CB
                                                                                                                                                                            SHA-256:D75CA8FB29D82F4B6EB36924E10A8F8A95B38CB7E63F3CB16F559ACD0B5076AC
                                                                                                                                                                            SHA-512:F07E04861EC294CA7F3E559983755FF244F6B10675007966078FF89AD4DC5E6FED44B9CD2EE2D6FAF5C53336D377DE63EA89A31FE5B5EAB2700055DB287B32A5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var common_fileVersion = "1.2.207"; ..if(typeof JSON!=="object"){LoadScript("json2.js")}if(typeof enableAnalyticsSDKForUWP==="undefined"){enableAnalyticsSDKForUWP=false}var GetEngineSetting=function(b,a){return a};if(typeof GetSetting==="function"){GetEngineSetting=GetSetting}else{logInformation("Missing GetSetting function; will only use default settings (this is expected pre SDK.2.3)")}var GetEngineProperty=function(b,a){return a};if(typeof GetProperty==="function"){GetEngineProperty=GetProperty}else{logInformation("Missing GetProperty function; will only use default Properties (this is expected pre SDK.2.5)")}if(!enableAnalyticsSDKForUWP){LoadScript("logging.js")}var getSystemPlugin=function(){var a=getScriptVariableStore().Get("system");if(!a){a=getPluginFactory().Create("system");getScriptVariableStore().Set("system",a)}return a};Date.prototype.toISOString=function(a){try{function d(f){var e=String(f);if(e.length===1){e="0"+e}return e}var b=this.getUTCF
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (842), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1050
                                                                                                                                                                            Entropy (8bit):5.331663611219219
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:nvVaMEhIBolSPnrVCYJqPse4A7PWLb/X0rbjIfJNoUy:vbEhDSPrHAPse4A7PW3/X2uo7
                                                                                                                                                                            MD5:64F0EE978A9AD6ACEFB78A9E65639166
                                                                                                                                                                            SHA1:D0448B2DAE8E0FCE91CE5D212C8FC1A14753E24D
                                                                                                                                                                            SHA-256:92831E44E8EB7792CFB274A2AF856B94EB3B6B2F494261B6542C1A129412449C
                                                                                                                                                                            SHA-512:2DD51E99D635C7C515011E2BFE0AC03B29F59A2696A7807AC8514579F1BB4AAE79D36AFF67A8CB1507B39FDB588D15E65732AD9012F7E54F2F92D76F3E07E040
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var config_manager_fileVersion = "1.2.207"; ..function CreateEventConfig(){var a={getEvents:function(){var b=JSONManager.getSingleton("events");return b.data},getProfileNames:function(b){try{return this.getEvents()[b].profileNames}catch(c){return null}},getAttributeRules:function(b){try{return this.getEvents()[b].attributeRules}catch(c){return null}},getPriority:function(c){try{var b=this.getEvents()[c].priority;return b.toLowerCase()}catch(d){return""}},getDataSetNames:function(b){try{return this.getEvents()[b].datasets}catch(c){return[]}},_setEvent:function(d,b){try{return this.getEvents()[d]=b}catch(c){return[]}},getThrottleRule:function(b){try{return this.getEvents()[b].throttleRule}catch(c){logWarning("getThrottleRule: failed, cannot find throttle rule attached to "+b);return null}},_events:null};return a}ModuleManager.registerFactory("config_manager",CreateEventConfig);..//953095630E5BC260E5E4F8B036C3C20CAA70AD6ED5B391112307B476B9CB80CAFE7A03BCA5581A55
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (3383), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3587
                                                                                                                                                                            Entropy (8bit):5.310702375397368
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:59Brq8ECI+Vttye8xYAAkSynknNkTv5ApLCYnawFwklt48ZI3OU2k9qM4JCZ0urG:trHEfqr6GpdL4RgI3OL8ACe0E9C0B
                                                                                                                                                                            MD5:15FBE1F6B7403B7F3E6123FDEB108FB1
                                                                                                                                                                            SHA1:15CB2FE8977BE2D30AFF5278992E2901991F59C3
                                                                                                                                                                            SHA-256:51A5D5E68164D2F41D9DCB72D9E8422976B228CFCCC7FF123227C6A72944B482
                                                                                                                                                                            SHA-512:53A5D02FB4CA42275406B0DCDEE30C180CE733A67C727EABD455D6363115A09A4DA10883352BCCD75494E43B91DC78C51ED5787F9D3A46C1AEE25F6F148B6AFD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var csp_client_fileVersion = "1.2.207"; ..function CreateCSPClientHelper(){var a={getClientID:function(c){if(null==c){logError("Invalid (null) appID for CSP::GetClientID");return null}try{var b=this._getPlugin().GetClientID(c);if(!b){this._reportGetClientIDFailure()}return b}catch(d){logError("Failed to retrieve Client ID from CSP for '"+c+"': exception is '"+d.message+"'")}return null},reportEvent:function(b){},getPolicyItem:function(c,b,e){var d="policy_general_settings."+b;if(e){d="policy_general_settings."+e+"."+b}return this._queryPolicyItem(c,d)},getCachedData:function(c,b){try{return this._getPlugin().GetCachedData(c,b)}catch(d){logError("Failed to load cached data for appId='"+c+"', service='"+b+"': exception is '"+d.message+"'")}return null},_getPlugin:function(){if(!this._plugin){this._plugin=getPluginFactory().Create("cspClient");try{var b={policy:"full_sdk_only"};this._plugin.Config(JSON.stringify(b));logNormal("CSP Client plugin configured to us
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (13754), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):13962
                                                                                                                                                                            Entropy (8bit):5.215759154605658
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:IWRhWbpBthL10g4fquSZHo7vwFCw43NvyLUPu1phBOeY4PZTIit6BUQ2wHAUJ6fI:xmbpJY4WXo1tYQZTAV2LhA
                                                                                                                                                                            MD5:644CE9F96B15B259E25F64B7CB8F9D7F
                                                                                                                                                                            SHA1:E032A895FEFC72F6FBC7BC8765ED91B6992E540C
                                                                                                                                                                            SHA-256:436A023C1FC0D163A4BE552E9701EF763769FB4CC61ED82B0B7D73C6EAB884EF
                                                                                                                                                                            SHA-512:753140480C744241063E94B55793F1BECBA88B1FB7839A656E869E2C0452F660C2BFD7293E79FC03F538EDD2FDAF393CA82C666743A2DF53578AC1000B2CD72D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var data_collector_fileVersion = "1.2.207"; ..ModuleManager.set("uptime_tracker",function(){return{fetchFromDataDefinition:function(b){try{return null}catch(a){if(a.hasOwnProperty("message")){return"[Plugin method failed: "+a.message+"]"}else{return"[Plugin method failed]"}}}}}());var Create_data_collector=function(){var a={setup:function(){try{this._logInformation("Setup Started.");this._loadDefinitions();this._farmers=this._createFarmers(this);this._refreshers=this._createRefreshers(this);if(!this._farmers||!this._refreshers||!this._definitions){this._logError("Setup failed: farmers("+this._farmers+"). refreshers("+this._refreshers+"). definitions("+this._definitions+")");return}var c=[];for(var b in this._definitions){c.push(b)}this.markDataExpired(c);this._logInformation("Setup Done.")}catch(d){this._logError("Setup failed: "+d.message)}},get:function(h){try{var g=null;if(typeof h==="string"){g=h;h=[h]}if(!h instanceof Array){this._logWarning("get: items
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):18607
                                                                                                                                                                            Entropy (8bit):3.675086040693106
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:H/62/66/63xQ2m5dMoaMMmO/h5/JMb//U/zM//2/ka5zP/Rb/Z/X/l/46/n/n/6N:WBmptHLSMn
                                                                                                                                                                            MD5:1AED066C47D366C4CF5EEC55A55CFA1F
                                                                                                                                                                            SHA1:5ACC4395BCC237DB6C9691A57F12A2DE13B0CA15
                                                                                                                                                                            SHA-256:ED8FEF7E21353ACEE5D98C9E29011E6FA94841F031FB847438F44751649B7F4F
                                                                                                                                                                            SHA-512:52AACF2ABAC3286DF81D10343CE08EA5BAF2899C9B8B6DA185EBE9B1C24AFF53AC1FFB4848C5320064BE5C44440A00BA2E23F447F7B8269277CCC840714A8332
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "version": "1.2.207",.. "data": {.. "product_analytics_content_version": {.. "params": "getContentVersion",.. "rule": {.. "ruleName": "notNull".. },.. "source": "engineContext".. },.. "product_install_type": {.. "params": {.. "name": "is_loud_install",.. "scope": 0,.. "default": "UNKNOWN".. },.. "rule": null,.. "source": "waSettingsDB".. },.. "product_affiliate_id": {.. "params": {.. "name": "*Affid",.. "scope": 0,.. "default": "0".. },.. "rule": null,.. "source": "waSettingsDB".. },.. "device_geo_id": {.. "params": {.. "name": "SystemGEO",.. "scope": 0,.. "default": "0".. },.. "rule": null,.. "source": "waS
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (7140), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7341
                                                                                                                                                                            Entropy (8bit):5.272776603492146
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:NSNaQstBT0ZVs64Hwxizhs2RS+R8Btmm9TsbYF0b4G:KWhxhLCPmz4G
                                                                                                                                                                            MD5:50680CF3ED41EBB5E92A474BB391B59C
                                                                                                                                                                            SHA1:5623E6C32E066200590D2B48AD621B7BC1CD44DD
                                                                                                                                                                            SHA-256:83B327F65C58A8A9F2F1FD1FAD1CD43B1A617FB42A8B3356383931895054E855
                                                                                                                                                                            SHA-512:4B5BE9CAE57A707C437A3EB2AAA4DCF4C54278977A679B5C197BA66B13D1F21E9E764169F489F0D006D10D0151DE90EBECDAD9517DC973D01CFAD62DCD22F3A4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var dataset_fileVersion = "1.2.207"; ..function CreateDataset(){function b(c){this._name=c;if(!this._name){throw"Dataset created with no name provided"}}b.prototype={initialize:function(d){try{if(!d){this._logError("No configuration defined");return false}var c=d.data_items;if(!c){this._logError("Invalid Data items. Config ("+JSON.stringify(d)+")");return false}this._itemsList=c;var f=d.refresh;this._setRefresh(f);this._logInformation("Initialization complete");return true}catch(g){this._logError("initialize: "+g.message);return false}},get:function(c){try{return this.getContent()[c]}catch(d){this._logError("get: "+d.message)}},getContent:function(){try{this._logInformation("getContent starting");this._logInformation("itemsList"+JSON.stringify(this._itemsList));var d=ModuleManager.getSingleton("data_collector");if(this.dirty){d.markDataExpired(this._itemsList);this.dirty=false}return d.get(this._itemsList)}catch(c){this._logError("getContent: "+c.message)}},
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (6749), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6953
                                                                                                                                                                            Entropy (8bit):5.406953542808857
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:DE+7wzRBsvJdOwfwrsEkRvtPYiNsnWPVybI6gNzgMd7e6peMYs5mIQ0Ql:DE+7uoJdSwHlQit0ONzgC7us5mIQNl
                                                                                                                                                                            MD5:0B3699EE9D6ADBC8BE5DE6DFBEFE9EB1
                                                                                                                                                                            SHA1:C8ACBF20D3DD65159D27468FDBB2350E4B57C3B1
                                                                                                                                                                            SHA-256:D7ECAB2ACF542B4F2208D7482C8AA5804ECED40160B2A7FD49210B34A03E2785
                                                                                                                                                                            SHA-512:92623EFFBC1EF55ADBF5CA37A0EC811A913FABBFF1A1A5698C8FD6397479E615C66AC66AF9176F8CFC141FD4C3BE92EF99D9D4A276462BF594C5168D80A42BF3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var dataset_da_fileVersion = "1.2.207"; ..var Create_dataset_da=function(){var a={dirty:true,load:function(){if(!this.dirty){return}setTimeout(1*60*60*1000,function(){this.dirty=true});logNormal("Loading dataset da");this._content={};var f=this._getTimeLastDA_Query();if(!f){logInformation("dataset_da: Failed reading query start value. Going to use 0 as start");f=0}var b=this._getTimeNow();if(!b){logError("dataset_da: Failed reading query end value. Going to quit loading the dataset.");return}var c=24*60*60;b=b-c;try{this._processRequests(this._da_queries,f,b);this._store_DA_QueryTime(b)}catch(d){logError("Failed to load the da dataset: exception is '"+d.message+"'");return}this.dirty=false},add:function(b,c){if(!b){return}this._content[b]=c},set:function(b,d,c){if(!c){this.add(b,d);return}var e=ModuleManager.getSingleton("rules");this.add(b,e.apply(d,c))},get:function(b){try{this.load();if(!this._content){return null}return this._content[b]}catch(c){logError
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2350
                                                                                                                                                                            Entropy (8bit):3.7724549775855634
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:HJEnvU2mEsWYFAnLqrtrMKKbDsHOrpFxssScJZQpcmG/VA7K:mvU2KWsALEJqbDsHofxsJ8ZQsD
                                                                                                                                                                            MD5:1ECA2971AD8DBFE9DF6831235966EA3B
                                                                                                                                                                            SHA1:69366788B2018049DA5F9250C659E3412DA759C8
                                                                                                                                                                            SHA-256:271307F6A5F0B88E9734F212D536962E70FE58587A3F1EB6B2EEF7D174532144
                                                                                                                                                                            SHA-512:B4AC164DB465E46481DAF0EF09913AEC723648C1F2D209E5CEDCB97310FEE7B2646980480371E52CE56F8353CB9113FC268A3CFC14D477AD22EE0375DED0AE32
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "version": "1.2.207",.. "data": {.. "default": {.. "data_items": [.. "product_analytics_content_version".. ],.. "refresh": {.. "useEngineDefaultTimeout": true.. }.. },.. "wa": {.. "data_items": [.. "product_version",.. "device_country_code",.. "product_subscription_type",.. "product_ab_test_group_id",.. "user_account_id",.. "product_productkey",.. "product_package_id",.. "device_platform_edition",.. "product_cpu_type",.. "device_platform_version",.. "product_install_type",.. "product_affiliate_id",.. "product_subscription_expiry_date",.. "device_geo_id",.. "user_global_reference_id",.. "device_id",.. "device_platform",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):11114
                                                                                                                                                                            Entropy (8bit):4.06719219286141
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:WWOHdgzPqNxXciNwSmX2C6mWaSgkzRqU8MAqZPh4U:IgziHGazGsh4U
                                                                                                                                                                            MD5:3E2557F41184A52A640FA7505DA746CF
                                                                                                                                                                            SHA1:0DF2A2AC893875C0A5A9B3EE7CEE49C09E47E0BF
                                                                                                                                                                            SHA-256:3E4B9EBE1EE082A4D9ACE5463AF166576B4CEC0D8C5ABA6DBC33CAA1F7854229
                                                                                                                                                                            SHA-512:F083E2A15261D3DD3F2DCC4F2D1C044CA57943B77733DFA42A3A61380DB5A754B5B4B81DFA504C7A1C3F2E9F5D9E1D1D95C118FB16E856BBA7D75D53E908E3C7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "version": "1.2.207",.. "data": {.. "event": {},.. "global": {.. "uniqueid": "hit_event_id",.. "uniqueidentifier": "hit_event_id",.. "feature": "hit_feature",.. "trigger": "hit_trigger",.. "interactive": "hit_engagement_interactive",.. "hit.interactive": "hit_engagement_interactive",.. "hit.user.initiated": "hit_engagement_userinitiated",.. "userinitiated": "hit_engagement_userinitiated",.. "desired": "hit_engagement_desired",.. "engagement.desired": "hit_engagement_desired",.. "useridentifier": "hit.userid",.. "label1": "hit_label_1",.. "label2": "hit_label_2",.. "label3": "hit_label_3",.. "label4": "hit_label_4",.. "label5": "hit_label_5",.. "label6": "hit_label_6",.. "metric1": "hit_metric_1",.. "metric2": "hit_metric_2",.. "metric3": "hit_met
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (4110), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4311
                                                                                                                                                                            Entropy (8bit):5.218987411673366
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Ayk11hc+35U8Md+O2SNyMZ5uGC2AjrkCOGnDbs2//klaeOoR:nk1I+5Md+O2SNtC2WrkCOGnDalJOI
                                                                                                                                                                            MD5:6EDB43E2B897ED058467005809A0A98B
                                                                                                                                                                            SHA1:0CBEE317745D4B311FAEF7FE8AF3A74302B2AE62
                                                                                                                                                                            SHA-256:683F13FF9CEDBC314FFA9DE4847DD44576DFD98C08D0DACF14130A9C33CCE9EB
                                                                                                                                                                            SHA-512:99B29C3D15602108084B6F9B98658486F2F9DBF0AE73561131057ADB6B8FE2B6B287C07E2C2C4EC75846303DD23691BCF5DD6B8AC90B45C2E316EF303E115289
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var emitter_fileVersion = "1.2.207"; ..function createEmitter(b,a){function c(g,i){var h=getScriptVariableStore().Get(g);if(h){return h}try{h=getPluginFactory().Create(i)}catch(j){logError("Failed to create plugin: '"+i+"'")}try{getScriptVariableStore().Set(g,h)}catch(j){logError("Failed to set plugin '"+i+"' in store as '"+g+"'")}return h}try{var d={configure:function(g,e){this.profileName=g;this.profile=e;this.transportName=e.transport;this.transportConfiguration=e.transport_config;this.dataSetNames=e.datasets;this.enableRules=e.enableRules;this.throttleRule=e.throttleRule;this.throttleMultiplier=e.throttleMultiplier;this.maxDimensionLength=e.maxDimensionLength;this.extendedAttributesLengthConfiguration=e.extendedAttributesLength},send:function(h){try{if(!this._isEnabled()){logInformation("_isEnabled() returned false. Will not send data to "+this.transportName);return false}h=this._sanitize(h);if("csp"==this.transportName&&"1"==this._getPlugin(this.transpo
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (11329), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):11529
                                                                                                                                                                            Entropy (8bit):5.251509170872591
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:k8+1u9z1l8Le62L9s9Zs2JFsIOSsnQSRTPd3uXsx14jxN2FhvsC7PquQQHDmksFD:Ge1LYpJyZQSRrdeXsx1AxNWFRddDmWM7
                                                                                                                                                                            MD5:D2B620DD44EAABD828691CD183544D77
                                                                                                                                                                            SHA1:F69EE6279E138B861C753B0337B64F97D650E0A7
                                                                                                                                                                            SHA-256:EDE3C3FA3231657C54873834025FC874812F66CBA5BBADD49B35CA41BB161819
                                                                                                                                                                            SHA-512:B70EE95087C2CE049FB95C82930D2B0AD9EB65DA177B725F14A705E569C9DBA13F818369EB5DCA2BDAB854A959DD18A06E68F6F637A1B4344E52A29D7F7CBB3C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var engine_fileVersion = "1.2.207"; ..LoadScript("common.js");var _factoryManager=CreateFactoryManager();var ModuleManager=CreateModuleManager(_factoryManager);var JSONManager=CreateJSONManager();var StorageManager=CreateStorageManager();var PDManager=CreatePDManager();var RegistryStore=null;var setContentHeartbeatTimeout=function(b,a){var d=getScriptVariableStore().Get("heartbeattimerid");if(d){try{clearInterval(d)}catch(c){logWarning("setContentHeartbeatTimeout: Fail to clear timer id "+c.message)}}d=setTimeout(b,a);getScriptVariableStore().Set("heartbeattimerid",d)};var engine={defaultClientAnalyticsRegistry:GetEngineSetting("Analytics.Base.RegKey","HKLM\\SOFTWARE\\McAfee\\McClientAnalytics"),heartbeatTimestampKey:"analytics_content_heartbeat_timestamp",datasetsRefreshRate:60*60*1000,userId:null,createEventJson:function(c,a){try{a["Tracker.Type"]="event";return{UniqueIdentifier:c,type:"event",payload:a}}catch(b){logError("engine::createEventJson: Exceptio
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (2529), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2740
                                                                                                                                                                            Entropy (8bit):5.307372536970292
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:jURsQEqp22+r9sEDQgWenZsEXRiRmf3djAFzsEysEBQsEsFsEBMCnUGsEaffL/T8:vQnp2fxsrsnZsEAEf3d0FzsFsfsHFszw
                                                                                                                                                                            MD5:4ADEEACD0258D40755E5A022B33F7546
                                                                                                                                                                            SHA1:2A02C96A0887BF6D2D46DCE1F59C9A0E6A1093C4
                                                                                                                                                                            SHA-256:CDD72A97AEEFEB56A17CE7EC7994D94F2814920307C97945B35C01035BA38839
                                                                                                                                                                            SHA-512:FB8817E0BAC93E97E621BF6F8CBC0B8089D7FEEFEF3EAFE202935D9DC7412E0F61A83BCDB4F59BF5F1F689534924BACED815D9A54927937C5258290E6650A10A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var error_transmitter_fileVersion = "1.2.207"; ..function CreateAnalyticsErrorTransmitter(){function a(){this.setup()}a.prototype=ModuleManager.create("transmitter_template");a.prototype.messageName="analytics_event_error_occurrred";a.prototype.setup=function(){var c=ModuleManager.getSingleton("config_manager");var d=c.getProfileNames(this.messageName);if(!this.emitter&&d){this.profileName=d[0];this.emitter=this.retrieveEmitter(this.profileName)}};a.prototype._generate=function(c,e){var f={hit_event_id:this.messageName,hit_category_0:"Analytics.Event.Error",hit_trigger:c,hit_action:"Analytics.Event.Rule.Failed"};if(findObjectSize(e.type["ruleMismatch"])){f.hit_category_1="ruleMismatch";f.hit_label_0=JSON.stringify(e)}else{if(findObjectSize(e.type["ruleError"])){f.hit_category_1="ruleError";f.hit_label_0=JSON.stringify(e)}else{if(e.type["rejected"]){f.hit_category_1="rejected";f.hit_label_0=JSON.stringify(e)}}}var d=new Date();f["__record.created"]=d.toISOStr
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (6709), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6916
                                                                                                                                                                            Entropy (8bit):5.332785368649959
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Xb+vdzkDCDfgTg3ZyHORvgaF22TYlpt3NnhYqBU3YYXCf1S/:wkDgrouvgaF22TYlpdNnhVW3YK0w/
                                                                                                                                                                            MD5:5D3894984C361C0872B32692D17E4C9A
                                                                                                                                                                            SHA1:B877DE05F412254B3BCB20376A768E82B4AFB403
                                                                                                                                                                            SHA-256:2BA37D92C9482CCA05EEB44B7D88E95CB7B2D923C2149DEAEE6F052060CE1BD5
                                                                                                                                                                            SHA-512:FF6EF80108F614BE3F3B6BA49262B1571ECC760E6467ECB83D2E5D5A69DEFF146D65F960E0B2D78FD02560AF4ECE6576FCD5106572F9DFB044F329C325845CEC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var event_handler_fileVersion = "1.2.207"; ..if(typeof dataManipulator!=="object"){LoadScript("common.js")}function CreateEventHandler(){var c={handleEvent:function(g){try{var h=JSON.parse(g);var f=h.type;if(("MessageBusPlugin"==f)||("InProcAPI Plugin"==f)){this._processMsgBusEvent(h.payload)}else{if("UWP_Event"==f){this._processAnalyticsAddRecord_v1(h)}else{logWarning("Unexpected message was rejected (unknown type): "+g)}}}catch(i){logError("Failed to process incoming event: exception = '"+i.message+"'")}},handleV1Record:function(e){this._processAnalyticsAddRecord_v1(e)},_processMsgBusEvent:function(h){try{var f=h.name;var k=h.payload;if(("Analytics.v1.AddRecord"==f)||("Analytics.AddRecord"==f)||("Analytics.Automation.AddRecord"==f)){return this._processAnalyticsAddRecord_v1(k)}var j=ModuleManager.getSingleton("data_collector");j.notifyMsg(f);var g=ModuleManager.getSingleton("observation_analytics");g.handle(f,k)}catch(i){logError("Failed to process message
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):111041
                                                                                                                                                                            Entropy (8bit):3.9348502925966873
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:MfTdafTwJm8IKF7aSFjNEwH9H44dfgLLwSf4DAEqCLZ++ZY9cmQjqLqjVLBe+82Q:+GVnLw4Vlc41Semf5ZC
                                                                                                                                                                            MD5:88E1A666137E08C1DF1184311EE4EDC3
                                                                                                                                                                            SHA1:5EA47571ED9826D834414F4FD3859081781124CB
                                                                                                                                                                            SHA-256:A3CF45EF0EFDE76EE0EDC622E4A060F9AD89D253D2789980B42585C75E9319DC
                                                                                                                                                                            SHA-512:443A6BECC9D649B63ED9B7C291F6873161F6429029E7C18EA683FFEA49650161A911CFD7F791441C59FA6689FE9D8C3564259EF507EABD6F008968A0CC85E014
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "data": {.. "wa_advanced_protection_signals_impression": {.. "attributeRules": {.. "hit_action": {.. "meta": "screen_load",.. "ruleName": "override".. },.. "hit_category_0": {.. "meta": "Analytics",.. "ruleName": "override".. },.. "hit_engagement_interactive": {.. "meta": true,.. "ruleName": "override".. },.. "hit_feature": {.. "meta": "TBD",.. "ruleName": "override".. },.. "hit_label_0": {.. "meta": "success",.. "ruleName": "override".. },.. "hit_label_18": {.. "meta": "AdvancedProtectionSignals",.. "ruleName": "override".. },.. "hit_label_19": {.. "meta": "Impression",.. "ruleName": "override".. },.. "hit_label_20": {.. "meta": [.. "ch",.. "CH",.. "ff",.. "FF",.. "ed",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (4059), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4260
                                                                                                                                                                            Entropy (8bit):5.611688326739459
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:vhGfe5Z6TQ25OkR/ZCpMJFU7Rz94+IFpRREbgMG6hxOIq4sU/G/HIGIkUNjYbXO8:vI14icRpVIbRybgMGyxOIq4sU+/oGIkT
                                                                                                                                                                            MD5:7983FF75E04CC866E9C3736EC6CA6E38
                                                                                                                                                                            SHA1:84DFDEC6B1C7DA0766F55C9B19B0208FEDA82FC4
                                                                                                                                                                            SHA-256:FD0C12EE4B5A3C229876C78E882C9C22E110D63DE0BDE7AB6755599B6BB7213A
                                                                                                                                                                            SHA-512:FD15671001D00170D9A46B6400776EFDA9C2C3F852D2C8CFBB76194AB2215FC1F94956D6026CA58AFB209C79099B1508EE518D4CEA2192358F4CD3B1F02B34DE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var hash128_fileVersion = "1.2.207"; ..function CreateHasher128(){var a={hash128:function(s){function L(c,b){return(c<<b)|(c>>>(32-b))}function K(x,c){var G,b,k,F,d;k=(x&2147483648);F=(c&2147483648);G=(x&1073741824);b=(c&1073741824);d=(x&1073741823)+(c&1073741823);if(G&b){return(d^2147483648^k^F)}if(G|b){if(d&1073741824){return(d^3221225472^k^F)}else{return(d^1073741824^k^F)}}else{return(d^k^F)}}function r(b,d,c){return(b&d)|((~b)&c)}function q(b,d,c){return(b&c)|(d&(~c))}function p(b,d,c){return(b^d^c)}function n(b,d,c){return(d^(b|(~c)))}function u(G,F,aa,Z,k,H,I){G=K(G,K(K(r(F,aa,Z),k),I));return K(L(G,H),F)}function f(G,F,aa,Z,k,H,I){G=K(G,K(K(q(F,aa,Z),k),I));return K(L(G,H),F)}function D(G,F,aa,Z,k,H,I){G=K(G,K(K(p(F,aa,Z),k),I));return K(L(G,H),F)}function t(G,F,aa,Z,k,H,I){G=K(G,K(K(n(F,aa,Z),k),I));return K(L(G,H),F)}function e(x){var H;var k=x.length;var d=k+8;var c=(d-(d%64))/64;var G=(c+1)*16;var I=Array(G-1);var b=0;var F=0;while(F<k){H=(F-(F%4)
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (3618), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3817
                                                                                                                                                                            Entropy (8bit):5.530625915891614
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CbxjvqEYontqQYCNRqihKDMl1Q9/+slg60yvb0Pz/RlOZglybLnE3L:hEKTGzg2sWqz+lybLEb
                                                                                                                                                                            MD5:20F5C2032879B10E8B580C46AC1EF8CC
                                                                                                                                                                            SHA1:DBCF94C479FDB1A8EF68516985D5119DCA24ED30
                                                                                                                                                                            SHA-256:F2B3D3B14C5F9333FB239A13F7E67F01C9376A1590149C93D19F10859BF85029
                                                                                                                                                                            SHA-512:865280D030E7D106B40DF9302EF18449B2AD15585309884C4762233D32B08FBA5FB63415BB1F91BCD6CB23C64BAD7A2C3443806A884647E73A28892BB3656A6A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var JSON2_fileVersion = "1.2.207"; ..if(typeof JSON!=="object"){JSON={}}(function(){var rx_one=/^[\],:{}\s]*$/;var rx_two=/\\(?:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g;var rx_three=/"[^"\\\n\r]*"|true|false|null|-?\d+(?:\.\d*)?(?:[eE][+\-]?\d+)?/g;var rx_four=/(?:^|:|,)(?:\s*\[)+/g;var rx_escapable=/[\\\"\u0000-\u001f\u007f-\u009f\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g;var rx_dangerous=/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g;function f(n){return n<10?"0"+n:n}function this_value(){return this.valueOf()}if(typeof Date.prototype.toJSON!=="function"){Date.prototype.toJSON=function(){return isFinite(this.valueOf())?this.getUTCFullYear()+"-"+f(this.getUTCMonth()+1)+"-"+f(this.getUTCDate())+"T"+f(this.getUTCHours())+":"+f(this.getUTCMinutes())+":"+f(this.getUTCSeconds())+"Z":null};Boolean.prototype.toJSON=this_value;Number.prototype.toJSON=this_valu
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (3176), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3377
                                                                                                                                                                            Entropy (8bit):5.479273243699144
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:BXNGJtGJIGM+GtH5jnV+g2CdWVvDK1lEwJ2MPRp0WvmQ:SJEJTMpzYVrKwMPv0W5
                                                                                                                                                                            MD5:B555BD6163BDF924B6C1B5074C601639
                                                                                                                                                                            SHA1:6C8589BB8C6DD5E3DA3601BF0EE4145A82F3783E
                                                                                                                                                                            SHA-256:A92DAFE1710A0C98889B1424A772C4D629B8AC3E64718B712EEF9A9398EA7BF9
                                                                                                                                                                            SHA-512:BD0803FCF279DFC0A957CB62B77001301D9948058F2937E46812D30A3916DEF715B8C24BCA03443A89D1A9D123E0CB302719010F64D7911827AB6AB13A21486F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var logging_fileVersion = "1.2.207"; ..var debugEnable=false;function callerName(){var a=arguments.callee.toString();a=a.substr("function ".length);a=a.substr(0,a.indexOf("("));return a}function getLogger(){var b=getScriptVariableStore().Get("logging");if(b){return b}try{b=getPluginFactory().Create("logging");try{debugEnable=GetEngineProperty("Analytics.SDK.Script.Debug.Enable",debugEnable)}catch(a){}}catch(a){b={LogMessage:function(){},WriteToConsole:function(){},WriteToSyslog:function(){}}}getScriptVariableStore().Set("logging",b);return b}var LOG_SEVERITY_NORMAL=1;var LOG_SEVERITY_WARNING=2;var LOG_SEVERITY_INFORMATION=3;var LOG_SEVERITY_ERROR=4;var LOG_SEVERITY_CRITICAL=5;var SYSLOG_EMERG="emerg";var SYSLOG_ALERT="alert";var SYSLOG_CRITICAL="crticial";var SYSLOG_ERROR="error";var SYSLOG_WARN="warn";var SYSLOG_NOTICE="notice";var SYSLOG_INFO="info";var SYSLOG_DEBUG="debug";var logNormal=function(b){try{b=sanitizeLogMessage(b);getLogger().LogMessage(LOG_SE
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (2160), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2362
                                                                                                                                                                            Entropy (8bit):5.341126002451161
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Ts7j7XL5Zqjbtkp2yI4XNJEE+yqAUfOh6A+33SRWVCYCZVpjCm:C/IkxXn1+yQOh6D33vCtVpmm
                                                                                                                                                                            MD5:201D239AC5641E21276B010729194627
                                                                                                                                                                            SHA1:BC28DE2C3B754F70E28AC6AC338B922A298C6355
                                                                                                                                                                            SHA-256:073705514949ECEFCF223B162CCDFB2F441B751D4F300E8C66CDDD97ECFA43FB
                                                                                                                                                                            SHA-512:DEB9B0F64A2C829933EFC574F3E89ED208D0A2764154F8B874FAF68C8C8128EE09C3F65810CC04149706730B7EBF289C00A66C5170B03A770613E0624B479A11
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var mappings_fileVersion = "1.2.207"; ..function CreateMapping(){var a={eventMap:function(c,b){if(!(b in this._eventTable)){return c}return this._map(this._eventTable[b],c,true)},globalMap:function(b){return this._map(this._globalTable,b,true)},daMap:function(b){return this._map(this._daTable,b,true)},profileMap:function(c,b){if(!(b in this._profileTable)){return c}return this._map(this._profileTable[b],c,true)},getProfileTableStr:function(b){if(!(b in this._profileTableStr)){return"{}"}else{return this._profileTableStr[b]}},getFlippedProfileTable:function(c){if(!(c in this._profileTable)){logWarning("Requesting flipped table for invalid profile "+c);return{}}if(c in this._flippedProfileTable){return this._flippedProfileTable[c]}this._flippedProfileTable[c]={};for(var b in this._profileTable[c]){var d=this._profileTable[c][b];this._flippedProfileTable[c][d]=b}return this._flippedProfileTable[c]},_map:function(b,f,h){if(!b||!f||(typeof f!=="object")){logWarni
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (1832), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2032
                                                                                                                                                                            Entropy (8bit):5.423277669449905
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:+s9YBy8KJU9hYErsYvZ5YxHqbWbb//yb07jcFl4ADv8TuScS:+aY7MErvScaiNXScS
                                                                                                                                                                            MD5:3CBF8AFC920909380ACB992BDF3E512B
                                                                                                                                                                            SHA1:04671BE11FE13EA1F94720F6000E8BDA4EC85A17
                                                                                                                                                                            SHA-256:C7A25297A77FA791908A502D7E2C9947495FEE364F4D0B082C840B160E8DAA8E
                                                                                                                                                                            SHA-512:BFE85B6B8900C53AEF2E2DC43644CCDDA69363CDAAA8152DC43754BA27F3B5EAE647564EF65C46E9EF11D6DBCD217F82B9339FFADF95120F5732B9F168D0AF4A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var mcutil_fileVersion = "1.2.207"; ..function CreateMcUtilHelper(){var a={_logError:function(b){logError("mcUtil: "+b)},_logInfo:function(b){logInformation("mcUtil: "+b)},_getPlugin:function(){if(!this._plugin){var c=ModuleManager.getSingleton("data_collector");var b=c.get("analytics.sdk.version");if(b.match("^2.[0-5]")){this._logInfo("This SDK does not support mcUtil plugin. sdkVer("+b+")");return null}this._plugin=getPluginFactory().Create("mcUtil")}return this._plugin},_plugin:null,_hardwareId:null,_softwareId:null,storeHardwareAndSoftwareId:function(d){try{this._logInfo("storeHardwareAndSoftwareId - start");if(!this._getPlugin()){return}var b=d;if(!d){var h=ModuleManager.getSingleton("data_collector");var f=h.get("WSS.Hardware.ID");b=(f==="[ruleMismatch]")?true:false;this._logInfo("value: "+f);this._logInfo("storeValue: "+b)}if(!b){this._logInfo("Not going to storeValue");return}this._invokeGetMachineId();if(!this._softwareId){this._logError("storeHardw
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (1151), with CRLF, LF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2017
                                                                                                                                                                            Entropy (8bit):5.26731779293553
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:nvCEumJTxfCViKARzApkiNOVBdDzdzHbp5db5GFDvVd9MGZdozuIdvm47q:nvVusTxfCViK0zJD5zHVjb5GFDvfb5IK
                                                                                                                                                                            MD5:ABBC3977ABF11A6939F540A6868D33C1
                                                                                                                                                                            SHA1:05369495EA24DFF62B8228AC6062C67161DCED7D
                                                                                                                                                                            SHA-256:5F866BB319EC2ED7439190ACCE6706C9B23A3BFDED5199A0E75A876A2A320D05
                                                                                                                                                                            SHA-512:6F504C616DFBD2B3C9C6B0593A34E7FAFE640DDF96C74FB0033DE8604F0970E3C4E6356D0CACB0EA2892BB4EBEE4373C51A7CB3D5AF2AEEEB6F8F1303CE5D842
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var observation_analytics_fileVersion = "1.2.207"; ..function getObservationAnalyticsEngine(){./*. * config format:. * 'Message.Name' : { // name of obsved message on messagebus that we will subscribe to. * 'map' : { // map from message keys --> analytic friendly keys. * 'Count' : 'Metric1', // ex. 'Count' : 123 --> 'Metric1' : 123. * 'Policy' : 'Event.Label' // ex. 'Policy' : 'XYZ' --> 'Event.Label' : 'XYZ'. * },. * 'default' : { // default values that are not specified in the obsved message. * 'hit_event_id' : 'XYZ'. * }. * }. */.var a=function(){var d=JSONManager.getSingleton("observability_datasets");if(!d){d={data:{}}}return d.data};var b=a();var c={start:function(){try{var d=getMessageBus();for(var f in b){d.Subscribe(f)}logDebug("observationEngine Started")}catch(g){logError("observationE
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (6532), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6736
                                                                                                                                                                            Entropy (8bit):5.338180967031238
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:1Ak6WqZs6S+qL5QaQlifjf9i/OCi8sdHvzqZ+SSf72NfoDc8H5sviXvn34Z:1EbS7yidGBdg4Z
                                                                                                                                                                            MD5:9EE3DA049A15DC1FED10A69374D29AA5
                                                                                                                                                                            SHA1:663BF2C28E76A62D7344C7BCE0E79CA981F6E37E
                                                                                                                                                                            SHA-256:626ED39BCBF1FD198FE95CFA0E41B3A4054E2012E9DB727ACFB98B621B3EBA3D
                                                                                                                                                                            SHA-512:25E75948D8FF66329D756E7F1A3CA326D1CDB674BBA7D9D986679BE877E07AAEC1A176FA7FB08A86B00C04FD98C8D523B7B6C5A1136C2E1EACAB6E58C6A33603
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var operations_fileVersion = "1.2.207"; ..function CreateDataOperations(){var a={apply:function(c,b){try{if(!b){return c}if(!this._isValidValue(c)){this._logWarning("Invalid value Val("+c+"). Operation with operationConfig("+JSON.stringify(b)+") will not be applied");return null}return this[b.name](c,b.params)}catch(d){this._logError("operations:apply: Excption caught("+d.message+". Val("+c+"), operationConfig("+JSON.stringify(b)+")");return null}},noop:function(b){return b},equal:function(b,c){return b==c},isValueValid:function(b){return(b!="[not assigned]")&&(b!="[ruleMismatch]")&&(b!="[ruleError]")},notNull:function(b){return(b!=null)},validLen:function(b){if(!b){return null}try{b=JSON.parse(b)}catch(c){this._logError("validLen: value ("+b+") not an object, exception: "+c.message);b=[]}if(!(b instanceof Array)){this._logWarning("validLen: value not an array ("+b+").");b=[]}return b.length},lenEqual:function(b,c){return(this.validLen(b)==c)},lenGreater:fun
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (825), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1032
                                                                                                                                                                            Entropy (8bit):5.407206303181614
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:nHaMLYQI/YCqYJIAb2sFsn5caYyb2srq7Y4cbfsk0RrnsEeEcEQ02ka+5X:9LVI/xqIXbTFsKrybTAncbfl0RrsnEQ0
                                                                                                                                                                            MD5:3A098C1847B809C74FA2F81A6EDB7A2A
                                                                                                                                                                            SHA1:44FE06FAFB93229C16B5AFCEA617A9FFD0FD7ED3
                                                                                                                                                                            SHA-256:50343A3BA19D3B1EA88CB25AFB793A6F3A9EF89F1536877FFAF63488B42171C1
                                                                                                                                                                            SHA-512:541DE8EAA210AFE0A8984BC4596BEE91676AA0266BA9C285B1F8206DD349F7E811C9A90B6C7813EE21C003B0859DD175BC7AFD4FA5791E70A5320A7C4C41E24A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var preprocessors_fileVersion = "1.2.207"; ..function CreatePreprocessors(){var a={noop:function(b){return b},splitByComma:function(b){return b.split(",")},joinWithComma:function(b){return b.join(",")},sum:function(b){var d;for(var c in b){d=b[c]}return d},toInt:function(c){if(typeof(c)=="object"){for(var b in c){logConsole("toInt value="+c[b]+" parseInt:"+parseInt(c[b]));c[b]=parseInt(c[b])}return c}return parseInt(c)},toString:function(c){if(typeof(c)=="object"){for(var b in c){c[b]=c[b].toString()}return c}return c.toString()},toUpper:function(b){return b.toUpperCase()},apply:function(c,d){logConsole("rules type="+typeof(d)+" rule= "+d+" value="+c+" typeof(value)="+typeof(c));if(!d){return c}if(typeof(d)=="object"){for(var b in d){c=this.apply(c,d[b])}return c}return this[d](c)}};return a}ModuleManager.registerFactory("preprocessors",CreatePreprocessors);..//2A8BA9A3CF28FE0B788EE8EE5EF460AE4C277718D31A3828255A026318A7D3CBC2DAE6A471F917D6459DA78B69D7D366DA
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5310
                                                                                                                                                                            Entropy (8bit):4.151562694252807
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Hm9y51drjiTX2/mIQft9y51drGhImxs9y51druhmmxD9y51drGhIme0mW9y51dro:Mf2/dGTYs62sBY0m821O62Rp
                                                                                                                                                                            MD5:77EC6811E64A2D1062B6D2B6E99FE511
                                                                                                                                                                            SHA1:AD89005E27D4AF9751C203D794E3BEE95857F834
                                                                                                                                                                            SHA-256:B54D150627770DB1B485F3B1C35D21A3B2680638146C435AA584B9375E223DCB
                                                                                                                                                                            SHA-512:509396EB87E906B49137C15FDC2A3BA2C01E47775684104734972ABFC26635A74715911BAD1E78AC358B6505724C683B63016ED960B1768E7F81AA5FE826572A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "version": "1.2.207",.. "data": {.. "profile_webadvisor_mosaic_100p": {.. "transport": "eh",.. "dictionary": "dictionary_wa_mosaic",.. "datasets": [.. "default",.. "wa".. ],.. "maxDimensionLength": 500000,.. "appid": "7b3ed1a8-7907-436a-ac6c-640bfd5db80c",.. "transport_config": {.. "apiVersion": "2014-01",.. "servicebusNamespace": "cu1pehnswebadvisor1",.. "eventHubPath": "new_wa",.. "sharedAccessKey": "IU1g+5XrDoldu/krnr8GDbVL/jHXoqZrH9alKG29J8Q=",.. "sharedAccessName": "new_wasend".. },.. "throttleRule": {.. "meta": 100,.. "ruleName": "dailyMax".. },.. "throttleMultiplier": 64.. },.. "profile_webadvisor_mosaic_kongapi_100p_qa": {.. "transport": "mosaic_api_v2",.. "dictionary": "dic
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (2785), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2987
                                                                                                                                                                            Entropy (8bit):5.391898752346337
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:kNToenoesA9R/io8udVQN7wfagenv7sboA+FNvf4uCmnWoGbA/WoGb5u4U74:gBVsuvsnvYc/UiWAWBun74
                                                                                                                                                                            MD5:C3DDA0578EB6C5E9E98822CFCDDD2F77
                                                                                                                                                                            SHA1:7465CABFCCEFCAFFAFF46748C4CE084479BECDDC
                                                                                                                                                                            SHA-256:42AA37BFA9397326FD2221029DB7F77555CFEFF9F3CE4220AADE522E22E93C71
                                                                                                                                                                            SHA-512:9175040B933F546B8F3C57CB38015C7E6A849C303FF9A76848AEF1DA2713F4CF49A3A77F11081154C6F6848CAC88CDAD380EB9391755426A691214BBA89F7E05
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var registry_fileVersion = "1.2.207"; ..function CreateRegistryHelper(){var a={openKey:function(c,b){if(typeof b!=="boolean"){b=false}if(b){logDebug("open registry in write mode");return this._getPlugin().CreateReg(c)}logDebug("open registry in read mode");return this._getPlugin().OpenReg(c)},openKey64:function(c,b){if(typeof b!=="boolean"){b=false}if(b){logDebug("open registry in write mode (x64)");return this._getPlugin().CreateReg64(c)}logDebug("open registry in read mode (x64)");return this._getPlugin().OpenReg64(c)},queryValue:function(c,b){var g=false;try{if(typeof b==="boolean"){g=b}var f=this._getPlugin().QueryValue(c,g);return f}catch(d){logInformation("Failed to query "+(g?"obfuscated ":"")+"registry key '"+c+"': exception is '"+d.message+"'")}return null},setValue:function(d,f,b){var h=false;try{if(typeof b==="boolean"){h=b}var c=this._getPlugin().SetValue(d,f,h);if(!c){logDebug("registry.setvalue failed ("+d+", "+f+")")}return c}catch(g){logInfor
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (6423), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6631
                                                                                                                                                                            Entropy (8bit):5.299670531341887
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:S8sCKa1ZC0CG20+M9wBFmGO1zadW9NvEPzs5C7c8a5dcQbefnLpNxZ:6B9PzpR
                                                                                                                                                                            MD5:F9918F7C56ADDF54DAC785161A448446
                                                                                                                                                                            SHA1:C35138433004A8DD0BE6AF271748B0348E653E44
                                                                                                                                                                            SHA-256:349E3AA4B233C2EDE4BB2ED593B6064D2EC432E8DEBDB43F99EA04ECD36ED0D5
                                                                                                                                                                            SHA-512:0CCDBA4EEBAB0FBDFDE7A36D4BA1244EDADC9E8E0971305FD9C78EB0580C70A98604E2503F03DEE753D876769DA13FE22D9B6D9232BDC1439D85252946156BCA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var rest_transport_fileVersion = "1.2.207"; ..function RESTtransportPlugin(){this._plugin=null;this._requestHeaders={};this._url=null;this.RESTClientAvailable=false}RESTtransportPlugin.prototype=ModuleManager.create("transport_template");RESTtransportPlugin.prototype.constructor=RESTtransportPlugin;RESTtransportPlugin.prototype.GetVersion=function(){try{if(!this._plugin){return null}return this._plugin.GetVersion()}catch(a){}};RESTtransportPlugin.prototype._createRESTclientPlugin=function(){try{this._plugin=getPluginFactory().Create("RESTclient");if(!this._plugin){logError("RESTtransportPlugin:: Could not create RESTclient plugin");return false}return true}catch(a){logError("RESTtransportPlugin:: Failed to initialize the plugin for '"+name+"': exception is '"+a.message+"'");return false}};RESTtransportPlugin.prototype._setup=function(){try{this._url=this._config.url;if(!this._url){logError("Invalid (unspecified) URL for '"+this._name+"', version "+this.versi
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (3246), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3445
                                                                                                                                                                            Entropy (8bit):5.356749738549081
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:YM0Vnh1PJzvkXv3i/kYrAH6aEPhZf3a4BdaFBLYFpGbaaPYFpGbMmUpXjJbO8iRT:Hfpkq4qFypHrVdiSN5bYQhavJHsI
                                                                                                                                                                            MD5:03E1CF256ECCA67F71C03E80F523E1E1
                                                                                                                                                                            SHA1:E0E40A0C65C991D5F4D66E11709EBC6F0DE7527F
                                                                                                                                                                            SHA-256:FCD1D2A21372C716729057E3B1204844FAF21755EE524B5582AFB997DC775970
                                                                                                                                                                            SHA-512:82ADA970915808DCB2DC926C48F7D121D711969DB7512AC15CB8EA3388EBAB968E80B77E99F4C6AE13B5FDA31CAFA600CB69E8CA13459280E56B1099F413F589
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var rules_fileVersion = "1.2.207"; ..function CreateRules(){LoadScript("sha256.js");var a={notNull:function(b,c){return(b!=null)},inRange:function(b,c){return(b>=c.min)&&(b<=c.max)},equal:function(b,c){return(b==String(c))},greater:function(b,c){return(b>c)},greaterEqual:function(b,c){return(b>=c)},less:function(b,c){return(b<c)},lessEqual:function(b,c){return(b<=c)},notEqual:function(b,c){return(b!=String(c))},startsWith:function(b,c){return !b.indexOf(c)},endsWith:function(b,c){return b.indexOf(c,b.length-c.length)!==-1},contains:function(b,c){return b.indexOf(c)!==-1},regex:function(c,f){try{var b=new RegExp(f);if(f.expr&&f.flags){b=new RegExp(f.expr,f.flags)}return b.test(c)}catch(d){logWarning("rules.regex exception: "+d.message);return false}},timestamp:function(b,c){if(!b){return false}return(new Date(b)).toISOStringms()==b},"in":function(c,d){for(var b in d){if(c==String(d[b])){return true}}return false},isType:function(b,c){return(typeof b===c)},isE
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (709), with CRLF, LF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):37442
                                                                                                                                                                            Entropy (8bit):5.182461810815972
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:wNLZ52t2LQdhrnY09gCZHAtV9EhhfVroWqA2l:wv5KUQ809gwHAlybqAK
                                                                                                                                                                            MD5:F537624BEFCF3D5C8BFB1B6E6E080C27
                                                                                                                                                                            SHA1:A05D1F1713A801A078DE5466DC98B113DF3542BB
                                                                                                                                                                            SHA-256:61CF3782570531EA00959C733C001E41191143224E9AA1F05A2C6EA7F9B81987
                                                                                                                                                                            SHA-512:6EDE0C255EA1A720ACDCF227CBABC07798C1F8390C57A5F4EC18C48DB0EFE01E3051E102A563EE47D4E5F32E162872021075B5C83302248A1D69227592F54BA8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var sha256_fileVersion = "1.2.207"; ../*.Copyright (c) 2008-2017, Brian Turek.All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are met:.. * Redistributions of source code must retain the above copyright notice, this. list of conditions and the following disclaimer.. * Redistributions in binary form must reproduce the above copyright notice,. this list of conditions and the following disclaimer in the documentation. and/or other materials provided with the distribution.. * Neither the name of the the copyright holder nor the names of its. contributors may be used to endorse or promote products derived from this. software without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS".AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE.IMPLIED WARRANTIES OF MERCHANTABI
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (663), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):862
                                                                                                                                                                            Entropy (8bit):5.490919968989528
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:nYmaMV5IOd09ODopDwLgmjNnbijyUIihtUR:tV5iOD+ss4NbieDGte
                                                                                                                                                                            MD5:EB3E712B17A036B166AF5F45974C73E3
                                                                                                                                                                            SHA1:9679D85A870EDB37A79A4536A89387EA9DF9EF51
                                                                                                                                                                            SHA-256:FFACAF239D4EAEF3E1CA8715932988D76E5538699E424D37852FA7A18D4111AD
                                                                                                                                                                            SHA-512:90650A8A3064FFECDECF462AFC8EAE283D429C15860ED0AE20F15DDDEFD106BA2A207CAE64F5D92A51C863B9D34A0953C18891EC77A810E95775F0F65BBC22A2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var subdb_fileVersion = "1.2.207"; ..function CreateSubDbHelper(){var a={_getPlugin:function(){if(!this._plugin){this._plugin=getPluginFactory().Create("subdb")}return this._plugin},_plugin:null,fetchFromDataDefinition:function(c){try{if(!c){logError("subdb:fetchFromDataDefinition: No dataDefinition supplied");return null}if(c.action==="canIRun"){return this._getPlugin().CanIRun(c.appid)}if(c.action==="GetProperty"){return this._getPlugin().GetProperty(c.appid,c.name)}logError("Unknown action name ("+c.action+")")}catch(b){logError("subdb:fetchFromDataDefinition: "+b.message+". dataDefinition"+JSON.stringify(c))}return null}};return a}ModuleManager.registerFactory("subdb",CreateSubDbHelper);..//510B6CF2F4B5F5627F98E3A207501510DF1A543E23B23AA0DC6EC97FB2920BFB822A063BC45B3DC4140D6895D94C8C9BE91339ACA6CAAA2FDDD05F839AB76744++
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (3717), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3931
                                                                                                                                                                            Entropy (8bit):5.348065191482385
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:TDeOIhVr9zrhSLCxNBpyX0irau/9lRCHfYMSWmL8s:2OIBzrhscB80irj/9lwH+Is
                                                                                                                                                                            MD5:233219ECDC73DDB26CA928030F2F0088
                                                                                                                                                                            SHA1:9C4F96173A42196DE65E2C07CF80FC6170C93FC8
                                                                                                                                                                            SHA-256:F0919941ED5D166FB99A5CC6FD3992B6D0C6FDC88A605E0E421951F21ED05493
                                                                                                                                                                            SHA-512:751957404FF4782C18DEC26B2114CE9BB57F4D9F488312494A6E142FD867E14F780F9ECC3B63068BA83D04F5DEE118D60AFBB876736FC2FBBF9F7CDCFC033290
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transmitter_template_fileVersion = "1.2.207"; ..function EventTransmitterTemplate(){}EventTransmitterTemplate.prototype={addDataSetNames:function(c,d,b){var a=[];if(d.dataSetNames){a=a.concat(d.dataSetNames)}if(b){a=a.concat(b)}a=dataManipulator.arrayRemoveDuplicates(a);logDebug("emitter ProfileName: "+d.profileName+". allDataSetNames: "+JSON.stringify(a));this._mergeDataSets(c,a)},_isEventThrottled:function(b){var c=ModuleManager.getSingleton("config_manager");var a=c.getThrottleRule(b);return this._applyThrottle(b,a)},_isProfileThrottled:function(b,d){var c=ModuleManager.getSingleton("config_manager");var e=c.getPriority(b);if(e!="critical"){var a=this._getProfile(d).throttleRule;return this._applyThrottle(d,a)}return false},_applyThrottle:function(a,c){try{if(!c){return false}var d=ModuleManager.getSingleton("rules");return d.evaluate(a,c)}catch(b){logError("_applyThrottle: "+b.message)}return false},_applyAttributeRules:function(p,o,a){try{var h=Modu
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (7089), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7292
                                                                                                                                                                            Entropy (8bit):5.239946272970433
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:5NppM62N2XDFDHmoHKvxOjrfFQdRn2ESa/ecRWUIWqdGE1SbGvkrC:5NppT2N2XDFiRvxOjDFQdJ2ESa/ecRWb
                                                                                                                                                                            MD5:90D8B73452EADCAE0E19455654E53D4F
                                                                                                                                                                            SHA1:82D9645BF9AC62C85D67A6C9D5CBE00D7532DAB0
                                                                                                                                                                            SHA-256:E2FFD71E0AB4184DAF2331002977BD9348E889103100BE41340BFE972BFA28EA
                                                                                                                                                                            SHA-512:16C187C5260127D9DF8E8EF557EC9B2676CDC891BED80CED0F1448F94B16990098594A25EF8B6FE09D651338FED253FE11D1E119622774DEBC00CF5857BF8CD1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_fileVersion = "1.2.207"; ..function CreateAnalyticsTransport(){function a(){this.retrieveStoredQueue()}a.prototype=ModuleManager.create("transmitter_template");a.prototype.transmit=function(m,s,t,c){logDebug("analyticstransport.transmit message="+JSON.stringify(s)+", profileNames="+JSON.stringify(t)+", datasetNames="+JSON.stringify(c));if(this._isEventThrottled(m)){logDebug("Event "+m+" was event-level throttled");logAutomationError(m,JSON.stringify(s),JSON.stringify({level:"info",type:{eventThrottled:m+" is event throttled"}}));return}for(var l in t){try{var o=t[l];if(this._isProfileThrottled(m,o)){logDebug("Event "+m+" was profile-level throttled by '"+o+"'");logAutomationError(m,JSON.stringify(s),JSON.stringify({level:"info",type:{profileThrottled:m+" is profile throttled for "+o}}));continue}if(engine.isStopRequestReceived()){logWarning("transmitter.prototype.transmit: Stop request received, so stopping all data transmissions..");return}var
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (2458), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2664
                                                                                                                                                                            Entropy (8bit):5.488185422412943
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:ktUciWIdy2hgcmGY2rVTOd6oNoP5vCuKKiWXUlK7oBCijzAq:dA2hqGY2rhOELKM0BCijsq
                                                                                                                                                                            MD5:049E091FD0F44EF44D0F8577E2145672
                                                                                                                                                                            SHA1:5956689F2AFEACC9A8D57B778353D457DD297695
                                                                                                                                                                            SHA-256:4860B53624E471C48DBC5028C24966FC506D98B36698B505824FCE6908225C8C
                                                                                                                                                                            SHA-512:BE2157468A141AA1ABBC3231200697F80C27CC7021AF3D15FAEC3C4D2CFEFD8460D7FD508EAC05206924982E814A5DA1C98E2B1A3A8E33546D860748A5193D62
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_ai_fileVersion = "1.2.207"; ..function CreateApplicationInsightsTransport(){function b(h){try{var j=/\d{4}-[01]\d-[0-3]\d\T[0-2]\d:[0-5]\d:[0-5]\dZ/;if(j.exec(h)){return h}var i=/\d{4}-[01]\d-[0-3]\d\ [0-2]\d:[0-5]\d:[0-5]\dZ/;if(!i.exec(h)){return null}var l=h.split(" ").join("T");return l}catch(k){logError("getValidIso: Exception caught: "+k.message)}return null}function c(h){if(!h){return null}switch(h.toLowerCase()){case"event":return"EventData";case"screen":return"PageViewData"}return null}function f(i){var h={};try{for(var j in i){if(isNaN(i[j])){logWarning("getNumberValues: ignoring value at key: "+j+". With value: "+i[j])}else{try{h[j]=Number(i[j])}catch(k){logError("getNumberValues: Exception caught at key: "+j+". Exception: "+k.message)}}}}catch(k){logError("getNumberValues: Exception caught: "+k.message)}return h}function e(h){if(!h){return null}switch(h.toLowerCase()){case"event":return"Event";case"screen":return"PageView"}return nu
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (3250), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3466
                                                                                                                                                                            Entropy (8bit):5.326893850767579
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:IEi5lyUHvoZQLbMF1YfEj05DK+wlVE15DkAPAjh:IEi5ZwibMF1YfY05DK+wkzDkAPAjh
                                                                                                                                                                            MD5:3A09D3B85D33DC30FD553CFA10169A16
                                                                                                                                                                            SHA1:1EB6CA315E21A823E829D0BDFDD578D168E78817
                                                                                                                                                                            SHA-256:18589CC1AA6AAED8302A28E05B22BD8B68E991D04317AAD2527A0F5D2EB3CFD3
                                                                                                                                                                            SHA-512:6BB2A45DE0836C167B43E6EBA3A69BC4FB0393ADACAB92BEED76CB5018FBC7D706F759D1E5F19D05702B4A50451EF2218C237E4606AA32B17D11A2CAE71A235E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_api_endpoint_fileVersion = "1.2.207"; ..function CreateAPIEndpointTransport(){function a(){this._url="";this._verb="PUT"}a.prototype=ModuleManager.create("rest_transport");a.prototype.constructor=a;a.prototype._setup=function(){this._url=this._config.url;if(!this._url){logError("APIEndpointTransport:: Initialize failed url not provided");return false}if(this._config.headers){var d=this._config.headers;for(var b in d){this._AddRequestHeader(b,d[b])}}if(this._config.verb){this._verb=this._config.verb}this._createRESTclientPlugin();if(this.GetVersion()&&(this.GetVersion()!="1")&&(this.GetVersion()!="2")){this._usingRESTclientPlugin=true;logInformation("Calling parent class to setup using the restful plugin");this._plugin.SetHttpMode(this._verb);var c=getSystemPlugin();this._plugin.SetAgentName("McAfee Mosaic API V1 transmitter_"+c.CreateGUID());this._plugin.Connect(this._url)}else{this._plugin=null}return true};a.prototype._sendUsingRestClient=fun
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (4753), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4974
                                                                                                                                                                            Entropy (8bit):5.40433259600301
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:gK44u2URXvoZjLFlE5WB1AwfitMQxHcdqbw:gK4LdwFFl2NwfitrxHcdqbw
                                                                                                                                                                            MD5:C84AE5F12BAE4A5B5901083E3B1AF7E4
                                                                                                                                                                            SHA1:E50A9FBC0F3A88D456809321694D7B42D328BD62
                                                                                                                                                                            SHA-256:5C470D788353E477219D77A29544D58890CED27CDF6B8683627CBDA9CD4D3521
                                                                                                                                                                            SHA-512:7D82FB71D1D8CB4E644186529D262FFE62A645EF6FE4EE33B0B3EFF01E21394A937C3642E21B03E6A293695C77AF4215F212B93E9771DDE2944E81ED11B49C78
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_aws_apigateway_v1_fileVersion = "1.2.207"; ..function CreateAWSAPIGatewayV1Transport(){function b(){this._apikey=null;this._partitionKey=null;this._url="https://{dns}.awscommon.mcafee.com/1.0/{gateway}/v1/record"}b.prototype=ModuleManager.create("rest_transport");b.prototype.constructor=b;b.prototype._setup=function(){this._apikey=this._config.apikey;if(!this._apikey){logError("AWS_APIGateway_V1_Transport:: Initialize failed API key not provided");return false}var c=this._config.dns;if(!c){logError("AWS_APIGateway_V1_Transport:: Initialize failed DNS not provided");return false}var e=this._config.gateway;if(!e){logError("AWS_APIGateway_V1_Transport:: Initialize failed Gateway not provided");return false}this._updateURL("{dns}",c);this._updateURL("{gateway}",e);this._partitionKey=engine.getContextId();if(!this._partitionKey){this._partitionKey=generateAlphaNumericString(256)}this._createRESTclientPlugin();if(this.GetVersion()&&(this.GetVersion()
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (2581), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2787
                                                                                                                                                                            Entropy (8bit):5.394292692824491
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:k+KC4cETZD7ThSwsnoK2NkNCalAVKp9oH259ln2W8HsFAS0+NN70JxAesVuCdL0j:tUvhSwODAAce2OpNS+VfBs/ks
                                                                                                                                                                            MD5:7EDA555B9A0E1761B0E7B789E0E70C8B
                                                                                                                                                                            SHA1:7CAA2741F2ECB2F8DA06D52C527C45AECBB43DC3
                                                                                                                                                                            SHA-256:E9F667C71FDC49970382128856373841C7CB24C737D59FD4612986153EAA9D9A
                                                                                                                                                                            SHA-512:2C9A633E91E0D9209393419FF6C47D86C38D830BE63F48850CA955904B4C023735C5B3EFD43D8FE25152ADD0584FED801A34BE2CF685FBDF00459E64BC67AA6A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_da_fileVersion = "1.2.207"; ..function CreateDATransport(){var a={Send:function(c){try{var b=this._getMsgBusPlugin();if(!b){logError("[DA Transport] Current MsgBus Plugin does not support request/response.");return false}if(!b.IsAvailable()){logWarning("[DA Transport] Message Bus could not be loaded; subscriptions will not be active");return false}var g=ModuleManager.getSingleton("mappings");c=g.daMap(JSON.parse(c));var d=this._ComposePayload(c);if(null==d){return false}b.Publish("Data_Aggregator.Add_Data",d);logDebug("[DA Transport] Emit outbound data: "+d);return true}catch(f){logError("[DA Transport] Exception thrown when sending da event: "+f.message);return false}},_ComposePayload:function(c){try{var b={};var f={};var h={};c["__record.created"]=this._convertToLocalDate(new Date()).toISOString();c["__record.created"]=c["__record.created"].split("T").join(" ");for(var d in c){if(this._indexOf(this._metricList,d)!==-1){f[d]=c[d]}if(this._inde
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (3274), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3495
                                                                                                                                                                            Entropy (8bit):5.199517939540756
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:JOXKiK/bXDX8cX0XkXRXUXL1XUXSwXUXNXWXBoX1b6iYikiXxxiEiQX4iw2XK/nF:JOXK9/bXDX8cX0XkXRXUXL1XUX5XUXNo
                                                                                                                                                                            MD5:257029E2FDA438BCDD5FBA8D84DA00DF
                                                                                                                                                                            SHA1:E6538A33232613B1F62064220139BD713679A99D
                                                                                                                                                                            SHA-256:FDDE7D299E825C5A43B95FC487A273FD073B7EBE8638D9109F3D8A10D95C146A
                                                                                                                                                                            SHA-512:15E34D922D863705A41B8929865F9232C22DD550465202D51800A92015F414AAA7B0DE4FF0C512F12EADDCD2E326EEC9EA4DB9791EA54705A79F51C4E7EE2F2A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_eng_observability_fileVersion = "1.2.207"; ..function ObservabilityTransport(){this._transport_api_endpoint_emitter=null;this._url="https://pl8qcwep6c.execute-api.us-west-2.amazonaws.com/prod_v1/v1/record";this._apikey=null;this._verb="PUT";this._partitionKey=null;this.logInfo("New ObservabilityTransport Created")}ObservabilityTransport.prototype=ModuleManager.create("transport_template");ObservabilityTransport.prototype.constructor=ObservabilityTransport;ObservabilityTransport.prototype.logInfo=function(a){logInformation("ObservabilityTransport: "+a)};ObservabilityTransport.prototype.logError=function(a){logError("ObservabilityTransport: "+a)};ObservabilityTransport.prototype.logWarning=function(a){logWarning("ObservabilityTransport: "+a)};ObservabilityTransport.prototype._updateURL=function(a,b){this._url=updateStringWithReplacement(this._url,a,b)};ObservabilityTransport.prototype.GetVersion=function(){try{return engine.getContentVersion()}ca
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (7985), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):8198
                                                                                                                                                                            Entropy (8bit):5.265738364412356
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:3ZONyk/DC0+p55U7voKLgIEpfEdvQKf3Jmn/i/6/lWqu/K/z1gdnxmVMdqAQ7FGv:3Zvk7uYwGOZIWEcQ5s0nx23VIHk4
                                                                                                                                                                            MD5:EB13ACF1CBE53258B4975A3A93B64593
                                                                                                                                                                            SHA1:3869F58347755A3BE0473B04BC0DF34CA864E82D
                                                                                                                                                                            SHA-256:7DB8C911B5E40C1D128909B5FEB8ACD249B7CB958D4A615A121413DF8B781C6B
                                                                                                                                                                            SHA-512:C200393EA9ABB67F16821552E84F9300010BF4092CF7B8C87DA57ACAB9C44FE041ED756659B58497474D162572FC43BCC17F6EBC842CF5734F7EA3B10C7088EC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_event_hub_fileVersion = "1.2.207"; ..function CreateEventHubTransport(){LoadScript("sha256.js");function a(){this._apiVersion=null;this._servicebusNamespace=null;this._eventHubPath=null;this._sharedAccessKey=null;this._sharedAccessName=null;this._sharedAccessToken=null;this._tokenCreationTime=null;this._timeout=60;this._url="https://{servicebusNamespace}.servicebus.windows.net/{eventHubPath}/messages?timeout={timeout}&api-version={apiVersion}"}a.prototype=ModuleManager.create("rest_transport");a.prototype.constructor=a;a.prototype._setup=function(){this._apiVersion=this._config.apiVersion;if(!this._apiVersion){logError("Event_Hub_Transport:: Initialize Invalid (unspecified) _apiVersion");return false}this._servicebusNamespace=this._config.servicebusNamespace;if(!this._servicebusNamespace){logError("Event_Hub_Transport:: Initialize Invalid (unspecified) _servicebusNamespace");return false}this._eventHubPath=this._config.eventHubPath;if(!this._ev
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (2200), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2406
                                                                                                                                                                            Entropy (8bit):5.484170892348279
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:kMoavQfNfXcBBCE+yR60SO4k2WMWsH6du4jTk7v9:3MXcgE+yWOd2WRsH6ZkZ
                                                                                                                                                                            MD5:9CDE7447BB10D521D0EEB8D8933A8A58
                                                                                                                                                                            SHA1:718E0E80C92E52EB73FC34CB078E795F94C7A2E0
                                                                                                                                                                            SHA-256:68D128F781F2C11A752BDA8CF4B667F4541406B558ADEA507E3E865960464C7A
                                                                                                                                                                            SHA-512:0CAE6268634CCCA394A48E2C92B39F330963911F2DFA93CB4CD9E2F9F13DCC61C514EBD1EC43827B5359042C21634691009D29B9A7DFBB30D16FE03D5F2F8EDF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_ga_fileVersion = "1.2.207"; ..function CreateGATransport(){function a(){}a.prototype=ModuleManager.create("rest_transport");a.prototype.Send=function(c){try{var i=this._ComposePayload(c);if(null==i){return false}var f=this.RESTClientAvailable?this._sendUsingRESTClient(i):this._sendUsingXMLHTTP(i);var d=JSON.parse(c);var h=d.hit_event_id;this._transportLog(h,i,f,this.GetName()+(this.RESTClientAvailable?"_rest":"_xmlhttp"));return f}catch(g){logError("GA_REST_Transport:Send: "+g.message);return false}};a.prototype._sendUsingXMLHTTP=function(f){try{var c=ModuleManager.create("xmlHttpComObj");if(!c.setup()){logError("GA_REST_Transport::_sendUsingXmlHttp: couldnt create a xmlhttpcom");return null}logInformation("GA_REST_Transport::_sendUsingXmlHttp: Using "+c.getSelectedObjName());c.open("POST",this._url,false);c.send(f);var g=c.getResponseHeader("Content-Type");logInformation("contentTypeResp:"+g);return g.match("image/gif")?true:false}catch(d){log
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (4495), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4712
                                                                                                                                                                            Entropy (8bit):5.252505075477052
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:5itfQ5N+gtjbS6iYikiXx8iHi17iwyRAinJOdtUinPM8:58fQ5Ig5VikCuYq7HyRA0Jwtln
                                                                                                                                                                            MD5:3BFF1CE9338838EDAE8C0EB0311E3115
                                                                                                                                                                            SHA1:994089983AF9D7039D92CD3DFA2AA8158509AF33
                                                                                                                                                                            SHA-256:AB4D2C30F4D4A1D59F9EA4E600F9CC2C3ED87FC02CE5CBE1AB0ABE275DF05B67
                                                                                                                                                                            SHA-512:39D47E7EC4C7A60A9AE87C159065F2995BA7DE334FB4B3EAB69565EF419790B7DD9717297031B3F481E72E259D2500C98F7BC23D6836C3B79CFEA7F73F9BAFD8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_mosaic_api_v2_fileVersion = "1.2.207"; ..function Mosaic_API_V2_Transport(){this._transport_api_endpoint_emitter=null;this._url="apis.mcafee.com/mosaic/2.0/{service}/{consumer}/v1/record";this._apikey=null;this._verb="PUT";this._partitionKey=null;this._service=null;this._consumer=null;this._environment=null;this._rtHeaders=null;this.logInfo("New Mosaic_API_V2_Transport Created")}Mosaic_API_V2_Transport.prototype=ModuleManager.create("transport_template");Mosaic_API_V2_Transport.prototype.constructor=Mosaic_API_V2_Transport;Mosaic_API_V2_Transport.prototype.logInfo=function(a){logInformation("Mosaic_API_V2_Transport: "+a)};Mosaic_API_V2_Transport.prototype.logError=function(a){logError("Mosaic_API_V2_Transport: "+a)};Mosaic_API_V2_Transport.prototype.logWarning=function(a){logWarning("Mosaic_API_V2_Transport: "+a)};Mosaic_API_V2_Transport.prototype._updateURL=function(a,b){this._url=updateStringWithReplacement(this._url,a,b)};Mosaic_API_V2_Trans
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (3000), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3210
                                                                                                                                                                            Entropy (8bit):5.2474011174074295
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:kr7AiguxG0OAO/YxsMY7/KK3q/JepiZOViXNlJdZJz7ISjV:IANwGPAhxeP6xGSjddPzckV
                                                                                                                                                                            MD5:3CA8F099BCD6E03D1081FE224BBAFB0E
                                                                                                                                                                            SHA1:9703BE5C345AFD5B28863DFF4277D82C220643F5
                                                                                                                                                                            SHA-256:B679EAE6ABE3313283BED1DE35D22435F841E3C6DE823D186F318EC06D391CBD
                                                                                                                                                                            SHA-512:E41D9F67B49CD225741639614A4AA23DB29EF66FA2C0681124674746BE965BCC976FEFB53462D105D68E97F665C5227E2142FFDBD4A41876519D7F3E5E24EDEA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_msgbus_fileVersion = "1.2.207"; ..function MsgBusTransport(){this._msgbus=null;this._msgName=null;this._processorName=null;this._processorConfig=null;this._processors=(function(a){a.logInfo("Creating processors");return{noop:function(c,b){a.logInfo("noop: Returning eventDataObj unmodified");return c},simpleMsgComposer:function(c,b){a.logInfo("simpleMsgComposer: Creating new message");var f={};for(var d in b){if(b.hasOwnProperty(d)){var e=b[d];if(e.startsWith("$")){e=c[e.substring(1)]}a.logInfo("simpleMsgComposer: Adding new key-vaule to message: "+d+" = "+e);f[d]=e}}return f},passthroughComposer:function(c,b){a.logInfo("datasetComposer: Creating new message");var f={};var e=b.filteredKeys;if(!e){e=[]}for(var d in c){if(e.indexOf(d)>=0){continue}f[d]=c[d]}return f}}})(this);this.logInfo("New MsgBusTransport Created")}MsgBusTransport.prototype=ModuleManager.create("transport_template");MsgBusTransport.prototype.constructor=MsgBusTransport;MsgBusT
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (1249), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1461
                                                                                                                                                                            Entropy (8bit):5.34278016822941
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:nk/8aMm3IGAIOt/m/HYu2eRejjysUutC9zf/98L4oIiAIu7LQ/Ho7/Ts7f0gB:k/Sm3FAd/m/Hz2xLcT/696Dx7/mB
                                                                                                                                                                            MD5:AA705B06B1B20E35AEAF8B868C5F4128
                                                                                                                                                                            SHA1:3316B62A89EF479F16FE937C72C5E62317C23C27
                                                                                                                                                                            SHA-256:E8800992443E9F4D70590C7DFC9B2927DE5EA49EB6B761EAE3205E465E017D39
                                                                                                                                                                            SHA-512:EDB9F9C4BD7FB4B31A1415CD6D6286ACD78F81E9C3BCDCE2D6A7001D953D33C85985C59821EE9F8047DD134F74F7B351F31FD78C469E6AD12852678D793CDA38
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var transport_template_fileVersion = "1.2.207"; ..function TransportPlugin_Template(){}if(typeof TransportPlugin_Template.prototype.GetName!=="function"){TransportPlugin_Template.prototype={GetName:function(){return this._name},GetVersion:function(){if(transport_template_fileVersion){return transport_template_fileVersion}return"0.0.0"},Initialize:function(b,d,a){try{if(!a||!b||!d){logError("TransportPlugin_Template: Failed to initialize (name). Config: "+a+". Name: "+b+".Dictionary: "+d);return false}this._dictionary=JSON.parse(d);this._config=JSON.parse(a);this._name=b;if(!this._config||!this._name){logError("TransportPlugin_Template: Failed to initialize (name). Config: "+a+". Name: "+b);return false}return this._setup()}catch(c){logError("TransportPlugin_Template::Initialize Exception caught with message: "+c.message)}},Send:function(a){logError("TransportPlugin_Template::Send: Did not overwrite function. Send will return false");return false},Uninitializ
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (474), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):679
                                                                                                                                                                            Entropy (8bit):5.528651726553457
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:UqbdaN47iGreq8C5qlHz0TTqB7kh8hqzfAImT0mgqmOYBx/T/gAVOQWQ8Xz5fT:nbdauiGf88qlHQ/qIUIqqq9uJTFOQafT
                                                                                                                                                                            MD5:683F4A83D1B003A49578D9C111CAD65F
                                                                                                                                                                            SHA1:191149157678970687DB152E356185308F85B29E
                                                                                                                                                                            SHA-256:925244EF5AEF3318A21E93C4CE94BBA4092F875DB7F10BF703B407868B06AB18
                                                                                                                                                                            SHA-512:352B6292A0CC93408028107E889AA7C6FDC954C74A0C98AFB4FDD58EB66070C4BF475AAB7FFDAD06911BEB05D9D5F9F2B7D9EDF11493DC95316B2DA1AA835186
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var uwp_storage_fileVersion = "1.2.207"; ..var createUWPStorage=function(){var a={_content:{},add:function(b,c){if(!b){return}this._content[b]=c},set:function(b,d,c){if(!c){this.add(b,d);return}var e=ModuleManager.getSingleton("rules");this.add(b,e.apply(d,c))},get:function(b){try{if(!this._content){return null}return this._content[b]}catch(c){logError("uwp_storage:get: key("+b+"): "+c.message)}},getContent:function(){return this._content}};return a};ModuleManager.registerFactory("uwp_storage",createUWPStorage);..//9D8D5538830D5DDA530017E019CC1928F5F33E59A7F6257D35764CCC7A2613215B5A5874F10B8B9B3D6BF582F358A7C2A0271967C57AE30B52AEEFA0482D0B33++
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (814), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1021
                                                                                                                                                                            Entropy (8bit):5.404669125329936
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:nxbaMFOX49BAsnzOURzngpy3WAsngFPSIO90doQUkQ0Ps8B2:xBFOSAZA3WAzSixdUI2
                                                                                                                                                                            MD5:AFD66758130673E67FD28B1198B8200B
                                                                                                                                                                            SHA1:1E2E680B1FDE12118C8B1EEF1C83ECFA306E18CB
                                                                                                                                                                            SHA-256:32FE98CB61D1A2E9524D2DDCCDB76D8629B70A3E3C0A9724D2F86ED7FC0023E4
                                                                                                                                                                            SHA-512:D0D1D8FA3A545BDB55E15DCBB34BE5F5AAC057157CE0DEAE7A10697792F0455D910EAEC265D9741D8EE6DF7E4798DBAF2F230C0223E04432F64AB40445FA58CC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var wa_settingsdb_fileVersion = "1.2.207"; ..function CreateWASettingsDBHelper(){var a={getSetting:function(b,c,f){try{logDebug("getting WA setting: "+b);return this._getPlugin().GetSetting(b,c,f)}catch(d){logError("wa_settingsdb:getSetting: "+d.message+"setting("+b+")")}},fetchFromDataDefinition:function(g){try{if(!g){logError("wa_settingsdb:fetchFromDataDefinition Invalid data definition");return null}var b=g.name;var c=g.scope;var f=g["default"];return a.getSetting(b,c,f)}catch(d){logError("wa_settingsdb:fetchFromDataDefinition: "+d.message+"datadefinition("+JSON.stringify(g)+")")}return null},_getPlugin:function(){if(!this._waSettingsDBPlugin){this._waSettingsDBPlugin=getPluginFactory().Create("SettingsDB")}return this._waSettingsDBPlugin},_settingsDBPlugin:null};return a}ModuleManager.registerFactory("wa_settingsdb",CreateWASettingsDBHelper);..//6D8DD7DDB36D91D32AAF8638B985F7ACF089948683CA6948892D84305AEDB7CACBE9573416041415E14F60F8EF13FA814BE9F7EAA489F
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (7401), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7598
                                                                                                                                                                            Entropy (8bit):5.385271350984257
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:lt40Xb6wcFz1g8o3IE/ADvEWgj0xOsdmMcJS+c04IqIz65vSzCT0:lt48brys3IE4D8WqM0S+c04wzlzCQ
                                                                                                                                                                            MD5:704BDC280B4C8AAE827052FAC90172DD
                                                                                                                                                                            SHA1:609D04ECF1DDC83F55CB8EB7C2E98DEDECA126AF
                                                                                                                                                                            SHA-256:B667E7A4414310951EC845AD81CF4D90A22DB4FBECB5D5E05CF009F0D2078A09
                                                                                                                                                                            SHA-512:E9B066D0B89E8FE1749D3ADC15F9B0126A078514E07FBD23F92671AA91643A309006A6F6B5CF26791B4A2CC6AADCBE62528C09644F7F90160D150BD40590DE73
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! $FileVersion=1.2.207 */ var wmi_fileVersion = "1.2.207"; ..function CreateWMIManger(){var a={_createAttribute:function(f,c){var g={_data:[],get:function(l,j){try{return l(this._data,j)}catch(k){return null}}};try{f.reset();var d=f.next();while(d){var h=d.get(c);g._data.push(h);d=f.next()}}catch(i){logDebug("failed to populate attribute object")}return g},_getMockIterator:function(){var c={reset:function(){logWarning("mockIterator: Calling reset(). noop")},next:function(){logWarning("mockIterator: Calling next(). Returning `null`");return null}};return c},_unavailableServers:{},resetAvailableServers:function(){this._unavailableServers={}},_getServer:function(g){try{if(this._unavailableServers[g]==true){return null}if(!g){return null}var c=this.getPlugin();if(!c){return null}var f=c.connectServer(g);if(f){return f}}catch(d){logError("_getServer: "+d.message)}this._unavailableServers[g]==true;return null},_queryWMIServer:function(h,d){try{if(!d||!h){return null}var g=this._getServer(h
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:Microsoft Cabinet archive data, many, 63363 bytes, 44 files, at 0x44 +A "aviary_client.js" +A "common.js", flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1503 compression
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):76467
                                                                                                                                                                            Entropy (8bit):7.975020219369136
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:oHzKTWi0+jyw/hdhS16Sc8buLdkpxl6ZggPJhNK5NyuFfUl:oHzKTW1+7hwccu5kpxdAJhIRfK
                                                                                                                                                                            MD5:001AAB25A9ED3A8EE5C405901E6078F3
                                                                                                                                                                            SHA1:939596B653E3ED74A5B76506C62CD68FE5C9265F
                                                                                                                                                                            SHA-256:0210CFDDC082F6DFD9EEAD5D8FB64B5B6B70E8938246CFE8E530BC47C10E05A5
                                                                                                                                                                            SHA-512:702C8B0DE00675331DAF53075091A773BBC316AA9E4AB142C71640E508E08BCF98F9A828820AAF96ADAB4D133D5C65468E2294B4003F4D9942D43559DFEF5043
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:MSCF............D...........,...................03............................{Y.. .aviary_client.js..8........{Y.. .common.js......?....{Y.. .config_manager.js......C....{Y.. .csp_client.js......Q....{Y.. .dataset.js.....]n....{Y.. .datasets_catalog.json.)....w....{Y.. .dataset_da.js..6........{Y.. .data_collector.js..H..>.....{Y.. .data_items.json.j+........{YZ. .dictionary.json.....W=....{Y.. .emitter.js..-...N....{Y.. .engine.js.....7{....{Y.. .error_transmitter.js..........{Ye. .events.json......7....{Y.. .event_handler.js......R....{Y.. .hash128.js.....Tc....{Y.. .json2.js.1...=r....{Y.. .logging.js.:...n.....{Y.. .mappings.js...........{Y.. .mcutil.js...........{Y.. .observation_analytics.js.P...y.....{Y.. .operations.js..........{Y.. .preprocessors.js..........{Yj. .profile.json...........{Y.. .registry.js.....:.....{Y.. .rest_transport.js.u...!.....{Y.. .rules.js.B.........{Y.. .sha256.js.^........{Y.. .subdb.js.[...6.....{Y.. .transmitter_template.js.|.........{Y.. .trans
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):656
                                                                                                                                                                            Entropy (8bit):5.259529720888838
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6csNwI62Td/sSEw+gwG8k47nC6VY16oBzkykHs/nIBiS5knn5k2:6clsh/qwzf8b7CwY16oBzkyb/dSennm2
                                                                                                                                                                            MD5:063B01ACFBC3E53986EE211B4E420E51
                                                                                                                                                                            SHA1:D482713530D7859CEE7FA935B56BA9A0BAFE65E4
                                                                                                                                                                            SHA-256:05B1E88EDB1E11DFEEF1F635C297D660B7A4019209AF233A39A4E7EEA754E083
                                                                                                                                                                            SHA-512:FF7D8505A4F5D37CF4D3D6EA86F64DE223AAA48B13414DB1934F29184FAF8CA84BB7F2BC4058FFF5C02CABEE2EF87553676FF0C0FE8FDEFC34B1DA4D61DDE985
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........4...6.......-...B...-.......X...-.......G...A...X...-.......X...-...9.......X...-...9.......G...A...L..........init.setmetatableR.......6.......B.......X...U.......X...+...L...9...X...+...L...._base.getmetatable........%4.......X...6.......B.......X.......+...X...6.......B.......X...6.......B...H...<...F...R...=...=...4...3...=...=...3...=...6...........B...2...L....setmetatable..is_a.init..__call.__index._base.pairs.table.function.typeB.......6...9.......X...6...4...=...6...3...=...K.....class.core._G...//F2B26E9DD241203C81C77BFECA6B630511697551E4152D1BF87BAD56E3CC9BD8698F46768662FB0027454CBEB274D612743D86C7F0BBB5EE6DAA8106C5A91BD5++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):10234
                                                                                                                                                                            Entropy (8bit):5.605516703152428
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:jWXBkgh/3g7O7qaNfEyc80vDGwVd4Wog1DYEZpQ7+hC+Tf8IkZ0JGlG:ckgBGO7q8RcTvf7xNZUqmG
                                                                                                                                                                            MD5:E6C5467CF4387066DD18ED54A17D0FCA
                                                                                                                                                                            SHA1:EFE872AD5F4537B1439400E63B2E780F8C554251
                                                                                                                                                                            SHA-256:5C9465F5979C568525708D1EDC98E582B01AA4D6647261ED908CFEA4E518DAC6
                                                                                                                                                                            SHA-512:F44EA1E701DED4F22F6838CD288B414211D1E0CD8425F702F321CA14BB681BBD0937D3F1B5ED21F1939BF9D58E8494C7E1C1015ACB9F2F3D84E49D8AC119B4A2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..>.......-...'...B...9.......X.......K........getmetatable.debug........'...L....null........5)...)...)...-.......B...H.......X...-.......B.......X...........X.......X...-.......B.......X...).......X...-.......B.......X...+...L.......X...........F...R...).......X.......X...........X...+...L...+.......J..........number.n..........w-...8.......X...L...-.......)...)...B.......X...).......X...).......X...).......X...)...............).......X.......X.>.).......X...).......X...).......X........... .......X.0.).......X...).......X...).......X...).......X........... ........... .......X...).......X...).......X...).......X...).......X...).......X........... ........... ........... .......X...'...L...*.......X...-...'.......D...X...*.......X.......-.......B...............-...'...........D...X...'...L...K............\u%.4x\u%.4x.\u%.4x.............................C.......-...........B.......X...-...............D...X...L...K...............A-.......'...-...B.......-.......'...B.......X.0.-.....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2315
                                                                                                                                                                            Entropy (8bit):5.736679766271146
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:5JwHko/hrVeTYVJe7yAeeSiQRlVavdyJmlF6AjmjAHfs:UHkoucKOA7jQzRm36k6A/s
                                                                                                                                                                            MD5:23B615D0D66D1113EA7F2F8C640A5097
                                                                                                                                                                            SHA1:C20551AAD8F385C6251254866CD839E381FFCFF3
                                                                                                                                                                            SHA-256:A75781DA1A65843FDF2266DC6BCDF2F9C9D31CF8F4D20CF840F03D3ECD654DD8
                                                                                                                                                                            SHA-512:3DD24BD30237A157447FC71CB3BBA86F4A7D589704888367FB161FB0F1E49F0C7A4BAB454137DBD341E4ED95A1202701B90490168D7A97872DB85653D7F90392
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........]6...6.......B.......X...+...X...+...'...B...6...6.......B.......X...+...X...+...'...B...6...6.......B.......X...+...X...+...'...B...6...6.......B.......X...+...X...+...'...B...9...8.......X...9...4...<...9...8...)...........X...U...8...9.......X...X.......X...5...=...=...8.......X...8...9.......X...6...9...........5...=...4...<...=...B...X...6...9...8...9.......B...K....handlers....order..handlers..insert.table.check_updater_flag.handler....handler..check_updater_flag..order._registry.handler must be a function.function handler id must be a string#handler order must be a number.number event type must be a string.string.type.assert.|.......6...6.......B.......X...+...X...+...'...B...9...+...<...K...._registry event type must be a string.string.type.assert........)6...6.......B.......X...+...X...+...'...B...6...6.......B.......X...+...X...+...'...B...9...8.......X...K...9...8...)...........X...U...8...9...+...<.......X...K....handlers._registry handler id must be a string e
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2305
                                                                                                                                                                            Entropy (8bit):5.843848594991481
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:DhmEnssOUb+Oi6ZNmMWpIJQtbNSE6N+iwgOLL2X7eKTGn8tAwlTzX:DUEssOUSOMtpIJQtbSEivXCKhtAGX
                                                                                                                                                                            MD5:3520FA72735133EAC7A2A4CF0EB8B928
                                                                                                                                                                            SHA1:B6AF95708C3C88296C3B83BE1FB254179ED94593
                                                                                                                                                                            SHA-256:13E62CF4BEE454DDAC70336AD8C28D063CF852DDB43E18912C954407797CF55E
                                                                                                                                                                            SHA-512:2640D6D81FA03703CABD082D7A38AA6D76D0758C82D41B0ED856FB94E66499A88629CB7F201E940076B3F4E4F23A2AF7695E2D7DA8D286A1AA66B4E4F52E3718
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........5...'...6.......B...X.......9...'...'...B.......9...'...........&...B...6...........B...E...R...K....require.Loading script: .info...luc.gsub.ipairs.mfw\core\.....dkjson.luc.handlers.luc.PostInit.luc.json.luc.PriorityQueue.luc.UiArbitratorHelper.luc.UiHandler.luc.UiThreadExitHandler.luc.utils\SettingsDB.luc.utils\StringUtils.luc.utils\PackageUtils.luc.utils\BrowserUtils.luc.utils\common_utils.luc...... ...6...9.......)...B.......X...6...9.......)...B.......X...+...X...+.......X.".....9...'...B.......X.......9...'...'...B.......9...'.......'.......&...B...6...6.......'.......'...&...B.......X.Z.....9.......B...X.U.....X.:.....9...'...'...B.......9...'...B...6.......9.......'.......'...&...+...B.......X.......9.......B...K...6.......9...........B...6...9...9.......9...........B...'.......'.......&...6.......9...B...'.......&...-...............B...X.......X.......X.......X.......9...'.......'.......&...B...-.......'.......&.......'.......&.......B...K......Found subdirectory
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):562
                                                                                                                                                                            Entropy (8bit):5.4883641051879914
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6uNkydLkg5M10kgPv7BkkFAtLvYUkjoU+TmUEf:6IoERB2tLHUGwf
                                                                                                                                                                            MD5:0C82522CAFF671B7C481F594411F2F08
                                                                                                                                                                            SHA1:3C6C1DC686DD524891079E382B4AEAE5974DBA9A
                                                                                                                                                                            SHA-256:5FA68D7AD18C33EEE4A71E838C7D951C2C2656D03F50ADDFC62291F11199A7A5
                                                                                                                                                                            SHA-512:CB2CF6834E66063CF34ACBFD534439996E5BF3235A36708E493105D4FA200E309733BF6F9DA55D8741F06BB1632584F947AB70344B49F8A91BCA81676879343C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........9...9.......)...+...B.......X...6...'.......9...)...).<.B...'.......'...'.......&...B...L.... pos: .',.), error: '.sub#Failed to decode json string (.error.decode._json3.......9...9.......5...D.......indent..encode._json.........6...9.......X...6...4...=...6...5...6...9.......X...6...'...B...=...3...=...3...=...=...K....encode..decode.._json....encode.._json..decode..core.dkjson.require.dkjsonTest.json.core._G...//5978B0CAF663886B7BA14FEFEF0D9A85B433B96C101A3A3F8D24D1927330B6E7FAB93BE793A42923F6DD3D8C6F65367041260F4FB3EBBAC7AC68A71D15BBBBC8++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):699
                                                                                                                                                                            Entropy (8bit):5.329885535844202
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6x5bYn4wF0WNYtAr78KQK78KTR78Ky78KSV+AQlm1ZMWOPGgMuM24An8bnNSKpdk:6u4wF0WNEUyg1qWOug82N8jAMAqTi
                                                                                                                                                                            MD5:5A0EF4664B797B6F7B6A26FE551B31CF
                                                                                                                                                                            SHA1:CABE08555ACBBEAB6C064A87C263A7E6A5CD5656
                                                                                                                                                                            SHA-256:4A51796B530FF23E6E7C2D986F17ABFF3B828E5F86F39EC4CC2B2CFCE0173B91
                                                                                                                                                                            SHA-512:C991F566D8C9F3D0C4361079FDDA85466EA74C5994529BA2A7EC46328C5CF9D3D3215EFD54D08CDD010B9F981C075A0D4F6F213C2A31011E4D8EE509BBD429BA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........G.......X.......9...G...A.......6...9...)...B...6.......9.......9...9.......B...K....currentline.short_src.Log.utility.getinfo.debug.format........-...-...9.......G...A...K........Normal/.......-...-...9.......G...A...K........Warning-.......-...-...9.......G...A...K........Error0.......-...-...9.......G...A...K........Critical.........6...9.......X...6...4...=...5...3...6...5...3...=...3...=...3...=...3...=...=...2...K....critical..err..warn..info....warn..info..critical..err...log.....Warning...Error...Critical...Normal...Automation...core._G...//0966E7F515283E273ACBCACFD0DD1C5E7AAC6239BC7C2766795554C272176E3F5A9B7F182B12F84F7F48C27D689C7045313EB127DE417BD8AD4E22CAF5736F0A++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):980
                                                                                                                                                                            Entropy (8bit):5.699909195659202
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6YDsnrMjnBNMVCXMgrmPJ4rAobrLQJxX+fThOhcqtflUDBs5:JuIjYVpgyhgbrLQTkEhcqZlsC5
                                                                                                                                                                            MD5:75D95D21674993A821F2D4FDF3871DA2
                                                                                                                                                                            SHA1:49736A6B2461EE9425FEC80F29FE81AA72C7DBE9
                                                                                                                                                                            SHA-256:8F9731CE44A2914F3F03AF3240DF4B4885309A98BBA53B4AFB5628FF8CD1A4C0
                                                                                                                                                                            SHA-512:A0B90BD93A3B43D55D6A702BF65E779DE86DF06ADCFC707E84614E74786113F0EB4A5AE0A4E842FD76707539551330D5673D2EA93F81468DBF1EDFA09FD69C71
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........96...6.......B.......X...+...X...+...'...B...6...6.......B.......X...+...X...+...'...B...6...6.......B.......X...+...X...+...'...B...)...9...........X...U...9...8...9.......X...X.......X...6...9...9.......5...=...=...=...B...K....callback.id....callback..id..order..insert.table.order._registry%Callback type must be a function.function!Callback ID must be a string.string$Callback order must be a number.number.type.assert..........6...9...B...X...6...9.......9...'...9...9...B...6...9...B.......X...6...9.......9...'.......B...E...R...K... Failed to run callback (%s).err.callback.pcall.id.order4Executing post-init callback. order: %d, id: %s.info.log.core._registry.ipairs.........6...9.......X...6...4...=...6...5...4...=...3...=...3...=...=...K....execute..register.._registry....register.._registry..execute..PostInit.core._G...//2CC7DF6538F086396E329725B3528D301943E946D4173342978FD1CDF61306157AC0B64DE87125C79877B3054BA56D61119326F5654ACA6D03C8BE5E8AB9D928++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1267
                                                                                                                                                                            Entropy (8bit):4.994679765460364
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6enUdjWd4nqwwDRmvA5bxMi0kdVxIXkfF32CG79lgxLEIeYlRl4R/Y8:znUd6UqwwdQA5bxMiNVjHyCdEI/mt/
                                                                                                                                                                            MD5:87A95CC6A3DDD7827E448B0A603C0693
                                                                                                                                                                            SHA1:E40A4AD03FA1EEE6AD5C2FD6E10855605B221CF7
                                                                                                                                                                            SHA-256:7F0FB6C90341D6FE50219A6557C22D89F4A08FF34AB07D026A4679B162518506
                                                                                                                                                                            SHA-512:418FFC2A26756D827977795D67011DC213EAD07E27ECB5E57F21186C612E4DE61D9A713E945E6C5A7F08A4ECE17E19447226AEC3DD1EA6975074DDF9F9A102CF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........1-...9...B.......X...5...=...=.......-...........K...-...9.......X...5...-...=...=...=.......-...........K...-...9.......X...U...9...9.......X...X...9...X...5...9...=...=...=...=...-...........K.............next..value..priority..next....next..value..priority..value.priority....priority..value..Empty.k.......4...)...-.......X...U...5...9...=...9...=...<.......9...X...L......next.v.value.p....v..p..priority........."-...9...B.......X...K...-...-...+.......X...U...9.......X.......X...-...9...-...9.......X...9...=...-...........X.......+...9...X...K..........next.value.Empty._.......-...9...B.......X...+...L...-...-...9.......-...........9...L..........value.next.Empty.?.......-...9...B.......X...+...L...-...9...L........value.EmptyB.......-...9...B.......X...+...L...-...9...L........priority.Empty........-...L.....&.......-.......X...+...X...+...L...............4...+...)...3...=...3...=...3...=...3...=...3...=...3...=...3...=...3...=...2...L.....Empty..Size..TopPriority..Top
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):476
                                                                                                                                                                            Entropy (8bit):5.403433806188916
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6gQrQouWHpCJHMjvoQwqbADclzB8AUECTCixs5Qx:6NpCFgAD8KAULmiKC
                                                                                                                                                                            MD5:0C7192E01776384350DB9D8385F969AB
                                                                                                                                                                            SHA1:A28D8131B4E00DD60E9A990D15BBA0C132CE1079
                                                                                                                                                                            SHA-256:BC3DEF1232BAA5BB547545F2C25CF5BAD52B9B47F2FC36F8A8859A0E5D65D5E1
                                                                                                                                                                            SHA-512:B36B532E747D0C6F498D14F1EC35D312B60C0FA33FB023AC05C9FB31FC7D92228A20F5C257334633CD3CF109EAC651E2994CCD48389FBD7A347E2C57E33E8670
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...9...8.......X...8...L.......X...+...6.......9...............B.......X.......X...+...<...L...6.......)...B...K....error.include.external.loaded.package=.......6...9.......9...........B...K....execute.handlers.coren.......6...3...=...6...'...B...6...9...B...3...7...K....HandleTrigger..loadPackages.core.core.init..require._G...//A04AE81F1AC78C57BEA1A6292D4647852EB9EAD9E9E484675B31EF517125322F9FD381B5934C3BDA6BE4C7C5B3CFBA3D19B596C1283C0E6BB1C045EA98EA8C66++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3788
                                                                                                                                                                            Entropy (8bit):5.552469780564675
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cklXeOJw5g1AGiz8wE8xxveb8ZvRXfy9L7W:ckRhwGKd8wE8xxveb8jXfy9nW
                                                                                                                                                                            MD5:81E0A180BFD797E6BA36FEEA6C102413
                                                                                                                                                                            SHA1:08132153CCDC3FE8CDF6D68A1F395B55853018B7
                                                                                                                                                                            SHA-256:9A04D219A19827DB88BCF1E7EEF2DC33A860B11F8A61E202123ECBFBE9C8F52A
                                                                                                                                                                            SHA-512:16AF20AB11D021953505D614EFA33139173AF2119457C6198B582264041EF6F22F2E5A5EC9B0498CE841C7B3E5497690125F303DD2AE44C0DFA937B28DE5B8AD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..T.......-...8.......X...-...6...9...9...B...<...-...8...L......new.PriorityQueue.core........-...<...K.....T.......-...8.......X...-...6...9...9...B...<...-...8...L......new.PriorityQueue.core........-...<...K.............-...........-...L......0.......0...4.......4.......4.......K............B.......4...6.......B...H...8...9...B...<...F...R...L....Data.pairs........"3...7...5...-...=...-...=...6...-...B...=...6...-...B...=...6...9.......9.......5...B...6.......9.......B.......X...+...X...+...2...L............StoreArbitratorState.uimanager....indent..encode.json.core.ShowingUiRequests.PendingUiRequests.UiRequests.uiId....uiId..PendingUiRequests..ShowingUiRequests..UiRequests..DumpTableData...............4...6.......B...H...6...9...9...B...<...6.......B...H...8...9...6...9...B...6...9...B...A...F...R...F...R...L....v.p.tonumber.Push.new.PriorityQueue.core.pairs.........3...7...6...9.......9.......B...9.......9.......6...9...B.......6...9...B.......K............ShowingUiRequests.Pen
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1220
                                                                                                                                                                            Entropy (8bit):5.915091404145217
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6I0lBHW+Tks5h4uxHN2+PBh5DKScPDDQ5c4acKf38tRqV1Q0rOjsY4RKnaZcQ/c:Kzd7h4uqwRKScPDvMtYlrq4RKT
                                                                                                                                                                            MD5:8F145C904518DB1406476CA8FB237EA1
                                                                                                                                                                            SHA1:EB440C3301F48AC4BE22CFB7FB93EE0F9092CEA6
                                                                                                                                                                            SHA-256:C91BA1420D89C87F3EC1CE84D460D7F531FDD89A3BC1C30238A48F2D294FF1A8
                                                                                                                                                                            SHA-512:F1CB7AB8461603B983C3799A2F318C417369E6BDCDD0D950AFD3217244756982ED2DBC018909312EF1682AA1869A6B82184186859B090B3725063EDA35FC9E6B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........)...6...9...9...B...9...B...=...9...9...B...9.......5...=...=...B...6...9...9...B...'.......&...9.......B...+.......X.......X.......X.'.9.......X.$.6...9.......9.......B...6...9.......9.......B...6.......9...........B...7...6.......X.I.6...9.......9...'...9...&...B...9...............B...X.;.9.......X...9.......X...9...6...9...9.......9...9...9. .6.!.9.".B...A...+...9.#.....B...6...9.......9...'.$.9...&...B...X...9.%.....X...6...9.......9...'.&.9...&...B...9.'.............B...X...6...9.......9...'.(.9...&...B...9.#.....B...........J...6uihandler: no special options, removing request: .AddPending"uihandler: adding to pending .skipPending,uihandler: Added a delay timestamp for .RemoveRequest.time.os.setting_name.setting_scope.SetOption.SettingsDB.utils.delay_data.delay.AddShowing"uihandler: adding to showing .info.log.ret.Show.uimanager.encode.json.overrideSelfPriority.TopShowing._.Browser.EventData.tostring.templateArgs.config....config..templateArgs..AddRequest.UiType.UiTypeI
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1141
                                                                                                                                                                            Entropy (8bit):5.941607065548458
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6Bld27yrNDybt88WP3CvwgefKS6VlceP1Q3D2c0ebE0+pwp+vE94:UsQgu8QgWaZ1427ej+Gp+8C
                                                                                                                                                                            MD5:D892D62313540E1ED073B6BDF7121A80
                                                                                                                                                                            SHA1:1E0BB14013D49F68DFDB90D767E4AF1A2E59DAD3
                                                                                                                                                                            SHA-256:376C12DC224A6A2F70A6B64A8E0B8AB25FC9D78E8ABB48D3A0BC6371F52D0468
                                                                                                                                                                            SHA-512:93F95CCE8C380C40502FDD52A09179BE825D7AD7D466C951EB4465AF9457508374BDD15188B821E45A4312791CC378F6313BDEDFEFB551E4FF0CDDB81EC0E58B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........$.z6...9...9...B...9...9.......B.......X...6...9.......9...'...B...K...9...9.......X. .6...9.......9...'...6...9...9...B...&...B...6...6...9...9...'...6.......B...'...&...B...A.......X...6...9.......9...'.......B...9...9...9...B...6...9...9...9...B...'.......&...9...........B...9.......B...9.......B...).......X.+.9.......B...9.......B.......X.......X.!.9.......B...9.......B...6...9.......9...9...B...6...9.......9...9...B...6. .....9.!.........B...7.".6.".....X...9.#.............B...K....AddShowing.ret.Show.uimanager.templateArgs.encode.json.PopPending.TopPending.TopShowing.NumPending.RemoveRequest.RemoveShowing._.Browser.EventData.UiType.UiTypeInfo'Failed to run onExit callback (%s).).(.load.pcall.tostring6UiThreadExitHandler: requestData.config.onExit = .info.onExit.config,UiThreadExitHandler: requestData == nil.err.log.RequestData.ID.GetInstance.UiArbitratorHelper.core.....j.......3...6...9.......9...'...)...'.......B...K....Core_UiThreadExit.UiThreadExit.register.handlers
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3251
                                                                                                                                                                            Entropy (8bit):5.531580876024518
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:f/BP24m6A8F6JjKtwxzqE+zqlRwr6RwEJdrNLu1hrdOWsaBA:f/BP24mvzxSwxzKz0+KRd01hoKBA
                                                                                                                                                                            MD5:2B4A67342C584C9B9C3668896884DC03
                                                                                                                                                                            SHA1:B6663290BEC311FC9C584A23FE20DBDFC5B8B147
                                                                                                                                                                            SHA-256:3FCF58D474734E572E264F83281C7D315AD4246ACB60E316FFB385A6F0E038CA
                                                                                                                                                                            SHA-512:EF2D9ADAA6D480930A56ACC1E4F66FD45F988DB1CE96C1DE2676D9059F5CCAC7B8AE2A6455C698336DE773924A7019B2502753A1BBA46F5E8877DF82070DE0E3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..a.......6...9...9...9...........B.......X...+...X...+...L....GetBrowserStr.BrowserUtils.utils.coreI.......6...9...9...9...8...L....BrowserTypeString.BrowserUtils.utils.core.........6...9...9...9...8.......X...6...9.......9...'...6.......B...&...B...+...L.......'.......&...6.......9...............D....GetOption.settings._.tostring.Wrong browser type .err.log.BrowserTypeStringLow.BrowserUtils.utils.core.........6...9...9...9...8.......X...6...9.......9...'...6.......B...&...B...+...L.......'.......&...6.......9...........D..."GetUserOptionWithSystemBackup.settings._.tostring.Wrong browser type .err.log.BrowserTypeStringLow.BrowserUtils.utils.core........"6...9...9...9...8.......X...6...9.......9...'...6.......B...&...B...+...6...9...9...9...9...J.......'.......&...6.......9...........D...,GetUserOptionAndErrCodeWithSystemBackup.settings._.Unknown.settings_error_codes.common_utils.tostring.Wrong browser type .err.log.BrowserTypeStringLow.BrowserUtils.utils.core.........6...9...9...9.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6002
                                                                                                                                                                            Entropy (8bit):5.582050221373269
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:zjx4bqxfcsUvEBsF5e8yQLv13RBgoNevPg/lsvebKlDPCeat:zjx4bqi80EcvpjNIPsCebKleek
                                                                                                                                                                            MD5:FF2C89AD86AA498588D50F222E1E1312
                                                                                                                                                                            SHA1:BF1DC6666EF3AB96A97A0829DB651BE64C1914E7
                                                                                                                                                                            SHA-256:52FC880CF8D169B38141A627982869348F9F17A138202B094F9AA9E1B502ABBD
                                                                                                                                                                            SHA-512:8134B235C9FCFE3171AAD7B6B5EA2050D030C3A1067F44D50EFF8FD20BCA5EF1787DEBBD6CFD4CFC897327AC41582CA90EB481AC5A4BF4CD96E0C35D805D2E55
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...9...9...'...'...)...*...B.......9...B.......X...'...L.......9...'...B.......X.......X...'...L...6.......D....tostring.NULL_AFFID_ERROR..affid.QueryValue.READ_ERROR.IsValid+SOFTWARE\McAfee\MSC\AppInfo\Substitute.HKLM.Registry.Win32.core................X...6...9...9...9...9.......X...6...9...9...9...9.......X...6...9...9...9...9.......X...+...X...+...L....WrongType.DoesNotExist.Success.settings_error_codes.common_utils.utils.core.........6...9...9...'...'...)...6...9...6...9...9...9...6...9...9...9...B...A.......9...D....IsValid.KEY_WOW64_64KEY.KEY_READ.RegistrySamConstants.bor.bit5SOFTWARE\McAfee\MSC\Settings\ApplicationInfo\MSC.HKLM.Registry.Win32.core........06.......B.......X.......9...B.......X...+...L...6.......9...)...)...B...A...6.......9...)...)...B...A...6.......9...)...)...B...A.......X.......X.......X...+...L...6...9...5...=...=...=...D....day.month.year....min...sec...hour...day..month..year..time.os.sub.tonumber.len.string.type.,.......6...9...!...-...#...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):867
                                                                                                                                                                            Entropy (8bit):5.420155880344147
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6DA+0TGrcQqcnEbbqTrc8u6BIuAfcnquJv:eJcQqcEfIcd6BIuAf/8v
                                                                                                                                                                            MD5:CDD29945D0C68EB61CEE10443472EEF1
                                                                                                                                                                            SHA1:823D487C44AE9B75A51BE9849380B42CBD621DDD
                                                                                                                                                                            SHA-256:1D2BFEC6357810B63C4D221C8542FDCE455FFC0686E9CFA695EDC631ED5B14DD
                                                                                                                                                                            SHA-512:E92E26B23DA060FB1134E80D71BE121BC4A93980E56E03E5F94A91859B98F8486E1DF57A64C087D254F44FDA24AF275B54E99C78B0FD26ACE5FC8D6D50159659
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...6.......B.......X...+...X...+...'...B...6...6.......B.......X...+...X...+...'...B...-...<...K.....%Package version must be a string"Package name must be a string.string.type.assertr.......6...6.......B.......X...+...X...+...'...B...-...8...L....."Package name must be a string.string.type.assert.........6...6.......B.......X...+...X...+...'...B...6.......9...B...'.......'...&...L....\.mfw\packages\.GetInstallPath.utility"Package name must be a string.string.type.assert........&6...9.......X...6...4...=...6...9...9.......X...6...9...4...=...6...9...4...=...4...6...9...9...3...=...6...9...9...3...=...6...9...9...3...=...2...K.....GetPackagePath..GetPackageVersion..SetPackageVersion.PackageUtils.utils.core._G...//EEDA1B62B0BABFBD34F253DA79417CD49A955337F0D4AE061213855F9E674327B5D8C77004B5CCF9ACC3E8B7B81F5CE1C051B86BB6B7C527AF3492D462FD8B09++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):761
                                                                                                                                                                            Entropy (8bit):5.493514972861823
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:67gclf2Magc5B/oQjf8uSIcz5qqxDax0fh99ATjS8tX8PN71u+xMIf8wQjXeqqxs:6RpaZB4uSIc/O4Du+xCwUe9eP6i
                                                                                                                                                                            MD5:30C2FDDCAB3389AE2E04F14ECCFEFE7B
                                                                                                                                                                            SHA1:EF74BC536D9A56A5BC3BD6787B2C805ED62EFCD0
                                                                                                                                                                            SHA-256:54006C552A5789278084466B52904D12E7AF1C07422267E4FD8EC5C1BD9AC250
                                                                                                                                                                            SHA-512:F5889A0C7D9D48C79DDFED1E224B298B60C56EBB91D76EA74977C24EB9261D013E98DF1185EDF307018625248727BBA636CC0A1A63963006E42B0E72C3F3CAF4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..6.......6.......9...............D....GetOption.settings.........6.......9...............B.......X...6...9.......9...'...6...9...&...B...L....Name.elem.Failed to set option: .err.log.core.SetOption.settings.........6...9...B...X...6...9...9.......9...9...9...9...B...E...R...K....Value.Name.Context.SetOption.SettingsDB.utils.core.Settings.ipairs........)6...9.......X...6...4...=...6...9...9.......X...6...9...4...=...6...9...4...=...6...9...9...3...=...6...9...9...3...=...3...6...9.......9...'...)...'.......B...K....Utils_SettingsUpdate.SETTINGS_UPDATE.register.handlers...SetOption..GetOption.SettingsDB.utils.core._G...//6BEA2EB0FFC1AEAD1F13002ED7939A51D869C6CEA7F2829DBC2904ECB1D774477B9D77FDB2FCDDEB8045986F792B45AE25E091A485D39495D98C89C1DFB2ADDA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):381
                                                                                                                                                                            Entropy (8bit):5.192806180869675
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6emuLqNlmHiRDPVj9fE+ATjS8JYcR7Qh9bFDVS62Zdu1t3wFPvdWQIn:67lmHiRDh99ATjS8atj5V3wdu1izPIn
                                                                                                                                                                            MD5:C7357C3ACFC7BF9BE6F1EE4DA1F9EED2
                                                                                                                                                                            SHA1:D2AD3BC41D5BCA5826BDB06BCAC064FF28179C62
                                                                                                                                                                            SHA-256:628F854469B54B3C88C1FB6035BB86270A92CF8D049889822CC316635CB20EE9
                                                                                                                                                                            SHA-512:9E102CD2206847C3E27E836EC9C38DBB6DE27547971391BB70983ADB19B078422F71FBAB065AD59631B53290D9AEEB254176344C2923FE5BFAE9A17F0D3B428B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..O.......6.......B...X.......9.......B.......X...L...E...R...+...L....find.ipairs.........6...9.......X...6...4...=...6...9...9.......X...6...9...4...=...6...9...4...=...6...9...9...3...=...K.....MatchInPatternsArray.StringUtils.utils.core._G...//F62C77D6F474015EDABFF60D7E46FA815F06323665B7150C7866A0657CF815BB11A0199713AF92E27F2E3D614D3B44514A71F277956673F679985E61330FB7C1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):30539
                                                                                                                                                                            Entropy (8bit):5.704642369166357
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:JX/CIGkba/ZqyBhyCTz5KamxnbxSHo44G29gJ6UOzC0Ob:Jfah5yAKaqboIrG29gJ6NzCt
                                                                                                                                                                            MD5:C4658946A09BD22D3E0E262A9EC1EBBF
                                                                                                                                                                            SHA1:2B45539B2F030D99689D7DCF839FE3C0B2A1072A
                                                                                                                                                                            SHA-256:02E3CBA1C4491E184C6583BD8C35263175AFD5A893EEBF11B3A2457A78BFF724
                                                                                                                                                                            SHA-512:CA76966A53D934121EC84FD6287C3CCC1825A42E59E5423C3F8094EE2C4E53DEC30B6113E183E12C56EC7C0A58F8213B588F565B0DE26381938A13D4FBBF9067
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..9...........X...6...9...9.......B...K....CloseHandle.C.ffi2.......=...6...9...9...3...B...K.....gc.ffi.handleV...........X...6...9...9...9.......B...K....DestroyEnvironmentBlock.userenv.Win32.core/.......=...6...9...9...3...B...K.....gc.ffi.env1.......6...9...9.......B...K....RegCloseKey.C.ffi........<....X...'.......X...).......X...6...9...9...9...6...9...9...............B...7...6.......X...+...=...2. .6...9...'...B...=...6...9...9...6...............9...B...6...9...9...9.......X...+...=...2...9...:...=...6...9...9...3...B...K...K...K.....gc.ERROR_SUCCESS.Win32ErrorConstants.RegOpenKeyExA.C.void*[1].new.ffi.hKey.rootKey.GetRootHKEYFromString.KEY_READ.RegistrySamConstants.Win32.core.(.......9.......X...+...X...+...L....hKey........n....9...B.......X...6...9.......9...'...B...6...9...'...B...6...9...'...B...6...9...9...9...,...........,...B...6...9...9...9.......X...6...9.......9...6...9...'...6...9...9.......B...A...A...4...)...:.......)...M.5.6...9...'...:.......B...6...9...'...:.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2338
                                                                                                                                                                            Entropy (8bit):5.634661983308953
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:ulTdkjpbD/Lcww/IvvfpNC28F4dHX879pKo1koJyLzF30F0LAw0q4k9F:ubkFbDwRwvvfpp8F4dHXk9pKo1koJyLD
                                                                                                                                                                            MD5:0BB0A2B9A63053149EE717E7D88BAD5A
                                                                                                                                                                            SHA1:4BE9E7378E349862653D4C42BACADB756A685AAD
                                                                                                                                                                            SHA-256:143BC8CB43D56F6E6B38C680344E6F179C245FD99BDDF2BA1E61D701222F0D53
                                                                                                                                                                            SHA-512:4A64181FE8D9ECD71CDB98F9DEF6251A15FFCC8471C491802617CCCB54A6E329EF34794821861962BB666126B46EFD1508BE01E30E77D3107951F8A10BE793A9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........Z6...9.......9...'...B...+...9.......X...6...9.......9...'...B...K...6...9...9...9...9...8...6...-...B...X.6.6...9.......9...'...6...9...B...'...6...9...B...'...6...9...B...'...6...9...B...&...B...9.......X...9...'.......&...6...9.......9...'...6.......B...&...B...6.......9...9.......9...B...X...6.......9...9...9...9...B...E...R...6...9.......9...'...B...K......handle_reset_event: end.SetOption.settings/handle_reset_event: local setting name is ._.reset_value., reset_value = .add_browser_suffix., browser specific - .scope., scope .name.tostring+handle_reset_event: resetting setting .ipairs.BrowserTypeStringLow.BrowserUtils.utilsBhandle_reset_event: no browser field in event_data. returning.Browser.handle_reset_event: start.info.log.core......../4...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...3...6...9.......9...'...)...'.......B...2...K....reset_settings.event_on_reset_settings.reg
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 54 x 46, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):509
                                                                                                                                                                            Entropy (8bit):7.265106458574301
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/76lJ/6Ts/4qfsK+Sz2D2cP03cbekp8LuwkWBjMAraM7P:9lJ/68fsPSyFP03gpLWqu7P
                                                                                                                                                                            MD5:B9239E137DA0942222FD6E7FBB95F084
                                                                                                                                                                            SHA1:4D8B1C9DA9E1A8772F5C6929A4337D5D9A659EF7
                                                                                                                                                                            SHA-256:FB3B5BE9639CDB51AEDA6F379B0E3D78E64035C53EBBD9D99D28E6913A6BB761
                                                                                                                                                                            SHA-512:02EEB55B6C2A00D6E638B57CF448A5110C40A0962D68121BB869C8CD82812AA50FCC882A0E3FCFBF9DA5047F15A2686176CCFA1F61044DD8BF7F0CC957A630BA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...6.........c..+....pHYs.................sRGB.........gAMA......a.....IDATx....M.0......kzH..+d.6..$.0BF..e..!7. ......B...I..g....{.].b.D.K.....".e..."}k~..Sk.y.R...1.x.R....rcp9'.!.......n.&.<.zc.9..(..W..7..9.ZbX.d..e*.....n2v5i.x.!.8.0d....l.D..7N..q.D...N..q.D..T.X.....Ccq.ah......S..MS<..b...C.KI;h......a...k.%..`fx......{e&.r7.)...P$.T.Q(....(........h..P.G..Q(...(....i(....(....0....p....i....5`....p.c...5`......i^.e....dC!.0M.c.....^...4?..R...Kb_}nL...i.....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 46 x 54, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):525
                                                                                                                                                                            Entropy (8bit):7.401937246200202
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7W7/6Ts/B2l3fqAXsMj1VswTbTfH9O95UzdOo9Fy2S97:F/6B3io1p79O/kdjHy2St
                                                                                                                                                                            MD5:CFD3007010FA11DFE25FA8D48E65E72A
                                                                                                                                                                            SHA1:9973303D168AECC57EF380EB705DB4B7C6055766
                                                                                                                                                                            SHA-256:8FFC2BAD58D0322050F9AF74D140A23A589AA6E0710D6E48285FCC123A80ACE4
                                                                                                                                                                            SHA-512:DA7514A4B7CCED85378E25B49742AB674937B7CE3AB714923D848CC1F3CE38CF6C11A0DEA8B97C2860B0BCFC770ED3CC39E74AA358A63BFE81E9DC47754DA60B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.......6......<......pHYs.................sRGB.........gAMA......a.....IDATx...MJ.@..........EA\y....y........'..R.B=B.."dmM.L...$........4...$......I..........\ '.r;..~.o...zy(Ujq.vu.,.C.W.!t<......Q..h.....@C(.(x......#.P.>.......pD4..W>'.<...........#g..s..........r.c...p.7"&....k.._.os...SL.b......../8.......w..B.%.K4./......9.......&5'....x).}.........P...3Oo.^.........P-^..r...h.W.,.q...2.\..>.........}2M.G.t.3I.{... .....Cb.b8u.....1.:.S.p..N..c8u.....1.:.S...Di.(.."....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 150 x 198, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):13807
                                                                                                                                                                            Entropy (8bit):7.980033051105471
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:r82XmabuE9fiCT7j5ggQkSDKoEBF4mRzzJt:40XiClggenEBp
                                                                                                                                                                            MD5:A7522FA80144583C5F0E070F50E06C47
                                                                                                                                                                            SHA1:FF32E2DB5468B183DE1FC7A68D3F82BCAC033262
                                                                                                                                                                            SHA-256:AE9F79BE354331730247196BAF87001D48330E8452593952820AFEE0DCE5724D
                                                                                                                                                                            SHA-512:FB8E730EB796F051AB4E84A1277C2C6B53CC8DFCA96CAD8B3CCE4DB48675B3D7AE008F1A1B100D776E1BB9F040CE0DCEC020462F13C9CC42126F463F87CC0802
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............0.y.....pHYs.................sRGB.........gAMA......a...5.IDATx..}m.#7.% _..c........{....X."upp........Uf. ...J...._......p.y...?.v.........UA.....k.i..W.+...f.?..8h.F.C..:..z.=...\.)..P.+yW.....km8.O.N.;s..9Hs....x....ni.2b..1.....$:.V.c%.~...4Q.w....VuT<N..... .....^.....j."Q../#n'....K..d...h.c...tQ'....L.U6@^.K..g.. .....>1;.@..m./...<.0.......d..o.t#........!d0.^9..|..D..K..6..Z....<....N-...M....%....B04Rr.. H......u...f.........|\.q...r.'Vt.g...,...[.V.....t%..]..H...J .G:.....x.....).....,.K..)....jC..........d(.m7p*9L.Lr=.Dc.~..f}8.J.c8.`..`i.Q.'..S.......ZT^1..L{n.Qy.._.6..)hv./41!.i.7'}..F.L:. .... K._Ag.L%{..:/[n.P.I..g].D.80J,o....)g..~.z.P......y.\..K..7^+..d..]42..k...+=.>.......k[..(....E....Zk.;..q.xu..?.H.t.*.N|.....].u..B/.TJ.+.x'.I..$@.)8.7..R..:9.)y....x...e...;^eP....K...H.G...#.)..t.=..>0..........I...n..,K|)8.....o.?.n'.....h......u.s_..`:A.....R.7G.v..$'..9w5v ,..x...xL1>.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 11 x 11, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):312
                                                                                                                                                                            Entropy (8bit):6.773823438465042
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhP8AMx7/6TsR/Jr5OhJTtEEc+GbxMWMEHFGejHr5fDp:6v/7kAMx7/6Ts/Jr5GJxJFmxMQHFG8Ln
                                                                                                                                                                            MD5:539828AA00E3933554AD071A88D2620B
                                                                                                                                                                            SHA1:EAB3ED1CE4E11D3428840E48870BC138DAD58499
                                                                                                                                                                            SHA-256:CEB6F6C99816B65716862B6353DF4D4425D9E023A6BBEF7180E63954BAFED91B
                                                                                                                                                                            SHA-512:0982F97ADA2F432BFAA87AD0598F4CB5AE482A4E57D5CD81F4848B62A7C9783F988DCE1E8DCCDB2C7D0F16DEF28387BB702E91C33E65E6EECE365548201536D2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............w&....pHYs.................sRGB.........gAMA......a.....IDATx.}....0....-.#...A..$.H&@....F.]..D6`.2B.T...d.X....>.g..)..\]h...ho.,.j....N.'p5.Jj.....0..Y.........<..1,.v.....Jj.wr...d0.....cz(..b......d...w.......eW...C'ah....0....`..3..b.)..R.#....3q........IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 44 x 48, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1620
                                                                                                                                                                            Entropy (8bit):7.801361627421433
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:y/6nDZIGswiTaw1GdSET4w+r3RMMzXVetutVp6ipbIlSmdTKS:ySn+UP4wGMMzXVEut/6gElS+
                                                                                                                                                                            MD5:6432DED3B3287224306B81E0204B1515
                                                                                                                                                                            SHA1:4CED825AC86462D8004F80FEB0D771A8BAB89D0F
                                                                                                                                                                            SHA-256:41998FBE91B8B250B389D89D1AA80D5817E4F2D51CE929A7D89F37AE0093D8B5
                                                                                                                                                                            SHA-512:25AD6EA2105CDFE64D7153DCBC27F6EB64AD2565ABF378F6B8E0B7B8BDCADC8F370962B843714137720FC290CF41277ED612EB4660A209C67B1C7B44A4CAE486
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...,...0.....j.......pHYs.................sRGB.........gAMA......a.....IDATx..Ml.E....&.*M..qZ...R%..a.....VH......ZG...PW.=.!..*R..'.........:.R...I.TD,5j..`;..M.;...7..^..H.K....L~y~...1.}..c..}.f..6*.r..;..05sei-bw.....@..Q.\..<.X..........C...A!....m.!.<....=.y.h_<...D.\.A. .q.....oW5mcn.o$..{..]...^..q..p..4...O..5..D.(g.Cv-^.O....fLZ.6[...A.5.EN..............6(.<.~.d.a.Yt...nX5.-V].R....?......l...."...x..].......~..Qh^I....,....S...u.....b.4...Z.j\8......_........_.W..<^...e{..8.(I..r.PPa0...)<."h4....g.$..j(J.....-J.;x.+......6...V..V=sa.)..R:#.........[...^.>K.&..J.V.....=.ww...5[.L...&.".b.../..e..........iq...K.Y...K,d.'.,b..c....a.A.9Z.j.c.^X......]1.\{......y..C.O....8..px......(\L-f.=..0..x)....?......?.-..k.e\c3.7'.N"..'..]....9..K...5...95..k."<.....&.a.Z..w.>........Z....&_SL....B7..FD...0.)J.a.O7....*.Bd...oU+.|Z.di......^.@.s.TF....u9.+E.|f^.K....u..K..v..^....N.n`%Z..>ZYw=6v.g......Q..._l.gFS.Yl.O.1.~b.^...s..~d.I.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):249
                                                                                                                                                                            Entropy (8bit):6.533034399677308
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPZ2/6TsR/UxOffGpLpMvlvtJ/Iu2+jgDjp:6v/74/6Ts/1nGpLSvyuGZ
                                                                                                                                                                            MD5:2172007725790B2B7A52D88DF43625A2
                                                                                                                                                                            SHA1:56FD774395C97B8FBBF783A9BBEAF2D332252C4C
                                                                                                                                                                            SHA-256:7537D8C8ED8AA44DD86002D4B67E0E14033E2A55CCD174F71D4DC504EE2BA8B8
                                                                                                                                                                            SHA-512:23D3347A1944A66684C4B5E02DDDA1BD3C4B3AC43EE2E48E30010DF6C64C0F627D43B88D3F968BE499164B956A43C8EE439937B00E461643DB2287E4F96418E2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............w=.....pHYs.................sRGB.........gAMA......a.....IDATx..T... ..L.U....QWq.......L$..%&F.;..h.H).2f...\k.e..W..#n..}...|....,...N...@.M......f.!q.@1!T\....).-rh..>...!\.....^.K.....7...q....$......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 176 x 190, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):18923
                                                                                                                                                                            Entropy (8bit):7.9861701934335665
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:rRQZ43uKP67gxwrBM1vfj16druGvBBuf9aDGCdOGuQ0Xzu:lQ/KnnAJdy1aNdpuQ7
                                                                                                                                                                            MD5:414AABA2691D865AF446A88F56DB10BF
                                                                                                                                                                            SHA1:C7DE664C4AE999D4F31678C106C336A8AA12FEBE
                                                                                                                                                                            SHA-256:A7B0B6B5834C71BF51DEA60B92CDB84692D7082D219F2FD460DA8B06D761B088
                                                                                                                                                                            SHA-512:394AAFB7F371DF5A2456E4D1F478515099EA077E2EC3B3F749D1CF7E2EA1FF27BBF28DF369345D785A74D920A6829F2E11C27B380C94E175EA1221DF90638800
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.....................pHYs.................sRGB.........gAMA......a...I.IDATx..}..^Gqf.....i.dI^dI.....&..c..-,38.@&..`.!...pfB..L.,..@..$.93$.r.@0.Y..`..[.-.................."..x.....]]]..uuu..}.=..Ax..1...S.v.m.h>e<....9B]....y..h1+B...]OO#.Z<s..t..*....2.Z+..pBhF..`.J...1u....R..d.OQ+^..\...S.3..I..b....a....V2..%..G.L$..e0..d.'*(e*xA... ..k...:E.B.........h.).%].!..&.&...y...<.......R.....]....k..P...|.X.[KUZ+..@`....h..qJ.....(?...@...NF.u*..<......D.Q..OXn.2.^6.N...tQ.]<......}.7. ....~..!"....%-.....e9....sA/*'.5..D....]...r....i.TfQ.".).d....E.&@.x..l..'7..]......$....+..... .P..<....r..2.1..0.h......?... ....E.@..[.n..<..y#..,..Eg.$.2.F~.K-..^n.3..S..x./}YHD......8..FI.gB..l.5.,..lN..C...S...'F.P.....a..-.a.p..E'.I\y..5M.;..'.........+z$'..x.N$u.m.`.`...+aHY...yT...$...j...G....P...N.....&n.nA...*....5....Z.^(`..7P.|.@.:... .......P.).C...^...Nc...J.b.b.....z.<;Le.....).V=.0.2.0Z)...;...:?r.Z..&.Z.4&..:O....W..kh...u.k...+....,.k
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 176 x 210, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):21212
                                                                                                                                                                            Entropy (8bit):7.98325864342395
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:O2GbDyxp4nQlUyEOZgtE0QsuSBmaibS7oiFaRXrDaLr:9SDyL4nOT9imai+7qXin
                                                                                                                                                                            MD5:F1FBD29E2D0C3FAA510DA6A8397532DC
                                                                                                                                                                            SHA1:FF5237B7D22A08182534B9083ABEDC36C0D3E349
                                                                                                                                                                            SHA-256:7371BE7448704F7CFD6A8776482774791ECA122397006DC5841CE1D69436F065
                                                                                                                                                                            SHA-512:EE496EC6F940CCF236FE8F86B7BAC8A62698049F2F310103A6BC4DCFEC4D2B3244762B844231A0326DC42197E3C851A82BF1E9E5D87A26B8EE7C5F686E4A2AD4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............J.....pHYs.................sRGB.........gAMA......a...RqIDATx....&.q.........f03.\.....^0.r%..D....k.&W.k.%..*V.7.P...I.+.....r7(KdH..eY.LZ.@..M..A.$.......s..w.?...U......;f...3.............:...!c. ^....R..g\.ri.....X..%..h%.B.....N%.F<.....X.~..\.^j.s...... ....q.:..IY).:YM....xM...L.......O.a]j.y..^.D..H..$........D.L..^..4>....8O......#B.y.8Z|JF.W....I.I.oD...2O...!3..)G.a.....J.|.(YCB>.,..*...f 0.|Xj4t..{.....!iQ~ i{.(...':......<.:H3B...$KezBs#.i.gc. .A.=...A.rF....cP.~C.|..!"...%}>..2m.2.y.,....B...."0.<....]...r`R}..%Oe..W.5e.....(....O...(..M(AW8..T.<.@z.......A..B9.....w/.IMx&4....!..r*.0&..t...8oe.j8...".>{...8<m.R..(.].Ss...O..5.+yx.rC>..q.....|HD......8.XGI.g..r.F...<X..<.....BL..B...C.&....#O.C...NQ.h$<.{^deM...A.I.e.c..r....|$..Ny.F$....r..)....C.E.P.F..hL.|..F.+y.PzW.....I.<#.....[.!...DCGe.,,T........TU.7#....5..0.<`(..E.r<...*...j.4F..u......Z8.e...T....."h5C..!........j...#.Uy.dY..D....7I.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 176 x 133, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):13412
                                                                                                                                                                            Entropy (8bit):7.975594232205093
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:w0HE4jJ0oyx9ehCCmVEKtChcK6pRhXUPFLe1iU:5P0o00Ej8cdnCluP
                                                                                                                                                                            MD5:12187FBB7EC8ADA4E6334B2297D78A6B
                                                                                                                                                                            SHA1:9155356FDC70C7BB4C60950ADC4EF55BEE023B6F
                                                                                                                                                                            SHA-256:05D775AC7CC5F970FA2A0DFF5A1F732B8DC43241F789242C17E39F4CF9AB39FC
                                                                                                                                                                            SHA-512:55920F35FDA8F19C2372439774DED2B8E7EC61360DB81C8DB78B2A2F75F9FD10556203067E129F4D52F3BD1C9DD2B28788A12853DA15EEC9C2C18086FD68CC0B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............r@....pHYs.................sRGB.........gAMA......a...3.IDATx..}....u........;......H..D..-n.DK".."Y...P.*.TRN....8..*;.Sv.E.n)v,Q.(J"...Iq_.. @.............g...x.p...L/.ow..}.v.<..s..DH-......>..E...}....Q$....+K.....n.%..+<.N>~\...7.}.S..oV[.rx.@<..>.....R.Gy../H.Y..4.g..PTD.Ne.:.t=J:.W)...G*_nN..(1...$\Iym0.2..By..G.4.._H..."$4N.........D.t..Dg..U\..'.....f.D..rEN.".8.A@....]......$,..xheH.)..S.N@j..........x.b...kT....#.`............^...J.......c.u:.(/..^.Z.+G./.........QR.:..*...H.6....ld\.%1../.{]P.........D&..S.P$...u...T.2@.$r....<.j...t.R...t...I."%.9..e..!H=......'.-....y`.5[...L.B..... QI....6....uX*..`..}\.Ga...5..4,...2..?.<.K.B,.0...._..............N[.+R.-..!mc.mA.N$r......Ny.MD.O.K.1.O....G.t}.L\P.g...F.f{..S.E...d0..)......R*.-.I2'..HN#...@0.f:.A..lm.R......?y...u.w..e.d6.)..'..w. ..EH..>c .($..V.$...g.R.1..Vf...a%.!O.&.l.x.q...............>......J..\....9+.||.%...d..1#...).,<p..../..X$cVX......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3166
                                                                                                                                                                            Entropy (8bit):7.890916051269147
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:b/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODx7FspC:bSDZ/I09Da01l+gmkyTt6Hk8nT3KC
                                                                                                                                                                            MD5:2048DF489A12C4C9E2341BEF42883205
                                                                                                                                                                            SHA1:281863D9F8B8D4D0DAD62E66E35F5C96CA0155FD
                                                                                                                                                                            SHA-256:DDA74B071B5869A22B327633D9641F1340EC5B913359BB389C34C44A6DB579A5
                                                                                                                                                                            SHA-512:815FC1E3A2E623FEA3B13AA2BCB3895FF9DDB2A7A05E1633C83D3F647EC4A4050AF0670ED01CABA47F02A920BF6AD84191B0B03EAD1E45105DD20D302D00CCE2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR................a....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 28 x 29, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):16099
                                                                                                                                                                            Entropy (8bit):2.1119107535632073
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:R/6qMh8k29WJsEv+jJ/Zf9lnkouuJvBLD1LpKLxN+Y9rNGcfNGvsc5jq7LcQEdBp:RSB8kEWmjtZCxNXrNGQNGvsc5sx0
                                                                                                                                                                            MD5:FE56C156669CA636CE71E5D23D9C685E
                                                                                                                                                                            SHA1:6EF641E2CEDB274F9CE2AA2037697372C49CCA25
                                                                                                                                                                            SHA-256:CD48CA4C27625C9286738652535097FCD7406C709371D85AD8297F8FEA19FF32
                                                                                                                                                                            SHA-512:B82ADD72111983CAB0DB650F3D12D11E3E2CCC9681DB18484F2219EC4A8AD7F4E5BFEDEFBEE4362CD7CA03A17A025EA1E54E566AD2C458C1221F6EADAD099D62
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............Q.1....pHYs...............<AiTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c138 79.159824, 2016/09/14-01:09:01 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmp:CreatorTool>Adobe Photoshop CC 2017 (Windows)</xmp:CreatorTool>. <xmp:CreateDate>2017-05-31T16:18:28-07:00</xmp:CreateDate>. <
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 541 x 82, 8-bit/color RGB, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6612
                                                                                                                                                                            Entropy (8bit):7.943206975174219
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:jSDZ/I09Da01l+gmkyTt6Hk8nTMVKh4rpfjDXliiulxWYwu4vw3eP29VIaUz:jSDS0tKg9E05TMq4Nf4QYw43v9V2
                                                                                                                                                                            MD5:13029396423BD78CCCBB0223EA143844
                                                                                                                                                                            SHA1:D23C69FE2AFA8469C06CD31FC8FF077B415EABC8
                                                                                                                                                                            SHA-256:9979AC854DABCBFFED54312E8EC33B5C0402E220E100E47F0A22852EC695F248
                                                                                                                                                                            SHA-512:32D34F2FF23DDF24D387D8A3B8A4B1D9258F525B785807466D9FD88A4097C288F0FC89E6B1C5A010F51E5C92F6941189404E194D9A3A85978F77418AA53AB85D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.......R........ ....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (32132), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):93205
                                                                                                                                                                            Entropy (8bit):5.288138808574008
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:fYcvR3VhH37Ha7EmakRhIHASkCDy08otU6myJXXxMZyYk0AjrzCqlKDo9YhnaTd4:fY8MaW2c+UELKUqnAdit
                                                                                                                                                                            MD5:15B82CF59C00E4671D2995CF6376F964
                                                                                                                                                                            SHA1:04B90ED14478B954002E1561AC3CE3063BE75BF2
                                                                                                                                                                            SHA-256:C2714DDC6328A8938937CEDB86849CE5B98575120E73041D8FE802324893F734
                                                                                                                                                                            SHA-512:B5CD7CAD33A92445750C5D5AEBB38B52BAC9B2F278FF103A9370809213D71ED39F995EF4810951DBA05040DC344B036FB0FCD68BECF0D0FEFA83B7B6A4B0336B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! jQuery v1.9.0 | (c) 2005, 2012 jQuery Foundation, Inc. | jquery.org/license */(function(e,t){"use strict";function n(e){var t=e.length,n=st.type(e);return st.isWindow(e)?!1:1===e.nodeType&&t?!0:"array"===n||"function"!==n&&(0===t||"number"==typeof t&&t>0&&t-1 in e)}function r(e){var t=Tt[e]={};return st.each(e.match(lt)||[],function(e,n){t[n]=!0}),t}function i(e,n,r,i){if(st.acceptData(e)){var o,a,s=st.expando,u="string"==typeof n,l=e.nodeType,c=l?st.cache:e,f=l?e[s]:e[s]&&s;if(f&&c[f]&&(i||c[f].data)||!u||r!==t)return f||(l?e[s]=f=K.pop()||st.guid++:f=s),c[f]||(c[f]={},l||(c[f].toJSON=st.noop)),("object"==typeof n||"function"==typeof n)&&(i?c[f]=st.extend(c[f],n):c[f].data=st.extend(c[f].data,n)),o=c[f],i||(o.data||(o.data={}),o=o.data),r!==t&&(o[st.camelCase(n)]=r),u?(a=o[n],null==a&&(a=o[st.camelCase(n)])):a=o,a}}function o(e,t,n){if(st.acceptData(e)){var r,i,o,a=e.nodeType,u=a?st.cache:e,l=a?e[st.expando]:st.expando;if(u[l]){if(t&&(r=n?u[l]:u[l].data)){st.isArray(t)?t=t.concat(
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 176 x 150, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):14533
                                                                                                                                                                            Entropy (8bit):7.978234763785096
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:vbRTZyLGqlTGW2+6E7JfwA1fKUCYhVwKqpU:jRTZyKK6E7T1SUCYhVwA
                                                                                                                                                                            MD5:AD6E786595C48812BE2D9BC7FE5D1485
                                                                                                                                                                            SHA1:E98E3B2DFA4354754EC58188D88F6687DC239E22
                                                                                                                                                                            SHA-256:4715BA3F13FB3554D64542BA93605E87DDB8601301F2C15B9CD65B708FFFEE57
                                                                                                                                                                            SHA-512:2C0735D80841CEA8CE8F4816E9548B5A9474530781B1510A1FB72951EB36679B43F4ED86025CB9C5B8E2E81432B356D3466ED5FFE5A783773A77B142253BB0B6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............~B.u....pHYs.................sRGB.........gAMA......a...8ZIDATx..}y.^Gu...M.V..kiY.dk.!v,..bl.c...c.....@&..0......rfB.29.....5... $..c[F.dc.,.R.%..t.....^U.......^..}.~..u..{..u.V...S..r...c../Mu..n..Z.8..@.......b5..Q=/.O.\t....r.TS.|.1......... ....`.J.s....~....$+...U.V./O..kf..t.g.*...x....J2.i.y.G..#...d.Z.5.(......K...o..4n.W....#G.>.<....'_.!.].P.P..*.._..=.ya...o..`0q...zd..T..f...7TXci.d6....1....9......._.p..9.i0......*....:..%.D.Q)-...e.u3.y,..:...<.VW_g..].....o.U_.n\C..8.kI...l..ux.Y01....WJ.q.Q.I&....C...J )..T....<.....v..b.u0..qv[.s0An.;..tC...S:.:XzB_G]....O.tc..1C!.....Ly.I.a.~xts.A.%.{....4...ln.g.)..........=y..@...:..QQ.]i...0....p........5K.xxTE.:.}...q|...pq.SSSX...5.Wa...hin...)N.p..G]H..O..j.F+.<@..x......F.}.[.F...2-...%...=hmiv...$f..a.4bI+...C;.L.6.iM.....G.......DH.}QO....|.Y..|.i.Y.....x.......e..:.eZ:t..p&,U..KL...AM.iw..7...T....t..\oy..2%.!..!.p(V... ..X. V......).,.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:GIF image data, version 89a, 200 x 200
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):61451
                                                                                                                                                                            Entropy (8bit):7.343059446968563
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:9fvs6a/gxRWNtTA4EOvbc51qb0zFy/Sc6mS8oyYVX3YeP8XFWZLNCih:9fkj8RWNtTA4EOzc3lBl58AdNCih
                                                                                                                                                                            MD5:CBE8A62A079FCC257A6334A506A865A1
                                                                                                                                                                            SHA1:B0135BD4B9A31BC7105111213C286FB3C06DEA7D
                                                                                                                                                                            SHA-256:3A0F2212D503E07BE1246CFEBBBDEB40B642A44B4A3DEB959DFF78063A9822E0
                                                                                                                                                                            SHA-512:C7AD87184B524C5908E9832675188DEC751484C849020031F91E5030AFA94AECEEB2DF3777657533947339A48A96A24C21D22D29C4A51C75BBF6000634993A05
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:GIF89a...........2/.50.4/.4/.4/.4/.4/.4/.4/.61.>9.E@.HC.HC.HC.HC.ID.ID.ID.LH.UP.[W.]X.]Y.]Y.]Y.]Y.]Y.b^.jf.nk.pl.pm.pm.pm.qn.qn.ro.ur.yv.~{..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!..NETSCAPE2.0.....!.......,............[..H......*\....#J.H....3j.... C..I...(S.\...0c.I...8s.....@...J...H.*]...P.J.J...X.j....`..K...h..x...W..[Un[.u..j...}.J.,.*..N.#f.x....B..RF...;..x...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):343
                                                                                                                                                                            Entropy (8bit):6.9403490183632535
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPUp/6TsR/N7FDkQp+Fj4zBeQzdHLqOkNTcvKMK5iloCQl53fHKxgjTfv6Rp:6v/7Q/6Ts/N7tWAHdETeKMKsoCc53v/+
                                                                                                                                                                            MD5:37F342F2D1658BF871B235B20CC254B5
                                                                                                                                                                            SHA1:137F20C7685717B19BB089041AA03FA001601D09
                                                                                                                                                                            SHA-256:432AF358A422B668D90A9B05D2329922BA20DE2E24F419232967601E7B8E77E7
                                                                                                                                                                            SHA-512:B20465A790529F063309426AB878CD67823EA40FC5B464C5ABE2DCD7A26721FB57D26BCFADDED47CE584E0F575CC0FF922C29DA2DF6B8A18AECD567B678B5DDB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.....................pHYs.................sRGB.........gAMA......a.....IDATx.....0..[....n...&8.n .8....t...6...;...[z..../5..g(9.B..5....5..7..K...fk.....D.......~.b..'Od.B_..%....P.T.(Y`......i!.....\...l.F$....l...=.ab}.;.f......N..Y.K...ffy.(.g.....,.<.M..2..Gdio?..A.W.~w.....5...:S...S....3.Z.......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 7 x 7, 8-bit colormap, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):535
                                                                                                                                                                            Entropy (8bit):6.070255751604191
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7nsXUyptiPCC0turztDt5q8j1Age/6TZ+RyxtWcHzSoLiKEMBLKBd:YynOf0tiztDt4yxe/6oE8cHzhmKEMBWn
                                                                                                                                                                            MD5:78118351597A04AE4CC8D899475BBA49
                                                                                                                                                                            SHA1:3EED037A8879EC6F84C2545CBC3D710494C2FF88
                                                                                                                                                                            SHA-256:D9059CE8A29D6CE4FB46BBC2292EFCA3478FB5D2DF106B33D4A37B50E41FEC39
                                                                                                                                                                            SHA-512:DB64A010162385441800F0CF0212C68791447EB5361793389BC632B7B14E15EEA3CE7DDA89987EBF7414334022FC64FBB1002816532EA106F0CD873D109A1081
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...................gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....PLTE[y.^y.^y.]y.`w.]y.g|.[x.ez.^y.To.\y.]x.]y.]y.Zx.\y.]y.^z.]y.]y.Hu.\y.]y.]x.]y.]y.]y.\x.]y.]y.]y.\y.]y.]y.]y.]y.]y.^z.]y.]y.]y.^z.]y...........,tRNS.............a}.C...l.3.>...=B. i.S.U-.`e<..*.>....bKGD,..q.....pHYs.................tIME......9.3.....@IDAT..c...g`..d.......``.....af`a...gcg`V.VTR.`PPQ.TSWe.........aa. .......%tEXtdate:create.2022-02-16T17:16:42+00:00.v\^...%tEXtdate:modify.2022-02-16T17:16:42+00:00.+......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 110 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1542
                                                                                                                                                                            Entropy (8bit):7.83009227115315
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:p/6xpdQeP1E+SD3r7bJsdU70sEDNdQ8Cxc:pSJ31UbLLDEMo
                                                                                                                                                                            MD5:66016348184FBD87A9732F55FF570A7E
                                                                                                                                                                            SHA1:DBF5CF9A220FFBA7513BB85A7008A292FCF2B8DF
                                                                                                                                                                            SHA-256:BA8A9DF4C31C08AD40EB4A81DEF7C41707350BCDD43718159884592E071446C2
                                                                                                                                                                            SHA-512:2939A8037E7824AB4603BF2C1C75A3F9A909C9CA559EF18EA535090C6D50EEF79AC3FF97D6FB52D3037481C94A488C217091EFDBDFB95B701AA4415F5FA92C72
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...n.........l..\....pHYs.................sRGB.........gAMA......a.....IDATx..YQr.H....@.........'.t..'0>@....'.>....=.....X.H.....U......A....._...M...._w.E.l.%.?..hC..MO.]A....Ctt4.]SI..>.m.....o.)/..)....t.L.Ng..A&"!"..5......Jl.-....[e......|.\.t'h4.!......+.s..R..A.r.~.^......--sH........]........8,.l..r.......B.."f9P..W..n}..=....{.1.@|...@..7N.r,.h...i{..'..I...x=.^..A...6q..~.E...g..=UT.....W..._KT*-......ND.....R~^'....j.2...!....B......w..=........8|(..u.r.E5.RF..r...L.d...Ow..S...M.2.....Dp...C.X.e~.....D..u.h...Y}.q.XI9EQ8..".#....'zsv.8........N..hV2.....e^.9UN&.V.X.3..I..F....)K............oLG...x.x..X.Kf...g..XV...G.+W....9..i].....B.K..1{.j.S..i...M..X....pl.....6..%;..mNG...K..C.8........Y.7...r.;0>P).:Z<c...9.....b8<.{d.:-.Pt.u..U....AZ...G..{.r..._.....M&m>....d.O)d{).A...Xr\...s.Ir..E..8...R..G......^...io.>...C..|lPc@.S.2Z.@.`.v....F.u.%r....F.sj...I\.paQ......|.;.c.i..)}.S4..K.DvQ.p...sfY..0*..v.M)w]..I;.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 87 x 18, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1559
                                                                                                                                                                            Entropy (8bit):7.837839289025892
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:s/6yUlzHLuHwW1nx0MX/pET0ltUxHPJH3jT2M0wlH2s3R3LqyT7UFStz:s/6yOLP6vX/w0YlPRT2M0wlHfLjYstz
                                                                                                                                                                            MD5:FA83BC8E14C9D2734DDBE84015E5BF3A
                                                                                                                                                                            SHA1:2A863213DC1905FE82EFE6B1A5C4A039A34569B7
                                                                                                                                                                            SHA-256:89F1D402046412A2921E41B0C4660DFCC9EE8C126EE8852CEE8B450038836B2F
                                                                                                                                                                            SHA-512:3EEF9CC44509E74A4147BE230A372FC5E29E7A8AC85BB08B03FC584D9AEDECDBCB609208BA8951802FC770F70CA570159AC693C8BDF3F1EA2EC9F1F160A694C2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...W..........]B.....pHYs.................sRGB.........gAMA......a.....IDATx..X.j.G.>g....Mb.J6.&..(O....^Y~..O.]...].-...V. .U..$?A..........hd...v...=.^....\...F.g..|..9g.?.]....;..}..eD'.V,.'&..(.......MO/..J........8.7.o.6..h..4Y...T'.....MO...1.,....I.....f..yqr.?.s..../e.lIeo.B...7.&....P.bSel".Y..y..a..:+@*>g....B.j.E.X....l..;t.h.A.vw..FhbHq.*Z.KH2WA.:H^...@...>.p...:{,...d.M..^.$......-M..Gp.S..).\.r.........#.Q...Z...1..g...(!...'.7_m.C.T:=....8.....R........%%..@...q...1....0.}.?....H......)..5Q..x........i.8.$...i84J...&.lr..).....U@..H..eaq,..k..P....h...b.Ur......-gN....7..OPd.=rt.)\E7.kC8#.IN..}.7ol.i..%...\.=......hMy...t..i.#.........$..r...n..2 %.zG.@.B[=...;.....K....<b.#C.B.B........K...^.B....!...V.mw.M...d...R+.\.......t.. ..i..13.b(}.!#..6.B..qH.cn....Z.....E#[%..........P.06....B...3......;ba!...-.w=!.\......w.....&.....T,.:...i...Q.k.~..w^..S.....'.P.<.G....G<14.`.p.D7..u...#.:e 7..L..9V....r*.\R..g...Ml0d.d.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1434
                                                                                                                                                                            Entropy (8bit):7.812188474968883
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:gB/6FZKjUohZU/XCYVDr/K62aGThNbG+NetmhomQlgLCSX5wi:gB/62Y8qr/K621ThUWe0hongZpj
                                                                                                                                                                            MD5:C564D03DCC373E6C01F4A0C8AEBDB30E
                                                                                                                                                                            SHA1:0B8065753F23EC09CD5F4B0232631C687F4DFD27
                                                                                                                                                                            SHA-256:1C7DA56A2BDE70E1CB265DBB8E8B04AB02D88B62A9BBF056A35F788D8D875993
                                                                                                                                                                            SHA-512:04AFEFF007F2F5098B8B28D3B4DAAE07DA8467B3ACA73AA838AD5DC3EED2AF4088D48CB20B02213F948686A34EEB3A3C6EA5384FAD59E58B876E7F63ACFB5FAE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...Y.........0.r.....pHYs.................sRGB.........gAMA......a..../IDATx..X.q.:.^..rc.I...P..+0Y..+.]..."U`...U...Q.D....2V.Cx3g2..-.R MJ..39xgh...X|..aa1.v#At..F.r....1.......?O...^.z..]....F[.?..<......g......\*..H.......w.]..#.0.7q..V..fd..@g.B.K.<.I...@g....<.bg....?....B.K..MW..........[.n.Y.Z..;(>:....h7..?.v_.;x>8....u-.....(jR....^...p.....|g.#...v@{.G.....dzP.jZ..l...:ET.....FT.L....?.{...]..7......Z-........^.L+.9..K. '...........pT.....6).8.5;..?5mUu.....U.+s8...<...y~.~..(uAG...kT..d..t..!.b...7....].....N......C....I[2...Y...;.su..u..o.......N~Y.....>)V...)'u...f.'O...N...5..ez..$......:'..0..AG...q.\^...&..#7r..^....@...|.XS....#I.QwpT.......@...}..Q.{.no....v._..\[.#*.E.....[.~.6.]_....eD?/...........<.h.~#kh.P.+eHY.T.#p....'.`Z2Q.....|......l.(...Y....c>....j...&..i..E.A6...<.ZA.....n,../J.Z.p..'...:c....R_...e..~.t.~_.)..:Z...usTY....c..P.^.x......C.........X...W.H..y..)2.N...:Z..0ux.6........k@f...:u.....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 112 x 22, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1940
                                                                                                                                                                            Entropy (8bit):7.870572433344458
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:XC/6ajsovRkZHy/em1P2FGb2bQ3t/3NJ4BNofx6yRQG4R:SSagovk+emwqQYbJIo0yRYR
                                                                                                                                                                            MD5:2E6E7984268E9D344B13491198D160B0
                                                                                                                                                                            SHA1:E88EED75E8E8CA8A2458761B561927B6DABB8C00
                                                                                                                                                                            SHA-256:3EF3E4739C30F116531F7B40BD0E14D3A487C3F28C27B52C47EB04D8AB0B9C5F
                                                                                                                                                                            SHA-512:E60EE5CE3183AEE8C157CFD0922F9310103F0B291254897FE504AC0F10C440F3F7D3A32AED6383E8AD63D4414BD8E27A0C773929B63012D9CEB792445FE5EDC8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...p..........M......pHYs.................sRGB.........gAMA......a....)IDATx..Y.n.G.>3.`T.\..6\d....d...O.y..U.6.5Hq..........^...^d..8i......~gw.....M....I.fg...3.9gFx.R[.5.:......t.J.<...2..V....mT:..N.v....]...,."../Ju..Q...v..k.....kB..$.<..s[.z...?.H.\L..E.bb..6.a2.._-.4{}W..M......._....e..W.q.!...!`H[x8....W.L.7dqD>....R..O.S).!...S.,pR.Pq.....wI.".d.M...bm.X\..y...f..:.`7{.e..*RH*.,.X.R...1.P.*...XD...2...]..{..S.S..V.5/.H*6.2eb..Xg.v....3...b..G.\5.|v;X.7.b..C.....R....LJ]..*...\..{..]:[....^../....Z..x2...M.]....jM..l.I....&4qF.bM.v:L.vE.'.Y.h0.."S...y93...W..;.........s......4C..H.t....n...((p.4k.5/.}V4..HF!8 a.k.........nr.r.j......CY.b.d.....H&.Y3f.$.4.J.Z....w{=6r..l.o.....V_>.?.'...x..b..zY..J....h...Ay/..s....o..*.I..c;s.\^..^4...U9...r$..\....l..m...1..6..q.........+.Y.V ;....|'.d...b.=..]....4Pj...BK..X..&..I......L_.m.`f..iQT... .....&.ou.0.'....c..;.=..t.c|f).....i01&R..7oZx..B.?.}....J3 .KTD..A!O<.....jJ..,cA.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 86 x 17, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2238
                                                                                                                                                                            Entropy (8bit):7.897965521812157
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:a/3bdLf7SAa7meAyze8p8XMnkL4NpP+Tl1TcVhCx4:qLddUJAyzVZnkLu6lF8hCx4
                                                                                                                                                                            MD5:2B2ED7BD7CD047459628DC4AE1728E85
                                                                                                                                                                            SHA1:F8F4933BEE5717D3CC67704F863896258EC023E1
                                                                                                                                                                            SHA-256:1DB0EC3C7FFD1C9DDEB5F0E4217C1EF38EB02700E4A7F3A557D1F052092D4E42
                                                                                                                                                                            SHA-512:B3CE912074BDE9758A93B18C6478AEB689A0AAEBC5F9D228A5C95F045C0BA24963FC7F32EC1E1BC93D50890132D3B1515247C9ED3DEFD99F517752A23BA7EAB5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...V.........G.[#....gAMA......a....uIDATX..X{p.W.....4,y.y.n..S..U.E.I`j....X..-.j..Gk.U..QFl-.p..V.Ne.hU..PBv.yF.....iI..I.$......../,.M........s..{..>vbAa...Tg.1....j-......R..M.?v..Vk..V..<.........y...t..%W|A.v..v..t:.......i........-.xud.!...\A.M.X.e...?0.7.w5..9......=1........~../#.wD(4.d./...-|..V...<f./l.Z..:..j].H.8..P...q....YZ....jsg-..I;'UqBJY....!.L..:......g.,.#W.4..y..f......=..<..B.......|..<..L.....G.uR.z.L..?L..H..al......W...4.3.......La..}.t_.".j.p.;.....'"..]yy5.... ......=.Q....QH.R...TU.I....f.......v{.V...?.{.......D,....}..b2..6.......^....nf""...\|.............w..J.i.W3!j....JCd...e[....$.U.F,OH.8....f.v.....z)z'.../...`8Pb....`xf.........^.7..`.K..}.c.S..7/z..Q..e.!9./..o..`.7.....v.$.'..X.v....v..".B._0Z.F..#......S]O..:.r.N.X..m...........Dx.....]....s"Bt.6.<..F.o+.z......B|..5DC..).,..y.0L.X.5$.Mh+.\].....Xq...~`..8..;YQ..t.{&....H.l.b..3..@(...#r..,......-...,..#..,......C7..6~.h
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 86 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1201
                                                                                                                                                                            Entropy (8bit):7.763272753991154
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:8B/659eWA6XuELEiVKshz96Ajxbd/ErBYPwxhYvjtcFpcG69X7VSkHVs6Lb:8B/63VXuELESZPxbSVYPwUvBcFpc1Dpb
                                                                                                                                                                            MD5:A624A806CD38AA64130A0C228271DE75
                                                                                                                                                                            SHA1:118201F6A512D67C5EE112CD0A0C4EBD5C66FAD5
                                                                                                                                                                            SHA-256:A6E96121FE3D151FAFF5B247F926F93D27790250F9E2A27BAAF841DF5D82B6E1
                                                                                                                                                                            SHA-512:D8C08C245A6F68FFC058D2571567034229EBB96A595B17469FC7B6E26F6BF47FDF34C2527B5800667790F88648CAE8C7F262677E53CCB713968A6C03B0D54FE8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...V..........W......pHYs.................sRGB.........gAMA......a....FIDATx..X.Q.J.n..b}["x"....dNr.."@....$"."...8.t.]>`G.2.n..w..t.j....v.@W.4......L.]..,......&.'TUGdL.|.r.....N@.XJ'.BL).&(........A...L. ...,...d|...`0,...8T...EQl.PU?.A...!..aZCL.w....^.....v ...xUuI,3.1......s.1....g.uj.#Z..A.Q...^.9ww).....Jz.....-..d....k...C.m.=3(....rc.'.avwKM.u!........%.._..;4,X.}vbh.r..s.W.4..o.3*.n.B...i{_..Z...7..}e.Q.\n.j2j}.T@"O....Z.B.....b/..l.[.....G..3d...&....AS.UG5..Q..)e..<.5....|...O....g..b#..Mb.B.s.t.........R..;.1o..`..[.a.,d`E.....9.oT.........9..}....Y....Vf. i.3.. .....]..&.)...S8..u.(u0.N|.....+.(........:.0.m<p(.[...X.P....`Hu....!..c...).Bw..|.F<".7..;..........fT.......|..P.........|..-l.E.Y....E....L....e........V.W.]....~\...j.a..8...G4J..uC....(.....W6.....\..FDk..1...n.. Z...:....C;.F...jvbp.).....n...r...w<.j.Z....Q..|...u....8e.(.M.,B...E'&1............._`..../....6'...VU.....amZ....E..;...Y....S..(..B.m..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 67 x 57, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2052
                                                                                                                                                                            Entropy (8bit):7.890065571351557
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CHjblGYXQQEZZyIOrNK6rC4lWVkOjKpgOojQ9dCe2LfmC:PYgNZKJKSC4YF+WjyOZ
                                                                                                                                                                            MD5:18344204EC04F1E95E086D3BC94FA0FD
                                                                                                                                                                            SHA1:87CA3ED8948774091B451F7CB2F95139E56D351B
                                                                                                                                                                            SHA-256:30ADF46FD9311E5C6DFEA8A2AB2176EBAF83E7019EE341896FC3AAA5F498D2BA
                                                                                                                                                                            SHA-512:13757DC62505D01E44523823F38001D28A2FB9CBA5ACBF9CB7D9BDD8D0F19583D814E5A47B2DB255E18CCC05C34D43A02C387B60D05D1E802F9AF527D3633C5E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...C...9.....ms......gAMA......a.....IDATh...l.........|u...4q....T$....IHK.u.h...lS..{.....i.6..h....@PX[.&...AH.&.($E.(.R..).......M..:..}.g.M.8.c3.'........{....}.``....q.. 0..b.=B..?.:t......1..P_f5.......).7\..e..Y.gA.......XPL...Hss. .ks..... ..aPx;|VO..{{{).`"...VAb....u.|..>_..#......2>V......9.g ....<Bss.T....LFI[[..+%.Y.....N...~X.!......h.q.J.l...A.s...p8,.|.K2..'.{.j..c.<.|m..<.....'.K....zF...nu..<...\.a#U.Q.a#`..ZF%`...6..=j{ta...ax.....\.<.H....<>.'...x......./n..g..'G.z.E.|.....(H~)2...U..O.?w...u.X{..j.v.D.M...z.9.|.a.......\v..f..0....0..1Xs..p&5.C.?....XY.~...K...p.._.+.*...KEF......5V.f....l.u...N..../o....t....b.......z.).....v............f......L.:.n+..s>.r0l.i..&.u...1.J)..sk0l.j0j0l.l....C.......*3Q#..7.......f.[..&).r.z..0..^Xs...z.-`....3..........{N.e...g...O..~[A.F...."....E.d|..?.8S.........}.|;.......>u..B.....Y Z.w.....W..:...Z+.r....+...7..._..b..........~.a..w..o........0.J...[.d...W..>...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7205
                                                                                                                                                                            Entropy (8bit):7.9471260512499375
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:KS4Do1RyFyKSZ4pTSumpAO/Ap6CQU9Uw/JLO/xvifnL:F4E1RCFpWumX/Ap2UeMq/xGL
                                                                                                                                                                            MD5:F2E3045621ADE164E9DA40F294BEB00C
                                                                                                                                                                            SHA1:36E9D967C679FC898BED1FF6751A73BB863EAF79
                                                                                                                                                                            SHA-256:D820CF499FC4A9453771A23209A6C63DDD2CE3439E8B651A98DDF0C36ED2BDA5
                                                                                                                                                                            SHA-512:7E515A44BD63B33881EE86E0A911897138F2BA0A6E81925612EAF19E3EDAC5A9FDCEDE30E3AFF3E906A4BBA8AA4570E06308D75783057015C882C7E62A880928
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...`...`......w8....gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....bKGD..............pHYs.................tIME......'..l.....IDATx..y.\U..?......./.@@....E&..P..GF.Q.F.....#..T..........D4.AC....b. +![w..NuU/.....q.z!.ToI@..SIW.s..}.y..s.U..?g.D?`..._T.(..}.n.I.w"+_..r0}y,.....`&....P......8.,....n.I..c@.4._....]@.J..UL.....A...[K........[.-...A.....g.'.N........#.l`.p'.d..o.@@T.P..tQ.A..........t..q`5.=...B.(Q.).."..`1j..&..n....}..e..].....-...x]..p%d.(,............g....o.C......p.j ..W~tW.3.]mq ...H.Q.P..-...Q2...v..O(..`...8....?.4...A..}#K...m......|-.....w.2.m..lwL....Ys..y.;..\.Q ..p..e....B'p..........^@m.c\..[..Z!v....*a5...T#R..B8YH|.....iw...8......,f.v......i`..:T.!F.\....t"5....0..._..K ...M.`.8d.5.9.x.c.v.A...Ug...Va.d.?..M]B.U..E.E.....: . .B5.B.1."......>...w7.-....@.P.;.d.LUp.D.0..R..TE......k..K[.>o...?.~....i..}bu...6......Pj.g.U..~'..+.|.F'......y..t.p..0.6 ........E.).n`...3\-D.......^~6..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):285478
                                                                                                                                                                            Entropy (8bit):2.4849077310090886
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:gtOQaZJ9Lhsvel7gsxdrTr8M4JnGirZTiAF9EOoRoQoPEgyY7oooxro:SOQaZJsvel7gaWNVx4AF9EOg5O7BAro
                                                                                                                                                                            MD5:F7D9142AC3C0C7228507E927D05F9727
                                                                                                                                                                            SHA1:7B8C9829534DF5B2BAAC806141F72B0AFDCB03A3
                                                                                                                                                                            SHA-256:F91461D2F81839CB58DA4A9FACA47C51352558BB636C522F9272519F7D910E61
                                                                                                                                                                            SHA-512:5C53D7B6496CFC4A855A7CA9F95D2F127139CCB812610F74790867F056EC48A4F3A6F2CB95574FCF0AE027B9B3497F0D80B1FF235828EA66C92D18603081E725
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:............ .h...F... .... .........00.... ..%..V......... .( ...:..(....... ..... ....................................................B......t...t:...........................................V..............u...t...t...tN..t........................j......................u...u...u...u...t...t`..t....................................h..tp..t...u...u...u...u...t............................T..............t...t^..t...u...u...t...................................................t...t...u...t.......................................................t...u...t.......................................................t...u...t.......................................................t...u...t...................................."..t...............t...u...t............................2..........t...t...t*......t...u...t.......................................u...u...t...t...t...u...t.......................................t...u...u...u...u...u...t................................z......t...t...t...u...u...u...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 15 x 15, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):195
                                                                                                                                                                            Entropy (8bit):6.068066723651005
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3:yionv//thPlJlawvlkV42/uDlhlp8Lts7CX9/Bxdzo1i9MsN2ocx1PmnCCj1vkxz:6v/lhP70wS7/6TsR/Dvo1oiPOnuMwkup
                                                                                                                                                                            MD5:DC1EB36132B94A110553E31FB69B06C3
                                                                                                                                                                            SHA1:B5E281F185E2A7159B4E1EE74C27FA31E00EDA03
                                                                                                                                                                            SHA-256:237B2E4C1D42366B7EC89852F5C43C7D12C961D2A8990A87FE5CAC827C6C2FC2
                                                                                                                                                                            SHA-512:3E51E41E82D903AC06A911CEB70861F49F682E6F22AB6EE07DE8FE4B351CF255F9D95FAAE7282C516C9226E56C6B7C8DF87135F0E7AC699F7179B4D176234E29
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............;.J....pHYs.................sRGB.........gAMA......a....XIDATx.....0.......A..9.....Y. .Kr..T..[W|@.]C>.q...bE.I.s..........TL*..V,.E.q......X......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:MS Windows icon resource - 9 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):334740
                                                                                                                                                                            Entropy (8bit):5.49770045405099
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:vYW4/fFn7A4xnC0IzntmbG8B7doDbtYdLVYRWns6yC:vJCffC0Izntm6S7QbKDYInKC
                                                                                                                                                                            MD5:83923FAC3D4E58231B7527BDFACA2794
                                                                                                                                                                            SHA1:492C8D0F08203EB28A2999895B1B5994F51F630B
                                                                                                                                                                            SHA-256:B6E7BDFA89B2445E120C0583BF97EFA915DFD43BB02CB129C2D9267AAF3BA618
                                                                                                                                                                            SHA-512:A8A5B976417B19313C2939BD2BAFD9FB918A1F413713259C120A296BEA00B49D36CFFA1DE25A9C58D2987007FC9BBD4AE8D198C7D37448080C8E34D8EEDEFE54
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:............ .h............. ......... .... .........00.... ..%......@@.... .(B...D..``.... ............... .(............. .(R...#........ ......u..(....... ..... ........................................../C..0D.*@T7,AS..$-../<......................................-@......:Ri5Qk.=Yq.<Vm.:RgS5K^.(9F.3HZ......................-?.Gu..!<UT&D`.>]x.Ig..Jh..If..Gc|.C^u.>Wmd:Pd.;Rf..........#3.0Pn."=U@)Gc.,Li.Cb}.Rq..Rp..Qo..Rq..Qo..Kg..@YoeD^u.........%@X.$?V$2Oj./Nk.-Nk.Ji..i...j...e...^}..Xw..Om..B\rqHd}....._|..:Zx.Cc._Qs..Gg..1Qn.Uv..p...q...r...q...n...d..._{..........^...]~.,\...[~..^...Qq..Wu..n...v...x...v...t...o...j...m..v]...Yz.'\~..a...d...b...?O..&*..1;..CU..Vo..h...r...o...f...c..;d...Yz..^...f...g...GX..%%........R...P...i.."w.+;{.:Wx.Pr..i...`...Z|.D`...b...:Sr.,1..--..."a...0...1...D...x...j..,R.Op..^..Fd...a...f...<Yu..2Y./2..01...!U...4...7...:...~...w.Jh..a...`...\~.89Zz.:Z{.9Zy.9R.../..-....'...$....z...Q......!}.Vw..`...c...b...;\}.;\}#;\z.9O..#$..$$..&&..&'........s...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 176 x 189, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):20549
                                                                                                                                                                            Entropy (8bit):7.986108821429097
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:ekwMaIBryFTsB7sckuOrzdqL+0ZgDdNiC+Pjo0eiTGhXDEi0t+XKWDt:TwMaINyFQhLRizdy+06DOLjBemmzEFWh
                                                                                                                                                                            MD5:0050197C4E3C6801D783762609EF6226
                                                                                                                                                                            SHA1:5B1E4016652C53EE3729D3125EB3F231DD69A206
                                                                                                                                                                            SHA-256:F42ECF07D3EAD5B48C1125B19F101FA4B3C6271F4FB43196876003615C31F31C
                                                                                                                                                                            SHA-512:B527E6A611394798E8467D797251A094FD9E06686CFDD95C40545697E79308246C51C007D9EBCF8B6A5B56BF810A851A10DAED9AE1DE9995B757558DFDCE0F73
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............)......pHYs.................sRGB.........gAMA......a...O.IDATx..k.e.u.......0......`.....H..IP$ER.c1J"G.Rq.J?.r.........B....-+....T"..-3$%.,.!>.........<f...}..{...k.^.....pa.u..w?V...z....q?z...5m .D{..K.....hC..c.|\F]V..]u...O_.nK..*..N%~V.#oW..........5....".....D}.%_.....MHS}..._/.G......Z).c..J....>..zsz.6..z...*...^[...Xy.h...l2..IT...\..R=.}..0.P].8.N..6..V.i.|...O.ur.|..u=.....2.x..>...K...>.....GP.<.3...6.R..78..G)..x........6(. .3...Q......r.^.....x.......q..@...]/~......F.v.W...IJ.3}......n>....l.-_I.0.;u..j.B=.9.y.?.d.].lB.C.....xQ(..2..dr..'C...B.]._.(e.k..O....9..2..p...=...y2.".V..&.lk..P=.x..K....J4..%1R...&:.%ax........B.k.q)....p..$...B+..:Y.s|.B,hR...j.K......-...G.1....-x.(G..1....+5..?..#.......P_.....$/.>.e..l..c...... ......@.p...Z`I...5R..BV.8c.L#.\.... %..B....)AS.,.>..296...B...y.l.b.r0.O.D0...^e.iDL.5Xyb.RPf...a...MTL.4.x.t....\uf2).J.6@r.../....$gQ.X.r0hvrV.|J.%...d+..#o..._.....G..a....+,v@
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 416 x 24, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):942
                                                                                                                                                                            Entropy (8bit):7.531868737958494
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:9s/6Hwf01d5/znYDjqWy8Yi5x7fzO/eoTMO/0T3hQ:9s/6Hw81fzYHqWyyDzD2h
                                                                                                                                                                            MD5:50A8EBBBE54E38389C31C82D126B414D
                                                                                                                                                                            SHA1:C93D3B7CB702DE03C6AB2C8CF7C6520F45613FCE
                                                                                                                                                                            SHA-256:B5750D21ABAD17B37896862D5B6598FABEEC4B45EB1C327ECFE4056CC2E890D0
                                                                                                                                                                            SHA-512:E67712C56B2B5465BF9481DEFB814A98439EA9656A6F65A0F6A7355D30979C65093FA5325751F5753EC615E8EDD7BA604B9E3E7A5BD46F95179C6DA56012002A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............).....pHYs.................sRGB.........gAMA......a....CIDATx...MN.@.......7.9A.B.r........i.u.m@..r..P.mo..u....]...:...i>....q.?..q...../D.........}...V...bzA".z....ZH.$...z................$^.HVi.Po.@......<.q+.N.>..o3...u;..:;zO.%.<..l.a..2.....$"A...Jd$..7....d.r....(RO..5.s.w....%d;.CCp...=.Z.<8~u...w.p.H.DN.............+..(."..W.t....$.;......pE6......Z.id`...Ob..O...C.yP..M.6o.......p.P..PB%..f........'...WT......%Jd...6...F....V(>N>#...P.....Y..Dw....&.Q._SN...G..?.../L.l.!Y?....:......d.g.]......c.8.O.l.B.1....Q.{,......|.=..,...-$..&L.6.~zL9m.>.F...(.0Y....$....!.M....A.uk.....X.....<..P..d..^...e.....Ku......#..8..<...%....\).(......F...eubo....<..........]..,..p.<.ZV....w.amk.V...%PT.Ff.<?9.2T.'.S..Z...$..!4.....t.g......"t....<@.....?I3`.\......p........?Hgj..>.?.....TQ.........<<.r.9...!..L..P....b).Q.......B.......f..#<a.\.X....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 416 x 24, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):936
                                                                                                                                                                            Entropy (8bit):7.559903053416362
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:9s/6BsT2qpwH99jdztSFrR1SZ5id3SBMKSb6b0oqqR:9s/6BsOjxQFr88SBTBYoq+
                                                                                                                                                                            MD5:1380B82254D9056AE17D2C9C333BCD5B
                                                                                                                                                                            SHA1:FD419D0EDF583E313F7F7F1BE565E7EB3F2519B8
                                                                                                                                                                            SHA-256:FEECF9909347B956549A39AB182F367F78E9C1306CA2DA146638CBDD3BFBA285
                                                                                                                                                                            SHA-512:9FC77FA74EA43F15ECC787FBC6299492196E8218FFCA1A6A4D750EBAF2A588FC14399D498FAD9B1DE5A3E0A316F3DD57350A1B2B0D67309CCA699BC96ACE89F5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............).....pHYs.................sRGB.........gAMA......a....=IDATx...AN.@...7v.`...NP..h...z..9.,.v.d...J..$..n{...knP.........M...#.......v....L./".....X..^\n.f......kQ..7....=S......Z.%.#@..'.<.-@...WE......x.:..$#...W..A...v..z.G8.U..Xs.p....<.N.y.+@vG...T..0`...........~.....;c...{..P.......!5..x...J..DoN..!@........]n.Uj.....]{.5cd...V.n....r.E.3.~x17.. ....C<..;]..43...h.1.g.<x..=4l.Kk..........O.......Q....<K.W.T...S].......`..eDo.U....y(%NZ......J<\S.`...<....0..$.R$...J.8.....Q3/..,@....~U>d.@G.j0.\%.0vvy...5..|.>.@....]...........<.....z3l.<$.!.!..@E..P`...]_U$#....\.zSp..c...B+..B..l.ly.....(7......os.Y..u%..!5..Z.$....M.E..~.J@.A...I.AgC.z..g.?c.O.sh:....fQ.yh..h]..#..3 ........;..x..L.......9...wS.{2.M.N.5.&.y...y...-.{..._4..'%o]U........~.F.....|..@@.....3.........M.=7..yA/......<.N^y...8.F*........3.9../Zt..cA...<........V..c.iK4....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 416 x 24, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):664
                                                                                                                                                                            Entropy (8bit):7.3611901561562005
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/705s/6Ts/vZBGTY1vFn4D3brB0lG92JFFC/aE8Eq3b8jd7sNksCjz:9s/6EZBGV0A8A08WNksCn
                                                                                                                                                                            MD5:FF3D7C0157D5D1D9A28E91FB2A0E6662
                                                                                                                                                                            SHA1:F6B73B87D42B63F7BAA5A6CDE25961B6314CA913
                                                                                                                                                                            SHA-256:D55C2405879639524333F7262828C370B5331C8A39BE070CCDB888BFB4F715B5
                                                                                                                                                                            SHA-512:698830E86647EBA52042F0CCADA114B64C4462DDA153B563662AC6E91AE502A275B498649E3154C7A90CE1BE883C29DDC9AB8445F580562741A2E1C8DD4B309C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............).....pHYs.................sRGB.........gAMA......a....-IDATx...1R.Q.....Ha...x.z.3....0..h%....T...!.0v..b...VO@G.$.w.d_.. .Vg7.O..,..;....E.....U.......=....l#9U.....).e...^_.........hs.)..$[.rqr.!.....B......i.X.}...S.d........D...........{pr...P...x.{.2.6O.v.i.<......P@.......%8... Y.L?..Pz..x.{....t.|.!.+...Pb..xE... ..V .YC@......C......wgnC...'..v....; ........"....,..X...(Ym....B.X....d?......w.j.T..f/,..^.uT.c.A.(..=8..E.5].e.\yY...........!.@_.sM'm...P@.........F....NtOflC....+.....~.?.z.|......O.....P!..x.{........$W....`4i../..../T.K..{.B.h[nZ_.-!6..Igk...l}.X...x......w..F6y....5....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:GIF image data, version 89a, 100 x 100
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):15416
                                                                                                                                                                            Entropy (8bit):7.756586242434715
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:eK1L3Lk1UyxwO8tIZrkr+8t4vR8O8t4vWn2x8t4yLO8iDd3TCqM1oOiOvL:P1nkKO8+pT8amO8aenQ8auO8iDd3TVMD
                                                                                                                                                                            MD5:365D3E659634DF5D5289F14E1855E714
                                                                                                                                                                            SHA1:51010713312E23DD9ECBCA17A57FE944A678576F
                                                                                                                                                                            SHA-256:651598C518BC9F405F1DBDBACF89343D87B70DD2DFF93A01FD20F96C524E78CF
                                                                                                                                                                            SHA-512:2243FEFAC77C3CDC1CAA5E17BB01057A6A343D1852B58B48F7F34610814CE8BFDD47E9E2D3D3D12C8ABA543786E1CEF8E22E42D6159F222F49534C03845F4D06
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:GIF89ad.d..?....)))............................................www...................eee...XXX.............................................DDD....................................................!..NETSCAPE2.0.....!.....?.,....d.d......pH,...r.l:..tJ.Z..v..:Y..x<..(.....r..@{...DL8...=..t[.....6JzhaG5#.....W....kI...E......V........C8...&.U....z.B,..$.T67..;H..?*.)>.T....F....T<.'.F!....G.J...G.F...K.t8..9J"..............c.....x.8..!Z..CV.r.CI..),........t.H...?x.....%L."..0..J.$.2E.7.&5Q.H".qS..1<{.4.a..aD0.h...:#Ls..8..X.G......F..j....E..g...0...!g....a...E..@...\h...em..=...x1..\.By.z,....X... ....U3Y.+D....+...y..H..<9.!....Ac.=lw..?.E@......h\[....c...q..Dpx..M...=..^.;...J...K....P.@......s......)Q...!@T..........Hr..w].0B..|P..,l..mK08....G...`...8.`....w....u..6.v.."LHD...1..C..X.l...T....'.GD.#d.I..*...l........h..X.".)....W..T.d...0...uc.Tn..BV.@.w...b%.e..v^T.U.).h...f.....8..........'&..X&......P.bC...`...$.f:.zi..&.,......B[.V...l.l........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 176 x 134, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):15075
                                                                                                                                                                            Entropy (8bit):7.979399641440617
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:B80mK0kjvC93yIZ97t991dRVGJyjz4poyVIor28Z2ci:TmRkjkRr7z9lwJyOoyVIuy
                                                                                                                                                                            MD5:2B183B9A55E2A55A566E6DF71751FBE8
                                                                                                                                                                            SHA1:F5EDBACF9DEF16D0DF52888EA7C398BF51601AD9
                                                                                                                                                                            SHA-256:6965355533AA0487DAC22F5D44CBD72BCA2C2ED2A75558DE725CCF5B8D1156D1
                                                                                                                                                                            SHA-512:47FB4AE6DCE69854D78190797DA2536C21C04E34F47CC4CADDF4746CA6B86EC522A6ABD2BCB01D2EF26E378513AB49E97AD470EB2503B345A15A80475768DC86
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............}.......pHYs.................sRGB.........gAMA......a...:xIDATx..}i.].u..o..`..X.....I.+H.H*.Hj1Iy..E......e;q.8.r*..8.b.J.J~D.....r..Zh.2m.&ER....H,\.....`......>.t.}o@,#.g.......>}.t...s/.N..!c...sY..EgR.s..-^.#JK.3!s..Rt6."...zn:...f6%..:6.....g.jU=Z../. 0..,...L.."..K.W..9..:.|...j3.&.........Q....^<g3$.i.<..S..`.Z..?VA(..*-...__.0R.9..|..`$......$.5).T.....7.l ..>.i.x...|t...wMx.w:]..@:i(Hw...N[.l.K...4...8]...7..Ho/..@....T..x.o'.+.....Q|..2....&..u....P.......uC;......,..kh..mHDI......l.....^..C.OH...Hh.$..ei.C..3d...U...S\..V:.t..qH.d...2..A.&X...._\.P?/.......C} ...M.e3..3B >..v..0.._@R.4&.GB.(.<.%....P.y...I.'.T.].%..4..4....ZW.<. g.......H..H.........(...k$o...]...9.d..]7bna.....0= }=....4..NQ..$2../...y....XS.^..l...O.].:.)...E.iKH..S.....%...&"5.4..@M".N...X.(~-g......&..l.......Q[.....*.3.....M.....h.Q..r...0..G.M%.Z._...S.4F...x%4CLJ.d.y.........).V.(.<t.a.J..&=hSi..'.Q.d.l[.).. G:M...)N....l............
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 41 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):617
                                                                                                                                                                            Entropy (8bit):7.439754348378905
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7T2/6Ts/V3SPmQjbXnqipYBFQAztUBU7oMDyREhY15wNpwtgLulRlO7:k2/65XjbXnQkAOm7oxkYqWiLGO7
                                                                                                                                                                            MD5:EB828ABEE8EA1DEE90FE34A41FD2970B
                                                                                                                                                                            SHA1:9F2C18E1765BB8953F9521FAB6446F730BD9B56D
                                                                                                                                                                            SHA-256:9CA1BDAD0200BA81AFC1DEB29782AFEB29D2E519AD267DB90D115BD6136952F1
                                                                                                                                                                            SHA-512:E0F40F67C78BF8DC3BE4CDAE824BC9E453977D79713FEC704F25567AC1E23A407C542D9D7B8F6AA9ED9811F829984DD6724784B82F1E658D8B7A4D635E3D3E1C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...).................pHYs.................sRGB.........gAMA......a.....IDATx..Mj.@.._...FA.n....Kw.@....A....jO.z.TO...Bp#M..B6....#cj4..K.0..|$..y.....i.P(t...j...... .:..B.P.5@p74....=....C..;..-.(..........%0.J.%......f3......a8..)..k.*.GvD$..Y.!..{...v:.[8...U:zG..0....r9..b4.A...NX...BZ...d.YH$....,.\..g..."V..G.....d`.\..0..I..6&.I.J8...?...%.L..~.p....AZ....4..t..0.L........}A..Q(..^.w...6R`..'1M../.@.$M.`..u...u...[...n..H..8b.T..^a{h7[..A......&..x@...M.Q....n.A..[...CZ.._..-. ......(JyK..PG.S.I(.)<`.~.I`V......l...O..7.e!..?*..+|<.~.x"oh_..y..{.....M4n......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 41 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):675
                                                                                                                                                                            Entropy (8bit):7.562211970325794
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7T2/6Ts/bVSd/4kRfv0fBejGezIcHU1xJe4p9HU1VtRPmmgWonwKvSa+BEMR/:k2/6uk/5vu1xJH30rL6vnzvSa+l7
                                                                                                                                                                            MD5:D227EFCE741CD468570862CBA8A7E594
                                                                                                                                                                            SHA1:BEE60BB46694FBD91CEF1588C8EF22EFBB35A725
                                                                                                                                                                            SHA-256:F18F4F91B5C4A6A6C1BF94B84329F7473DD9DB3E3507DCFC5BEE49034DB95FD9
                                                                                                                                                                            SHA-512:56E060EB9A6F81BB2662DC6F31364C18B72B4255460F03BC5F8C39EAB29F4EA7CDFDBD082C5AAAFE4A0AC2C8A5C70E0190D536C84960754DEEB487EC81EA51DA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...).................pHYs.................sRGB.........gAMA......a....8IDATx..MOSA...3.XI(i.+>"...F..\ado....d#...].Z........H..1*.@.!.+L.V....L..-..v1...igz2....w..@...x.....z..5:`.....U.W.}..5...^?Oh..B#.#F.I..jY.....,.....F.n.......l.D1.~..-..v2f.2..!....OX..G-Q#i.X.$,.h......c. r..M.}.]V..iB.. 9=....!../..U;.8........Tf.-..5.....>.6;..=:.q..J;..,1.Y{...}+3.z.A..........+.LRtU...S..V.".2...)....<,q .B..m...4h......z.p..".._......d^..:,R;..Q..HM)7...YX ..`|.s..1....Sj.R..Vn....a....F.f..Q.....s,V...w....Qn<.%Z.M|..0...+D..V./7.Z.C....r..}..L.$.B. AmrP..O.....H.r..G6C.&...<..[.....u}.....z....".v.hZ....;..........IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 150 x 150, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3245
                                                                                                                                                                            Entropy (8bit):7.9134385325834735
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:5Sxtw6uF4h1IoiShJRcX3/okKqShNmdXXs8oG0S6Fc:5S3w6X+0XZcsFNS6Fc
                                                                                                                                                                            MD5:42B15F32E9F2B2FE7874BC8B5CEC3FD9
                                                                                                                                                                            SHA1:0095AEB7A50DAD717D5C831DA04FB692ADCED9F9
                                                                                                                                                                            SHA-256:0AA2F6F56226AA14901D0FC02DCC9FE7B45A86F49725C1B638252F90117181B5
                                                                                                                                                                            SHA-512:2113BDE6D0E5F0D96F55C1DC07A1351A697B0C1193FDCA41C5E452DFAE38B96E53D717C74A840793E53696D0C3503D8693B403639C30D56955B47DA0787C7866
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............<.q.....pHYs.................sRGB.........gAMA......a....BIDATx..._l.G......;.v.Z.%.I.(U+..mihCs..@....T...P....."......H..!!.#Q.}JC.<..VT....RKJsvZ..N.R......;g..8N......}$.......o~;.3..B.!..B.!..B.!..B...YQ>;.\.S$..g.3Q.r,...F..Kf/..h.@O$.-R.$$.>..>...e....{.).q...D.-.5...0.Z.R{.a`......$\.rV.FLS.....%6.. B..|v2eD.G...M.V.r`2-Lq.0..m. .B....DOK..#..k.....)N..]C....k>;......).N.G.BV..K..t.T.T.t..BuZ+...Y=...c..V.....0).......8s..41..@-.P..7D.&X...s~..Gw.c..5..cA.......~..}hx,#.9...H_.k>{..<r.Q...Z><......h.1....X/..k..{Q'.>T.R....')T..T.8o.VS,..@R.....0.uPs..SS......E......Y........;_?5.i.g_}.....>.z.U.*.L.^.g..A.C.9.[...\$..>.`Y....!..j76?.....#.^.F.....h.U?%.....{.<...>*.3W.Eu.X..'P'u.T.^2:T..@l......hR.TU*..._.y1.:.[...w.K...U..q.k.k.|../..y.uR...BU..........1%..L.G..%X.L.q...TCu.....kU..0....L|J..........?.x..X-.......Gx...._..B.'.-..l.. .z...~3.f.V.>E_.^.=shk.k.^.@....[.y.(.dU.k.Rajm-......Tk.H.d....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 150 x 150, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4647
                                                                                                                                                                            Entropy (8bit):7.934941782690532
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:5SrHsLRJGNY3SJ7+U/I+TWVdFP8FFYTq3+Nas4YCiuSuWozqB1phz:5SrHaZ3k+UDiV7P8FFY6o4S/oO1x
                                                                                                                                                                            MD5:06438B94B66EEB804C86F363C62BFBC6
                                                                                                                                                                            SHA1:CF3D09AC9D952D6FF0A85D0AC9BEEBDA22CE0EDA
                                                                                                                                                                            SHA-256:C879FAFA5892DA6841E0EA09F2EFC9F68762E5A4752D62ACA8C9B95828B6FEAA
                                                                                                                                                                            SHA-512:38328E330AE12BC31EDEABAD908C86A1C486CEB0D14E9FF946E459D0E88243F3DE0EB603CDB6E31B4CA2EF6BF70428DB5EC54B3C705E3043C9FB0A649E11FDA5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............<.q.....pHYs.................sRGB.........gAMA......a.....IDATx...l[.y...^.zX..Fvl..:Mj.[`...m..y...Yn.>....(..N.n..`..tK..v.4.....k..c$..Hj.(..nk.A.;.`Z.dG.P.eQ"y....EG.. /....`..i>t.....w.s..P(...B.P(...B.P(...B.P(.#..YI%..r?.b...l...#.~...7.h.......i.@K(.....8k.wE....,......1.~F......./.."e..+'..6].]BD.....F....w._:..ub.P..J%.[...sSksGH..F.x.i...C.me.eJ..k,1.R...&..>...c.4..pU..C(3.FX...6.c..hE.r4!...rq.@...l.nO..P....9...c..V9.j&.0...U`..Vzlx.7..\.5..../D.FX4..4....;.a.;hd.O.E`......^{...X...i...0....&..A.u,..W(3..]....0.t.k.Z.E..h......X...>.M?.Du#...i..Tb...7.......A.aXSS......8h0.g.U8..h8.I..........._.......^.+........5A..i.}.s.n.E7.G.FX..0pH........-..o....m(.E.N..7..P..o.vY.:c#....l.z.ZD.^...4.$=......n....a..\*...?..b'<.3.D.....-P,..q.K........k8...$.R.*..a.{..........C.....KT.;...#/...::.[R.cI\.j]....'.'.l..j`(.1..r%.{..E......2..XTR.....r.t.O.........i...8.7..=.5......k.E..JT..[.Eu5.....0.J..LS@<.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (33246), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):37458
                                                                                                                                                                            Entropy (8bit):6.111535768912929
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:h9DDI1HkcKGBrgXjhvgVfk4rcB7uGzQtn4rZT:h9DDI6thXjez1jtnA
                                                                                                                                                                            MD5:852058901C74A64253F8A30307342E99
                                                                                                                                                                            SHA1:43713FAD9753DC649C6203091187371FDF30EBB1
                                                                                                                                                                            SHA-256:110D789973B78ACCC07EABA2FBA8BC9732223935570DD607ADB0765C54D39BF6
                                                                                                                                                                            SHA-512:2E7803BC7DEF0B614A6C8ACDDFA75FF7BA37B31227E4174549AF8C7782739A6D1B669A9AAEDC1178E0C6A031B1742D2849F3C3713FC8BCDA878D46A7D3A24C88
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Open Sans Regular */..@font-face {.. font-family: 'Open Sans';.. src: url(data:application/font-woff;charset=utf-8;base64,d09GRgABAAAAAGEsABMAAAAAsTAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAABqAAAABwAAAAcbEIkOkdERUYAAAHEAAAAHQAAAB4AJwDwR1BPUwAAAeQAAASiAAAJmCwaFlhHU1VCAAAGiAAAAIEAAACooF6Ikk9TLzIAAAcMAAAAXgAAAGCg5ZlGY21hcAAAB2wAAAGGAAAB2s9AWKBjdnQgAAAI9AAAAEYAAABGE1sNN2ZwZ20AAAk8AAABsQAAAmVTtC+nZ2FzcAAACvAAAAAIAAAACAAAABBnbHlmAAAK+AAATOAAAJGkMGdKhmhlYWQAAFfYAAAAMgAAADYJip5GaGhlYQAAWAwAAAAfAAAAJA9zBj9obXR4AABYLAAAAjcAAAOm2kNYqmxvY2EAAFpkAAABzAAAAdZ4GFVubWF4cAAAXDAAAAAgAAAAIAIHAZduYW1lAABcUAAAAgcAAASAUcWdxHBvc3QAAF5YAAAB7gAAAt15xIzucHJlcAAAYEgAAADaAAABfLpWDR93ZWJmAABhJAAAAAYAAAAG7JdVfgAAAAEAAAAA0WhVmAAAAADJNTGLAAAAANGknRZ42mNgZGBg4AFiMSBmYmAEwpdAzALmMQAADaEBGAAAAHjarZZLbFRVGMf/M51hxoKWqtH4CBoyNrUGjQ1J27GwatpaDZZpi4MOig/iAkJCY0hMExaFgbgwIQYrOTxqCkyh0FmQUpryMkxXLNzhaW3jyuVJV8QFIY6/c9sp4EjVxHz55dw597vf43/OPXMVklSpbn2qSEvru916/rOvenep5oveHTtVv+uTL3droyL4qFiU9/0316GdO3p3K+6vAiIKB2NcoXhv4
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (33246), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):34216
                                                                                                                                                                            Entropy (8bit):6.048936621948461
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:E9DDI1HkcKGBrgXjhvgVfk4rcB7uGzQtn4rZq:E9DDI6thXjez1jtnJ
                                                                                                                                                                            MD5:B66C073D57FA28ADB8AC3B4179DB653D
                                                                                                                                                                            SHA1:552B48197375DBB8CF21CF946C7E79459B226101
                                                                                                                                                                            SHA-256:31DEEB6D972CB0FC43CE887AAB0F8DE07C0871F84D9B5E37A1FE4EFDA871702E
                                                                                                                                                                            SHA-512:EACC937F48503FC6BB88D96D2BB7D31EC97EB44228C6F85EB84E952ADF4391A536DA9A2806C113094B2BE7DF582D213AEBDBAABA79922690A917ECF37366F8B3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Open Sans Regular */....@font-face {.. font-family: 'Open Sans';.. src: url(data:application/font-woff;charset=utf-8;base64,d09GRgABAAAAAGEsABMAAAAAsTAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAABqAAAABwAAAAcbEIkOkdERUYAAAHEAAAAHQAAAB4AJwDwR1BPUwAAAeQAAASiAAAJmCwaFlhHU1VCAAAGiAAAAIEAAACooF6Ikk9TLzIAAAcMAAAAXgAAAGCg5ZlGY21hcAAAB2wAAAGGAAAB2s9AWKBjdnQgAAAI9AAAAEYAAABGE1sNN2ZwZ20AAAk8AAABsQAAAmVTtC+nZ2FzcAAACvAAAAAIAAAACAAAABBnbHlmAAAK+AAATOAAAJGkMGdKhmhlYWQAAFfYAAAAMgAAADYJip5GaGhlYQAAWAwAAAAfAAAAJA9zBj9obXR4AABYLAAAAjcAAAOm2kNYqmxvY2EAAFpkAAABzAAAAdZ4GFVubWF4cAAAXDAAAAAgAAAAIAIHAZduYW1lAABcUAAAAgcAAASAUcWdxHBvc3QAAF5YAAAB7gAAAt15xIzucHJlcAAAYEgAAADaAAABfLpWDR93ZWJmAABhJAAAAAYAAAAG7JdVfgAAAAEAAAAA0WhVmAAAAADJNTGLAAAAANGknRZ42mNgZGBg4AFiMSBmYmAEwpdAzALmMQAADaEBGAAAAHjarZZLbFRVGMf/M51hxoKWqtH4CBoyNrUGjQ1J27GwatpaDZZpi4MOig/iAkJCY0hMExaFgbgwIQYrOTxqCkyh0FmQUpryMkxXLNzhaW3jyuVJV8QFIY6/c9sp4EjVxHz55dw597vf43/OPXMVklSpbn2qSEvru916/rOvenep5oveHTtVv+uTL3droyL4qFiU9/0316GdO3p3K+6vAiIKB2NcoXh
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):26093
                                                                                                                                                                            Entropy (8bit):4.77525155455544
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:J+6T4vNmgN8k0+yycVCI6z0jG7RXDX43UMRmvm/I:aDIpQ
                                                                                                                                                                            MD5:88AAD1628908702DC40728E4B844DF2F
                                                                                                                                                                            SHA1:214B674B1C41884C60BC038B91494CCB4B76A2CB
                                                                                                                                                                            SHA-256:841908E604B67209B61219433FAFFF57B5F13DD053A76857D86B0CB424754A4B
                                                                                                                                                                            SHA-512:A47D16ABEEBCA23BA2F8476C2639C0CAC2908B5D53A1A416BF276512003FAD9737E45D63F27604A351E75D4AE4F29C2BD3FFDC65BBACAED288C16A31D307675A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Core */..(function (wa) {.. var core = wa.Core = wa.Core || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External;.... //Component.. core.Component = function (name, status, key) {.. this.name = name;.. this.status = status;.. this.key = key;.... this.isIgnored = function (key) {.. var isIgnored = false;.. var startIgnore = this.settings.get("startIgnoreDate" + (key || this.key));.. var ignoreDuration = parseInt(this.settings.get("ignoreDuration"));.... if (startIgnore && ignoreDuration) {.. var today = this.settings.getToday();.. var startIgnoreDate = startIgnore.parseBasicDate();.. isIgnored = today >= startIgnoreDate && today <= startIgnoreDate.addDays(ignoreDuration);.. }.... return isIgnored;.. };.... this.isInFixGracePeriod = function (key) {.. var inGracePeriod = false;..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 162 x 163, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6397
                                                                                                                                                                            Entropy (8bit):7.947947094706784
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:GSzkZH+IG8+1lqPrujYGCbSDp98cti4FSwgfYf3:poZHw1lNj9f98trfS3
                                                                                                                                                                            MD5:4538CF17F5E72D4AB6748D921AAF47C3
                                                                                                                                                                            SHA1:0721FB317398B3F389FC85B57D7BBBB5A5C8EAFA
                                                                                                                                                                            SHA-256:CD03355615D11022E11EE57F35A0E994F42F60A03CF9063FFA7AC0321276129C
                                                                                                                                                                            SHA-512:D9DC3ADB291EEC7CFCD317DB6D9BE5C662BB25DE22AC8056CEE7B16F710F119392A46CCE4250900DFF59DB4313A6B23FEBDE30240DB9A3244C3B008A49ACC422
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR....................pHYs.................sRGB.........gAMA......a.....IDATx...tT......I2I.....B..-..[.GKJ...+.+.(.j[{..t......O...n..Zc=.........Z8TA..=U."2...7I..w..M.'3o...wf.{.>.h..L2.......K.....V.....S..N...9ts.>B.....Z.G::..e..\.....c.i ..`.....k.J...[.*v.v>.D<.?}..C..p./.@k::.@.S.B..No./.\...PZ/.X....7.[...?.....x.-..U..]PF...Qx:..Bts..\.It.............l.).I....LY..P.D.....G8.....#....th..JE\..^.:1.t..Q|^Mk...ek.2Q.}V.o;..E.IR.#........u..`..!.....n......`=.)..N..2..ex?.. ~......y.......`M.0..a...m].J..k,ik...W.....Q.......O..0.m'H[..X.LP../.z.......y.F.6.E..l....`......K.H..1.6.......o.....9W...-,"&!..[9.....w.......=.f.......(......2Jy.l.F..7.U?.......>.u...WY.][V.F..j7.:`.X..g6.[.Z.Z|E.....)kk._..X.....nx2.2.....6v..V....b...\.Fn....W....[.::.%.?H.5.H.C.....X..h..1.d..3...gPb,#D......I....K....#~..*.....>\..=R.9~l..D......w..2P[..%..B4\1..+.... ..@..c.9@.....iG!........d..'}..F.D....m.(.....=v.lz.:..N...F....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 162 x 163, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5418
                                                                                                                                                                            Entropy (8bit):7.941310197666969
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:GSscx0y/nkoEVlqHdvygby9KULounF17qTN/Sxgn7ylwgwIMyce:GSscKy/koGlCdv29hLJqxiEybYyv
                                                                                                                                                                            MD5:A1373F9C03567C27AF0DE96E770E45B7
                                                                                                                                                                            SHA1:A97E90B04460E4AF1D8425A9D9716782739C79B5
                                                                                                                                                                            SHA-256:EE56D3790702A7A91CF1BBD73326E6852CDF648C77249876D8D4410D5E1DD52E
                                                                                                                                                                            SHA-512:D65BA6F131F7EBAD0267FEF9BD555121429852DDB58F1D51CF3CBC800114C93BD8BC50CB06437BA999B7B585E943930CF7AB8A65632C1B9BBACBE5627027BE3C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR....................pHYs.................sRGB.........gAMA......a.....IDATx...S.Y..3.........A...6,.{...{",..a.=Ll.,.....8b.....=..r.eo....o{..........U..R.T.{U.*.O.m\.!.2_.x..4#.._Z8......C...U.M(.4=....St...S..<!, ."".....-..6.#P..j@X..*.QG....sU-V....+:h.../....F~8.."..NU....|......L..'D...t.....Wt..V.&...@.v..$.s".8w..d.E.{....A.p.G6..2.Bt.....O.h.F....4..f)3%D.d.7..,...d.a)..r....r2!...El:....)...wMi@9.V2.Bl...L....r....c+m.L.....#..J...*!j.....\%.L..9.iNSYT%..fh.k.$.5.....5QZ+Mb........D.X!zIhsWX.E.(..:]y^...8!j7..I...$......k.F...s..*<O..@b,bZ....u._.M...k=+.M4..i...D...t..o..$......E5Q6.....3].i..o...}.3...3...1......;.(..|./.U#.b.h.......Jy..XT..0f.....Sm87..?l|..Y._.k../....?.AY.,.x....q...=Bc...X.... .2/...pQ3.j.........N.n.C..E.s..e.O......Tr.'. . f.(-":..&J.n.]..........K.h....$./...B.E!.".H.).X.8..Q.?.c.....|.h.-d...?.5........K...1....<..:_...d..d....h... ..c.BlUJ.c)........... .T..1Q.1R!.'.l..ai...Q.1R!.&..R...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 261 x 265, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):32309
                                                                                                                                                                            Entropy (8bit):7.9804976554334655
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:7NFP/8lSUsE2h18x4Su69ZU+VJpszMXneyg5PTg:fP/8lSkLd9jpszGneyg5U
                                                                                                                                                                            MD5:FFEBD5099333A2223979DDC7AD6E75E4
                                                                                                                                                                            SHA1:5BE640F0A871C4B1C9B2858ACDB8795B96F44586
                                                                                                                                                                            SHA-256:4F80FA15BA8934B3E4612BAF88F1DD2A633A1368A18F4F592D17FBBFCB635851
                                                                                                                                                                            SHA-512:359A50BDF3CAC8AA7B4D8CE42CB83F52CFB61AA969EB8B258F09B9BF1311C0B7FB3B974CEDEA72A0B94FDB0055CDF1F7489390E492F07547DEBE75B2EE5FC728
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............T2.....pHYs.................sRGB.........gAMA......a...}.IDATx....\e.6~.[.^.g%...t ..H*.#::iFG.uh..7..3.gQ.HG....F...g.q!......."J.i...v.$.....{..9oUu.;.Iw...._..[.}....lD...0`.......0`.......0`.......0`.......0`.......0`.......0`.......0`.......0`.......0`.......0`.......0`.......0`.!..9.e..."O.B'..6M.."(.rQ8..E..9.....\.*.........:.$.Q...C...{C!2p.. .9.....o.I..D!(.k.A.L;....&.s..).Q.-.}+....B.....m!.s..).1..A.;.o....T..)b.a5.M.....\.fKA......Z..M../X..?/p..H..%...R.#`w...3\.G....t.L...Kkz..!20'`....[....U;M?.p'.....{.....T=.R.rp.....!......07`..U....)}.F........k.j(d.j.LR.l".."..d..aX.U..6.z'.B..Bu....&...,. }#..Z..B....D..f/"..X..0......P....N..~....@U. ...>u)..!.J2P.0H.....c({.q.......A.U.].z....z.202.R.>....).A.U..0..L1.R.:..2``.a.B...9h......)T.2...:|.........t.&.U........H. .._....7.........3.6\&..[.^;.....d.*a&..FA%!0V_.,].x<q....w..[7..%3S!Py.9c....0H....m.#.....v!......xa....... ..z!..@Z........F......w.&.....K$Q.U......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 300 x 584, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):32345
                                                                                                                                                                            Entropy (8bit):7.970403798736529
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:b4L2222222222gBS2222jbjKQiIlGtteBfKZiPb6++0SqnQcI:bybjbBlGzCCI0qnDI
                                                                                                                                                                            MD5:EBE97C44DDCD9F77F1BBA3B2438385D5
                                                                                                                                                                            SHA1:42648E15E7B62FCEE58CA5EAAF0CBD81A63E35C2
                                                                                                                                                                            SHA-256:26EF082565402F86EB018C87E41473F4FB2D52EEAC73B9CFD8FE81D51931AFE6
                                                                                                                                                                            SHA-512:552D36347A3943830B04A4DE2D0E4E2032A9A108203E824ABBF16595781A2A19CAF36FC813422AA6F4FE74F4B219ED376305D424E0CF17332397969E26DFC5D2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...,...H............pHYs...%...%.IR$.....sRGB.........gAMA......a...}.IDATx....-.f..k.c.........l................RO...x.@..A.R.......Q....\.*......j>.HYVdCuv.1.#;.y..W.zg......De....|.gE.,+..:-.......<g.e...>..._._a...V...+.@F...6hJD..+.H......m..+.H......m..+.H......m..+.H......m..+.H......m..a...U......l..6fW..~.T.J...zy.]zX..(...!.*.g./ _.9#......GPH.#.....(?#..c...k.6o.-..e._tO.Mk...'.B..W...V+.. ].N5xW![.y...~.vx$....U^K.....~.I..GQ&.w.{ye.l.6.hug.ff<V.HD&....e..r..Y..L.F.j.....I..9..+u..@...._..lGWN..l..J.H$.F>%L$..A:.D"q...J$..A:.D"q...J$V.O......wbm7...g..\..5............a...QS...*..k..4....3Y.:..ioq...VN./K.b.S.../...r.o.]Z.(f........(.........p.#...E'...J......j.&.......AG+....X.}%,_.t5.......T_.C.<...!...C<.>! .._..#....3./K...#.Q.@.b.iz@..U...h....&.5nD..UEFQn<.nu..qVz....k.-......)q..+..0..V.E.....h/.....w..+.xu...t.D.Y...5.(._f..Jg.......;.8..".....C.j.f.U$...tw........0.H......m..+.H......m..+.H......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 26 x 26, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):550
                                                                                                                                                                            Entropy (8bit):7.365785777829338
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7X/6Ts/Zxu2I2vTmxfqMm1xZjwZh+YVZofYnTZZg2DDb7:O/6UxZvmtmFQ+YVWwFZg2v
                                                                                                                                                                            MD5:CFFD59876BEA5DA102DFE5C50782E14A
                                                                                                                                                                            SHA1:7A595D0A3E0173AA809662B0A5F83D3287DD31DE
                                                                                                                                                                            SHA-256:22AC71BF547FBEFC2283435A497C80A69156A11C891833DDBCF417C101504D6A
                                                                                                                                                                            SHA-512:3E7167EB0C6A61FE607DB78981B4DDAC4F791F7763428EA68062B5C93B7ACCE205595881CEDBA1E6D415237F0954341FA2D947A5D3D9FC784B9BB9FB096FE41F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............JL.....pHYs.................sRGB.........gAMA......a.....IDATx...=O.P.._*:.+.M.8..@G...uq......!:I...+..(....N$.ap.V./.k../..$Mii..{.7.-.....@......|..\....Q....-"....u ........<...p...;........pP.....Y..c.V.......4..Q.... ..!R7...dB..#.(jB....u.".....HD./Fy...=t".1T.k.z9...C.Q.P.v...N...kn.Y.|4.....\T.t....7....!!..'....F..b3..T7!l]..\......%..y.e<3i..x.V....Y.6..NA..^qL.i..).}..dni.[d.q.sKc;.^.....M.CalH.a...8..y..y|.g.\+...52...8.Z:.......<....5.-.6.,F...%!.=.($B....~.].../{......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):296
                                                                                                                                                                            Entropy (8bit):6.650770439855377
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPZ2/6TsR/fQjojnzBBtSuJ6arOa04YiAoYNvuuzsVc/jp:6v/74/6Ts/fZjnzBGuJBia04Cu4/N
                                                                                                                                                                            MD5:B0965466603DFB1A6A7009873BB14424
                                                                                                                                                                            SHA1:098819CAC978EB75AE5962D17009A8E0F88BF0D3
                                                                                                                                                                            SHA-256:C842640AAAA593064CE50946E600B6D18D320B9B728F4E26D9C634761D88F622
                                                                                                                                                                            SHA-512:6F859EB75FD3CCEAE302C16FC29B25052AE91C28E3D3306AFD10323AE6618122C2CE43D45215EFB2108D8FFAEA04B7B93AFAD976A9CF6A1D410F0CE589CE08DB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............w=.....pHYs.................sRGB.........gAMA......a.....IDATx..... .E....A7.Q...t..@70N.e.'...@.......?n....s....q..a.a..1R.G..h.....j... .....s........_Xk}VJ.....m.O.........|..>..-.-.........Z...n..4.[...9....E..mv..../}..Q.+..I...ZP........IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 150 x 150, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4352
                                                                                                                                                                            Entropy (8bit):7.936868086263868
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:5SztgGRFF3naAmb6OcDu2Y+rOdlyhreiigpekbx8b:5SBj93naAmWOcDuHuhSiZDa
                                                                                                                                                                            MD5:08D943758F483C9EE8BFBF0640CD101C
                                                                                                                                                                            SHA1:0000FF8475A54933618D517B45765FDC893E97CF
                                                                                                                                                                            SHA-256:E8212768A46B73CFA917727B1B01649F4D57748A4DA3D237902E1639C1E71DA9
                                                                                                                                                                            SHA-512:5A981900ED3D49B86EAA1CE1EBD9B8A380CE3EF4AA055E4C6395B957AE3C457E1D64C936573C8F105656A14C4DAB3D5356A4C37EE2295BB7B3874EBB37192910
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............<.q.....pHYs.................sRGB.........gAMA......a.....IDATx..ml[.y....II.DKT$[vh.N.tq.$kltk..6.X..[1`.el.......t@./.}..a.Pl...K...S.E..V.4M...&}...v].HI.H..==.h..I......3.x.b.\..<.y.s..(...B.P(...B.P(...B.P(..N.A....6P@l...@.l......O.f..F......D.<....l\.<...h..2.<#.r...j`.%....<:...V>{+......)......u./..=.O...!.ZX.....>.4.$..yOFls.q1...E....$.S3rb..u~!..,..x)..)..O3........@e.(.._.......b...N.0..i.........k..JX.".G...^>.7..FX..k.{]..y.1X<9<.. ...+....w:.....z.e?X/..S.......j.qM.\+.,....b..*i}..j,.h.H..U*.S.Z/.ES/.Wy...K.....)...R....BT..D.[..]..5Jc............O..I.BX.+K..x.:.l>.k'X2...x.,!........w.Nx.."....W.C.......'G...(le.W2.s...S......./;n......>.B....8....E.O;)0.u..|.1..K.....Q...H.AX....;..&0.....c.bw..p.G..4.,......p...<~....{.=..&..'...c...j.O..$..8.3.R.}...9.O...!..]..~M`.m.>c..).r4..p........f._..Z)....X..e\.WC./.~....r.qKW..V}\.......=x7.P....@....?.=9-u..y.+..P..=..f..Jy(...X....]X.....F.B.#
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 200 x 40, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3472
                                                                                                                                                                            Entropy (8bit):7.914294719380596
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:0BOO0xiRfpQu8pTvaIyE0E+y2Y5NTIMDBoY9I6ZDS9vH8C9SHZ/R0Jjnjc7xa0Dx:CryTvkE75NTLOY9IuS9vcCnU/DW2
                                                                                                                                                                            MD5:DAB5B1667C76E51B013C1C4AD2F7D532
                                                                                                                                                                            SHA1:49375ECB91B075E06624BFB5FEDB3A0DC4F1935A
                                                                                                                                                                            SHA-256:A4B95F7D7A776BBC6A84997A601993D3D4E0EC66B48F7D1DBB816497A248A24E
                                                                                                                                                                            SHA-512:843E8852408E5962C9FE62EE2441E3A41622CC929CC22AC9C692B5B9C8CA9D912AB143BBAF274899C59132A429B9032BDFADA51392E221F6F98E25C3DF0119B0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.......(.............pHYs...%...%.IR$.....sRGB.........gAMA......a....%IDATx..]Mo...~g).,..]... . ..(P;..T/..R..z.....Ut.n*..\b.?.q......-P.P..P...X{..@.AW.Lq..;;kQ..~S.e>......pv.y?g......^...=.Gc#%..v{.>...pbb.n4V.{{{.E...2gl...iA...I..Z3L..O\.|....9..^..Y..ax.....'o.g....1........-0$...-..i.e!......6....u.u.I}."..A.....xI.......~5...~....|......L......y..iBB...w.^...]R(.y.q..T...}.3.4.pf.Q.A.)...../..kmp..$9.Bg.?....."...=....G..W_..?.._M....;H........g5....r..g..... .....jA.($.o.y...7*)......c..)..T7.h....W I.{.5#I...|. .].p....Op...\.q.,.@.@.r7.Q>......5{....O....."...#.L....]..-.U..\,iZC...|.......i.s..-d.R.....4...(B."51.MB."..g*.'.<....e....8..'...!Ks,....i",A\.D.............{.U.0......:..x........~.P3.x....x..o...,..-....3-.{..Q.+y..+m..!...m.$..|..U...H...O@...8..rQ'.J......@....^..P.vvJ.....L.......m_..s.$[...dK.}...L...~8...../^|..U...x.De........>..jk.r.saK..\.:..".....3......S. &:...}....T(..?......k....Q".....^.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 227 x 301, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6759
                                                                                                                                                                            Entropy (8bit):7.889394285207192
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:ZgNNLlmxVJnzXmgYshy0/MMA+SJ3zjaVDRL3Y9M8jX10ZYUQhyG:Zg/lmrVXnPVkzJ38dL30M8X14G
                                                                                                                                                                            MD5:F17683FB6249E0FD8188AB2844EBA5D2
                                                                                                                                                                            SHA1:A084098F96F87604F96737B202935BB1AD023F71
                                                                                                                                                                            SHA-256:A0977CF048480EC62B8CF0BE174466A31612C21CD57C20A28DF69EC7A465E8B2
                                                                                                                                                                            SHA-512:3E2406EE7F4BC41059D4F5ECEDAEBDD0377906EDBA31423AFF86163C217DE47181201272641688AF52FCD00F10BC3F0D90A819D5F48868F598941A4B8BED32DD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.......-........<....pHYs...%...%.IR$.....sRGB.........gAMA......a.....IDATx...{.T.....~.L......pI"B...M...j.+HRV...T6Q....M%Z...U1.....q.&fAQ.a)...DA....0.# ....=.......3w.=..{...p...L.t.4...9..;.^"....:u.Ot...D...[Hy.\..<.!...R.~.#...;wP.j........P.....Cy#.#..m...y..o..F....w..]..uS..u-.,.Fs:.;.|~=..].R>w...g=Z..%....4.....x..9y2.....sC....q<.......P6.Ea...k. .4.:...r|..._..~.0..`..@3.y......,..u.#.O|].....ty7.7.SU.^......... ._....~!B...S.p...].~...y.^.s..$D.......O.g..z%]...............~.n.t.^:0Ju.X..n....sd....0H..:6../.q........?T!. ..8s.~..HM?.......)?.....dB...xt..i..;. ....A.d.|...........)A.^..?.1G.j.R..&.........w|..0.O...._...8..9..0....x.(.:..^=.....3.5|..B./..`......@..vT:F.k...!..}..... X.P.<6,......S...t.d..P..J.;..W...|.."P.....S........~k.........._..W..T.fr ..z.=...^T...T.u.}.qEu...=.}.w..~.&.x..jm.VD=A,..V!.G..g..".~..}^R#.Su..S...8.z'..0.....@...@....8.. ..6..@...@.^..r.....Um...~2.....1M...a...a...a...a...a
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 262 x 206, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):14880
                                                                                                                                                                            Entropy (8bit):7.950282493364645
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:LA1gTOQhDAZ8uuVkJ/2hWTEGdjzZkPZa9HS0SI30pNceqnUk0d:SgxVu8kJ/TEGdjtAQ9HOWeqnUk0d
                                                                                                                                                                            MD5:FD7583B7091CC8A4BC321D3CD9CA4986
                                                                                                                                                                            SHA1:DE974AA0EB8A39AFF09AF8C9E4971EBC26D35ABA
                                                                                                                                                                            SHA-256:D0CC78D7C65ABCF0A5956AE2CF63DFD1CD8B3F9C3543D6EA307B20E218B58D6D
                                                                                                                                                                            SHA-512:9067272C7F83C83A3079069AACCD181AB8D06923F98035C1A64FD06140AF23CBDF010927E1E7BB907267769D9FB832FC0053A4BEE8C6FFE2432DCC9CCC0ADB75
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR................Q....pHYs.................sRGB.........gAMA......a...9.IDATx..{p[.}....A.!........?.8..4..i.m.X.6.v...m....a..v.v..:..ifkgg.z..X..nwvv,wg..d[..&..t.glY.C.$."H...{.....^\^......x>..I..!..{....w~.@.P(...B.P(....y.(..f../O..N2...`..%....,3..4..a(73}..(|A..".|./...p8z*..u.....7...o|..(.B.."..../..?.G.....)..M.^.>..;...........E.a.~z7.i......J..'8...{...r...Q.."........B....2.n.....E...=.GE...1..'.n'..D......L......+....J..]....|...G.87..%..P.......w...C...`ya..@..Q,...&J...#jhu.....h.R.;x.q.....\}.....EW#.a...a.X.;...(aPt=...C.aX.|..c8...EU.0(z.........W^Cu.0(.G^3...@..%.`\...#J...#.....%....db..}.3&@...E..>..Y4....2$..(...9p.F@.H.....4......c.."j ..(..{0^7..e.........5.`6.o...[.."...K.r.....#bo.U,..\...X9.B_..@.W..`.:..X...?8._..q......Y.r.0(....i|.t.r_.L..}.A...l.~[Y.8L.^..AD7...v.o}%..?.....qK.T...G...Z.<....P....Bmc.{.....~.O...x..D.3.(..|T......x.|....F$?m...6........;.ms!T..,..8{.|..H..JTD.S.....x....2..........i.V(..F
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 276 x 275, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):19622
                                                                                                                                                                            Entropy (8bit):7.964460896615546
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:ZCSTirkma9GdgvgI1QZB22IVMEyndB+cGthWFRi7dlQYNx:firkmawGYKzVc+ptA0dlhNx
                                                                                                                                                                            MD5:D1592D005A64FA7F6D7BCE9399A21535
                                                                                                                                                                            SHA1:571F4B18460FF47A95A77B8B4CFFC43665132586
                                                                                                                                                                            SHA-256:B3FE3FA9475C41A88F736AD8313228DDF33412CDB55032AB66E0C40267B4E7D6
                                                                                                                                                                            SHA-512:D5700F93B24614B6C11CCAABE300AF02AE8075380EEE7B596624F77A80B32D648D203DA006D63EB9AD35AEC3E185DCCCC545EB812D47D777FCE4D17DF3788FB7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............u......pHYs.................sRGB.........gAMA......a...L;IDATx....\..}.{.Y.&..J{i....$@.-..6n..,.k3Lw.H........t{........7..........1=..Xt..L.%.L.1X.-@...v.J..5+....s_..Y/.-y_..G..eeU.....9.....d...N.....H7..}.,.4....7M.F..W.~u...".P4..;....f......8.:b....p...~.,(.6..4..?..MB.,......(f.E/.T..(Ai...<5h...t2.=q..D.b.t.H. e..+{.r.......a...2O.Q..T|......]..X.d!..W.~. (..%(.....3N...t....X...dBY..1.^..5..(...Wr..]1..K{....!.J.,.3.p....C.<1|`...FQ.(Ai..F..}....6.....~.*........$P.=JP.....r3..\9sNj...A.Vv...>P.5JP.9`..l.J...L[.h..,.@..[..(...:,._..S..@JT..%(...t.....J[w'._..2AQQ.O}..EQ....h...i. ....xj..u....+.,e.....5r@....%(..Y.%..20...?c.D.U.2.R.:B...3h...^..c..D...E....JP...6}y.B.U.R?(AQ.B........@.JC@...(*c.....a._.(Ai......T..r.%eM/|.QQ;(AQ..e...s...4.C..y..4..8.B........Q.~..P.<JP..b..!d.O...=..h...(..%(...8.e....<T.hL..4...GP.<P87..;OEQ3D@Q....5t(.8...3i....5f@...l3.4Dum....(.$D..[\&8.....3....@..f.PC...]/<3^."..L{p@.F,^.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 201 x 200, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6756
                                                                                                                                                                            Entropy (8bit):7.951030240191849
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:pS+9td5bblCdVjUvfClRVD5BOj8vdEH0x:Q+9tzl0UnKp5BViUx
                                                                                                                                                                            MD5:D06A434769F945571023E8769557B8F6
                                                                                                                                                                            SHA1:BDBEFB036EA02A0CFCA1F2A508097D0AE90AA7A0
                                                                                                                                                                            SHA-256:0BCE929EC4011A5D69B37DEEFC5D197A6934B0B3FD369B7E94B48AE3EBD924A3
                                                                                                                                                                            SHA-512:C8D9857187F5EE14B2E57EECAA158715A0CC750E063DF1ADAC33AFC4A12CE86E905E2633FBF51C489E5318763C5347A5AE1BAA3EC6CB4D4281625E61A215EC8E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............B......pHYs.................sRGB.........gAMA......a.....IDATx..Ml....g).u,.Y..j.....i...b'...^.\....Shs.|........l..zJ`..].zI.%..:........a.u,...B.....]......V......}........w.^3...Z....SSS..m..&....a..O>...!..q...v....'.w....y.0jx....U.....H..r......{...}.W....}..$*...k...I4w^..g...W.....I@..q.....+..B..8..{.3....Z.......C..eX$.H....0:X(..A"....e8t..$.mW...W.?|..?..2??_.f ,.>.0fff.....*@.H!..,J..I.4+SO..f.b<~\...,0.>aX...<..f.^...`A6...c...`:..Hr..]+..^.........U..F........_.Z..f"E.F....E.1....]$...p..R......._...2Q"I:j..c...~Ke.:>.....#....2;;[...v>.w.i4..@.V+....b.........o......v.&...I..p.p..b.b..5.......L.R..y...]p8..Qy1;{c.R...I\.pEq..U....!..;......`.C.8y.I{D..6-.0...Ht...x\..]..GigW4..E..iP,........S.....Nqx....`...d..N..l.X..E~.4..\.<Y.'.?."q........Ac.....c.....".0h.....6."...>.q)z...P.@q\.(.<I...SQk6K@b..a0..9v....m.F....{.h....!.....Q..........b..B..<?.Qe.D.6.)r,BH.k`j...P.1..."^.QR...K0b..H(z..f.......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 201 x 200, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7617
                                                                                                                                                                            Entropy (8bit):7.944155200733493
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:pSsseu8KqDq779ZHPEKV0CHg8InzYJsFMOr85A3+YqtSfw:QWuZVpZH8eBHgDzKsFTr4AMSw
                                                                                                                                                                            MD5:94EA6CDA5A520897E4D0ACF2A78AA7E3
                                                                                                                                                                            SHA1:E15726ABF5DF7E9E0886C818ECAC8224ED745649
                                                                                                                                                                            SHA-256:CCF6F60DD727767420FDDA34154F9338E8EB1237CFD43B66D55939AE28DCDEEF
                                                                                                                                                                            SHA-512:443881E06CCA839A38244ABCBBCD122B4E1F9E81F249956007E935457414390190E431A89F8A5B89E47989757724871D7A2069F98441712F21E4A4CC92D34A69
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............B......pHYs.................sRGB.........gAMA......a....VIDATx.....}..g..]I....-...........A`...F]...z..4.....<h.....WK......A.P`W.CZ[.RI].q......j.&F`..Z.83'.7.....9s.......p..........H.../..~.VI/j..Y%nA.3...l.cn...r.^........u...:\|0.1.......:...V..D`@D......2.Z.2YE........~R..g........w.~..h.x.C".Hy.l.3..,^......6.nY..K.m.(..X..{>....6..!.(@Q|.T.^....g..3u.r.k....g....?h.<x...HH$..0......q@%.."....f....iB...6.C.H....U.^.k.I0.L.H..v.*RH'.h..-...."5.6..s?Z.F......m5....n-O.+..".........use...T.........*...u.....%2K..6....6..f...W..2~..z)e.4Qc1.keQ+..J.......].....}..=..&L.S!..K.I..}1..^cB.....w...GS....u46+..#..x. 9...w.2...D.$1q.Qp..1....Y...x.....*X..4.h.ENt...+W.9..e"E..88. f..B.h..4(.C.>.../.I.&...I..@.JT.....6.........E.#.`........[G')....`..w..S.Zw.@T..ah...(.Q.............^$._..r.zD.....i.0wj..1.G..E1..b.....{...?Y..).1....[k....B..P....&...x.L-.uA.....W..;.`k.7o.{.7..e...#08)..-s`.]Z...?..9#W".7....+
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9632
                                                                                                                                                                            Entropy (8bit):4.045654384803325
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:jUSSVnGzSsn2hwPYeTZK+GzoulH8OJo6Jbtyxo9+jRusFRLLDeWn4e:ASSVGzSoJweTZb6JbwkEukZB
                                                                                                                                                                            MD5:AD9F6D74C87EA1132769CD664291BA96
                                                                                                                                                                            SHA1:CE0EE3C4BFD3327C6ED6F19D50252619EC78CE06
                                                                                                                                                                            SHA-256:ED584F3EAA82F35F195C7ABF92E8D211BB76512654F3CE76DEF554BDD211C27D
                                                                                                                                                                            SHA-512:91DCF88B39DE827047356B2B72380B3866E13301E2A6BE15B53793933014CBA567D3A051A81BCA39CEBADFD641755BAE1A5C09DA4616F1B842BB3B3E6201CEE2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* CheckList UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.... ui.closeDelayTimer;.. ui.CheckList = function (options) {.. var el = {.. $checkListWrapper: $("#wa-checklist-wrapper"),.. $checkList: $("#wa-checklist"),.. $messageWrapper: $("#wa-message-wrapper"),.. $message: $("#wa-message"),.. $messageImage: $("#wa-message-img"),.. $closeWrapper: $("#wa-column-four"),.. $close: $("#wa-close"),.. $logo: $("#wa-column-one"),.. $state: $("#wa-column-three").. },.. checkDomLoadedInterval,.. animateDurationInMs = 400,.. self = this,.... setState = function (options) {.. el.$state.. .html(options.state.template).. .addClass(options.state.css);.. },.... setMessage = function (options) {.. el.$message.. .html(op
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4238
                                                                                                                                                                            Entropy (8bit):3.7823688858786118
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:kZ2B5nzQw2n95lN1i1BMHiKHzReZDeVBvwCh:kZEe0fIpHNeZDQBwCh
                                                                                                                                                                            MD5:6511C984D3369BE3BD0F02FE28DBDC57
                                                                                                                                                                            SHA1:B1486826379412D50840282F708D08D85B30C35D
                                                                                                                                                                            SHA-256:C6BE3E68BA49079B739CE7A26C31862B10B00D129092935FB31CA7D17727DF91
                                                                                                                                                                            SHA-512:D94B0A67C069B12B307B8B6249848A48029C8F7C85FBCBFD133B6C22990E1FFDF05A93D3EC2AB29DA3461F634C1EF9F82EDFBBB8E50D92CD9B52A859806AA40B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Dialog UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.... ui.CheckListDialog = function (options) {.. var animateDuration = 400,.. el = {.. $dialog: $("#wa-dialog").. },.... create = function () {.. clearDialog();.. createHeader();.. createContent();.. createButtons();.. },.... createHeader = function () {.. if (options.header) {.. el.$dialog.append(.. $("<div>", {.. id: "wa-dialog-header",.. html: options.header.html.. }).addClass(options.header.css));.. }.. },.... createContent = function () {.. if (options.content) {.. el.$dialog.append(.. $("<div>", {.. id: "wa-dialog-content"
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3395
                                                                                                                                                                            Entropy (8bit):7.880811480479431
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:WS0DKX8AWw5a9tRVEGCtbiHX+VGIGW09iYl1Avo:WS0DnAH5YRVItSLjIYDco
                                                                                                                                                                            MD5:E423607709409638253C24C3688A88D9
                                                                                                                                                                            SHA1:8ABC653F71614F6B707B01862449FC800D27EC61
                                                                                                                                                                            SHA-256:3B7849200BA0C2EAF22C3D111DAB6A630A00EA4A6EA968344EFB900E79084E4C
                                                                                                                                                                            SHA-512:BF70D4EE71BB441C7C36D0AADBB73C68B089D7E431694E54FC1606FB5CEEB8A30FB50F28FB5BDF5815EEC600364B0AEF98F57C23C8C160FCC704728918886259
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............>a.....pHYs.................sRGB.........gAMA......a.....IDATx...r.G..O.H.!..6..@Y.[..[./r..\lQ[......x..'`.....r...T..\d..m....X....56..K..9c..}.4.fF..U.I3...........B...b...3..%....c1.<.....x.7r..s...`./..<...WK&.......0v>?.2.%..4..y.....9. S..{y].9s&..#...>|.......\.Ry.4.G.3..9.=66....F........c)..Y.o.......b.....w@..-....q.....]....`,.bH...A.&.)....\7....79]...b..(....5.W.u}v4....!........:*....."..]c.*(`.)..u2F...).m.+x.f@BF..67.&&&4....@..;mn..+'...."..~.....T....[.......5.._.@u}o4..,..Ao.!.?.Gl...,f.......[..Uo$...'.{KO=.............,x.'...~p`.&...I.Psqcss.V...0..H$.O.A.......@.{...\..4.O.,.W. ..3...m.H.w..D.H..T*..6LQj.....UE...w..|f]..Z.q].Q3...rN>.....J]RU.F....q...~......./p...c3......{......L.+..............9v._..:..h..@o_....p..9.3......p...?....G..F=z.X.....#.1..A.?Rz}..I:....T}7..V.?.R.....X...Z.....H.C..OU...Fl.....a..?.......n<.VWA-.~....x.......{$..I..V..X.AU...^.|Ys....T...c.`...hg.......vy...{.v.......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):16591
                                                                                                                                                                            Entropy (8bit):4.4196633349386865
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:BZwBjFVz+j5csy4h11lidEaCaNz4UcEm7damvbat2RSFZC9On/P:WBQj5csy4DIE3oUUmMmvbaHH
                                                                                                                                                                            MD5:DB8946366F7FE015D78D693B641E9BB6
                                                                                                                                                                            SHA1:977C2A6228E318AC970A149FFD1EDF22D2117C9E
                                                                                                                                                                            SHA-256:5534A02FF547945751DD3509DE7A4D5A651C0B15AD22E0F45877E7FA1DD14676
                                                                                                                                                                            SHA-512:50F4C324B026749E6125DFAA0E0505237B283B6162FB1912A222F85FC3865B2524F2AD3798237154C83FE0807523318E1DF89EC074A7A17DD8CBE24DE259926C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Utilities */..var _langResources_ = {.. checklist: (typeof _lrCheckList_ !== "undefined") && _lrCheckList_,.. options: (typeof _lrOptions_ !== "undefined") && _lrOptions_,.. shared: (typeof _lrShared_ !== "undefined") && _lrShared_,.. uninstall: (typeof _lrUninstall_ !== "undefined") && _lrUninstall_,.. sstoast: (typeof _lrSecureSearchToast_ !== "undefined") && _lrSecureSearchToast_,.. install: (typeof _lrInstall_ !== "undefined") && _lrInstall_,.. webboost: (typeof _lrWebBoost_ !== "undefined") && _lrWebBoost_,.. waiff: (typeof _lrExtensionInstall_ !== "undefined" && _lrExtensionInstall_),.. ut: (typeof _lrUpsellToast_ !== "undefined" && _lrUpsellToast_),.. overlay: (typeof _lrOverlay_ !== "undefined" && _lrOverlay_),.. newTabToast: (typeof _lrNewTabToast_ !== "undefined" && _lrNewTabToast_),.. ssToastVariants: (typeof _lrSSToastVariants_ !== "undefined" && _lrSSToastVariants_)..};....(function (wa, lr) {.. var util = wa.Utils = wa.Utils || {}
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 14 x 14, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):558
                                                                                                                                                                            Entropy (8bit):7.494810764492959
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7iIHftwTmWkW3O+xbR/GfmNFycqV7o5jNiXrj0IGDfjo/1:zT5+aVefmORm8bnGD09
                                                                                                                                                                            MD5:F8AF1796D709A69C3FBDD16822596FD6
                                                                                                                                                                            SHA1:D216CB9A49EF4223138BE20D027B3ABEEFAC7DB0
                                                                                                                                                                            SHA-256:055E07F760351C3F33E708E4720D5A34A60ABD8D13F2FE05A473DFD5ED9714C2
                                                                                                                                                                            SHA-512:FBD9C93490B818798F4614E6EEA7EF9FA05D535F50071806E763CD9EBEE478559F614EAC90720E4B5F88D803DB0AD459F1D1C67954C2C379B1BB435CCA74390A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............H-.....gAMA......a.....IDAT(.u..k.Q....1&.k..T..bO.K...DP....I..{.PRA..............QA..J/....eM.tS..7..v...y.7.7.f..R?......W.......N.....G...z.N.a._.X=.sg.5..r.k....Z...R....[..X..W....N....v...H.1x......L......R..@:v.w.....W........v.lc/F..b .C\.:.[Q.`..E`.L.J..!....<..m.q....R.&...""%F(^M.`..e.,N..q..y<.../.O:.mP..,A.QrZ}[u0..,3...S.K.\.EM5.!mH......}N.+j....p.O.E.......[..C.\x......nMi...~%.vv...|8...y.xV..v<ZZu.....y]@.1......]..).6.M.'.'.%o.T..5.Rq8..l..;...Ha......5......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 14 x 14, 8-bit colormap, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):785
                                                                                                                                                                            Entropy (8bit):6.380231936591206
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:nmwBSRPy8iSvgv+aYS0NFVO/6cgDHNUPZ7SCOr2zhxNoEMBxNB:mwBSRVL4v+/jNFVO/6cgDHWhbOKHCEIj
                                                                                                                                                                            MD5:5367B11C1B0484E2B64AFFF761DB5B69
                                                                                                                                                                            SHA1:CA05EC2A55FAB6A4035920C38B6FF198044DA594
                                                                                                                                                                            SHA-256:1CAE0E0663BA559CA8FE7AD3A1E07AB23AB9E3DBADA1AA572AD9C2C5D51D5627
                                                                                                                                                                            SHA-512:322DF7AFB16185EB4D39AA4881A27E04B1D310773FCFBB77D0F1C83237A56D100F6567091E30BF0DC6A11EA29A22A52BF091B66C5863823596108C155C031588
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............(.......gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....PLTE...#..$..%..$..#..#..$..$..$..#..$..#..%..%..$..#..#..#..#..#..$..#..#..$..$..$..$..$..#..#..$..$..$..$..$..$..$..$..$..#..$..$..$..$..$..$..$..#..$..%..$..$..$..#..$..$..%..$..#..$..$..#..$..$..$..$..$..$..$..$..$..$..#..#..$..$..%..$.....p~.S...NtRNS........................T....L..........K..T...S.....JJ...O....r)1N.T......L...P.....bKGDOnfAI....pHYs.................tIME........l.-....IDAT..-.g..`.F..o.PISC.[.........|..s.@.Jr.PM.3.Ah.&....dI.01..t...v.K.h.o[?..^.....Gc.&..8....A..<..r5...QY.F..n.8..@=A.l.u.....n.C.....>.o.4...&!.KUd.&R$>.e*o..T....:...~g....%tEXtdate:create.2022-02-16T15:21:59+00:00h......%tEXtdate:modify.2022-02-16T15:21:59+00:00..x.....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 12 x 12, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):327
                                                                                                                                                                            Entropy (8bit):7.1140535970703365
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPIcWn2ofLbzmoGGaKdwjXI76l4AXT8ctmzXxNuJpTqAp:6v/7DWn3btahecDAuJp1
                                                                                                                                                                            MD5:C0708D1E58F1EF1BAB621620F3B09130
                                                                                                                                                                            SHA1:0BEB49A1CC1E71F364BCF42B474890F35CB8CC3A
                                                                                                                                                                            SHA-256:834380BD8B6F9BFEF000A555541AEC2BEC01DC46C91DCB7F950D109B81BAE5C2
                                                                                                                                                                            SHA-512:241C93BC2677B1F0788C2C0DDD9A7FFCCC7A865DAD427EA8C89E437FC796FD12F80D2A962A8D02B1B2391E10CFF768F17E34BD45502A0E31D6E1C8F443C2AA34
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............Vu\.....gAMA......a.....IDAT(...On.@........=J.&....5....8A..M]{..s......Q#0.7...0.......yr).q8..s....sp.....W.u.q+..;|.5&..n{..{.............>..".^S......#q.6B...4.t....~e.[@B.&...L.o...h..8.......Q....+..b.i..MhxRaG....Y..F....,......G.E....`(....V.v.4.b.$..S.O.....Sh.B....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 12 x 12, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):272
                                                                                                                                                                            Entropy (8bit):6.591404605834916
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPIcE/6TsR/nQV32e46OIoiMr6FRK7MhtCxllbp:6v/7DE/6Ts/nnPIcr6+ozCjz
                                                                                                                                                                            MD5:F79A1953A8E6CC342847B4B00DDBD736
                                                                                                                                                                            SHA1:9AC411CADB6652F4FDBD854300ADCB5C21C04BAA
                                                                                                                                                                            SHA-256:4F8EF204C1884F868866D03B4D11DF1237480C1CAA38ADEC1C13444050105B88
                                                                                                                                                                            SHA-512:DFB54D3D20FF53B867328945FE3D69B56055D5861EFCE2A069653B1792A5477AB4C3B73A3DEE82DD1377D1573099AB70C2F6C285C694DDBD0B1EE9667CFC4F2A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............Vu\.....pHYs.................sRGB.........gAMA......a.....IDATx.u.... .DW>...>.RRYJq>).>|E...!..3...t...a.?..w.!.P..../l....2....Q..ZS.%'.........y^.Q..H.T.V.D..W]..t.*X4t#9O;......=U%u0...f.......3`...[.S^..m..$..?[...{4.Y....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 14 x 14, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):428
                                                                                                                                                                            Entropy (8bit):7.367179920202989
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7iIHbGI9XbxzlcdqzUCOXC5pC38WWn9:eGIrzlcdL4CZW9
                                                                                                                                                                            MD5:0EF65600F5A2D01876B6F9EC668C9D2E
                                                                                                                                                                            SHA1:31F378D2D6BE62F3A426523B1AA3D61323B2B9AA
                                                                                                                                                                            SHA-256:17DC5C3BAA1D35CA60C7DEE7CC70B76446765769960FC5D4852E065478C871C4
                                                                                                                                                                            SHA-512:7D9EC74CECF8DF49D4F8E676053573798A029D889E8676CFE90891EB68E49A2FE9AE828F38BB99851888B25A76581EBE2B62694D3C66D193016B4446004A9271
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............H-.....gAMA......a....cIDAT(.uR.J.A..f..&Q..*....h..... ...(.........K...!Vib...B...qf..{.9....|..3C............@..........5..8.b...z`-....s.ID..G....PEQ.;?1...p.h;..z6Z..4.X..c..$E3s.b..ry.|..yVy...0.Rr..W..S.......A.1.....s./".j..g.H{l...Q....d................fE..;..'+.).j.F...J......~.s..Y./...6.v....|......,...m..[m....n......D.E.OvU.n..W<.m..=h#.O..Zm.yj..@.tums.....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 233 x 30, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5361
                                                                                                                                                                            Entropy (8bit):7.956335361585333
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:tXYxwio7C2guemm5poLpMmjxiN4f7DsCk7RkuxKBaKeVfGJiQmiMQ2qileA2I:toxpo9gKmsMmjwSXgyLBepQblA2I
                                                                                                                                                                            MD5:0D8F8EFEB474FC9B2C825D7F2A875471
                                                                                                                                                                            SHA1:ADBC30FD0131A01B3150753C7EBFD6EF648F0DE1
                                                                                                                                                                            SHA-256:ACC40FDA844EADDF65B9580C484F1FE2E17358B352D99BABC6865BF0C74D9B00
                                                                                                                                                                            SHA-512:90FEBC4B2165D37CBB1CF09295CF2F5B5713DD14A02CDC101318426CEB55D35B7C47B254D0F20CCB8297FC69EE77EAA5969FF98A0965D325C94AD81B6A56BA9E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............9B....gAMA......a.....IDATx...xTE....I .D..l,....(....Q.\..ftf...qA..D...?a..o.#.8..<.9:....A..."......KB...?7...M:......}7U..9..N.s.T..hZ"%$..@B...$$..@B...4!.UYY.E].Ln.%Qu.K.8....Z+I..m...m%v.6...K..]ki....W.}.y.%.O.1"dY..5...{...x.ef.X.~a..3K.u.l^.8'..?.z*#%.._.}.yT..Z..k..b..3{.{.>W_.,x,J......LM.T.>.x.....^..c.'...8^..(]...z(..._.......&..w..9..)..W.,s1.>.):.0.4.Y...nq...7....;......7)Xk.a...O...g.l...c.^..)8.%.e...h....U..7.O.'$.....]K.r0.Y5u..K....tH?.NSzwl.o..IG6...........X.(.z-.X....ju.+.Jpd.j......t.>...../?TW.0u..7........@B.. ....yYZ.iZ..:s...}_X2.O.....1kJ..3.*.9+... ].4.Y.2.....r>hM....}..-..|!d..i#U...F...Dr...5....D[..]..u._u....[.>.{5.xX...t.|L........}?........J.H?P.....M.n....-.......d......pQ....3..[...;vT.dg....5.@..0...[.c..1...U....i........a...o..[.PB.....E..^......."|........$..."V....tZ..`W...[...z.1..[~.Buu.[.........]/..x.(.`Z.A....`p...]RR.4u'u.]..u'...p..[sh..w.....g+
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 232 x 23, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2938
                                                                                                                                                                            Entropy (8bit):7.909981061900822
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:nv/69bTJ0Ji4hnEhRHzXJH3ndGzDr9zHUeqr7zpiT7efEgo3cRE0+U9sLBCYv2ZG:vSdJN7HziDr3S9i/efLQcRZ9sowGdK
                                                                                                                                                                            MD5:65938FC9439B2307513A95D515BCA1F7
                                                                                                                                                                            SHA1:DDDFE8D64ED371E973C46B6726B60BB0C0810BF9
                                                                                                                                                                            SHA-256:B2703E2E2A404B90EDAB7A67B23037C32BE2780F20CB15FFA6F6E44666B8EFB5
                                                                                                                                                                            SHA-512:93F755F5E208CA08955684D7789F6B8AF49F542DD41AFD9D678EC417CB535734C9C8182B87EC2EA8B8AA9FA502AC8BA90E383A9977F7E01BFF393AF0D1F400BA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............m......pHYs.................sRGB.........gAMA......a.....IDATx..\]R...o.T.yZ.'.8..y..f_"N.8.....`N.r... '.y...>,{..'.}....n..%[..!U.)..|.t...G..O?.. .~....@.N...a;..e.....1}.?....>.Ma...>.?..u.}L...m.N. ..8.>fe*.z..dr..u.D.1.R<.....T..J.......\.ZP..V}....M?...2..3.....)...T.yG.4...kO....t......b5...-....4F].q%c...-....v.2...O....g0...g.&R.2.n..<?P.q9.....+l3...X&T;...z."L).12..D..a.G3..OQ.Y....%..P.=.....2....%u.}4.(..N.!.)t....w...M.@.0.pt.a%..N...|.|\f+H.Rk.?..G..v.q.7.5.'..F}.....lm....rS[.4..F2..R.-..V......AU....!./.\S;...M/..K`..w...>.f'm..bf..y>..$D@......1....3.>...Cn!.:.........C*..-.PE14....$&}..?..I...._2.m.<....L.<.........92.p......jT....%.~..Q.U...6.4/.U..4L+HK.\i.z...Au.@>Z..Y.....kk...pQ..!....|..1g8...Uc$.....Y......9.....`0t..p..(...R.N....w`......\...<......M....-.95.f..W;xx>.7"..'..._z.REq.=e2..bg.S..r..VKcI.j.....\.O..T...q.>....H..6AE...{'?.....w.X.J...w.d.......O%..-%...1*.53..NPB.O.[M./.:..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 175 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2517
                                                                                                                                                                            Entropy (8bit):7.899112131446941
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:/O/6MOvIltQSb2EVW6+mjuOR6aPFUCJou7qDnUa+oNWsYFKaUCBmb:2SrOtQFglR6a9U2f7qDMoEh7UCU
                                                                                                                                                                            MD5:C5FFDD4032AA96D998DF4BBE0DFD49D3
                                                                                                                                                                            SHA1:46BACEE7C5C587024EE25C2E900C7580B1F12FF9
                                                                                                                                                                            SHA-256:010AF7BF170A9355D191C042768D37E4E8559EC4384F27EEA39A79C4BD1C3AE1
                                                                                                                                                                            SHA-512:BD89D324B107FC6B7806B3E5C098ED19C7D19DE47430D68C903F632A4471DE2C00B4290F306366C51EE71819AB8E4C9897C4827846EEE604F7F6539DCC38B6EB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............`./.....pHYs.................sRGB.........gAMA......a....jIDATx..Z.o....YJ"...[$r.(P#Fc.\."...^E.....=.:....@.9.....d.^...S4.6.@..D,."Ll.....Y..!.T. z...3o.y.W.....O.yrq....b.l......u.z............O*....uZo.]..A.xu1....M..c.+!6.N{,n.P..{B.<.....9....~.W..z-..#.1..q.7p5.._%ja....w..\.W..H..........By.%.?....CQ.Z...j......bV.f.....c.](..6..d...|)..hTe6.O....X.\.:q....^.I..fZ.y..q......}!.....v........U..x....].e..o...P.]...u&A._........c.<...P..3..cO]...z...:bFh.~....`......1V..&.......4<..{.*..t....S..j.S.s..Q........'../..b.PRn..P......`p.......@...8T.P.Q.R{..A.\.).N.i0...+.=<9...k+K..vz.DL.M.^.7......O.. .o...@... ...wU...m.3....x....l.|u-...2.M.N{^i.d.......s...R.H.`.09.;.....U:..c(.D$.N.(G.P.2.....T......r.W)...@h..1<..CI...<........M...X......$....[S..#.r..C3..y.R.P$z..).n....Gy.W......d..H{.3.q}....q....H..T._~...@..5....U......n.......1.)..'.M.x...Ab...x..=.<...&.x...k.q_.4#...l.6.i9.;.C.9
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 175 x 18, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2146
                                                                                                                                                                            Entropy (8bit):7.878767198815235
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:X/6uYit83CnCOqfU1paiFTeUpKJX9+E+orrs30ocDx4/OcrG1:XSXi6SnChfypRFTBpu+E38kNxKOcrQ
                                                                                                                                                                            MD5:39D8F472934136936FF3FEE841245A9C
                                                                                                                                                                            SHA1:812281447AAE48A891F8A5FA9CA63C117E5E9ED1
                                                                                                                                                                            SHA-256:DA9F72BF2AF97A5A1D5C8884F8D5BFB2CF232A7026CF9123E02F5909AAAD2F70
                                                                                                                                                                            SHA-512:7C3791E59F161A31486E36F6FB6A23E0589286342FE4A11D9DCBE975194ED0EC0EF223478072B2360E3CA276D6BA5BE0C4E2FE64FC82BC646945965E03556447
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............-......pHYs.................sRGB.........gAMA......a.....IDATx..Z.Q.J.m-.....G`9...?..".C.^"."@D.D..........8..........>==.HH.k1..v..y..zN?.d.?..nA.?.......L.M.o#...f.GOK|m..O...........KW_.P%...*.k.X.........;.v...|.|..KH.,.@4.....d#+{(WcN....... ......C..).CG~.g..M..*.jQ.y-S.u.}FA....4........b..9.&\.../)=&.3MY6Mc.5.SS.r.rI..NX."Q. .;PH.@..$....3l.(.1.x..|=...CE...*......Q~.J.......r....d.$.9...\\D.x/..;.%>,.p|.EO..].4"r..i......D..Z..%.-..bQ....m .~...k.a..n..lR...>p./(.f:-.k..lU.!.7..]Ut...~\9.....@...L...|...h.W..R..e..PV..vt.x_..I.h.4...]<...G..K.T.V.)...w.....,fv...^..)........)..........Y....@.8.....[..|x.wYYW.9.X..C...p..nP......p+|.-.q.F......>%........FL..s..?.J.%NH....;....b.dy.HN.13^.y.3`.zM.0.....u[-.....A.|e...4..P.3o1r>.y.`.gM}...H.R..;..F...<.zT..T..[.+.P..Q.>QS.Y..aN .>.....vc}.?u}].c6}..y...y[._....Z.@....P..o.S...^...yg......h....>.jB...+.1?.&V..V....<.O.......|uX...m...::..9...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 100 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1627
                                                                                                                                                                            Entropy (8bit):7.826159192497283
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3F/6TZYDTDiZweTZamTAaTJ6r/OIQz5URWkUX:3FSCXi6elamQ/Eb
                                                                                                                                                                            MD5:E6797831954D0AEADF1E7CD268F4BE8D
                                                                                                                                                                            SHA1:8CDEAC8420271C46DB443A03C58AA2E039EBDE50
                                                                                                                                                                            SHA-256:9EE5FC5E12400AE65711B9B664E75EEB3273C051E29FADF4FE2104B59C89437A
                                                                                                                                                                            SHA-512:EB53492D4B7BF87E09D049006E8759A87C4062950A9F88A636E7B7469AA5937DAB463DCA22294FE64A09DFDA19BDA711A6160E7762F147E5D2F5A95E3EEDE984
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...d.........{.......pHYs.................sRGB.........gAMA......a.....IDATx..X]n.F..%.@F.V)b[z.OP...O`...O`.H.j..h..>A..X9....A....E.Kv..H....7.%..(J.%...@.........n..DGN.sH......B...w[Y..R.....]..'......3.#...+........q|..).*.....$e.M.d.;..w...*.^C1.Z..h....O.o.X||.,.&A.....>).vF...p..S)e......./.y.pW.Ph.Z_Hy*.h..LG.{..,.b*..4.."~].qg.Q....(dx,..5...sFh/.n.0. ../....y....K*.......\F.R.....R.. 8z+....7 ....[b..dS.^.vQ.X.+.B....W=n.b.m.,..q.?...<....l.H3..V.a....r.V.|?XP..t.E$._?..k..[.x.].E....5....^y...b..6.9.u......e:....<@iV..-C%W.....8..C&M.o....!?KY.\o.6gr.j....../......@p......r&C....D.v:....[k}.X.l.u:..vv...Ve.....:.....J.@.~G...^4.M...4-W%....p.z....[.D.J....0....K.K.Lm...K....@J..vvgd*..Iyf........O''...%....MS....V..2.\2-..O.y.iLe..x....k~~.Z..6.H1.h.@:...;PF...l|...}.|v..)3..q....nw...6{...i3iM......}pe4..\..... ....d.]....D.`.a.C....FD.!/...s.4%.I....|S....-...nK...D....&Ov....a:H..V.&..."|.......:#.S...|..u....H.:..../...a4j
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 18 x 14, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2902
                                                                                                                                                                            Entropy (8bit):7.8683772202551845
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:i/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODW3O1:iSDZ/I09Da01l+gmkyTt6Hk8nTb1
                                                                                                                                                                            MD5:E4C0EC02D11F61DA1A702B0EFA2EC744
                                                                                                                                                                            SHA1:F4E64300F14D0BEA27129A72BE91A668A9B9FB9E
                                                                                                                                                                            SHA-256:2AC30B35B0BC163BC18B3B4B2982A6EE4095202FCF2EF8E35BCD415D8FFE04A8
                                                                                                                                                                            SHA-512:6E659358DC715D700E4FB9BED2B8054408D3BD79AF8B492D6197D53038990AA12558957CA9C4BD436D83C2507DF165C55F2F0FB4E93C13480DF932E58E16EED1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............".L.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 5 x 6, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2816
                                                                                                                                                                            Entropy (8bit):7.867254837776759
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:/h/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODM:/hSDZ/I09Da01l+gmkyTt6Hk8nTM
                                                                                                                                                                            MD5:59934A5C534B8372CC2ACAD83B1F55E6
                                                                                                                                                                            SHA1:8285F5654E3A077445E73685ABFD638BE7F1F4C6
                                                                                                                                                                            SHA-256:130541A07A3D9E2050A6AC15D659E29A21F080F6CB1D7DB2800255FF94FD8310
                                                                                                                                                                            SHA-512:37D1BA15D460F33B62FEF40B32DB95F136C268727AEF5ECFDFD3ADA471D26C78FE89438D0BF13FD966E19FBB7A9E06BD3FA27DFC326AA42699330145AD634BCE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............TK....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:GIF image data, version 89a, 4 x 18
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):376
                                                                                                                                                                            Entropy (8bit):5.513362384873133
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:772Q1kVEn88d0e6FEVU5drwF0cVe6FEVU5drwF0cVe6FEVU5drwF0c4e6FEVU5dH:772LVEnl6FEC5drwns6FEC5drwns6FEM
                                                                                                                                                                            MD5:BFE2AF9C7C0433C86314783E61A437BA
                                                                                                                                                                            SHA1:4CB221B2CC8ECDE82AA813C3E136DB749BFCE3A1
                                                                                                                                                                            SHA-256:0DD3C3D9570BCA1ABC663C5E301B9CC8025F92EC0C12B6781A8A521663A8DB75
                                                                                                                                                                            SHA-512:22E3EBE60BCBBFE6B728885CAE1B16BDB8D980B1AA80F931DDAC4020EC13CB7F3AE80CCD0A1A7465FB513D1AC70AEB59B12FB5E88CF6EC809EB178CCA2DB5405
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:GIF89a........2^.q..Aj."Q.a.....Qw................E...!...2...,..........#p..$.u24.K2)....0..d<..0.....h;.3..!.......,.............I..8.m#.!...2...,..........#p..$.u24.K2)....0..d<..0.....h;.3..!.......,.............I..8.m#.!...2...,..........#p..$.u24.K2)....0..d<..0.....h;.3..!.......,.............I..8.m#.!.......,..........#p..$.u24.K2)....0..d<..0.....h;.3..;
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 13 x 17, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):391
                                                                                                                                                                            Entropy (8bit):6.968282594262006
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7Y4njM9CusK7SWlR4oPfMrjbi7voD7:0njM94QSWlR4oP0XbVD7
                                                                                                                                                                            MD5:A85D5FA023FD935DDA508A42B9DFECC4
                                                                                                                                                                            SHA1:2EE82A16CE7120CB2B211A3502E63023DD011C4B
                                                                                                                                                                            SHA-256:A47F084F275C50D52E4E74E44E554E4810210029337B13DCE3E98EF29FDDD35E
                                                                                                                                                                            SHA-512:1E07CC1A5CB220AE4C3FFE1860DA715C2C9E569B79A61818B4FCC2EDD4C9C6D05EA597DDAAB20B37950A005B642CBBF995AE809C0774D2D8584D87D2C366BADB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............&.....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Adobe Fireworks CS6......tEXtCreation Time.10/1/14........IDAT(....DA..._.V.%D.h.(x....(6^.+(<..3H4:...S*..M&...2.w.f.w.sNf"...s....0..6...8.~.`....u..(.0pU.~..X.&Nq_xn".6:..a.......SJ.6("V.u...H..]....\..X....k5z...Z.q..X.NhR..X,f.....Y+0...jhXC)..`0X*..}~..&-..J..>.:@..;.......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):449
                                                                                                                                                                            Entropy (8bit):7.31532155890383
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/74/6Ts/MYcGVkHcafQ2ueaTxpJz8mbEYST43v9u:x/6C3VkHnQ2vcxputYST43v9u
                                                                                                                                                                            MD5:DE0508D8669FC70B4D92B58076D288DF
                                                                                                                                                                            SHA1:AE206B763654EEEB4457853BDBD46A510A693ACA
                                                                                                                                                                            SHA-256:2ABBD585797B5DCF4CFE7908B5325E51CB5A0A5EEA117723A78444D484C1B269
                                                                                                                                                                            SHA-512:212BC0318562BED2CEE66C6BA4855F9F4A6A69125B869859AEE7BDC3F08A02EBAD9C6F5C432E6DDB3C091E4D8796FCF56AE6F2253A0C40DC2DDE7F97F49B3413
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............w=.....pHYs.................sRGB.........gAMA......a....VIDATx..U=N.0..R.....J`.1...%6...#p....M.'ho.#.7..ea0...*M..8.*..>9...s...=..~....+..1.....R.-...t`$.si=....W2...E..,...$gh..{.j....<.T[..O!A<.?..&<'G...!.M..T..|.@H....N..S...K.8.Z.p@....|M~...(Lc.........).......E.....#....C..]sxlS.}6=....~.._.?.;.K..5..)r7h..nV.E.).=.F5.u3.2i..)`......*.....$@.}..] .9W.7......8w...y?....r.OW../c;.v.^.....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2354
                                                                                                                                                                            Entropy (8bit):5.633221367466797
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:RRlHOHSm2ejO/XYJ8ZRSLiPcvfkXKGm3kqZQuVQQBKwv:RSHfz6fEcsukvfqm3kquQUwv
                                                                                                                                                                            MD5:7169C5E4E176BDBE7D40E69398C96FFF
                                                                                                                                                                            SHA1:C3F3A9B8F21C11214E0091F9496207ACE7345749
                                                                                                                                                                            SHA-256:4388582267EE6EDBD053B96CBE9747A736BB564B11BE5C2DFC2C60564C3C462D
                                                                                                                                                                            SHA-512:0FA589D2D41CF5B40C4C96BD4835287221C8A7524EE843A7A4F465FCC310839EE4F2412841AB971AF15000A27E8A76C9B6BF6EED1D25F42CD44364F0F2A84DD1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...9...9...9...B.......X...6...9.......9...'...B...)...L...6.......9...+...-...)...B...L......GetOption.settingsPpackages.edge_search.search_ext_popup: web view is not enabled or installed.info.log!is_web_view_installed_and_on.common_utils.utils.corev.......6...9.......9...'...B...1...K.....Cpackages.edge_search.on_search_ext_popup_coachmark_exit called.info.log.core........--.......X...6...9.......9...'...B...K...-...B.......X.......X...6...9.......9...'...B...K...6...9...9...9...B.......X...6...9.......9...'...B...K...5...=...6.......5...B...1...K...........tooltip...balloon_type!edge_search_enablement_guide.ShowUi.EventData....onExit<packages.edge_search.on_search_ext_popup_coachmark_exit.EventData..web_view2_ui_templatecfile:///[WA_FILES]/mfw\packages_web_view\webadvisor\edge_search\edge_search_ext_coachmark.html.UiTemplate..UiType.overlay_uiPpackages.edge_search.search_ext_popup: web view is not enabled or installed!is_web_view_installed_and_on.common_utils.utilsQpa
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2200
                                                                                                                                                                            Entropy (8bit):5.875568146350153
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:920riK5mljJJVdRquhrp6G5hRCmkasNfK0xxPUCyo:PriKOVJ/RquhrgGHRjstK0xSdo
                                                                                                                                                                            MD5:D025A17244204760C0F7D3A9356E62A5
                                                                                                                                                                            SHA1:AD60FF86E7CC76584907642E341776CEFD1CEC87
                                                                                                                                                                            SHA-256:FB16B671B4A7EDD07CBE8F5D695593F40EEBB30997F8AA1A84BE42375AA4F2EB
                                                                                                                                                                            SHA-512:A5F5EE4A01AC1C352BFBFF71F20F422B80FFB37851F7B68F13FAF570505FFAF3BAB08BBA36701F425DC3B71B5E428A0A6F75F50E2828C1BB6784317F9F2EF063
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..:.......6...9...+...=...K....checklist_showing.mwb.packages.........5...=...6.......5...=...B...6...9...+...=...K....checklist_showing.mwb.packages.checklisttype....checklisttype..ShowUi.EventData....UiType.mwbChecklist.web_view2_ui_templateGfile:///[WA_FILES]/mfw\packages_web_view\mwb\wa-mwb-checklist.html.onExit#packages.mwb.update_mwb_status.EventData..UiTemplate2wacore:mfw\packages\mwb\wa-mwb-checklist.html......$...9...6...9...6...9...9.......9.......B...A...6...9...9.......X...+...+...J.......X...9.......X...6...9.......9...'...B...+...+...J.......X.......X...+...+...J...6...9...9.......9...+...'...+...B.......X...+...+...J...'.......X...'.......&...6...9...9.......9...+...'.......&...+...B.......X...+...+...J.......X.-.6.......9.......B...-...8.......X...6...9.......9...'.......&...B...+...+...J.......X...6...9...........)...+...B.......X...6...9...9.......9...+...'.......&...+...B...+...+...J...6...6.......9...+...'.......&...'...B...A.......X...+...-...9. .J...*...6.!.9."
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 95 x 72, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4147
                                                                                                                                                                            Entropy (8bit):7.943867399456676
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:rwd191zRv2ElL3+eYGSRCvWC7P4cHALED9gqwptnaO6:rwdXjv2Yz+mbuuZ09qwnaO6
                                                                                                                                                                            MD5:96E5352C228F18132282903C3CA79F35
                                                                                                                                                                            SHA1:9D7D72FB9134B222D7FFE36811FCC82FAB5FE0B1
                                                                                                                                                                            SHA-256:64BDF768575AFA7B3ECB4786F55F67983F5EFA2A8882D1F0131F8C28F646F5EA
                                                                                                                                                                            SHA-512:992F49CFAEE0692705D769F906CBCF7479FD87D2506D95DACF198E3457D6AC5A91776C710312405A7B5FF651B8C97CB10DD54B5D86DA202B8A1E9CEFC7D53955
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..._...H.......).....sRGB.........IDATx..\.p.......n...G....D$.b.H).2.tl.Vgj.....L[.N;c.T.vZ:.b[;..C<PK....$*.p.B ....{.....mv..Hv...!.?.....{........i.g....~..hnu:...l.B#....4........6t..........$^..|..l.M1u7$....8u...hYy....#..Z...|.u.N.?$..#...n....<..O..j....d*&......*...^x.?.9}...=..^.... ''...J.;.8....]...Lo.\tvtb....gW.k<....._.c.........2.k....NG.....F...FBBB@A._$se@.?}.c...._{......o.l.5%.F....@..:<......._.'.[...$o.....X.x>./X.}.......M......;.a%zzzQtCA..P.<}....B.#..C.7....*|...a...L.-m8..)....V...|..sf*q.j..RPp.r_s.<..:.am.tZ./.7"7;.{..Bcc..-..7.O......^....Y.i>q#.I.>.[.nG]]..'.I..i.............&..o...uy.::....r.8q..a....1.............y4._C\.nZ..{..7.|..u:-.W.Sz...2...[..G...e.7q...\......]{QT...w.q...q.....<.}..QTT..^..?..If#..{..ErR"j....^..9..9.=..x%.lCFZJDeH...d.....9........p....>.C.......q[i).>:...7....#!.=.....V..N...;.........O...C........W....y.ts..x..188.GC%..q..G..-PDSV.....E...47.lhh..5e..+....N.|..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (315), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9731
                                                                                                                                                                            Entropy (8bit):4.511171296508002
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:b4H4SSJczePaYszA8XnTMAPVwqAc7g4UM+:MYSSJes8XnTDPV4c7g4u
                                                                                                                                                                            MD5:718CE1B892CEB6151C1A89B418CE8457
                                                                                                                                                                            SHA1:CEA68426F13210D1DE72D0169D6F92D9479272FA
                                                                                                                                                                            SHA-256:D90B950687B7B090A7C2D68341B082564E1054ADA60F9854D6305E7807B1FE69
                                                                                                                                                                            SHA-512:5B1D79CCF7FF9DF295AAA595DD8EC42660B7470794903E9D6DB23A4983F890126814C5DB7F5A265A7ECD0A636CC533FEC8052DA915B83FB31AC0DA5F9A7682A5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* MWB CheckList Controller */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _tmpl = wa.UI.CheckList.templates,.. _core = wa.Core,.. _window = _core.Window,.. _lrt = wa.Utils.Lang.ResType,.. _l = wa.Utils.Lang(_lrt.WEBBOOST).get,.. _checkList = _core.CheckList;.... ui.CheckListController = function () {.. var self = this;.. var browser = _window.getBrowserType();.. var wbShown = "WBShown";.. var wbLastShown = "WBLastShownDate";.. var installDir = _external.getInstallDir();.. if (browser === "FF") {.. wbShown = wbShown + "_" + browser.toLowerCase();.. wbLastShown = wbLastShown + "_" + browser.toLowerCase();.. }.. this.update = function () {.. _window.ready(function () {.. var args = JSON.parse(_external.get
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2398
                                                                                                                                                                            Entropy (8bit):4.93822260700824
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3OTFbMv26ITWDE5CFqOcqehQORDe2SVXA:EaEIqOcqiQq62X
                                                                                                                                                                            MD5:C12300C6B42BAAC68B61C8DD1BCCD123
                                                                                                                                                                            SHA1:E0BC246A5783C9B1548FCBCD3973EB73A0020A56
                                                                                                                                                                            SHA-256:3ED4AF8DB1B04416E157A1B3D569156F0F43C1E51AF18B59D17523E26FCC2C8D
                                                                                                                                                                            SHA-512:9F1E39762811D3E8448502D3C8468AA4F4254FB562F1D91B0982F38AF7C037009A1B15FB0A64B59835C0DDD63B93AFACFA3864BED50624943CF802E97A306781
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-checklist.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-webboost-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-checklist-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:m
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 20 x 19, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):435
                                                                                                                                                                            Entropy (8bit):7.339595422017506
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7op8DZNN+N/mjoPou/d3mFiRWpK2NV9V6/v7CFmP1:lwwN/fPouV3mkWvn9VSmMP1
                                                                                                                                                                            MD5:17F00098D9F726B994583103F81EB7AC
                                                                                                                                                                            SHA1:18DF2437F9019ED8A7E111EEE48E1CA17F3BB19A
                                                                                                                                                                            SHA-256:71983847EA4F7014741BD89DDF4A33AF884A7636414E55912077CC00959199B9
                                                                                                                                                                            SHA-512:2BD4C0C36B43B61E1544C99E4B8B7C46789EDF91206929EF7EB1F7E5E5B810439D2A673E3EDC200BAC295003D544B9B9B94275AA29D3DDE9F5585E550553E6E0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...............-.....sRGB........mIDAT8...=K.A.E.1...&....X..(.....V..h.O.....J.l,l..t.je.."..Z....B.DD..d.f...f/.f.{sov.%.T..a...p....R..6X.O0..;.w....7...,K=V .n..'*C....D[..ds.N.4...W..C..]..}0uM1.. .^...C6..O{.3....8....\...t.#.Fc..eks...x...K.....W..o.}@.N.pH.l..H.E.....ix.....z.1....=....P.SG.y..]CL.p....=.@..`..^..~/.8.,k..5(B.........di.IZWi..t6........&..n.c...4.'..e ...]3..........[....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 70 x 69, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3947
                                                                                                                                                                            Entropy (8bit):7.943205117846418
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:XpIVSotMeomWtuupLHgHzDJhbpmV3G4fNjirxU:mSCJodtwTDJhFu3G4fNWq
                                                                                                                                                                            MD5:744E7ECE73DE770613033AF4C28735FE
                                                                                                                                                                            SHA1:F7598A712AB76AFBFC8B880FAFA9C307D0942952
                                                                                                                                                                            SHA-256:7D324265349E5DF77B3A3A56112E5D13B7A1C9827C4B886205DAB99C279B19E5
                                                                                                                                                                            SHA-512:2BB6285603F134BFC6B3B0AA9B4F97B4156D354558AC3B73CE5661988D3A6516528D79DBCA1F82996BC395FE780F41AF7CF144ABAA3CAFC951C0D3FE0A08B165
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...F...E........*....gAMA......a...."IDATx..\.l\.....zw...^{.qpBB...........KA..Q.P.Am.......j..E .r........P..BI...hP.;.......|....}o.y.g.1.d.y....7.....f....C}........f..gE.Y"t......I....d.>d..O,r.&.d3+.x%..G.J...$...P8.....FC.4!..0A`.fk.a.n4....A|..~.@,..'....7tF...Q..C........d....Y.&2..29.HR"..Fs..L.J........<sZ..0..f..[M.A........?w..FcIJ...l..A..l.H.h.L.Fj...+...L.g.....)..x.f..M]mQ&^.Q........-^..v.....n...Y.-.pN`..j!..N.#..?4*g_.`>.s.h.?I^. W..E.K$ a..M.Dc.....{..z8.."...40..v.+.f.......C..Hb?.H*9..1+.\N./_K...082A...(.%...;H........".....n...=.#%+.&.b`...wP...e.t.......X.......:;..+......../.N.............>o.*Jb.#v...>..].j9g5_.....;8(f.).....V..V....J.Q.g.........>.?.p8J...v8..,.$.>.n..aE..;.m#.t.J.t....wkKY>...\Q.e.Rg.....1.....Dc..&EQ4.....t..."......'.?.&.c.I.....I..:.i...:...9..UUg...z..kw9....7;.O..xVq[...s~{..`.SO..E.....n]..gv..w.ib:.F.>...Uhi...z..p:r.].+]...U.m....ZB...P..1mm{....9.a.c...:..l.....=v.g..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):301
                                                                                                                                                                            Entropy (8bit):7.008936185757553
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPfAlD5bn3S1bu/6BIMYE00yLbOxD/WeahrkSiuBZ4dp:6v/7HAthII3MYEJ41lBiuBiz
                                                                                                                                                                            MD5:B437E1CC057558224FEBE4A96FE66CB7
                                                                                                                                                                            SHA1:DECA512775F0FF42BB1B6F734BDDD07DBCFA0AA6
                                                                                                                                                                            SHA-256:5F233229050143BA35B24A5DA5E1DB5F2ADCFB0E0F2B78707FFEAF39DAA19249
                                                                                                                                                                            SHA-512:EDACD7B9B7674FABB02BA5CB3B2BB5156C992C95715A71D6415353F9B62E9936335F490D2AE4CE7D58DBA68AAFC583AAEAD482D25DFAC459879CF289E2EBDB0A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR................a....IDAT8....JCA..?.[...$..+.........|....BD.....i.*..V..h..+.>....*...X.s...f ..U..X}..B.U.s~SX.}..2..=.........0Q...D]U{.M.?../..}....... .eu.x..~.6..3`% ....y....+..BP../..8.)pm..\..M.h..Q.....-..Y.....u...T....S..0..e..%....u.8].^.........1....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6035
                                                                                                                                                                            Entropy (8bit):5.764128715208747
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:iGHQe1nDk6k/Lap8sPnYuOKWi4s0reMRkyi0DlbwOxjHXExCDw:Ce1DkFsPnXLWRs0reMRkyi017xjHXExP
                                                                                                                                                                            MD5:7482EABE836445A6C8FDA14A4E353014
                                                                                                                                                                            SHA1:C176AFF8F7129E9B691A3F6B5ED52F501AE2101B
                                                                                                                                                                            SHA-256:C7D0F5B0E46EE308C4FC511F3CCEC0E7A4038B7BCF02D9B3C3681A268CA7A888
                                                                                                                                                                            SHA-512:E6EFAC00A5A8BF329583A1077B73E74F2D94903F5F21473CB48D0A4D2B6CA57297CD8CC51D11757A014A88839CD97AB16B381D4A69C341BE2D6222976D29763C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...9...+...=...6...9.......9...'...6...6...9...9...B...&...B...K....tostring*[NPS] packages.nps.isSurveyShowing = .info.log.core.isSurveyShowing.nps.packages........#6...9.......9...'...B...6...9...+...=...5...=...6.......5...=...=...B...6...9...+...=...6...9.......9...'...6...6...9...9...B...&...B...K....tostring*[NPS] packages.nps.isSurveyShowing = .isSurveyShowing.triggerType.shownTimes....shownTimes..triggerType..commandName.showNPSSurvey.ShowUi.EventData....onExit$packages.nps.UpdateSurveyStatus.EventData..UiTemplate2wacore:mfw\packages\nps\wa-nps-checklist.html.UiType.npsSurvey.web_view2_ui_templateGfile:///[WA_FILES]/mfw\packages_web_view\nps\wa-nps-checklist.html.nextSurveyCheckTime.nps.packages![NPS] TriggerNPSSurvey start.info.log.core..........6...9.......9...'...B...*...6...9...9.......9...+...'...+...B.......X...6...9...6...9...B... ...=...6...9.......9...'...B...K...6...9...9.......9...+...'...+...B.......X...6...9...+...=...6...9...6...9...B... ...=...6...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with very long lines (458), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):26004
                                                                                                                                                                            Entropy (8bit):4.106993065693765
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:toM7vbmeN/beqwi1y42ykBkbae2vx3D00:+Gbm4i+1M
                                                                                                                                                                            MD5:4A4FA65EEE365D21F9472C766BCEBD07
                                                                                                                                                                            SHA1:BAA05813862F4458C37DAE97612CB4400C7A9612
                                                                                                                                                                            SHA-256:D1C2AF320923448FA198A84A10CB85EF17E6932E15A41EAAC1BBF046257D9B48
                                                                                                                                                                            SHA-512:C2699F065E347AA8066E8BE307E7DB6FC72B619D933B611710D12EF094B2A2F458A7D10D26756BF4E4F1438ADE15E3B927057F3D6ED99C63E2FEDCC29739F102
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* NPS CheckList Controller */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _tmpl = wa.UI.CheckList.templates,.. _core = wa.Core,.. _window = _core.Window,.. _checkList = _core.CheckList;.... ui.CheckListController = function () {.. var self = this;.... this.update = function () {.. _window.ready(function () {.. var args = JSON.parse(_external.getArgument("template_args"));.. if ($(window).height() >= 630) {.. self[args.commandName]();.. } else {.. _window.close();.. }.. });.. };.... this.showNPSSurvey = function () {.. var html = "";.. html += " <table style=\"border-collapse:collapse;width:450px; height: auto;font-family:Open Sans; color:#53565A;border
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2305
                                                                                                                                                                            Entropy (8bit):4.925005434064277
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:csY0TlGNVMz7tVMz7EVMz7VMz/VMz8AVMzjVMzJVVMCFqOcO/TP3G+PxCQOR1FEg:3XTFMv26ITWVMCFqOcqehQORDEsD
                                                                                                                                                                            MD5:BC8B8A7112D4C26814EA5FC4EF0016AD
                                                                                                                                                                            SHA1:C3BDF889D3A0C6C22F6177CE92BD3E375EE23EB5
                                                                                                                                                                            SHA-256:AB05C74F771C1B31157779B7BC7B761A30B59967340BD14F288909A752046123
                                                                                                                                                                            SHA-512:57B13FB0C6AC3A1140AAF9A8DD5C72D7F7B9F9D9B6B39EA93BE00833FD1C65E31D988A7E1C643561D4A898BD8443E81A4563BDB7CB0BEA93F0C5CCD0665EBDA5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=9" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-checklist.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-checklist-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-ui-dialog.js"></script>.. <script type="text/javascript" src="wa
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):477
                                                                                                                                                                            Entropy (8bit):7.351051330229087
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7y2VDhNOYjroguA84jleUzz0BDdbNSp42duo1:wVlYq7kC02yNSp5Qo1
                                                                                                                                                                            MD5:8DD33EC0D498CB6C2FAA490D5FFCAB72
                                                                                                                                                                            SHA1:E278EF1E92293D41820D83E115A7195E30509BAA
                                                                                                                                                                            SHA-256:C43CDCDA1172EA4E55CD6725B5FB3B0F2ED9F8AC2C3DFAB3CB5A927550C00492
                                                                                                                                                                            SHA-512:20257C6B39D94376C69118E91480F101B96E168E0C1AE599E505E76C4785A08C7CEC0297B84B8FB99EC690C16FEBE8985C8558AFEE13A7503D053760FB52B242
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.....................gAMA......a.....pHYs..........o.d....tEXtSoftware.paint.net 4.0.19..d...ZIDAT8O..1(.a......QJ1... ....2.3..`R2.u...*.h1. ..,.1...=..9}.........y.._....E..M...%;j....}|.Z....m5........;..,.v.l6...X....^].F./{.q.-V.0.sGaf...\.S.*WV..7.3f{U.A......Q.....L..%.Q..\.'....M.Q.lOn~.;.p]s...j.....5G...c.QV|a..(....1.+..W:.2l;....b....)7.3`;.....Z...Y.....KY.V...Jx.V.G~..V......+.!..U,.........|.O|.s.`...'I...-Ps4m."....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):621
                                                                                                                                                                            Entropy (8bit):7.440301212402691
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7y2VcCkoWVpXHvC+N3Pei2PrEyBvatOrED0uapdvoXP:wVZk/9/ei2D6d07m
                                                                                                                                                                            MD5:CAE22AF422FC994E24E8CCAE7ECDFCD2
                                                                                                                                                                            SHA1:E237654EE11A51773BBC840A27F79D6EB2DB0000
                                                                                                                                                                            SHA-256:48B34A024F5B925DFB6B8973876708BDD49B363712E74981078661D638E8440B
                                                                                                                                                                            SHA-512:8A818292FB67F81A7339DC2866EE5884DBF5DD97707F6567F4B1A6DA7CDD8FE8ED8BBEAB04CA610FFF2C1B80C36A1873ED331187FD9A8BA8734DBAA401076379
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.....................gAMA......a.....pHYs..........o.d....tEXtSoftware.paint.net 4.0.19..d....IDAT8O..1H.A../!Q....@@kI.H...AmR......w.'.W(j..UHa%H..b.(....R^.B,...!M .I.B....x'..`.._.....y....U.e.D.4.D..Z..Z...I.+...B...i~.R.=.2.Ci...3.zw.c...;...n.ju...(.G.e..(}..<w...Y.R.b..v}.='0.V.^.tQy..,rf"T.B.Ry..&..._sQvw...%g$p....8.8...,...R.I..........'......g..m..^F.7N..Q.i.....<..O.8....y..<"..I}...,...*...<R&...s..;\..J.'8.G....f..o...l .^...(e^..;..t.._.....F%...k$.......:.'..u.n..g....@..N...E.....m....4M.\Do...H.b^?...t....}.......}Ahl.G....~..>.@..3g..U(\.Q....L......IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7069
                                                                                                                                                                            Entropy (8bit):5.1158379235764695
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:OWZxXMHRMroWa7b6xEgPGquAED+YhAAA8b89Y/5Pbqx51E5hh565/M7buH0eFDeW:OW0H28Fguf+y89K2kCdMunbH
                                                                                                                                                                            MD5:DA38A5E3FA021CA0E9369FA61CC3C877
                                                                                                                                                                            SHA1:6DF68EBE3079FB3A73204CF97ABAD6BAF5A487ED
                                                                                                                                                                            SHA-256:1E1599C4C24FCAE4F1A19B19BF21277D3210D6A3ECF155B767940A628C890223
                                                                                                                                                                            SHA-512:6FF562D1E2577294FDE65240B177FFBA950D90AD26421C4AC1D5B3DD6BFB892D7AEB916E23F78FD55FC3108E30C67CD4246204E467124C3A422C7E10E0B82219
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* version 2 3 */..* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", "Poppins", Arial, Helvetica, sans-serif;.. font-size: 12px;..}....body {.. background-color: #f2f2f2;.. color: #212934;.. line-height: 24px;..}..../* Parent container */../* version 2 3 */...toast2_3 {.. position: fixed;.. bottom: 0;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. background: #FFFFFF;.. overflow: hidden;..}.....toast2_3_larger {.. width: 761px;.. height: 565px;..}.....toast2_3_smaller {.. width: 761px;.. height: 500px;..}..../* version 1 */...toast1 {.. position: fixed;.. bottom: 0;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. overflow: hidden;.. width: 524px;.. margin-bottom: 6px;..}..../* version 2 3 */...card__content2_3 {.. background-color: #fff;.. margin-left: 297px;.. width:fit-content;..}..../* version 1 */...card__content1 {.. background-color: #fff;.. margin-left: 150px;.. padding: 24px;..}..../* v
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3649
                                                                                                                                                                            Entropy (8bit):5.081162908198535
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:jMsaeRv26XbWZNG50ybUYoA1gPeaNS6cD2QXIan75FfEl:jDbGNw1AYomgPeaspDfXIandO
                                                                                                                                                                            MD5:2E0C29524877E42439C96690D076A58C
                                                                                                                                                                            SHA1:971F598A61BC322699CA2BBC121603AC0E3908B6
                                                                                                                                                                            SHA-256:A3CD22B2F53A0BF69A217D1B48CF1627F7B26BE33E0C1083D11A71503AF09DB4
                                                                                                                                                                            SHA-512:79131D93033948B63559F074139E5BF7B4E898FC07341D77968A5F9C5B453709CDE48E14BB680B8D757E5C1D0D2CC8E0D5ECCCDD2C48AD19DEE28DC8A8F92EF6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>.... <head>.. <title>WA SS Toggle Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link href="https://fonts.googleapis.com/css2?family=Open+Sans:wght@400;600;700&family=Poppins:wght@400;600;700&display=swap".. rel="stylesheet" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\aj_toasts\\wa-aj-toast-toggle.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-sstoast-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\pa
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7536
                                                                                                                                                                            Entropy (8bit):5.116758318348117
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:lAvUEJU5h6oVXuVdDE6hYkBaWPwT0JrrvG10qAvlaVXkfldXF:mvhJYrV+fEGIj1bVUdtF
                                                                                                                                                                            MD5:5E844B469ABBDEDFB4DA21AC1E37A143
                                                                                                                                                                            SHA1:760A76CD1476D6D9642DA62ED433FB09FC25E28B
                                                                                                                                                                            SHA-256:3C1972F7E069789006A13B076526748E2804A852CC3CB963BF16EFB0CF667F6E
                                                                                                                                                                            SHA-512:21E0BAE0F3C42C0C25A657A1D9F440474709760BD5104C4136F8089A85F2D6E4308F1EFC22263EA3593BD5556085B27B9D995FEE7F58C2B0C7B28770DAC7EDA6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _instrument = wa.Utils.Instrument;.. var _settings = wa.Utils.Settings;.. const TOGGLE_COUNT = "toggle_count";.... ui.accept_extension = function () {.. var $el = {.. version1: $(".version1"),.. cardContent: $("#card-content"), // different css for different versions.. cardImage: $("#card-image"), // different css for different versions.. featureDisabledSection: $("#feature-disabled"),.. progressPic: $("#progress"),.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. feature1Label: $("#feature-1-label"),.. feature1Name: $("#feature-1-name"),.. freeLabel1: $("#free-label-1"),.. feature1Desc: $("#feature-1-desc"),.. feature2Name: $("#feature-2-name"),.. freeLabel2: $("#free-label-2"),.. feature2Desc: $("#feature-2-desc"),.. checkboxContainer: $("#switch-se
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1238
                                                                                                                                                                            Entropy (8bit):5.704980533812439
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6wBTG+3j9qlatg94bXSx7ngIdMKWF8gGX5p0TA5+CUTm2X+0XLYJAvM2:BBiIj9qlatVXEngJKWqg8+CUTvxXLqA3
                                                                                                                                                                            MD5:7B318AA9AEEF6B2FC46F676281E71CA2
                                                                                                                                                                            SHA1:C35493B7AF124AA746F60E39DA5B9A0100FC49E4
                                                                                                                                                                            SHA-256:2828777A6FE9009E76598C92530A3B9215918A4392CC6AB5FD5540A833E3B8E7
                                                                                                                                                                            SHA-512:51B21277A6EFF823E90D9BA6AC2CAB7932219014B80D1889507912703D12582CAA5016F21977125C65B21F3AABA0EB1DEC41ABAC654DFE70550520A8A8C3CB21
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........J9...6...9...9...9...9.......X...6...9.......9...'...B...K...6...9...9.......9...+...'...)...B...).......X...).......X...6...9.......9...'.......&...B...K...4...4...9.......X...9.......X...9.......X...6...9.......9...'...B...K...9...=...=...9...=...9...=...'...=...=...'...=...6...........B...K....ShowUi9wacore:mfw\packages\webadvisor\wa-amazon-upsell.html.UiTemplate.EventData.amazon_upsell_toast.UiType.toast_cohort`amazon_upsell_handler: amazon upsell requires toast_count, amazon_extension_status, and url.err.url.amazon_extension_status.toast_countEamazon_upsell_handler: amazon toast upsell is disabled, cohort: .amazon_extn_toast_cohort.GetOption.SettingsDB9amazon_upsell_handler: amazon upsell only for Chrome.info.log.ch.BrowserType.BrowserUtils.utils.core.Browser........$6...9.......X...6...4...=...6...9...9.......X...6...9...4...=...3...6...9...9...B...9...'...'...)...B...6...9.......9...'...)...'.......B...K....upsell_amazon_toast.event_amazon_upsell.register.handlers.a
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4661
                                                                                                                                                                            Entropy (8bit):5.817994241035366
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:XE0GptOJE462KfH+ge9YYdWkHm18LbWQY6guNx6gk:Uf8Ej/+gKPWkq8XPYduNx6D
                                                                                                                                                                            MD5:FD3B335D806C8CAD98DDA121CEB7B977
                                                                                                                                                                            SHA1:A4D7D3A76EF0FB23AB8480D06CD3EC8E5056B0A9
                                                                                                                                                                            SHA-256:696A025E9730DE200A85127C3C2253E1AFE7D9F836291A22C66137EA5A968A0A
                                                                                                                                                                            SHA-512:18E9BECC79A56B7DD2B9C8580F79EFDA28CBDE50FBF2662A60EBACF863FF869BC412345E960CEB804A96C7F6EDA2B66B01875A9072EB4C039025C36BFD3C57F6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........5...=...=...6...........B...K....ShowUi.EventData.UiType....UiType..web_view2_ui_templateJfile:///[WA_FILES]/mfw\packages_web_view\webadvisor\wa-checklist.html.EventData..UiTemplate5wacore:mfw\packages\webadvisor\wa-checklist.html.........5...=...6...........B...K....ShowUi.EventData....UiType.downloadWarningToast.web_view2_ui_templateHfile:///[WA_FILES]/mfw\packages_web_view\webadvisor\wa-dwtoast.html.EventData..UiTemplate3wacore:mfw\packages\webadvisor\wa-dwtoast.html........U6...9.......9...'...6...9...B...&...B...9.......X...9.......X...6...9.......9...'...B...K...4...6...9...9.......9...+...'...+...B.......X...'...=...X.).6...9...9.......9...+...'...+...B.......X...6...9...9.......9...+...'...+...B.......X...'...=...X...6...9...9.......9...+...'...+...B.......X...'...=...X...'...=...-...'...........B...K......checklist.showChecklist.showUpgradedUserWelcome *DisableUpgradedUserWelcome.showCryptoLearnWelcome.*DisableCryptoLearnWelcome.CryptojackingDisabled.showNewUserW
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1682
                                                                                                                                                                            Entropy (8bit):5.571913634634723
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6ICRoYslDAbfu+oqxMdiyUZXuUBRCziQGePQ6NNL9aN+j/bOJjI:+YkbfuhxdiHuUKtGaHy+j/bOJjI
                                                                                                                                                                            MD5:E5766C1FD44D8EE493D5202B0A9E93F2
                                                                                                                                                                            SHA1:507FDC8FB49CC2AEFA89F1239BCF688B00AE936C
                                                                                                                                                                            SHA-256:ECD2F3584E6E28DF0ACB3A8996FFF3CC8E02732A38104B1FABC8E3D4504FD6D8
                                                                                                                                                                            SHA-512:6F9E9E86067F257DB424CCA0E9BD84780AECB0DA37F20447C00DAF80D18288245AD37C88B0906CD5E449069D944B64CEE6AE9C49D8F46A3089B7A6A585CDA8B5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........&...6...9.......9...'...B...6...9...9...9...9...9.......X...6...9.......9...'...B...6.......9...'...'...B.......X...6...9.......9...'...B...K...6...9...9.......9...+...'...+...B.......X...6...9.......9...'...B...K...6...9...9...9...9...9.......X...6...9.......9...'...6...9...B...'...&...B...K...6.......9...9...6...9...9...9...B...6...9...9...9...9.......X...6...9...9...9...9.......X...6...9.......9...'...6.......B...'...&...B...K...5. .9...=...6...9.!.....9.".....B...6.......9...'.#.....B.......X...6...9.......9...'.$.B...K...6...9.......9...'.%.B...K...!chrome_ext_push_handler: endRchrome_ext_push_handler: Failed to trigger LogicMsg browser start on browser.OnBrowserStart.encode.json....Reason.browser_launch.IsExtPushTriggered..Browser.., no need to engage1chrome_ext_push_handler: extension state is .ext_no_entry.ext_enabled.ExtensionState.ch_wa_ext_id.get_extension_state.browserSettings. is not supported.tostring&chrome_ext_push_handler: browser .ch<chrome_ext_push_handle
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 170 x 167, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5286
                                                                                                                                                                            Entropy (8bit):7.918352410896778
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:VadOXrG7NapBuqn5EVYrylb7le57jdIt5X/pu660z4GKbAkhYaPQGflW1:B7smri6ryhGGX/JNzoAkhjYGfe
                                                                                                                                                                            MD5:992B99090456FAE196C91BFCA1630D5B
                                                                                                                                                                            SHA1:5079D7427DB7384162CFD4917A87D1B9C3235A55
                                                                                                                                                                            SHA-256:F86960D443E848E83A2BA3B27B68EE488623A6E6E80E74594E69802FC472AC8C
                                                                                                                                                                            SHA-512:80A8DACF479B444979889F0D9B5DDE429AA794D8D7E1430B4555571513FB3FB5F6F950B2FD989A7DF9B4EBAB7ADE271B5C8A635C4B247FD9D3D97EA96FEA0AFF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR................\....pHYs...%...%.IR$.....sRGB.........gAMA......a....;IDATx..{.T....{.a......GO6...*E..`.n!<$+L$.ML...X1.qe..V........M\.2C.v.'....uf...$.Vx..0.. P............}o?.....3}ow&...;...HA.ljYLzj..:Q.........(."I.LOj........Q4q..)-2....\..>_.^."K.|.f))H..F.XTF.XTF.XTF.XTF.XTF.XTF.XTF.XTF.XTF.XTF...'.V5..b.G...4.Qv.a._..21...4...=...g...WD.....\.......d;.....6......D..N$2........3J..2J..2J..2J..2J..2J..D.r.t.-T*..n..OS.......C. .....r*..^5...E...n..%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%`Q.%.[..fc.....:.g.0..Su.%^...kkg'.Z]K[...).?H...N|z...[..v.z..........x.>|8UVV\y.....X..xf..g.....5v.r..?_@..K..N.(g..?....o...cFSuu.F...kcE..V.....o.LRY..9j<...i.>...>S=.n.i.x.....k.......VB#.ow.b.X[...^.3..w'.#......P....}.....<.T.F.b./U;.n.{B.8.v..t....rA.W.....[......h..5T...<U.Pg.Pk..5.~v...J'.B.5;.ijv..vB.Q.?.-.3u...R.S..kj!].....H.T..o<Pr..PE.eO=).H.I5 l{..I7.d../V....N.Q.P..E...u..E
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1239
                                                                                                                                                                            Entropy (8bit):5.772003971685495
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6uhfXWnvmJJdPObNlpwgMT9CFbzxX0TA5js2X+0XrB2T:dhfXguTdPCFM4bPjNxXrMT
                                                                                                                                                                            MD5:68179B44FCA2D4E28A150AAA035C55F6
                                                                                                                                                                            SHA1:3FDAACAF09F869EE78C8B8FC98AB4E1C6DFB1F61
                                                                                                                                                                            SHA-256:11E9E1FB984B24FC1191FE78F42BA82A0679EA6CE850B2457EDFE94503FBB38C
                                                                                                                                                                            SHA-512:EA6048A3BF9B3DD1A277184C1EB4AD697CA97F70AF680E8224FE315CBDD61008D89AB0FC9C31629D63697527C93C865E561C45FD791B4FFB349EC356ACB447CA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........<5...=...'...4...'...=...9.......X...9...=...6...9.......9...'...6...9...B...&...B...X...'...=...9.......X...9...=...6...9.......9...'...6...9...B...&...B...X...'...=...9.......X...6...9.......9...'...9...&...B...9...=...6...........B...K....ShowUiEshow_ff_extension_install_toast: got implicit close event name: .implicit_close_event_nameRfile:///[WA_FILES]/mfw\packages_web_view\webadvisor\wa-ext-install-toast.htmlCshow_ff_extension_install_toast: got custom WebView2 template .web_view2_ui_template.web_view2_template=wacore:mfw\packages\webadvisor\wa-ext-install-toast.html.tostring=show_ff_extension_install_toast: got custom IE template .info.log.core.UiTemplate.template.extension_install_toast.UiType..EventData....UiTemplate..EventData.........$6...9.......X...6...4...=...6...9...9.......X...6...9...4...=...3...6...9...9...B...9...'...'...)...B...6...9.......9...'...)...'.......B...K...$Builtin_InstallFFExtentionToast*EVENT_SERVICE_InstallFFExtentionToast.register.handlers
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):407
                                                                                                                                                                            Entropy (8bit):7.1407976551071055
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/74/6Ts/+smsfwZQlyCzDSkG+ZlfDN+y9X:x/6afkRChDZ1DEy9X
                                                                                                                                                                            MD5:52488EF2BAA65366C96F39947B5CEC32
                                                                                                                                                                            SHA1:580C1612E3D607EA8C3C83B03285ED6B5E5AFC23
                                                                                                                                                                            SHA-256:C0E9102EF0C19E55052516B7B11F95E96A13A93A19DA66328DE5B66740CE4A4E
                                                                                                                                                                            SHA-512:0D54D10933E441EB624CCE78C293162AF8150134199D7C2AA54554476CDB70983A3CC069B23D3C93D736612C80EF6C31CA1842EB72385FA4BE359A40F36A5B67
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............w=.....pHYs.................sRGB.........gAMA......a....,IDATx..k.P..H.....;.P:..Z....[.QG.I\..]}L...... 8..........1W1\|../8.....|9.;.r.@>. ..(HZ.%'p.Y..;...[..r..m...Z..&.l^.....k-B...Pk...~?.....{.....b...f...}...ty..C..`...@<..,.]..R<u~.{@f=.w.<..x|.zsjq V.......I.KC<.}.....V{.l].Lg2..v..m!c....@g..-.>...@v ....L..l.y.>.)....."....%....P*........IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:GIF image data, version 89a, 148 x 50
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1686
                                                                                                                                                                            Entropy (8bit):7.777921392960299
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:I/sUg09pp/qKHlZpbkXt8K7n5bTh5lTdAiwy9QntZ9C:onJpp/qKXpbU2g5DlT+i9QnY
                                                                                                                                                                            MD5:DFD80EC6F7EE421AEAF3F785922438EF
                                                                                                                                                                            SHA1:DD3FCFB2BF921A6C67933093B1AE64CA23E1AF26
                                                                                                                                                                            SHA-256:FF31AC8E9802988BE162D31CD350711F460E8AB292CC45950C202ECD1A8FEEAF
                                                                                                                                                                            SHA-512:8391CD280487F73F7FDF5529BB6677696BC815DC99ADD5AA229EBE1B569B94C1D8C5370A86C0665F5F20CF918325B23338EAAE347FE441550C0758A687297C06
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:GIF89a..2......'.....-..&..,.."..,..(.....-..!..&..+..(..5..)..(..2..$.....!..2..&..*..+..1..&..... ..%..0..6..*..&..+..0..-..:..5..+..0..2..-..5..5..;..@..6..7..=..?.#<..>..E. C. >.#@..<.'H.$E./K..N.*S.,J.6I.,O.1K.+@.+N.1N.)W.4W.>J.9R.;P.6W.=Q.:V.DW.A[.GW.>].HS.E^.J].Bc.EX.Mh.Nc.J[.Re.Pg.Mg.If.Pb.[h.Ls.Mm.^o.^u.]p.gt.dt.jy.g}.qz.u|.{{..~.x..{........{.............................................................................................................................................................................................................................................................................................................................................................................................................!.......,......2........H. 7Z[<DX......#J.H....3j...a...B..)O.?~.....J..........8s.....@..MP...HM..._.. 4x....X.j.:..Q."..S........a.*.p..I.(.....O^...6..Pu...}............A...3kF.x.g.'..........`.....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:GIF image data, version 89a, 27 x 50
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):369
                                                                                                                                                                            Entropy (8bit):7.019028949718389
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:aPd7Wm9a7S6xP+rDzujMhsACN1brSF+dmz0fmBDbf92buPamIPW19mW:aPd7Wm9a7zGDu91Ppdmzka/f8bQasX
                                                                                                                                                                            MD5:3D32D5CBF24BDCC2C74E876AAD4C19A0
                                                                                                                                                                            SHA1:E4F405F07DC0D870A2CF4E5EEF48C91393676290
                                                                                                                                                                            SHA-256:7456A5B53B0E7BAD980926BA86EF437ABB19F5C2D397031C83B27198DEA3C5D0
                                                                                                                                                                            SHA-512:DB97E6E8E062B75FE46D49558BDA19674AA574476F85458A22A536FD07384618524007342098E5FA095532A2D8CFC2612CAD0AD77AC406E5C12029E48F112830
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:GIF89a..2....................................................................................................!.......,......2.....".di.Y..l.bp,.tm.x..W...`.B,...r.l:...tJ.Z.X,e..z..xL....tZ.n..pxdN.....^.........................................'..#..................................................................................................&.....#J.H....C..;
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:GIF image data, version 89a, 2 x 70
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):361
                                                                                                                                                                            Entropy (8bit):6.510176350874939
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:DvjkRhk/NruDE9Q0QVlMjlFGCyzVwFECgVp/R5i9pNoj3f31XoB/fNfkc/:zjkRiFrFQ0QELV8VwFELjZ5ii3f3No1z
                                                                                                                                                                            MD5:2D1CCF8BB4F2013151F9BEC12542D9A5
                                                                                                                                                                            SHA1:9AFEE504C285A2FD7B09BA3AA745B3CD4AEA3ECE
                                                                                                                                                                            SHA-256:8CE5E1DE817FCEF6618DC2279753936423A975ECBA3C28732FE0CF0DAA52E1D3
                                                                                                                                                                            SHA-512:C640B6921D144E76417CCB433CD7B0359FCB8298E546454AA31067FF70D4356DB86A223C83E70F2C43F46420CC4D6554834D3998150DD2D6257F65F8F7708942
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:GIF89a..F..2...$..$..$..$..%..%..%..%..&..&..&..&..&..&..'..'..'..'..'. (. (.!(.!(.&&."(."(."(.#).#).''.$).%).%).%*.%*.&*.'*.)).'*.'*.(+.(+.)+.**.)+.*+.*,.++.+,.+,..........................................!..Created with GIMP.!.....?.,......F...q...).V..+...0....XX.j.J.P...d2.H..H$..@...C.p8..F..`.........................................................A.;
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1059
                                                                                                                                                                            Entropy (8bit):5.249212112534314
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:xmp5UoZR3xQiD3RJMZcUhiLKyFc43bZApRmWo0p+oh:xmp5UoZJxBTM3Q3SDf1o0pL
                                                                                                                                                                            MD5:AE88695F4ADDD20D33EA6AACBB7F1D25
                                                                                                                                                                            SHA1:8DC007E69E01A3D1BBD2153733104811D5140886
                                                                                                                                                                            SHA-256:A2B29F3671BEBA78918FB3CC82ADB90DBE501BECF1B4495359032B10E06DD3FD
                                                                                                                                                                            SHA-512:DEC7230018A67EFF845138EFB68700034A003A4402AD72757E1C97784F108EB0D1FFD3896E7B262318444E75B2D90C87644E69EFA1CC76CE5D595155A332BB7F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. background-color: #f2f2f2;.. color: #212934;.. line-height: 24px;..}.....balloon-chevron {.. height: 20px;.. width: 20px;.. border-top: 2px solid #E6E9F0;.. border-left: 2px solid #E6E9F0;.. position: relative;.. top: 10px;.. transform: rotate(45deg);.. background-color: white;.. z-index: -100;..}.....chevron--centered {.. margin: 0 auto;..}.....chevron--right {.. left: 337px;..}.......balloon-main {.. box-sizing: border-box;.. background-color: #FFF;.. border: 2px solid #E6E9F0;.. border-radius: 24px;.. padding: 24px;..}.....enable-ext-btn {.. background-color: #4989EB;.. border-radius: 4px;.. border: 1px solid #EFEFEF;.. color: #FFF;.. cursor: pointer;.. display: inline-block;.. font-weight: 600;.. padding: 2px 8px;..}..//0D423BC8330C17B5B4E4C044594DC91C3192F1BEC8579C99ABEF24DC5D02DB03B0A7FFD
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1585
                                                                                                                                                                            Entropy (8bit):5.2846423292021445
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:LswDjYlGNVMr7xnVMr7EVMr7VMr/VMrlpVMCrNM/QogXORMeu2J68WF:oOjmxuneCKCEQxymF
                                                                                                                                                                            MD5:ABF7554B9F2E6199B3DF205DD0BB1084
                                                                                                                                                                            SHA1:795F0DCFDB12CD34411F0F24E165D7109B976E15
                                                                                                                                                                            SHA-256:854F591ACDACB13376410E99F5D9245BAC0FE293D15DC03982919C3F2C51B979
                                                                                                                                                                            SHA-512:046ED98143B13CCF173EA5DBA1650C63A4EA23BDB98F1C562B0CA5218E18C1F2AAABCFC1E055DC7F743A8461156D8BF770D1045532A0A52043A095FAD149CB62
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\new-tab-overlay.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-overlay-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\new-tab-overlay.js"></script>..</head>....<body oncontextmenu="return false" on
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4111
                                                                                                                                                                            Entropy (8bit):5.083124051310355
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:T0AmdonK4uoOPV1PixEeB0NufP9SdaQbXkTJsR:AATK4bs/jeCQS9bXt
                                                                                                                                                                            MD5:473EE8868F2C6C123846FEDDEA5D8220
                                                                                                                                                                            SHA1:3E4FF22A368CC8A7191615C1EC7A98FF30A4336E
                                                                                                                                                                            SHA-256:90B448842B7527F46D92D7F359957DB5DCDFE4F0600AC864D950BCBE8560A339
                                                                                                                                                                            SHA-512:7ADAD4C83DAC4DB3F7CB10163EF5A8A41DD66840BC7F90D02C175924A40A7394C36C594507B68267BACBE975868E3BC7D8BD058BA4CADC93548BE6C0760C7BAD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = (wa.UI = wa.UI || {}),.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument;.... ui.accept_extension = function () {.. var $el = {.. content1: $("#wa-dialog-balloon-content-1"),.. content2: $("#wa-dialog-balloon-content-2"),.. arrow: $(".balloon-chevron"),.. },.... show = function () {.. _window.ready(function () {.. var settings = JSON.parse(_external.getArgument("overlay_data"));.. var overlayType = Number(settings["overlay_type"]);.. var extensionType = Number(settings["extension_type"]);.. .. // Polyfill of isNaN for IE version < 12;.. Number.isNaN = Number.isNaN || function isNaN(input) {.. return typeof input === "number" && input !== input;.. };.... // Validate toastCount is valid;.. if (Number.isNaN(overlayType) || Number.isNaN(extensionType)) {.. _window.clo
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1660
                                                                                                                                                                            Entropy (8bit):5.235995809978379
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:xmp5UoZJxwqqZlmlXMwWlYAlCiIpcDFru:xArxzqvmfWlYAlcGDw
                                                                                                                                                                            MD5:FB8EF52C258FC344B95AA5BFDD8AA77E
                                                                                                                                                                            SHA1:7A64338DE9C5891A0C43FEEE277E318338495F6A
                                                                                                                                                                            SHA-256:C2613A3876EB168728CD4FF9933EEB0FC6D079B265A5A2C83A1CBF535261BB50
                                                                                                                                                                            SHA-512:39FEAF64C8764A02659261F6AC21E0CB1A3F05F733B1721924FDDFE705ADCA7F536595A9402CA4E48C800CD68DCB11BF5E2DA76F4930D7E48A5A8F1A01D19FB9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. background-color: #f2f2f2;.. color: #212934;.. line-height: 24px;..}..../* Parent container */...balloon {.. overflow: hidden;.. height: 255px;.. width: 505px;.. border: 2px solid #E6E9F0;.. border-radius: 24px;..}.....balloon__card {.. background-color: #FFF;.. height: 100%;..}.....card__content {.. height: 100%;.. padding: 24px 20px 24px 24px;;.. ..}.....content__images #wa-logo {.. height: 17px;.. position: relative;.. margin-bottom: 10px;..}.....content__text {.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-weight: normal;.. font-size: 14px;.. line-height: 20px;.. padding-left: 24px;..}.....content__text > h1 {.. font-weight: bold;..font-size: 24px;..line-height: 32px;..margin-bottom: 16px;..}.......card__image {.. float: left;.. height: 100%;.. margin-right: 24px;..}.....ca
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2027
                                                                                                                                                                            Entropy (8bit):5.174314651406783
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:LswDjYlGNVMr7w9VMr7EVMr7VMr/VMrlWWrVMCrAedmsQ26qK/OFhItaIwV/qIPN:oOjIxneC4WCCFy26qAqIMImqIuNZEH
                                                                                                                                                                            MD5:C61D30E433E043A81964C66234189A36
                                                                                                                                                                            SHA1:A4A60D150AF521EBB07AB860A377D9188618448B
                                                                                                                                                                            SHA-256:05B8A62D01E2582B7FC61F06C7C5861231BEC9EB60343627053E973F091E1063
                                                                                                                                                                            SHA-512:1313BDFD44F075966364FB32102C9690C2DE8FDCC8E3218FAE1C6199E50254B8D863ECB278149279DC045E280B97DB3E9F0DF91BEDD169E42CF7CB8A2145C11E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\new-tab-toasts.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\new-tab-res-toast-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\new-tab-toasts.js"></script>..</head>....<body oncontextmenu="return false" o
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3498
                                                                                                                                                                            Entropy (8bit):5.173544369475828
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:m5Y7fVMKxAX955IGIyy8CJ/Z1gu0VKz1hauWSvAM0w4SVzz2eE/NXkN1n:n3AXKffHguIKz1hauWSL0WVf2bXkN1
                                                                                                                                                                            MD5:A79B65FF309360695882F58E59B1041D
                                                                                                                                                                            SHA1:7041D648B9476BAE73A68C6AD64855DC40B970B9
                                                                                                                                                                            SHA-256:C2FF635BC8A1240BC781F33B05053CCDEFF3E31861107E23B47B1FA2BB577510
                                                                                                                                                                            SHA-512:BF9BB26100EC477D0992F4E8AEA7FF11BC79D0128F9F26F7303EB81891F936A683C2224289022431C47C4233A93CB7BD959894B28289C62087130629BFB940C7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = (wa.UI = wa.UI || {});.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _settings = wa.Utils.Settings;.. var _instrument = wa.Utils.Instrument;.. var browserCode = _instrument.getBrowserTypeCode();.... ui.accept_extension = function () {.. var $el = {.. balloonCard: $("#balloon__card"),.. headerText: $("#content__text-header"),.. contentText: $("#content__text-description"),.. acceptBtn: $("#content__actions-accept"),.. declineBtn: $("#content__actions-decline"),.. };.... show = function () {.. _window.ready(function () {.. var payload = JSON.parse(_external.getArgument("overlay_data"));.. init(payload);.... _window.show();.. });.. },.... init = function (payload) {.. var lang = wa.Utils.Lang(wa.Utils.Lang.ResType.NEW_TAB_TOAST).get;.. var toastCount = Number(payload["toast_count"]);.... // Polyfill of isNaN for
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 155 x 252, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9836
                                                                                                                                                                            Entropy (8bit):7.914414293589123
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:4SzlM0MAc3Z+8WM/h/Cl3oKSo5i1TL999zhgwfnt1ztUOTGgz7dEM:/zYcc/Cl3nSoIxL9XuwVhtUOTGy7dN
                                                                                                                                                                            MD5:89FC18BBBA9A69CFEEBFB5ACC4E9089C
                                                                                                                                                                            SHA1:1FC704BA2ED65674BC9DD7B7D882D8F588C1F898
                                                                                                                                                                            SHA-256:DDC5EB8EEBD2874C5774A4266EBF0A064FCFBF94A34686839B3FDF7E73235F62
                                                                                                                                                                            SHA-512:12099A1DA49A4AEA5A5BEA2E41C94E8151743191B48AD6B0F099B43A3532FA57ED7D335C9A2748BAC7F43C11212C04CA63D42E38B0D278C20A3A0D2DBB49A632
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............`..n....pHYs.................sRGB.........gAMA......a...&.IDATx..Y...y..........")..J",J.ER..(mh......a....~X.F...v..z..#|...."%..D..i.4...%..@..qc....g.3.*.2....{.s03.lTu.=S...jr..9..b.. .!Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1Pl.1R.....Jp...{.S....c0.~.V.(.ef..4<.....k'l...y.v....jDG..=G.Y...~.7.........|........m..+4.........`..b[&..#4.7..YX.........Z....m.8v.| ......J..f...'.."..J.lX.0....?z....n'..}...dPl]...S.....`%.n..p+.).........../o.l*d.;...>4...._.".tPl]D....3{...<.....eVA...f......{.C..Z.nO?.*.tPl]......F.....IB\^|.......n%Pl].$4n.U.lb...,
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):8509
                                                                                                                                                                            Entropy (8bit):5.661293428262151
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:NLDvJHOV9mMOoxNkya6eQ4fV356VPUbkOtxO:NLDvJHs9LWB6eTUVMbO
                                                                                                                                                                            MD5:98EBCF3476AB4A6BD3073B2CA58248A5
                                                                                                                                                                            SHA1:96D26050B42BCB8ED858EF5A039E8A0350C0FAC4
                                                                                                                                                                            SHA-256:D2DFEE520D072EEF92D196CE3BF49EC3F7F19EC915949AE38449A13CA694116D
                                                                                                                                                                            SHA-512:2242B693060CBA1969F6105D7468CB55FF9D5989E081A12012D71022489C1A6D22E73F290483CDC0A2330604F4E354CB76977AE0C0C2AD98D38D02D50FA0A9E5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........-...8.......X...6...9.......9...'.......&...B...+...+...J...6...9...9.......9...............&.......B...+.......J......GetOption.SettingsDB.utils3overlay_ui_handler: Not a valid browser type: .err.log.core........66...9...9...9...9.......X...6...9.......9...'...B...+...L...6.......9...B.......9...B.......X...6...9.......9...'...B...+...L...6...9...9.......9...+...'...)...B.......X...6...9.......9...'...B...+...L...+.......J...Doverlay_ui_handler: edge onboarding from process start disabled.edge_onboarding_option.GetOption.SettingsDB,overlay_ui_handler: Locale is not en_us.en_us.lower.GetLocale.utility,overlay_ui_handler: Browser is not edge.info.log.edge.BrowserType.BrowserUtils.utils.core.t.......6...9.......9...'...B...1...K.....Apackages.builtin.on_search_ext_warning_coachmark_exit called.info.log.core........P9.......X...9.......X...6...9.......9...'...6...9...B...'...6...9...B...&...B...+...L...-.......X...6...9.......9...'...B...+...L...6...9...9...9...B.......X...6
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5962
                                                                                                                                                                            Entropy (8bit):5.806694956330883
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Nr9fZOY+cM0cyS6fJ8YfrmJ/zAbWIYCx7B3it0BZkJzg9g/0pRu0heDBoQSQPJdQ:t9fX+VmS6zfrIIYCx70cZkJ09g/oxhew
                                                                                                                                                                            MD5:402C57B5A5B5E7DBABF63513B218D74C
                                                                                                                                                                            SHA1:AD550C41A36203F82734F5BA9D43521FD437AE64
                                                                                                                                                                            SHA-256:7003380895DB75B85AB96EC37E4DDB8D458C8A714F0D794D88C616D79E3AACF0
                                                                                                                                                                            SHA-512:AD7DE3917D1B1FF9D8065D7F57B2807B03037C30F2A0478198D01E35E009270C2FB0AC9C09F5A22AC71CF6491D7AE6A5D1BE321FB2154714BB8DAB484E3C89D6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........!6...9.......9...'...6.......B...&...B...6...-...B...H.......X...-...+...<...6...9.......9...'...6.......B...'...&...B...F...R...K...... removed=packages.builtin.updateSSToastStatus: toast for browser .pairs.tostring6packages.builtin.updateSSToastStatus called with .info.log.core-.......5...8...L......._ie._ff._ch._msb._edge.........5...8...L......2Global\{8DB68CEC-1C6B-46B8-8808-90838C14CA3F}2Global\{F84F0E05-209D-427A-A977-A5AEAA90EEBA}2Global\{64C7DD73-FBD5-4B1B-8A82-B49950F36A97}.........5...=...=...6...9.......9.......B...6.......9...'.......B.......X...6...9.......9...'...6.......B...&...B...K....tostring:Failed to trigger LogicMsg browser start on browser: .err.log.OnBrowserStart.TriggerLogicEvent.utility.encode.json.core.Reason.Browser....Browser..Reason.........H-.......B.......X...6...9.......9...'...B...K...'.......&...6...9...9.......9...+.......)...B.......6...9...9.......9...+...........B...'.......&.......X...6...9...9.......9...+.......)...B...X...6...9...9
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):379
                                                                                                                                                                            Entropy (8bit):7.24199845007647
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPW/E8kQoywGZy2QuloYCnWnXmYFOwrMFOfzs9fOPrmi/MsTjWnDU4p:6v/7uMpQoji+YCnWn2lwAAfz/jmiU8SP
                                                                                                                                                                            MD5:0D006D29C298D5D75780C5514DFD7E02
                                                                                                                                                                            SHA1:47231ADF89D53E452EEBA1A7A4F6F51697B93C4D
                                                                                                                                                                            SHA-256:CC72D82ECF19CB08D92F5EA6A612A12FD54B86D8E6AD1019D3516CAC0E90353A
                                                                                                                                                                            SHA-512:B35A08D6FB781DFEEAE99CA78F70C85517DCEC702E59A920967AD146C38B06442C95FDE021EEBB47901CA9D8B4B3DE3E2192DCA910C68497D5D4F5E721B5F35A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............V.W....gAMA......a....2IDAT8....N.A..GLL.....U.....Di.....k.m.S.<..`.&.....M.u.c.......~.........N....\.x....|.....z.X.......)(..?vDzF...q.h.B..r..S.....j.=.`@8.A....F...g...._ .E..*!.Z...aV.IL...z...?. r...q..j-..0{r3Y..M...m.)....Z..^....$|..... n&.....RB.1...v..~.#..t....4..k...E.........~M...S..>.S..&6t..oB.Y......C.Q....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):366
                                                                                                                                                                            Entropy (8bit):7.181473502943194
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPUyCfW1DINGm00Q6GhmVMWW5tDGMYmw3H0zPsXFdCkhY1+8EtWmTp:6v/7yfW1i700sMVI5tDGMX0VdCWY9EZ9
                                                                                                                                                                            MD5:808F5E9FF7B694D5926CE6CFFA336085
                                                                                                                                                                            SHA1:58C5D8F14FEA91E715F8B3CB9B84421FBE99317A
                                                                                                                                                                            SHA-256:5331E5CCC4E6F8082F7AAC9492FC3DF5CB810087E6F0CB71D99B1582E233A61D
                                                                                                                                                                            SHA-512:E2DC4A40D8BD68D7DD31A002F480F3D0C5ED7433D0CB6F966EA11D437FD38A2B12C3F9CFC057DA9118E05BA5E81C1BC0896C5844D78F256084AC81554FC89A82
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.....................gAMA......a....%IDAT8...AN.0.E..`i....+.-.....(..E9GO.[..._e....P!.....x<v.4...m.<v,c._...?.....*.p..p.7...d..-T.....B..p.G...m=a..Y3.qm.B..m.WWq.p.Q.C..^.w......&bd....^G..W...TMM.....R...~])...]$.#.jA.Qq..<o.....*..-.M.-.j.k.8..>..b.....w.-.Q..|(.&~..M..Y.>..=.:..Y..n.....S.&....)s.c.T...v0.%..!.Y...J%....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):617
                                                                                                                                                                            Entropy (8bit):7.536368903712138
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7y8A6KCbdR+rqKuKRLIRBG9EtiJjt+KxqMK:R6JrXe+BGkiJ4z
                                                                                                                                                                            MD5:112768C9A06EA1AC8783E7EB786450C3
                                                                                                                                                                            SHA1:15312DD4FD8F87FD23725531726261CFD73888C9
                                                                                                                                                                            SHA-256:3AA7CF0C447D88B8CE2C2FC0B50E80E49851217D0CB3BB7D4E38FC22209DEE03
                                                                                                                                                                            SHA-512:87E13AA38498C7E76EA9B017A893CCEF4819FBC13EB387C8A4946C721EAB176A44A5F3B181FD23AC2D16943D12B452EB8462FE7A57F6572EB047F3876BD2CFEE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.....................gAMA......a.... IDAT8..S1k.Q...K.H...p...TV...../'v...6V.U..PP.;q...H%.&V6...!.i...;~.[&..q.,taw.....f.........z.G....j.Z..Gg.dg..F.l.I.oX..H2.t.\T+...A+....vD.\...6X.....\.R.-.v.{..>....|jb....@7C..Q l.]....A.47.....O.X........$C......p.*_.d&.......M..?m.!.,.C.a......../.8...@n8gw.....@7..1.X.p=......._67.V...a.)...V&....a..R^.b..eN.Q.>?.j#4..A......_C+...A..H?....,o:.>........g...[._...d=\..^:.~.?......A?.cN.,...B.q..M..h.7.I.pT.T.4[.o.o..*.\..m".. ....6.0jk1..../..o....J>..6...C.6l.q.)1..N...s.....^..Y6.p..7......,.....:...C..y....IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 48 x 30, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1523
                                                                                                                                                                            Entropy (8bit):7.849513030462221
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:4V7JCN3mFRJOJsHKyzBNqS+s6snN326HGGeV6CouULfX7GBo6Bqy4XoRE8ndBAQe:507Zzas6s9lH06EUSBnBqy3dBAPl3
                                                                                                                                                                            MD5:0A57D1C2AF64AE52DF0CC5AE10897E72
                                                                                                                                                                            SHA1:923C6AEEA726F5BDAE43F4837C7FFFFE34E90B90
                                                                                                                                                                            SHA-256:541865D3715C481C1C111ADF0729928E0F6DE4A6B8E1687BB2DA2D26166E8C57
                                                                                                                                                                            SHA-512:2466E5EC410C6A9484A792B5F431FE3A527A04C01127CF11DFA6AB2ED49860FA052DC84C8AB61441359E03E2DF62341CD7E05F3CD94612AABE1E37564521CD38
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...0.........j.......gAMA......a.....IDATX..X[lTU....;.N...R(}D.-..CA.1.T[.`L4..5~k...*.|..~.eI0..DA..H../..6..VZ.J....:}..{.......bO.....Z..}.>C.P....F@..Zi:z.X..v.!.-.*'.*d..=.%i...m.d.}.d_].E'..}.J..t....c.......7M.T-.$vF.. ....U.....M..2..}..$.P}.....:....[9|..KBx>7.=l2..<ZS.O..fQ0.M'..iht..........".zV...xB....-.8..P&.....s.B.8..+..ris.......s~.M.......{.<^.M....a%a.<...5.}*......y.|.g.OW.QmU..qu...E....$T....."...e9. >j:.*';.=...7>YJ..+\.NU..z....x...k.dB...!'.]....P.......$.....A.[...i...[....M.|#......K~.|...H.;.@ei!m.. .gd......QLz..S.../..'....^mr.......(..|.`.sf!7...E...M....x<C.t2..:e.n^.D...SiqA&.......a...?.i.....D....}.q#....p...I...nl\...|j..s.s.w").a..Wm...$x.A......8.)......_.i..a...q..$!gb...U$.%...o..X.O....D./.....4.[X..yG]../..:..d.%....................-.g>_....h.$.%b...l.....|7\..>.j....[_6'aSs.:n.'...l.|.z.k..h....yu...TU.r;Yv;.F.b.38b..s..$...L.5.....r.9....)+.C....K......'g(.....P....,#..C..F..!
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 48 x 30, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1568
                                                                                                                                                                            Entropy (8bit):7.855339992904692
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:URY+DGIp5LXcjQxWPQjWqIiU27j2NbCYv0WGYKmUjDeQuksU:Z+DfdXqQihAv/WGYBFQuksU
                                                                                                                                                                            MD5:1CCDA19F6B165F0487EBB6C65E870492
                                                                                                                                                                            SHA1:3CB6473AE58648F9E6365DDD44EB6A24529DD55B
                                                                                                                                                                            SHA-256:8A3C7A2285AF72210C4CEDEB87701596B05C96A435E200A1BC3F0FE1947DB566
                                                                                                                                                                            SHA-512:D681758B205597B043FFF6F8BE779B5D05E37708FBCC9C08C88DA963B2B4681C33BB3E3B5912E8DF0CAB819A89D520BF1D21DE1C7B7499B5738AB0D557329C57
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...0.........j.......gAMA......a.....IDATX..X]l.U.~.um.....l..!.i"..8...J.@....+.....41A\.K.B....;.:T.1(.B......(l.u.l.m]...k}.....n.vr.....<.{.s.{..[.(..........w#.z.....F..)8...T.pL"V.e....g]...C<.....K..eq...0.o..S.g..T.E\.I.3%.....Mh1i.3...O......fG..Ez.J.....g.t.6...O.H..J.W...;..P........?...,.......H.......$..V$W....B7Sn}..e-.'i..=.....k....3::.....8.p%...6.g)1OT,.L..W.84.....u...7v....!$E.-....j%L....C.T.....&.-~N.b.wZk.y.......:3.W....s...w...1....a."..Z...n..1!........J&/x...b@.=..}.U..rTF.a.....N...A761?q=..~ZID./..Q8.s8....U.m%......3.x....D....2.7V..C.....}..Mj..y....\e..`1.`...Y..i.*I6....o....5..?.kzz.dN.*.......9.........8,o.%...5T..o..cH...j,o...5.Bz.;......<....x.x.._nq...<.{V..o!..!.....S....tx.\.U............u$j.>.....4.....H....F.,..b.Z...R]2}WP.,1L...m.........W.....R)..a..Nl%..s&....9S....F..:q.`..1....b......j%..S..<v\J..]..5z>?=65.Qf)....hd..rx..QtS...pR....r>..G.J.Qj..]Yn........L......L<*..T..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):245
                                                                                                                                                                            Entropy (8bit):6.356933018581735
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPe/6TsR/h2Ogt2PfVuymklNXULhg+/qp:6v/7m/6Ts/NutyJlNn
                                                                                                                                                                            MD5:BE47EB430418C03DF89E2CA140BC1325
                                                                                                                                                                            SHA1:A099F0ED4114F8476D6558BAA30E3DDFDF0512C7
                                                                                                                                                                            SHA-256:F651001BDF0AD41D9BFB7D5942F136CE75ECCEF744752EE72934980B8ECFFA4F
                                                                                                                                                                            SHA-512:AD150D115D35F1F796BB0E24C61FFAF72401FE2857A0A4475A2CB7E36325A5130CAAC1F167628E26C7AB6D053B7A3757D57EA3A07C71FC14FC848CFD2771232E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR................a....pHYs.................sRGB.........gAMA......a.....IDATx..S...0...$..F....J&.i..X.b...w.|.pXJi*.N.|..-.."s.Y.`...MX...._.6.mU..aD.0FY*.T.O.....@C.o....&A...Y..C.Z..G...D..5:....9...s..............IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):473
                                                                                                                                                                            Entropy (8bit):7.236375221337779
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/74/6Ts/fWEpw+mmdlVkAV7AnpSvLkXfwtelX8EFQgdPjSTFN:x/6MWNmXVfV7opSYp8eZPev
                                                                                                                                                                            MD5:640A9A68216D3ACE0A04C70F745760F9
                                                                                                                                                                            SHA1:DEF457CF4CC59B638CB4C988652925CBBD7A972D
                                                                                                                                                                            SHA-256:40171CFFE5FB5BBFDA44569BBF7BBCB3848ECEF6A975CCC237F475B3141CCF4D
                                                                                                                                                                            SHA-512:A1CFC930207C1F468D423F072CB80CE6D6BC2FE6E8ED54A8A21386445882E9A922BE55AE627330E7810EA3BEF6108F06B4A2E0A3E62EDC659E1992046FD9D8C8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............w=.....pHYs.................sRGB.........gAMA......a....nIDATx..J.P....&........8...... .=|.}...y.....A.X.5.N.P.&1.{.X...B&...$7....O.c.,x..D1x.@q..P0..a...:.Zb..%.........%y..Gp.X.9...ze.$p.UQ]..~u*Nt6,....3YX..F...2.....O6..]...]+#r...`[TzyP......c......Py.... ..j).......5uD.c*......?..1.;..3.x..P.gA..3..=.M...ns3...C.U.L....VO(.............tq....WJh-.o....0..y..0..-u%.+.g......Z@..V...-...P..{....I........IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3856
                                                                                                                                                                            Entropy (8bit):5.632480978270416
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:lV4Ubfff6DbxWUY8vIZOETrptTDWlL07vk/jn621GDmrQ+2L+CMqKZc9Ppqo7Kl+:lVvGHx5uXl00jS5V2KCM49cyp/Zuxo+E
                                                                                                                                                                            MD5:CDB3D65FBD77FC0A7DEFB85A9598D925
                                                                                                                                                                            SHA1:126FA51C81FB59B48B7CE3DE9680440431188010
                                                                                                                                                                            SHA-256:0EC2D313D7F01C708C0F7AE628BDDB4AF0745C15C22A38B45BE85653A351B6AF
                                                                                                                                                                            SHA-512:4226C28E3B5661916CE401F5804E1FE76E7820B0A5A79115208E433C7763DAA0C536634E37A86251C6022F2D03EA367251B33B4D6224C4274CA9E8038E3505C2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..X...........X.......X.......X.......X...+...X...+...L...+...L....new_tab.browser_launch..........D6.......9...B.......X...6...9.......9...'...B...+...L.......X.......X...6...9.......9...'...B...+...L...6...9...9.......9...+...'...)...B...6...9...9.......9...+...'...)...B.......X...6...9.......9...'.......'.......'...&...B...+...L...6...9.......9...'...B...+.......J...Hupsell_toast_handler campaign one: show campaign one - take_a_stand., do not show campaign* equal or greater than xml threshold 9upsell_toast_handler campaign one: client threshold .threshold_take_a_stand.tracker_take_a_stand.GetOption.SettingsDB.utilsdupsell_toast_handler campaign one: Only browser launch and new tab are allowed for campaign one.new_tab.browser_launch>upsell_toast_handler campaign one: User has WSS installed.info.log.core.is_suite_installed.utility......&...9.......X...6...9.......9...'...9...&...B...+...L...6...9...9.......9...+...'...)...B.......X.......X...6...9.......9...'...B...+...4...J...-...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 150 x 314, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):42124
                                                                                                                                                                            Entropy (8bit):7.989049214597359
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:LJZubuFGvQ0hVNPAb14MPMrY0iJyMXbAjw15AIJgW/8QjzastNBmwQ:LJsbu0vQ0hje14M6iJy+sE15AegW/8c+
                                                                                                                                                                            MD5:6F1B48189D2C835EC68CC9C30BA53360
                                                                                                                                                                            SHA1:93D78939DA261C4D7CC06E8B8341D9B3D93CEEB3
                                                                                                                                                                            SHA-256:29ACC284AD48147B1B5FC3F6F8E79F8D7481002E12B7D0B631DF91D9D22E5749
                                                                                                                                                                            SHA-512:D47ADF288217FFC8AE2F6D9DE1A2FF5E240355EEF3E31F3B204C16A226ED7470D60021E23F155883A9F77275FD1712994565B58392694CEBDC4E28BE7F3AD1E3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.......:.............pHYs.................sRGB.........gAMA......a....!IDATx....e.U...}.My.%.F..b.fK.%..........H..@../$|.../...~.. 6.d06`.{U..{.......Y..g.....7..aKo....*......7?@.B)....|...w......}..X..Q......Ju{.k#x......sm...G.@...R...)./m().Q..mwM..'............w....z}.;Sk[Oj\;G........A+....X....g.U..}g%.?..z..U"..A....t.....F....i.4e..X...4..L..LZ.b.. _/J."..6.~.QJ.8EuB.."A~.....j......%VU.sF.i..;....m....|@3.vJT.6...R.S.[.I.m.....=..D.6?...h...]...^^.........X..[.Z.0..BT!<a....TQ.xr...2K.......D. ...m...).xf..<.D.#.J.K......qY.;f.h.U..yfZZ..J.p=...R@3.E/..8..U.:t..W}.4.g=-....4.G7'g.:.\....5J&\4..Ip.....Pk7.........l..f).*.G..yh.D...?~p.0..k5_0.UT..E.L\T.8q..\.>..Y.r...o.B..k.n...jV{....!...YH{U..Y't...b5.A...5..........9zZD$T../.F..Kue.....z......un.h..G..J.!$ru..2......0..n=........U.0.....Qu_.....M..7.@.4.v..3bQ..Q5..zB.}..0....^.L...V.!,.*...D.^.3..._j.....t.(PC6.... ..c.......M.P....H..A.x...........J.#
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1957
                                                                                                                                                                            Entropy (8bit):5.208734343017381
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:xmp5UoZHx4Yli5FZSFIuMDWlYOlZiIpd3Rp:xANxhi5FUAWlYOl5Tn
                                                                                                                                                                            MD5:BD38056590D01D49F997A7120F05D65F
                                                                                                                                                                            SHA1:9796FA5A40B605914A1510C26304A94680437A37
                                                                                                                                                                            SHA-256:CBC3F26DA52AC8BDD100B02282CD60CD108476819F69E456C1D510F092002182
                                                                                                                                                                            SHA-512:03B3F3DB4358D52070D71A3DAC957E75F105589592F6F77A6B14E3B2D15B9F7E4A731674DF375E0B8004F97DECF78FA3ECB86A23DD9CADC35FC53CAB8E1C55CF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 16px;..}....body {.. background-color: #f2f2f2;.. color: #212934;.. line-height: 24px;..}..../* Parent container */...balloon {.. overflow: hidden;.. .. width: 510px;.. border: 1px solid #ABB2C3;.. border-radius: 24px;..}.....balloon-I {.. height: 314px;..}.....balloon-II {.. height: 370px;..}.....balloon__card {.. background-color: #FFF;.. /* height: 314px; */..}.....balloon__card-I {.. height: 314px;..}.....balloon__card-II {.. height: 370px;..}.....card__content {.. height: 100%;.. padding: 16px 20px 24px 24px;..}.....content__text {.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-weight: normal;.. font-size: 16px;.. line-height: 24px;.. padding-left: 24px;..}.....content__text > p:last-of-type {.. padding-top: 18px;..}.....content__text > h1 {.. font-weight: bold;.. font-size: 24px;.. line-height:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1974
                                                                                                                                                                            Entropy (8bit):5.292418064990269
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:LswDjYyAGNVMr7OVMr7EVMr7VMr/VMrlygVMCrAedmI4O7P7K87DO6IrIw2/qIPL:oOjEJneCWCFf7P7d7DtIrINqIdmfMGC
                                                                                                                                                                            MD5:AFC5C4BF6EE9B890F666CA81E9ADB918
                                                                                                                                                                            SHA1:6C7414CAAAF0F60D30580A05146DE6D06E3178CC
                                                                                                                                                                            SHA-256:A45E80D4E3A6C9A53C29D81A57BEDD939818FEA90036F2744D32FCC8D08579DC
                                                                                                                                                                            SHA-512:0DF1A142F1C562B05966E7C55DDCD2369E9D41ADF4BBFBAB2E8FC8FE14883A57F7ECB5FE5BA1A55A19C2292253B708304587F4775FD13040369D0D13055DC5F8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-amazon-upsell.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-upsell-toast-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-amazon-upsell.js"></script>..</head>....<body oncontextmenu="return fa
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5813
                                                                                                                                                                            Entropy (8bit):4.8566147736196745
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:4G3AXPfTEzni3R4uISETACySbd0SE13z8acglmVnIJ+BHBbXks:4oAmMR4FfCSERz8k5IbXR
                                                                                                                                                                            MD5:6FE7A5BBDB292E21CCF9987C837EB52B
                                                                                                                                                                            SHA1:E8B630BD2D5AF019B5CF393AAF6B2AB3A2670F43
                                                                                                                                                                            SHA-256:C7D5BEB5E6121270CBA1CFEEFF4D25778419BB405E2760A9E1D8367B0083D39E
                                                                                                                                                                            SHA-512:4C1A1FC16FF51B6FCADE285DC57C897AD2B86CDCD9B877AFD04999CA5753068999BFF81F7EA3D078E0C83A388A102C69D80FF9E90F2744C9CCD58D37C88826E5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Amazon Extension UI */..(function (wa, $) {.. var ui = (wa.UI = wa.UI || {});.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _settings = wa.Utils.Settings;.. var _instrument = wa.Utils.Instrument;.. var browserCode = _instrument.getBrowserTypeCode();.... ui.accept_extension = function () {.. var $el = {.. balloonCard: $("#balloon__card"),.. headerText: $("#content__text-header"),.. contentText: $("#content__text-description"),.. contentText2: $("#content__text-description_2"),.. acceptBtn: $("#content__actions-accept"),.. declineBtn: $("#content__actions-decline"),.. footerLegal: $("#footer__legal"),.. };.... (show = function () {.. _window.ready(function () {.. var payload = JSON.parse(_external.getArgument("toast_data"));.. init(payload);.... _window.show();.. });.. }),.. (init = function (payload) {.. var lang = wa.Utils.Lang(wa.Utils.Lang.ResType.UT
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1484
                                                                                                                                                                            Entropy (8bit):5.247167898152739
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:xmp5UoZR3xQpxVYHhLcY39U0M+mtFl2zZRVchpKIjvVCfnvv/UQsUM3QiisA:xmp5UoZJxDHF3uBjFloZKY+YfnHcQe3o
                                                                                                                                                                            MD5:CFD0651F1C8146B4DECF69C514221FA6
                                                                                                                                                                            SHA1:CF49EFF69D1D676702ED360736DB884275EA7421
                                                                                                                                                                            SHA-256:0D20CFABE63FB1ADFB88B7AF39846FEB46E38E92423D58113DD455398D26D0EF
                                                                                                                                                                            SHA-512:2B6BE8A9F26649EA32F15966B8DCBC60D7BDFC1844E90688DDA76CEDF72E00B85BB1E8BA0FD02A579E44F396D6DEC4A9FA4BF1F3C8EAD734525F6A6DC31BC98C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. background-color: #f2f2f2;.. color: #212934;.. line-height: 24px;..}..../* Parent container */...balloon {.. overflow: hidden;..}.....balloon__card {.. position: absolute;.. right: 55px;.. overflow: hidden;.. box-sizing: border-box;.. background-color: #FFF;.. border: 1px solid #E6E9F0;.. border-radius: 12px;.. height: 200px;.. width: 328px;..}.....card__content::after {.. content: ' ';.. clear: both;..}.....card__content {.. padding: 16px;.. height: 100%;..}.....content__header #wa-logo {.. height: 13px;.. position: relative;.. top: 2px;..}.....content__header #close-icon {.. float: right;.. cursor: pointer;..}.....content__text {.. margin-top: 12px;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-weight: normal;.. font-size: 14px;.. line-height: 20px;.. color: #5A6175;..}...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1849
                                                                                                                                                                            Entropy (8bit):5.246021501122015
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:+swDjYARGNVMr7xnVMr7EVMr7VMr/VMrlmVMCqAedml3+u4wXRM0cPh/m5:NOjXxuneCnCa63+Wxct0
                                                                                                                                                                            MD5:BA6E3307F6474161D905B49A808E1643
                                                                                                                                                                            SHA1:02985C4B755D0F9E50D904726654F262C96D87F3
                                                                                                                                                                            SHA-256:8CFEEF41B4ACE006C12AB7B6564FBA1EDBA6ADCB5A22021DD2A0FA9D2AEFAFAD
                                                                                                                                                                            SHA-512:3A15A75D308698934842F94F1B3D58B133004262EF6BAA147AAC1D225DA9360324E001D91100B1BA11626828C400BD9FCF026774FD233EBB3CCA2F5BA6B0EE2A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-ch-store-overlay-ui.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-overlay-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-ch-store-overlay-ui.js"></script>..</head>..<body oncontextmenu="r
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3042
                                                                                                                                                                            Entropy (8bit):5.134325068794321
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:h4D7pOAoHHxRUoV9PhPkD4OEbN4d0Bk/5LiMCH2qJoNugUoV9PhPkOOJOMaOfNXR:cMAo1V9PqREed0kMTJo5V9PKgMaGXlQO
                                                                                                                                                                            MD5:A6978A2257A0405108B5FA83999FBEB9
                                                                                                                                                                            SHA1:F3E4061D40C0662445F0D1BA05088090D81201AF
                                                                                                                                                                            SHA-256:8C0D004BDB852052AC370CE5F8704FE6868FF88469DF7ECC1004E88DCFDFFA7E
                                                                                                                                                                            SHA-512:1C595B5AC92E7C621404318E172CC43DCEF1C04CFBAAA0D6D4D35E06D19049FEF4781BA1D9D020EB63BA152B14CED5005F91CD9B7DE4EE669C6DD7BE3BA48C34
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument;.... ui.accept_extension = function () {.. var $el = {.. contentText1: $("#content__text-1"),.. contentText2: $("#content__text-2"),.. closeIcon: $("#close-icon"),.. },.... show = function () {.. init();.... _window.show();.... //Send Telemetry 3.0 for dialog balloon.. var browser_code = _instrument.getBrowserTypeCode();.. var screen_flow = browser_code == 'FF' ? 'firefox' : 'introduction';.. var hit_screen_id = browser_code == 'FF' ? '300.1.2.1-windows-onboarding-firefox-webpage' : '300.1.1.1-windows-onboarding-introduction-coachmark';.... var analyticsEvent = {.. _event_name: "wa_onboarding_balloon_impression",.. hit_label_8: screen_flow,.. hit_label_18: "Onboarding",.. hit_label_19: "Impression",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 20 x 20, 8-bit colormap, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):743
                                                                                                                                                                            Entropy (8bit):6.485906014360001
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6v/7MRUwaBLht3zHOuVKg7/6Tnpb+R2pi5IDyc1RX25gbhbzS5/IEMS:kwaZht3zuKKC/6jptpAIeEoglbzegEMS
                                                                                                                                                                            MD5:1ED7DBC29E984E621DB85633607A39EA
                                                                                                                                                                            SHA1:77CF88D52CB9A32A8EE377E37DC2CA70EBC79143
                                                                                                                                                                            SHA-256:C364887E094D6235A4FD5774D7CB5D9631A2983C8626998BAD8CA294BC446A19
                                                                                                                                                                            SHA-512:57CB41F770F5586041F9FCD9E934FEF894301AE8DDF8EFC498E2743FAD006D5C0D4AEF7D2A2086A9D3E60FC08B02AD2505D02E95B039786555522015EC9C41FB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............W.?....gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....PLTE............................................................................................................................tt....WW.ZZ....[[................................r....%tRNS....#BSR$.7}....~9.k.....l.y....z.....>....bKGD...-.....pHYs.................tIME......*..uk....IDAT..e...0.D%....;f.@ ......,`.r.]..J*.Z....jl.3..D...M..q.....(b.."I.6MD..=E...e;..{.<*..X."..$..}..r.el....-..z%..(.^#.f..H...07Up.S0u...a.8.r&#<.N......r9..H}..R4...R...]Y.).3...S.....U..TW..+.z.).3...(.....s..m.....5..3m8....&1@.....%tEXtdate:create.2022-02-18T19:30:12+00:00z.a....%tEXtdate:modify.2022-02-18T19:30:12+00:00........IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):285
                                                                                                                                                                            Entropy (8bit):6.92410222781354
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6v/lhPW/ETnWvTVFX9ls1mDf0J7KzAvC7gnh+i25wp9M+S+N0XXnTp:6v/7uMTWrVFtW1mQJe7ib2uPSjX9
                                                                                                                                                                            MD5:527825CC6A463D4D1A8E7019B4773D02
                                                                                                                                                                            SHA1:C58CE479BCED1BA8B47339D6A9867E3D75A96672
                                                                                                                                                                            SHA-256:87A2C49BEFA3F59750E91A1FCE86FB9AC9BA928A04D4ABE1A7BDFFB25883EC2C
                                                                                                                                                                            SHA-512:38DFD2D59C8D8A9195BC9D45E45A71FAAA69AB3E7C4777F3A448C31A95D44AA3E97303EF3FABAF13B3BD4F7DA1BCC6269B8A6A668EC758E28EBADCE2F949D0DB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............V.W....gAMA......a.....IDAT8.....@.E.I@....V.AK..K..[.`..zQ<X...EP..&.a3D../..cg...a...o..v.38@.s.|4.....`.;....a.G....k.m".....w........&...`.{..C.2q]jx...l<)OC%4.....'../H.+!y..S].,A..J..stM.^.M[.....2....^...T.(J..7.?.....t.QL..r.........IEND.B`.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2224
                                                                                                                                                                            Entropy (8bit):4.9541246398353875
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:csYzTlGNVMz7tVMz7EVMz7VMz/VMz8AVMzjVMzlpeVPhFj/TP3G+PxCQOR1F3Imq:3OTFMv26ITWWhF/ehQORD36pz
                                                                                                                                                                            MD5:BABAD8554691BE8A63D9B4709EEB5934
                                                                                                                                                                            SHA1:E74D107B5544B3CEBB75ED60C74B45B62EEAE9A9
                                                                                                                                                                            SHA-256:10F4F0324BD1A6B0C42724221E9C1E6C0AC6AEF4FE98B2EA3E527E40E3F7CDA9
                                                                                                                                                                            SHA-512:BA1420797B4BCB0CFE924D3EBCABFAD9D1ABCF69C5A952B046F0760770924C8FDD7240DAA255189D66D57CF64268021024A1F465787C683956D544FE26D456D5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-checklist.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-checklist-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-ui-dialog.js"></script>.. <script type="text/javascript" src="w
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (339), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):20241
                                                                                                                                                                            Entropy (8bit):4.031550033483697
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:cD3PO1JLKGbm4Ny+e8yfR/ZfiuLeeY0WR9dZGei:Y3PO1JLxbm4NyljziuLa0wZGL
                                                                                                                                                                            MD5:07E07A1EB472F8BB5AD0F36E99DC5969
                                                                                                                                                                            SHA1:1A71EA9434F307F8EDAF16EB2F21FA6FF55FA983
                                                                                                                                                                            SHA-256:4BDC420C4529841499DEA7FA4DD005E8A14721657F8AE9E4AD15124AB145429A
                                                                                                                                                                            SHA-512:CF52673B370443D94D0182C70F38A8753D1600E2779072FFE020CEDEF57D791FF89A0B2A1AC715748EAEE89790969233B075E5F81418D664C62D33A57403DAE5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* CheckList Controller */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _l10n = wa.Utils.Lang().checkList(),.. _tmpl = wa.UI.CheckList.templates,.. _core = wa.Core,.. _window = _core.Window,.. _checkList = _core.CheckList;.... ui.CheckListController = function () {.. var threatStateCss = "threat",.. infoStateCss = "info",.. greenStateCss = "green",.. waitImage = "wacore:mfw\\packages\\builtin\\white_timer.png",.. alertImage = "wacore:mfw\\packages\\webadvisor\\wa-checklist-risk.png",.. ignore = _l10n("IGNORE"),.. fixNow = _l10n("FIX_NOW"),.. defaultImageCss = "wa-state-img",.. alertImageCss = "wa-state-img-threat",.. keyMap = { "NUW": "WelcomeMessage", "UUW": "UpdateMessage", "CLW": "CryptoLearnWelcome" },
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):802
                                                                                                                                                                            Entropy (8bit):5.277894961878517
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:xmp5UoZR3C3dDUUhiLKyFc43bZt7nMP3a9:xmp5UoZJkxQ3SK7nMU
                                                                                                                                                                            MD5:A631FB3B67B4579F57702E1E13F796C4
                                                                                                                                                                            SHA1:94E7B8C6F46249BD91687E29B134CCD8DB951B7E
                                                                                                                                                                            SHA-256:B364801B56A9CCB6E67A967B0809BBA7BD7EA8DDD398338C22E6121954EE3182
                                                                                                                                                                            SHA-512:DFA586FC418C281274E5A7C8C9B86A1F37822A9AAA9BF3A082D952E031410A733E9FD0F634BF8A56FD89164DE8C352872A49F1B22691260855C2D9D58BA79209
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. background-color: #f2f2f2;.. color: #454545;.. line-height: 24px;..}.....balloon-arrow {.. margin-bottom: -6px;.. text-align: center;..}.....balloon-main {.. box-sizing: border-box;.. background-color: #FFF;.. border: 2px solid #E6E9F0;.. border-radius: 24px;.. padding: 24px;..}.....enable-ext-btn {.. background-color: #4989EB;.. border-radius: 4px;.. border: 1px solid #EFEFEF;.. color: #FFF;.. cursor: pointer;.. display: inline-block;.. font-weight: 600;.. padding: 2px 8px;..}..//7900B9930125B2E2FE55905E988F41A21C75AA3DC20FBF9659E6E92E4E2E3E8AA1C54BBF39F105CA386D6DD5B2F89B2E8887DB94D2C7FAA569F1CE1A3F2DD653++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1786
                                                                                                                                                                            Entropy (8bit):5.2644080547860606
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:+swDjYI2GNVMr7RHVMr7EVMr7VMr/VMrlTMNVMCrnr8ymTQogY+ORMqnPPQ:NOjPOROneCZNCzsTQ++yU
                                                                                                                                                                            MD5:6254108E6A4AA9806F2756FEC26D005B
                                                                                                                                                                            SHA1:58D6D47AC90C766415FE60D30178D2230C0D5B17
                                                                                                                                                                            SHA-256:A30B4FEC24176222C7D411E5D4A0379701F7090FB87ADDC6521F80D396655FBF
                                                                                                                                                                            SHA-512:9BC9AF5E7009FA776A0897B3E2689A2BA3B8D7684437ABEA67EBE585DE8C7070109E7D9DE3F0E51709516A2D89F09C176E28C5A6A320F041CE1645D73D8ADAF6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-dialog-balloon.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-dialog-balloon-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-ui-dialog-balloon.js"></script>..</head>....<body oncontextmenu=
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1653
                                                                                                                                                                            Entropy (8bit):4.929425962777782
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:3JYmsL0yXFeRZ7kkbslksjsjjGbb+CDBXRDDNEVRK1tzZtg77OgKqDRjnnTMUHu3:9ByXIcrH4fGbaYTEV6tk77Og9TTu3
                                                                                                                                                                            MD5:EF8EE9D11F99FC1787822E5B2A8FDBE1
                                                                                                                                                                            SHA1:D6096EF088D6DE16307D0C9ECDA6F8DBB04980D7
                                                                                                                                                                            SHA-256:FA0785854808DFC38B1F18B740D97A4D49A33C3DD8F8551E33158BFEAED6C515
                                                                                                                                                                            SHA-512:300A37ADB535FC034E7F222804689E06050DECC082CCBF95198221609E455FC84F8459DE9575C1C55987758F4CE2D24755D77254FE0E922785E36CE333015EAB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:#wa-dw-toast {.. height: 245px;.. width: 425px;.. border: 1px solid #B1BABF;.. background-color: #FFFFFF;..}.....header {.. height: 20px;.. padding-top: 12px;..}.....content {.. border-bottom: 1px solid #E6E7E8;.. height: 132px;.. padding: 12px;..}.... .content img {.. margin-right: 8px;.. }.....content-header {.. margin: 0;.. color: #EA1B24;.. font-size: 14px;.. font-weight: 600;.. line-height: 33px;.. text-shadow: 0 2px 2px 0 rgba(0, 0, 0, 0.25);..}.....content-text {.. min-height: 32px;.. width: 99%;.. color: #53565A;.. font-size: 12px;.. line-height: 16px;.. margin-top: 8px;..}.....content-footer {.. color: #53565A;.. font-size: 12px;.. font-weight: bold;.. line-height: 16px;..}.....content .body {.. float: right;.. padding: 0 0 0 0px;.. width: 99%;..}.....footer {.. display: table;.. background-color: #F5F6FA;.. height: 56px;.. width: 425px;.. padding: 0;..}.....logo {..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1693
                                                                                                                                                                            Entropy (8bit):5.123238382138251
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:V2sY0TYttGNVMz7tVMz7EVMz7VMz/VMzlGVMCqEjIYcdzV:3XT0tMv267CjjKdzV
                                                                                                                                                                            MD5:06808795BDCE5F2B3101F594A66CF92D
                                                                                                                                                                            SHA1:F29FB92B8BF454ACB3DF58A2CC572245B7AAFDC3
                                                                                                                                                                            SHA-256:0CDA42FB307B25CC6D9EA80D7AE1D046F9A6A89160E110E249E0A01D38D15DA0
                                                                                                                                                                            SHA-512:A94F404AFD5A9DC345391B9DEE0AE3E4AA8F188C5375434CC10284E3BA82DC4E1DC5621D4D132C2447824D0C720F89E1364C281A2234AB186F1F0270576399EF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>Download Scanning Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=9" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-dwtoast.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-checklist-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-ui-dwtoast.js"></script>..</head>..<body oncontext
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2137
                                                                                                                                                                            Entropy (8bit):4.907956363205003
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UUzf2hkRg/q4HWcJ5/VFeICFeI75jYKubJsbnbIeIpqeUr:Uh2gy4HWw5/jC75jYbJUba83r
                                                                                                                                                                            MD5:AFA7D01D32A223434ACFC7879ECB9080
                                                                                                                                                                            SHA1:34B1B321B7F4E4582E7F8F782921EFA077D7C3D2
                                                                                                                                                                            SHA-256:72CEA2AEF37DF1307A5888206BA4D1CC16502E7CE62040653A8410DA7BAB748E
                                                                                                                                                                            SHA-512:C0D9EA8DCD8C9680030B6ED87BA63D784A2869CBF02FC7DEE91CDB1D046A3D5F269287ACA1D248F40B7D9F42F12CA3EC507FC5A3F332FD810441C4A2F5D10288
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:body {.. margin: 0;.. font-family: "Open Sans";.. box-sizing: border-box;.. background-color: #FFFFFF;.. border: 0.833333px solid #BCC3CC;.. box-shadow: 0px 0.833333px 8.33333px rgba(0, 0, 0, 0.254218);.. border-radius: 1.66667px;.. overflow: hidden;.. }.. .. h1 {.. font-style: normal;.. font-weight: bold;.. font-size: 16px;.. line-height: 32px;.. color: #383434;.. }.. .. p {.. font-size: 13px;.. line-height: 16px;.. color: #454545;.. }.. .. .main {.. text-align: center;.. background-color: #ffffff;.. height: 210px;.. }.. .. .main-logo-container {.. display: inline-block;.. }.. .. .main-logo-container .img-wrapper img {.. max-width: 105px;.. padding-top: 32px;.. }.. .. .main-divider {.. display: inline-block;.. margin: 7px;.. }.. .. .main-description-container {.. display: inline-block;.. text-align: left;.. vertical-align: top;.. max-width: 295px;.. height: 100%;.. position:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2505
                                                                                                                                                                            Entropy (8bit):5.088559098371566
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:V2sY0TYaGNVMz70VMz7EVMz7VMz/VMzl+VMCqX+Q7hc8A5TTD14KtYJCKWbeIwkF:3XTL/v26TChnR+5WbeIwEeIYOzCUOm
                                                                                                                                                                            MD5:A0CCF1DBFCF4AF5171FE1F20984AC5C3
                                                                                                                                                                            SHA1:607C8BCB3A7237B3754B0DD7CAD192463C82F3BA
                                                                                                                                                                            SHA-256:6D9D64996071A2C2AB6A6A69B02E46B98AB87DB145B45B786FDB52066671C5A6
                                                                                                                                                                            SHA-512:6B8451AC352CDEC8F0E0B6250ED8E0F2CD7192691DD6D8E399BE8E3D3CA34ECAFB0A295F27C6BE58DE40F9687FCAB8C3CE6BC83027FE9DF1DA293C08710C8C5F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>Download Scanning Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=9" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-ext-install-toast.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-ext-install-toast-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-ext-install-toast.js"></script>.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3583
                                                                                                                                                                            Entropy (8bit):5.331474129475065
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:nPT2likPJkhmmVkH0zf6lui5TF+Ezkb00t+lkz0tRZ21:SMLhmmVXzf6gahLzz/lvtG
                                                                                                                                                                            MD5:F2F95A23D0BCA2FABC7FD472179C2026
                                                                                                                                                                            SHA1:601BDF930BAA7EFA33D401741FAF37C7261F7FED
                                                                                                                                                                            SHA-256:8A1123F61B3E83C294ADE344726A676C384F218D56A96FCC95538099D12B2423
                                                                                                                                                                            SHA-512:11E710F81C0C9D2B514519C390437F02753718C93705C62D0E3F4F01257606A2F347F7797943C285DCBE2F737FCC091A873C779BBFE0CE7CA90ED99592C37635
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Download Warning Toast UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,... _instrument = wa.Utils.Instrument,... _settings = wa.Utils.Settings;.... ui.extension_install_toast = function () {.. var $el = {.... header: $("#wa-sstoast-heading"),.... description1: $("#description-1"),.... description2: $("#description-2"),.....acceptBtn: $("#button-accept"),.....ignoreBtn: $("#button-cancel").. },.... show = function () {......_window.ready(function () {..............// Set toast window size......setSize({width: "485", height: "265"});..........// Get settings data.....var toastCountSetting = "ff_extension_toast_count";.....var toastCount = _settings.get(toastCountSetting, "0") || 1;............var lang = wa.Utils.Lang(wa.Utils.Lang.ResType.WAIFF).get;.. .....// Initialize toast......init(lang, toastCount);.... _window.show();.......// Send telemetry for toast impression................var analyticsEvent = {.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 126 x 104, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5630
                                                                                                                                                                            Entropy (8bit):7.947897963110471
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:QSToxeyGItzC74o5BBiMAxI0Roty8QTzTuWjP4IMqQidjQFl1JuKOrzmdc4z+S3:QScxeyDtMzPBiMAxZtqIXQ6QhJZyS3
                                                                                                                                                                            MD5:F5D9337BD302C183FFE6B9613EA4E236
                                                                                                                                                                            SHA1:6C622ECF659AE65E7F6ABFED4FA831D230B51A02
                                                                                                                                                                            SHA-256:DDC6EC93BB8B7AE8C90D42476ACCC47CB7E9EE28B01A312346462AD54206151C
                                                                                                                                                                            SHA-512:40270893584E34AD27B7E89DE9466D08464A4A869D96D5CA414FADF7332BD02B7AD1F28725FA82D7EF8AF4A0973494CC8633A202F58F0A2E60933CF482591BF0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR...~...h.....7.D.....pHYs.................sRGB.........gAMA......a.....IDATx...xT...G2..$<B...6.@?E...#.~U..b..Z.j......E........\...,.......A.V...A Iy.H2.y$s..g.'3.sf..$.{~.w..}.L....Zk..(A.....Q.&...`Q.n.@...j..Wz..2.I*.....f...q. .%..[..x.:B...:.....F.a.,\....O...>.t:....`.Ut...Y..34.O'q.%<..b...B.I...q.%3.n....k..#..=F.J.5.9...;o.R.^...D.N_...9...i?..~A....k.%..l.kiU.\@....`...M.`.....9.L.n.%....t...9..;YK......aT......4-......yq.D.8...>1..."...v#.....]t..i$S..$..H.C)$...i-n.Q(5];S,.Utc......6.....4.WOr..%...-D6v.\.m.m.....r......@..6..1..fQ.......`z.e...J....I...At...0.;..B......?...,...0..8.. ...n...Y..o*....r.6.b.......V...M.....v.J.d.K..y.Hq.|....~...e.=_....x.t...x.x.z.i.%4..~.k>.n..$.&..^.S4s.c...!r...].3..}9M..Mz......u..\..6....=3N.=.#.N...SQ..i\...I.<M.~AdP...G.o....A=.}.L...N.R....N..[nQ<o.8..V.&...,......MMt..a...r.[^..F'9.Ix..t..N'.q.....N8.!.8..%...t...Q=..U[+..Lcs3..j...:r.\I.'S..."9....:Q...YR.WP5[<.w.A.m.0
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6632
                                                                                                                                                                            Entropy (8bit):4.863979137870073
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:yH5SvRvxVoY2bZ8/C0jBkY52Q5YsYmgdFZR9FNGA:yH5EvxVD2bSq4BksV5BLgd3ZgA
                                                                                                                                                                            MD5:DB4B9B953E26355D626388BB9E3D0D4C
                                                                                                                                                                            SHA1:892EA969F63EF86DB81504EE485A4043D785585A
                                                                                                                                                                            SHA-256:71111AF2BA5C3A186577DA9A1B28A57A21B18E1CA1C4391E9FF943A851CC9A3D
                                                                                                                                                                            SHA-512:4F92FA9CDC6CE7E77EDFA6467BBF9BF8F2EF80E09A726748E0E6A3FB340B6FC1E0434EF58571A1B269D453063583F9B69E23713087AE03AADB359E0276752B99
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:#bottom {.. bottom: 0;..}....#left {.. left: 0;..}....#left,..#right {.. bottom: 0;.. top: 0;.. width: 2px;..}....#right {.. right: 0;..}....#top {.. top: 0;..}....#top,..#bottom {.. height: 2px;.. left: 0;.. right: 0;..}....#top,..#bottom,..#left,..#right {.. background: #939598;.. position: fixed;..}....#wa-button-donttrust {.. font-size: 26px;.. right: 2px;.. top: 5px;..}....#wa-button-reset {.. background-color: #00AEEF;.. border-radius: 3px;.. color: #fff;.. font-size: 14px;.. font-weight: 700;.. height: 40px;.. margin-top: 12px;.. width: 145px;..}....#wa-button-trust {.. font-size: 24px;.. right: 3px;.. top: 4px;..}....#wa-close {.. padding: 8px;..}....#wa-options-about ul {.. line-height: 23px;.. margin-bottom: 0;.. padding-left: 12px;..}....#wa-options-content {.. font-size: 12px;.. overflow-x: hidden;.. overflow-y: auto;.. padding: 24px;.. width: 550px;..}.... #wa-option
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1426
                                                                                                                                                                            Entropy (8bit):5.271802199703987
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:csY0TYJGNVMz7UAVMz7EVMz7VMz/VMzlQVMCmFgtHG9pQ3jc:3XT8sTv26ZCJtHwV
                                                                                                                                                                            MD5:7ACE7021513254597642A241CE4E4A89
                                                                                                                                                                            SHA1:96129C24FB0A1950DD597AD5D2A9513E86EDB8EA
                                                                                                                                                                            SHA-256:56A31554439DE4DE7EE6D7A9F335C19E2E3A2A4BC81CD76C14A84FB9162B7CF5
                                                                                                                                                                            SHA-512:EDDD30C61BD354D0E280D2BBC53CF2E44B9CBC3807BCDB533FC3E1E4DB165D76B7F9D1C2EBDD1A3CEE95794D3FAF4AEB60DBB4893C6823CD0D11AA81FC1BDB78
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=9" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-options.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-options-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-ui-options.js"></script>..</head>..<body onselectstart="return fa
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1594
                                                                                                                                                                            Entropy (8bit):5.200218132677803
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:xmp5UoZR3xQpxsVecZa95p4H3rn39UDSyPVhilb39U0M3JtEN8vWZRVcoPu5xt2s:xmp5UoZJxRVXw9n0gA3uBHEN8vWZBct
                                                                                                                                                                            MD5:1B5E95B4DE976B1CD0ECB0198B8477DC
                                                                                                                                                                            SHA1:339303A95A250261D8D1BED2FD91118E34F0D3C5
                                                                                                                                                                            SHA-256:DF34889C77E490A35F28E1544FABA79E6DF5289A22E55D217EF2328EF0B666A4
                                                                                                                                                                            SHA-512:1F740C183D97BDAD3D808891C43C1F6071CE47BDD4A1ECA6D404958368265F2D0D5FF177E423BAE2E67DDC6229126F6223A6F593B0A922F050DE283AB7634002
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. background-color: #f2f2f2;.. color: #212934;.. line-height: 24px;..}..../* Parent container */...balloon {.. overflow: hidden;..}..../* Arrow pointing up */.....balloon__arrow-up {.. display: none;.. position: relative;.. text-align: center;.. top: 8px;.. width: 440px;..}..../* Arrow pointing to the right */.....balloon__arrow-right {.. display: none;.. height: 130px;.. line-height: 130px;..}.....balloon__arrow-right img {.. display: inline-block;.. line-height: normal;.. vertical-align: middle;..}.....balloon__card {.. float: left;.. overflow: hidden;.. position: relative;.. box-sizing: border-box;.. background-color: #FFF;.. border: 2px solid #E6E9F0;.. border-radius: 24px;.. height: 130px;.. width: 100%;..}.....card__content::after {.. content: ' ';.. clear: both;..}.....card__content {.. ma
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2055
                                                                                                                                                                            Entropy (8bit):5.214758180847983
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:+swDjYiRGNVMr7xnVMr7EVMr7VMr/VMrlwVMCrAe+xdmn56+u0INBeRMmRz0ZD:NOjPxuneCNCO06+PCBCBRwp
                                                                                                                                                                            MD5:1425654C854108A36AD043C1BC2BC640
                                                                                                                                                                            SHA1:5BCCEBED3A1C6D43212C34041C03E21B06F8CE47
                                                                                                                                                                            SHA-256:C97F364901BD668A99D6680B17B01A465FAB81C0F057B82A7835659B17B9E4D2
                                                                                                                                                                            SHA-512:39315DAA4685F5F590DAED72B895819C97BAFA213D3D068D0BBC9E06F6CD9A954436E6B6820E2A416FCCD5C199A4156EFE4E3568D419561FBE5955D9DFE49CF2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-overlay-ui.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-overlay-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-overlay-ui.js"></script>..</head>....<body oncontextmenu="return false" ons
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9485
                                                                                                                                                                            Entropy (8bit):5.218603054151627
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:2Ar/3qYFqFmMKuhiXdeRh3tEznLe7aAHKmXi:7SVIIh3t+4zri
                                                                                                                                                                            MD5:A07A8FC925038CEDA7CE76853BA03EA7
                                                                                                                                                                            SHA1:D7948C6C63C150569F492DF97B2730CEC8CC837E
                                                                                                                                                                            SHA-256:1C018D342E32C6FB39573C2E2C56F704BD108494C10C29E3610CB637BEE0429C
                                                                                                                                                                            SHA-512:C63931BD243334875FF0E227015181795829550B995E4D62C51FFAD0F776239646FD00593FD1E2024334646E634EEFD3C9E0A4C7DBFE635DEA199E837C8B1B9C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _settings = wa.Utils.Settings;.. var _instrument = wa.Utils.Instrument;.. var browserCode = _instrument.getBrowserTypeCode();.... ui.accept_extension = function () {.. var $el = {.. arrowUp: $("#arrow-up"),.. arrowRight: $("#arrow-right"),.. balloonCard: $("#balloon__card"),.. contentText: $("#content__text"),.. cardImage: $("#card__image"),.. closeIcon: $("#close-icon"),.. waLogo: $('#wa-logo').. };.... var ENABLE_EXTENSION_OVERLAY = 0;.. var INTRO_OVERLAY = 1;.. var SEARCH_WARNING_OVERLAY = 2;.. var SETTINGS_OVERLAY = 3;.. var TOAST_OVERLAY = 4;.... var WA_EXTENSION = 0;.. var SS_EXTENSION = 1;.... var overlay = {.. types: {}.. };.... overlay.types[ENABLE_EXTENSION_OVERLAY + ""] = enableExtensionOverlay; // enable_extension_overlay.. overlay.types[
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (65389), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):625899
                                                                                                                                                                            Entropy (8bit):5.616570429523557
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12288:57MdRhPEceKr1GPHte7zA+0hung074P2Ej4ITdJwuwvMaSPwCDVrx76I9kO29Gyj:qFvzIo/PWnP8
                                                                                                                                                                            MD5:48D07C122F7DEA56B862C8158A2176B6
                                                                                                                                                                            SHA1:8D4588D11134A23211B4DE4D84BBA42530148B39
                                                                                                                                                                            SHA-256:CABA02AB7A59CE0DD0D4938A62EB421EE041E7CE48BC677CC9D1707E7D1AE29F
                                                                                                                                                                            SHA-512:5D12E2C1A36B5428A751806468D85F20A7F5B8EEB1608BC4318A2FEC092746705D6420F5C68373F4529D3F4B5702F94636F044ACE25C4394242DF21008665938
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* CSS file for the new bing rebranding toast that replaces the red SS toast */..../* Poppins Regular */..@font-face {.. font-family: 'Poppins';.. src: url(data:application/font-truetype;charset=utf-8;base64,AAEAAAANAIAAAwBQR0RFRgkWCRkAAAFYAAAAQEdQT1MXRyG6AAAjKAAAE+ZHU1VChSeQLgAAWagAACZ0T1MvMtnrd+0AAAGYAAAAYGNtYXA1CTsUAAAB+AAAAtJnbHlmUcOS0wAAgBwAAeoCaGVhZBrJJGEAAAEgAAAANmhoZWEMdQYgAAAA/AAAACRobXR4ZsjwMQAAEpwAABCKbG9jYQsjgYUAAApUAAAISG1heHAEpQEsAAAA3AAAACBuYW1luw0UrAAABMwAAAWIcG9zdDq/aJsAADcQAAAilQABAAAEIwCVAAwAdgAGAAEAAgAeAAYAAABkAAAAAwACAAEAAAQa/qIAZAnt/e35bgoHAAEAAAAAAAAAAAAAAAAAAAQiAAEAAAAEAQab98VTXw889QADA+gAAAAA2KSpvgAAAADbFjbM/e39xAoHBCkAAAAHAAIAAAAAAAAAAQAAAAwAAAAAAAAAAgAIABgAHwADACIAIgADAHkAegADAH0AfQADAJIAkgADAlwCXwADAmcCbAADAnMCcwADAAQDUwGQAAUAAAKKAlgAAABLAooCWAAAAV4AMgFIAAAAAAUAAAAAAAAAAACABwAAAAAAAAAAAAAAAElURk8AwAAA+wIEGv6iAGQEbwJzIAAAkwAAAAACJAK6AAAAIAAEAAAAAgAAAAMAAAAUAAMAAQAAABQABAK+AAAAmgCAAAYAGgAAAA0AIAB+AQcBGwEjATEBNwFIAVsBZQF+AY8BkgH9AhsCWQK8AscCyQLdA8AJAwkLCQ0JEQ
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1750
                                                                                                                                                                            Entropy (8bit):5.237505222218743
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:neswDYEuGNVMe7OAVMr7EVMe7VMr/VMrlEwrVMCrYt1bQSk4CNiebvFUuHRMjg5+:tOKfnrCjCC88YkVeg50w61
                                                                                                                                                                            MD5:3B9B1D63B84AA8FDF550571AE62F2E3B
                                                                                                                                                                            SHA1:B21220253F01DD8FD12889CEDF562EB95FCEFFF0
                                                                                                                                                                            SHA-256:A72AD5F4ED76D8D56C0FD81FCD1677BDD83943C336DC1B3D2115C3B44491F096
                                                                                                                                                                            SHA-512:D76CEB797A4B49A65DDB8FC0A0E11345853954B4FD05CDE803EFF3226C5549CF164DF1F7636047790BC3338B4B14192EF93EF3218FCF34EF2568B605B4D92C84
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>....<head>.. <title>SecureSearch Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-ss-toast-rebranding-bing.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.... <script type="text/javascript" src="wacore:jslang\\wa-res-sstoast-bing-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.... <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-ss-toast-rebranding-bing.js"></script>..</head>....<body oncontextmenu="return false" onselectstart="return false" role="dialog">.. <div class="toast
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2510
                                                                                                                                                                            Entropy (8bit):5.158348945730247
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Fa+J3ggs19E5sFHDjJ60LhrqJ6MLhr3aS/dxJ6HLhryeEpOZ0a:VQgy9E5sFjjkUhWkchpnkrhePOZd
                                                                                                                                                                            MD5:942046677902A21A83DF2FAE7D2D330C
                                                                                                                                                                            SHA1:F8D0C55282D897FCC8DBE20B739F59551A5F54CD
                                                                                                                                                                            SHA-256:40C002EFF4B7C5B1B2DC0233D2CD540E01F58F4465DCE29C34B161504EDA2EE2
                                                                                                                                                                            SHA-512:FA17C8BD4CD5F460B5A88F3E7E1CBDC03CE2C7CDE389997551D9A6D7231742B4147BA384E713AF9526428C0E9964684C319F53A6FB9B23FD0D29731E77FC279F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* SecureSearch Toast UI */..(function (wa, $) {.. var ui = (wa.UI = wa.UI || {}),.. _instrument = wa.Utils.Instrument,.. _window = wa.Core.Window;.... ui.SecureSearchToast = function () {.. var $el = {.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. checkboxQuestion: $("#checkbox-question"),.. subFooterText: $("#sub-footer-text"),.. doneButton: $("#done"),.. declineButton: $("#decline"),.. },.... fillText = function (lang) {.. $el.contentInfoTitle.html(lang("SEARCH_TOAST_HEADING"));.. $el.contentInfoText.html(lang("SEARCH_TOAST_SUB_HEADING"));.. $el.checkboxQuestion.html(lang("SEARCH_TOAST_BODY_TEXT"));.. $el.subFooterText.html(lang("SEARCH_TOAST_SUB_FOOTER"));.. $el.doneButton.html(lang("SEARCH_TOAST_YES"));.. $el.declineButton.html(lang("SEARCH_TOAST_NO"));.. },.... init = function (lang) {.. fillText(lang);.... _window.setWidth("579");..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (65472), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):626133
                                                                                                                                                                            Entropy (8bit):5.617814771341909
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12288:y7MdRhPEceKr1GPHte7zA+0hung074P2Ej4ITdJwuwvMaSPwCDVrx76I9kO29Gys:DFvzIo/PWnPV
                                                                                                                                                                            MD5:CD387543A50F8B0AA81A58EAABED3C72
                                                                                                                                                                            SHA1:B0B8B31AD884A0C8387293A3A765674509C264D1
                                                                                                                                                                            SHA-256:7EFB66D19DCD9CCDA892C2688A1A1EAE0639C5664E8180DE5DA46701C4CD8716
                                                                                                                                                                            SHA-512:2E54876F0F2EB5BE51B248E98B1E328526B732421B5D7B6FFEAF5B39D1F78D4CCBE3CFD94A1162729128A37EA26A1C97C736904334F3471B7398440119A337A2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Poppins Regular */..@font-face {.. font-family: 'Poppins';.. src: url(data:application/font-truetype;charset=utf-8;base64,AAEAAAANAIAAAwBQR0RFRgkWCRkAAAFYAAAAQEdQT1MXRyG6AAAjKAAAE+ZHU1VChSeQLgAAWagAACZ0T1MvMtnrd+0AAAGYAAAAYGNtYXA1CTsUAAAB+AAAAtJnbHlmUcOS0wAAgBwAAeoCaGVhZBrJJGEAAAEgAAAANmhoZWEMdQYgAAAA/AAAACRobXR4ZsjwMQAAEpwAABCKbG9jYQsjgYUAAApUAAAISG1heHAEpQEsAAAA3AAAACBuYW1luw0UrAAABMwAAAWIcG9zdDq/aJsAADcQAAAilQABAAAEIwCVAAwAdgAGAAEAAgAeAAYAAABkAAAAAwACAAEAAAQa/qIAZAnt/e35bgoHAAEAAAAAAAAAAAAAAAAAAAQiAAEAAAAEAQab98VTXw889QADA+gAAAAA2KSpvgAAAADbFjbM/e39xAoHBCkAAAAHAAIAAAAAAAAAAQAAAAwAAAAAAAAAAgAIABgAHwADACIAIgADAHkAegADAH0AfQADAJIAkgADAlwCXwADAmcCbAADAnMCcwADAAQDUwGQAAUAAAKKAlgAAABLAooCWAAAAV4AMgFIAAAAAAUAAAAAAAAAAACABwAAAAAAAAAAAAAAAElURk8AwAAA+wIEGv6iAGQEbwJzIAAAkwAAAAACJAK6AAAAIAAEAAAAAgAAAAMAAAAUAAMAAQAAABQABAK+AAAAmgCAAAYAGgAAAA0AIAB+AQcBGwEjATEBNwFIAVsBZQF+AY8BkgH9AhsCWQK8AscCyQLdA8AJAwkLCQ0JEQkUCSgJMAkzCTkJRQlJCU0JUAleCWUJbwlwCXIehR69HvMe+SANIBQgGiAeICIgJiAwIDogRCCoIKwguiC9I
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2171
                                                                                                                                                                            Entropy (8bit):5.170488523740939
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:m2sYqYEpGNVMz7eVMz7EVMz71rAVMz7VMz/VMzlEtVMCWt1bQSk4C1uQraPxUFIc:SPdRvtT26hCW8tutJPf6F6eT
                                                                                                                                                                            MD5:80420F17AC946CD198A70122064A3848
                                                                                                                                                                            SHA1:17A79D51AF96E0388F63BCA01809873348F5FBEA
                                                                                                                                                                            SHA-256:830A6EDE3CE0C75AFEA87B7632CF84D975B36CC6BBB68F7FB91EBFA0608DE7A5
                                                                                                                                                                            SHA-512:6EA38C3C91F3A6A7D291E7AE04446FABD9BD33D40B3CE9FFAD543572D699A2BC37415B73E3C78F4CD05A27AAF2D1AF24B114D5B604ED25A3CB030CB5ED5F90FF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>..<head>.. <title>SecureSearch Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=edge" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-ss-toast-rebranding.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-sstoast-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-ss-toast-variants-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-ss-toast-rebranding.js"></script>..</head>.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6193
                                                                                                                                                                            Entropy (8bit):4.97084920450951
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:Xxb1BFoFPtYdY01kA55YUr11thN4GjCYWPe:R1BFoPg71kA55nhN4ox
                                                                                                                                                                            MD5:5323C0F428E5AB2C5B98D70CCAD96D82
                                                                                                                                                                            SHA1:5A6FFB27924A4005AF7D2C3B2D3474296CB8DAB4
                                                                                                                                                                            SHA-256:ACC9C869943127467F0EC94E2442E6DC32D612AEA7B3CB4BC79E5C9CFE29FFEB
                                                                                                                                                                            SHA-512:5C0D7CAC166D712A24FF32179C32A0222ECCFA546180BC095562540BE0343C4446EA58149E0BE7D459912164D6967CDC4DBA8894FA5DCD245E9967B9B1F05672
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* SecureSearch Toast UI */..(function (wa, $) {.. var ui = (wa.UI = wa.UI || {}),.. _instrument = wa.Utils.Instrument,.. _settings = wa.Utils.Settings,.. _window = wa.Core.Window,.. _external = wa.Utils.External;.. var TOGGLE_COUNT = "toggle_count";.... ui.SecureSearchToast = function () {.. var $el = {.. cardImage: $(".card__image"),.. cardContent: $(".card__content"),.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. checkboxQuestion: $("#checkbox-question"),.. checkboxInput: $("#set-secure-search-checkbox"),.. checkboxChecked: $("#checkbox-checked"),.. checkboxUnchecked: $("#checkbox-unchecked"),.. setSecureSearchLabel: $("#set-secure-search-label"),.. doneButton: $("#done"),.. },.... isCheckboxChecked = function () {.. var isChecked = false;.... if ($el.checkboxChecked.css('display') === 'block'.. && $el.checkboxUnchecked.css('display') === 'none') {..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2101
                                                                                                                                                                            Entropy (8bit):5.242260723103398
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:xmp5UoZJx7MdDjTPWfx9gczwPpCRulmZzhs:xArx7M5TPWfx9lzwsvzO
                                                                                                                                                                            MD5:8875B943E4A0478DE115297F7AE15374
                                                                                                                                                                            SHA1:2A7FE3E91F0311F1E3F0C866433B486ABAD993FF
                                                                                                                                                                            SHA-256:46A73A0ED9727F5A8FB11B6BC2C50BFCA61FB7D1E4B378B2A872EF542A2E6184
                                                                                                                                                                            SHA-512:A54387EF1EBFF35ACFDC09898ED9E3F48115085099B8C142D29FB24C8405E6FB70548D1B39E762AAD79852882DC7440A2664AA8785FEB811348EC54EDA82E70D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. background-color: #f2f2f2;.. color: #212934;.. line-height: 24px;..}..../* Parent container */...toast {.. position: fixed;.. bottom: 0;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. overflow: hidden;.. width: 524px; /* Window width is 530px */.. margin-bottom: 6px;..}.....content__checkbox {.. margin-bottom: 16px;..}.....card__content {.. background-color: #fff;.. margin-left: 150px;.. padding: 24px;..}.....card__content #checkbox-question {.. font-weight: 600;.. font-size: 14px;.. margin-bottom: 16px;..}.....card__content .button__unfixed__width {.. background-color: #1671EE;.. color: #FFF;.. padding: 8px 16px;.. border-radius: 100px;.. display: block;.. margin-left: auto;.. height: 38px;..}.....card__content .button__fixed__width {.. background-color: #1671EE;.. color: #FFF;.. paddin
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2093
                                                                                                                                                                            Entropy (8bit):5.211627809076251
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:AswDjYEZGNVMr71rAVMr7EVMr7VMr/VMrlEa0VMCrmglB7vURFWS4CicmQZmqEgF:DOjNlTneCp3CTRSFWSO7QmqPOJa
                                                                                                                                                                            MD5:09D7B08CF2AB5A9740F2E1410F640C05
                                                                                                                                                                            SHA1:99D525CFBD73E32C52FAFDE0D4E31014A1AEAFE5
                                                                                                                                                                            SHA-256:2D34CB6BCC22E9AA2D7726826822591E4BF4D357CB93AC8CBD5640B8BE3CC953
                                                                                                                                                                            SHA-512:2176A29ED9EE9CAE03466959D74F8B30D809CC6A9EF36B7E2B5BD96E098360709B47BA51E42DDB94AD2CF46991732729D33282DEEEC3C0EF967B9F7C390B7759
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>....<head>.. <title>SS Toast Variant</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-ss-toast-variants.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-ss-toast-variants-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-ss-toast-variants.js"></script>..</head>....<body oncontextme
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):11553
                                                                                                                                                                            Entropy (8bit):4.9747928509257235
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:lAGSRh8MezXoRYhsCSRyTe7TSlR2R1pUnoKWERjW18jEcYyhd0hyfXt:m3hFezXmYhncyTe7TSjg1unoKWyq18j7
                                                                                                                                                                            MD5:6B3E4AADE37EE300112C3E9158F9E5DE
                                                                                                                                                                            SHA1:EC0B1942E728314C4C059A28AD14D7051AD57846
                                                                                                                                                                            SHA-256:495B033EDB2E89A93B5FEA0F356E8A49F5352752DCA4A33E07075599C6DFE570
                                                                                                                                                                            SHA-512:89B259322322E060DCD391231DCD2F3F3A78ACF53A98457EB7420F75FB2BF593FF8FBDF609B46057185E7632777599E6026B6AEDB416355BD1B99DDC8DA0A619
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _instrument = wa.Utils.Instrument;.. var _settings = wa.Utils.Settings;.. const TOGGLE_COUNT = "toggle_count";.... ui.accept_extension = function () {.. var $el = {.. cardImage: $(".card__image"),.. cardContent: $(".card__content"),.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. checkboxQuestion: $("#checkbox-question"),.. checkboxInput: $("#set-secure-search-checkbox"),.. doneButton: $("#done"),.. toast: $(".toast"),.. setSecureSearchLabel: $("#set-secure-search-label"),.. };.... var variantsMap = {.. // Toast variation phase 2.. 1: {.. InfoTitle: "TOAST_VARIANT_1_TITLE",.. InfoText: "TOAST_VARIANT_1_INFO",.. Question: "TOAST_VARIANT_QUESTION",.. Label: "TOAST_VARIANT_CHECKLIST",.. ButtonText: "TOAST_VARIANT_BUTTON",.. T
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7462
                                                                                                                                                                            Entropy (8bit):5.112046421229621
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:OWZxXMHRMrola7b6xEgPGquAED+Y8AAoYE9Yl5hpeA8h9Y/5hbqe51E5T9565Cgn:OW0H2zFguf+c9Ug9K7aO9Y1bZU
                                                                                                                                                                            MD5:886734F8EF0F7A2BD7AC8EE63EAFC745
                                                                                                                                                                            SHA1:71AAC29E2B35E35315E9CEDF61B1F514FD7371AF
                                                                                                                                                                            SHA-256:AB8A4CD13E6BE8A35CFAD9B47251B46C28F9AEF9FF607B87C01AECA35595507C
                                                                                                                                                                            SHA-512:39AA1ADAC25DB607A5CF8627768238A5AB51100DF0D4E57D0E29D3A09D1B38FA562AB84E48C6EC0CB37C465E0191AD0DADF1D1123C737E755758851B7186052B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* version 2 3 */..* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", "Poppins", Arial, Helvetica, sans-serif;.. font-size: 12px;..}....body {.. background-color: #f2f2f2;.. color: #212934;.. line-height: 24px;..}..../* Parent container */../* version 2 3 */...toast2_3 {.. position: fixed;.. bottom: 0;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. background: #FFFFFF;.. overflow: hidden;..}.....toast2_3_larger {.. width: 761px;.. height: 565px;..}.....toast2_3_smaller {.. width: 761px;.. height: 500px;..}..../* version 1 */...toast1 {.. position: fixed;.. bottom: 0;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. overflow: hidden;.. width: 524px;.. margin-bottom: 6px;..}..../* version 2 3 */...card__content2_3 {.. background-color: #fff;.. margin-left: 297px;..}..../* version 1 */...card__content1 {.. background-color: #fff;.. margin-left: 150px;.. padding: 24px;..}..../* version 2 3 */...card__
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3851
                                                                                                                                                                            Entropy (8bit):5.043335582612994
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:jMsaURv265bWZNY0TUYoAzgs3CZ4ea9S6ghD2QXIanvOksN:jjbGe9Yo2gs3JeacVDfXIanGk6
                                                                                                                                                                            MD5:194D0B9162D444B0DBFC81EEB847DD7F
                                                                                                                                                                            SHA1:90F0A30B758221B2F2C4499BF66B1D122329A253
                                                                                                                                                                            SHA-256:02DFC1A9187AE8D00620CAFA3653085BE3E32533C33A304C902654666A439E58
                                                                                                                                                                            SHA-512:7BFA894BFD24D9CC6959CF166B25EB2DAE771E89524CC398CFD3FD851F3031874E89ABDE29A3DF3CE307D701D85D8240F316BF09D4612ED175DC427BA66C2FA7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>.... <head>.. <title>WA SS Toggle Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link href="https://fonts.googleapis.com/css2?family=Open+Sans:wght@400;600;700&family=Poppins:wght@400;600;700&display=swap".. rel="stylesheet" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-sstoast-toggle.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-sstoast-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\weba
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9145
                                                                                                                                                                            Entropy (8bit):5.149275800236925
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:lAZ3m0aWPwT0JrrvG1zuLIhHQnJC16yhu3Fo65Dcw+hdlgX+R:mZ4j1yDJsu1oprfs+R
                                                                                                                                                                            MD5:4E75CA82B63BF0D7CE816D5E07456841
                                                                                                                                                                            SHA1:3392B5074F72124100DEE3CC1F63393C30C58C0E
                                                                                                                                                                            SHA-256:6436CD5A82FBA6D79412856952150658ADA7B06AC0C06A2CCFF41684D28733DE
                                                                                                                                                                            SHA-512:8A70EAEF47B0722794E87461668C8B9775D52FAFFB24BB9AE7B9C15AF263EBA74C014A12DC5FD179385AE741C64454185290A2C87A35186C122AE39BDD10CED5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _instrument = wa.Utils.Instrument;.. var _settings = wa.Utils.Settings;.. const TOGGLE_COUNT = "toggle_count";.... ui.accept_extension = function () {.. var $el = {.. cardContent: $("#card-content"), // different css for different versions.. cardImage: $("#card-image"), // different css for different versions.. featureDisabledSection: $("#feature-disabled"),.. progressPic: $("#progress"),.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. expiredSection: $(".expired__section"),.. expiredDivider: $("#expired-divider"),.. expiredLabel: $("#expired-label"),.. expiredName: $("#expired-name"),.. feature1Label: $("#feature-1-label"),.. feature1LabelContainer: $(".feature__1__label__container"), // dynamically change container if text is too long.. feature1Name: $("#fea
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3034
                                                                                                                                                                            Entropy (8bit):4.638682919992348
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:B4j7B2AacfdwtxqApUQVVPhPkzYOEbFQO0HR/1xRzi1CePNXDtw2:scAa+dwtVVVPCxEeO011xReXDW2
                                                                                                                                                                            MD5:B90AC515CF2471538F252204450BD9C6
                                                                                                                                                                            SHA1:FF6F2C0CEF15E3047F8C4A510D2CCDBE7030F7DB
                                                                                                                                                                            SHA-256:0334EFDA0E4D28ADFCAF4C7AED0EDD3EB3EC1BF98981AE8122278A25B4B93AAC
                                                                                                                                                                            SHA-512:94581EF550DE590DC11A4496E07D8877C19DA470B661B08AB544B1251FFEE99A657115BFAEA2C9B0B9CA848BE3F6C01B04A4FA51DE47340FF00563E1C728A97C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument;.... ui.accept_extension = function () {.. var $el = {.. button: $("#wa-dialog-balloon-button"),.. content1: $("#wa-dialog-balloon-content-1"),.. content2: $("#wa-dialog-balloon-content-2"),.. arrow: $("#mc-dialog-arrow").. };.... var telBalloonType = '';.... show = function () {.. _window.ready(function () {.. var settings = JSON.parse(_external.getArgument("overlay_data"));.... if (!settings.balloon_type) return;.... init(settings.balloon_type);.... _window.show();.... //Send Telemetry 3.0 for dialog balloon.. var browser_code = _instrument.getBrowserTypeCode();.. var screen_flow = browser_code == 'F
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:C source, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2413
                                                                                                                                                                            Entropy (8bit):4.801374194851256
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:H45ikVjkpq/nWp1qgVsk0HuKAh51nhtlUT:Yjk+WlcsBhtlUT
                                                                                                                                                                            MD5:706EA6AA85B81C7698F191EF1182BEC8
                                                                                                                                                                            SHA1:2EA6643CE2EA042DC4B0B0BB048EBBC4ABCE4F3C
                                                                                                                                                                            SHA-256:20CEACF0E32F77DF4ECE5DDF4A8EC6411B04916701DEA3919C311BD4C5AFA3B9
                                                                                                                                                                            SHA-512:EC75CC071062E8C5BAD474EBF993A0931342EE071B92FCD71565082B509864781DA3B68B009F36BC1853428DCB66023E3530EBB24552F6105B11AF9E3B54351F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Download Warning Toast UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _instrument = wa.Utils.Instrument,.. _window = wa.Core.Window,.. _dw = wa.Core.DownloadWarning,.. _wa = wa.Core.WebAdvisor,.. _l10n = wa.Utils.Lang().checkList();.... ui.DownloadWarningToast = function () {.. var $el = {.. logo: $("#wa-dw-toast .logo"),.. status: $("#wa-dw-toast .status>span"),.. content: $("#wa-dw-toast .content .body"),.. block: $("#button-ok"),.. allow: $("#button-cancel").. },.... show = function () {.. _window.ready(function () {.. var domain = _dw.getDomain(),.. fileName = _dw.getFileName();.... $el.logo.append(_wa.getProductLogoHtml("wacore:mfw\\packages\\builtin\\mcafee-logo.png"));.. $el.status.append(_l10n("PP_STATE_TEXT"));.. $el.content.append(.. "<p
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):21369
                                                                                                                                                                            Entropy (8bit):3.8672869876322054
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:LravuBFTItBHDiF9ymq4pZpnXEB25hmmvYXOergIzKN:PavuBcBHDdmRHpXEB2UEI+N
                                                                                                                                                                            MD5:135EFC09A3C04100FFE3C123FBFDC6CE
                                                                                                                                                                            SHA1:8D940249DB78E559209CB78520E100188487143E
                                                                                                                                                                            SHA-256:1C99E219D44E98E1750368C7EE4DCEBDE0BE93675E4CE31F340143704FFCAA8B
                                                                                                                                                                            SHA-512:7CDA9587E90D3ABBDB5102D493C0D72CB62B82D4F1C4A9B869ED433620E40616AC3B2C9E237779A2ADC6F707918EA0C2C58101BF2EC1E3693B3BB1FA96184351
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Options UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _instrument = wa.Utils.Instrument,.. _settings = wa.Utils.Settings,.. _lrt = wa.Utils.Lang.ResType,.. _l = wa.Utils.Lang(_lrt.OPTIONS).get,.. _core = wa.Core,.. _window = _core.Window,.. _webAdvisor = _core.WebAdvisor,.. _productNameHtml = _webAdvisor.getProductNameHtml();.. _external = wa.Utils.External;.... var OptionsMenu = function () {.. var menuItems = [],.. el = {.. $menu: $("<ul id='wa-options-menu'></ul>").. },.... toggleContent = function (id, delay) {.. $("#" + id, el.$content).. .fadeIn(delay).. .siblings().. .hide();.. },.... itemSelected = function ($item, delay) {.. $item.. .siblings().. .removeClass("selected").. .
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 210 x 180, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):12312
                                                                                                                                                                            Entropy (8bit):7.968450241648148
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:yRBdas2d1PJ4BYvAHpw+9zCUu3lsOgtPaITUL:6UdVTUoUTHs
                                                                                                                                                                            MD5:4FB51E8F6008C7C9C8F0A1075BED12A1
                                                                                                                                                                            SHA1:39C35D6482BF2D7B8A347991BC99F4EB408B7FE7
                                                                                                                                                                            SHA-256:866910A9732E353EDFE938958BF6F4B6FF03FFA6B90589BD03C44011D2E41C37
                                                                                                                                                                            SHA-512:6C39FDEB9036823547E8515A7F0505B41A519F5F70D55A1D2B51A10B9FAC6D8738EB3D78D2DE2BEE55666C5712A4753D72450760B69836C7F1B71577760FD99F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR..............4r.....pHYs.................sRGB.........gAMA......a.../.IDATx...|....vyU.xO.. ..8.%!.8.PJ......t..RHx....@[.......@i...-.<..H..%....x..y.l-3.+.<.G.i...~>.F..5.9.=.\.,,tp.P...rr./~<...h......a........A?.i.m.R.y?9a.y....".......0.,0-........LS,!Y...al...G..k....V.a.NGQ....p8.o.A#..<...<...0.+.`..0.....!...k..Y.x..ax~-....T.8w.t.T^...`..&.a.#.h......}Z.8...(..4.^L2.....&X.M0<.....B.T....d..62......`....,...'f...I<R.....!..t.T..(,.e.."......x..9...Z..(0.BH.]...2....lS.D.'".h)$kU.. 0....:M...z..6`..1.1.|.VI.%.9...3.B.NS&......i...G..i.mS..M...f....x2!.5.....:M......y(......V<...,.%....!.W.d........s.:.BJ.W0...WO.!#.b.E..Z.fP0..r./.j.....lq....M.u....L....3.2PLD.O.Ao.!,.!?.....2...iR.D..[Y...-,. ..d...cC[.%..,,..a..U.m.<.4!%D....`aa..d.L..%".."_.......,.YL.d.|s{gp.L1.......Qv..I....38.q......*pH...j..0!.u..,..XXL.SV.j..p4..1...w...k....$.s...:.e^.Dd..`...g.>.dr......U.b.O.....&.Drr.."_..C..MV..."a\.V.."?.B`.3y.y....E.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 210 x 197, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9639
                                                                                                                                                                            Entropy (8bit):7.959929359756836
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:8Sx+XNV33b9KE2nQId+RaxmxmDzMeRPGUhtGrnGyzcgJSzJKlkY+BjJJnjYdSPay:7SX9KbIRARfvRtklzcgJS1Ukz7hjYdJy
                                                                                                                                                                            MD5:0960D91DFEAF52DB02812BF775B62C55
                                                                                                                                                                            SHA1:125D3E9976B984B6BFDD698140626CB92D393722
                                                                                                                                                                            SHA-256:9E7C4BF9C4911967D24A948BFFE7268F5925A1B1E3DCD5D9CBEB7721DF32DF24
                                                                                                                                                                            SHA-512:C2AE53F305F34A3E6B0EF8E29A1E21A477C4A62F6AD27A69A91C7F1CD601A94DA1012341169F7E11C293D12AEC9B07B14CCB23185829A8C7F05FE0EDC718B681
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.............!J.a....pHYs.................sRGB.........gAMA......a...%<IDATx..{t...._..j..%...`.....!..q.....&.N^..$....Hrv.....v...........l2I&..a.....O.[......l...WU...[.wwuwU...9..]...T..=.D".H$..D".H$..D".H$..D...DR.}}.@.-.iG.k...D........RH..\..&.*.r.M.|..j:.M...a......a..Dkk....)$I.I.pU...w.C.P].p..ok..."bA....>..T.r.!\.&.....R..8..9...8.(..F........;..K..wp.N).rB.){...\gk0....$..]twd..#w.\...Bh.0.....j(.R..*\....7..8.o!..B2-O=.g.}..),.0.....5'..{*.).i.ZW5....UBrP@9..`w.b-....6!.]..O.B1.o[h..5B........r"\A.]..]..B....S{..|....6.\(^B.4.n.o..g...Y+7.q]...N5.R.Hx.....H.Vz\?.....$3..l....Xr.....Z.{.bj".Y.=.v+d...z.J\..1;2...a.(.`].r....U....8..S..../{d1.A/@V*..z..,.o-..MF....&.(.S'..p...V6.w..7.N7.z..i.Lx...vCB..P.(".,..K5pe...l<$q#....B.P..+,.=.H....d..fE.......].FL..I.H........7.G..$...W..>..D..EH.X....H...'....FT]H...9....[.|.5..1.Yl...!...C.......TMHT..*;*...Z....:......q..I.I...G.N>TEHfrA..I.C...G. ....(.K&.$....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 142 x 114, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9195
                                                                                                                                                                            Entropy (8bit):7.974458734523204
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:qSgxF7Rxse5mfaPumPCqZplpMCwhsoYl6Va1uaOyplM/0zPMyWEu0:lg77RxsRaJCqD/twhsFl6VaD5KyWEj
                                                                                                                                                                            MD5:985990E7B49221E68CA85928ABFB55B6
                                                                                                                                                                            SHA1:A625326AFC180A99526B9C1E36C85718A8AE4E53
                                                                                                                                                                            SHA-256:6FCA27CE0ADD2712EA1CBAF52291BBC2C9AA3E5B8411348DA4459082E53D456F
                                                                                                                                                                            SHA-512:AD415F9B2242675A26DFD9FAB9DCC9E2BA02191EDFB4B938C688458E92379263C9E1357EEDF8E97D4956E3A28E69D59A80C6FD23777371A33CC1A02D2AF45181
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.......r........j....pHYs.................sRGB.........gAMA......a...#.IDATx..].`TU.=.M.d..R.%..{...*M...(.k..UDqw.U..]uuw]...H.^..RB...u..3...L2.2....}.d......0..#.0..#.0..#.0..#.0..#.0..#.0..#.0..#.0..#.0~.h.v..W..#..%....]..M....e..rA.iI.>q8...E......qI.Y...T. ...Hr..]..{.V;.....G...S.J.........Z.Y.6...(...Dv.%%l"`..`.%X...m...a...J.#...,.....G%..:]...I.^9z..-."#.......B...%(a..0:t.0.`<.@.K:?!G.@...42.`..%..X..\>z.3R..N..}.b..%..:A.N.B..>...d.H0X...C..H0"...,..m.EQ...t....N....Fi.v.Z"y#SE..U?M.....mv...S...T.[.7*.'.T.0<.,..E..%:.ce.Go..g...&G.U.A......;.m.E.k6...%..2.tt..#J.w...|X~.R)h.g.a...6.(c........U.UZ..$.1a.........Pq...+.%....`....p8.6..ZNoWl...8.....$.#.$I{.m4.+`.7...0..B...SC.e............2....;..E..A.H3.^.}.W..E..9.....).Bs.b....K.. .q....q. (...... ..........`.....*..s.........C s..6oJ..Q...F.I.&..Q.N;v..... M..~D..P..Z'Ga.<..{%.....<l...')....A..."..ATT..x.z.c..B...A.q.k.....;...M....0....5.6n.P.7.......w.(,.%..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2407
                                                                                                                                                                            Entropy (8bit):5.148335532359029
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Uk73uxPuaasQ8+FQv2xfdleIileIjOmkRlYWBheIpJqqeGzeNeIp5eNeII64J:UDj+aOxf7KjiRlYWBxadt+t4
                                                                                                                                                                            MD5:ACE11B7FDD8896AFE05BC6A25081BC72
                                                                                                                                                                            SHA1:B1C2D5F41C3719AD8EDA01DC4B50602B35BEFB09
                                                                                                                                                                            SHA-256:761ED2999CD3F6DB58CCBD00F3CF4874564C30E5B9E21DBD13501E909748FA68
                                                                                                                                                                            SHA-512:69B07BB9CE7AE4FE71E93562E80D23410878820593D743634582F9B0FB4F2107B8B5FCCCC3F32B4BB0527B8ADB680CE3884533F2BED58943064F1C521E175721
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:body {.. margin: 0;.. font-family: "Open Sans";.. box-sizing: border-box;.. background-color: #FFFFFF;.. border: 0.833333px solid #BCC3CC;.. box-shadow: 0px 0.833333px 8.33333px rgba(0, 0, 0, 0.254218);.. border-radius: 1.66667px;.. overflow: hidden;..}....h1 {.. font-style: normal;.. font-weight: bold;.. font-size: 16px;.. line-height: 32px;..}....p {.. font-size: 13px;.. line-height: 16px;..}.....main {.. text-align: center;.. background-color: #ffffff;.. height: 220px;..}.....main-logo-container {.. display: inline-block;..}.....main-logo-container .img-wrapper img {.. max-width: 128px;.. padding-top: 32px;..}.....main-divider {.. display: inline-block;.. margin: 5px;..}.....main-description-container {.. display: inline-block;.. text-align: left;.. vertical-align: top;.. max-width: 295px;.. height: 100%;.. position: relative;..}.....main-description-container p {.. font-size: 14px;.. line-height: 20px;.. color:#000000;..}.....main-description-containe
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2529
                                                                                                                                                                            Entropy (8bit):5.078446846524373
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:cXTxBv26HCe8+DSSqoFbeIwEeIYuAXYgY:p8zFb1DgY
                                                                                                                                                                            MD5:7DFFD407F62727E6E1D71AE78001CC1F
                                                                                                                                                                            SHA1:D92F03545A15D360453E09679938EEEEEB8B5EEF
                                                                                                                                                                            SHA-256:D1456E95B707A89DA12600233EE573004066B7A13CBCDE7FEEAB1CD43789DC08
                                                                                                                                                                            SHA-512:3FA0C2E556EA1ED15962A6417643AFD35F389ED796D6C6B23BA4E06348456394F9C88995E14EC1897B7FDC1E0210858C92B8544748AA85B5D189DA099EBCC40A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>..<head>.. <title>Download Scanning Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=9" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\webadvisor\\wa-upsell-toast.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-upsell-toast-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\webadvisor\\wa-upsell-toast.js"></script>..</head>..<body on
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):11903
                                                                                                                                                                            Entropy (8bit):5.080001554604501
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:80/PfJTvqz3NbDdvSNOsxyVVXMT2Opb6/0Q6w:JPfJTvECBxyHcTRA6w
                                                                                                                                                                            MD5:44E2C89A41EF766119A1270F68A2BE83
                                                                                                                                                                            SHA1:031169D58949342543F3F16A20897B7D127BE532
                                                                                                                                                                            SHA-256:1B66F9F4A2EFA6564DFC205AF5EB78A1AB54DA5D156544AB677AD56B4407B0A3
                                                                                                                                                                            SHA-512:0CBA3EE2670698FE27E07999392A04B4FC1CD3F3BAF255B7DF154F394B3A52E97BFC074C8A5EF4E60AF91218FE6FA3AB6E590A14599140AFDDE1558C35711FEC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _settings = wa.Utils.Settings;.... ui.createUpellToast = function (toastData) {.. if(toastData.campaign && toastData.campaign !== 'none') return new ui.CampaignToast(toastData);.. .. if (!toastData || (toastData && !toastData.cohort)) return new ui.AvScanToast(toastData);.... switch (toastData.cohort) {.. case 1:.. case 2:.. return new ui.DirectUpsellToast(toastData);.. default:.. break;.. }.. };.... ui.extend = function (Child, Parent) {.. Child.prototype = Object.create(Parent.prototype);.. Child.prototype.constructor = Child;.. }.. .. // ----------------------------.. // Base Toast Object definition.. // ----------------------------.. ui.UpsellToast = function (toastData) {.. this.data = toastData;.. this.lang = wa.Ut
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PNG image data, 47 x 46, 8-bit/color RGBA, interlaced
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1793
                                                                                                                                                                            Entropy (8bit):7.876784630522941
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:qaOARKiy6Zk/fIEJo8VsjZhQ78P49eiQgPO4sP/ulgafKd6c:/OATy6Zk/1x0TQg+wvPmlga1c
                                                                                                                                                                            MD5:0649B7E9A67DE6931312BDB5BE3FA6D6
                                                                                                                                                                            SHA1:285B792941D7CCB34ECC8749A367CAFE4A51D4B1
                                                                                                                                                                            SHA-256:CBB5964B1888A95703984990FBC9C71448ACBA8A5E19BC0A96E626C2129F7E22
                                                                                                                                                                            SHA-512:12B8E6C4F3EBFF51BA6CE1FE66D737461CD0C30F0B9E65443256886DDBF9E1518E3A26D9186CD8F2CA95EA09D35F910372558BE1C997073E0E26603C4DABC22E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.PNG........IHDR.../..........|p.....gAMA......a.....IDATh..Y]l.E....R....?.y.A@1.mi.)F.....#J.F.'..O.Q..#Q ......>hPH...X....b[b+..@.Q @....{w<g........W...9s.7...93C...7..e.b..\.d.....d!..'......G.....k...2.1J.a.6.1!.{.E.0..r...D.....I.5k.../.@..&QD.*j.oW.....6...}.2...\O..,..f...q....U...1.....Lf..U....bs....:.0!..?Q...j.e..;...X...qN.JM.[..../....=..2T....T?..VcR...qFl.._.T@.s...rP.....L...3!1...L.Z..xlh0.....Tr3..D..V......^.^..t.....3O.ED....8j8....k.E.`...{.>....v8...R...@.8.R_.. ..|&C..?.....rG..( .y....}.z.p.28w.....k..v.7.~.......7F|.. .@.8"..,..L...Q....7.a......oI*.z.f.{.j...`......}g.....!Y.... ..J2p..IJ...2...X..G8..Y.. N}..t...26.....M.._.....c...fs...{....)t[.,....e.&............t%.PX...W)..%..........t.`>.....7...H..s.CW..........u}.nS...~...&O..1...C}.....#..G.IH0.mjj(.._....M...=..C2..==..V&...~1..?...en..M...\.Q.%...B./.g.S...... .#.(....*..q...jb......p;../5.m.T..-...SE.h..(.|le...[.**!...=:TJ..!m..q2..CI.$
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):292
                                                                                                                                                                            Entropy (8bit):5.419707792418915
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:KYCutJFlCutfwEr+gCutF3GHKllj3kkkQ+sCRXU2QcK0bJB0YndswRFOh:lCu77CuuSCu3TlljUkZ+sCRPQf0bJxng
                                                                                                                                                                            MD5:2D4716CB6396867898E638FBED581C92
                                                                                                                                                                            SHA1:CCE452A7EFED51B864DDFE0A67528BF9ED46A6E7
                                                                                                                                                                            SHA-256:A4877EC3224DB3A15202C61314851CFD3F3AD571D5415A6FFC94418B98DB833D
                                                                                                                                                                            SHA-512:5750EB789C2F648A6614E034C847177F2631628F61427C168141F4717814AA5BDB29A6EDEA730711E00593723BE863B13EBA4EDAA8E2DC7F029DE2C9DAEF5F1B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:input[type="checkbox"], input[type="checkbox"]:checked {...box-shadow: 0px 0px 0px 1px black inset;..}....input[type="checkbox"] {...accent-color: white;..}....//CF7A624574F35B686A76C33FBAA5D5626E68CB421789FDF19DC592634B8E15619F996FF07166DE1B52F3241BA149933E8DE73A28070A49845286C956C22317BB++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (65446), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):89637
                                                                                                                                                                            Entropy (8bit):5.297773771322314
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:1536:ejExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1vz:eIh8GgP3hujzwbhd3XvSiDQ47GKl
                                                                                                                                                                            MD5:A64BAF7831B8FBBC144FCE258F8001E1
                                                                                                                                                                            SHA1:13FFDDA846919FDC59679D1B125280F248929D43
                                                                                                                                                                            SHA-256:AE6E5367B413CA6723DE305E5DCA0C0798802ED8D7173F8D54572AF32C724329
                                                                                                                                                                            SHA-512:F27F2119AB74FF94F620E0D0158CB78D56D4907F5B7B82770A1D40F7C8AD8D55C891BC9ADC99777CC5FB6291A34A8DA372FDBE3F8937DECB87A8E7FD892DCCA9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */..!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}func
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (33246), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):658029
                                                                                                                                                                            Entropy (8bit):5.645591473547629
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12288:L47MdRhPEceKr1GPHte7zA+0hungs74P2Ej4ITdJwuwvMaSPwCDVrxT6I9kO29Gi:BtvbIo/PWnPo
                                                                                                                                                                            MD5:73749C67AB20082E7B11AA59ECAD88CD
                                                                                                                                                                            SHA1:5260894A20670E0F2380166E929F76B9AAC1F626
                                                                                                                                                                            SHA-256:21A4157938BAD6BA8759799F72725704270B9C49D90097FB7F7E45FF0543E841
                                                                                                                                                                            SHA-512:561A0E1BD2ACD1FE4F4790054F6BB45DEC7394417F2AD79323ED1B96D7DE2DD5537F2A1C3D568B7192FE9E262FFCBA1DFA46DFAC9F943B6EAF4B39FAA678BFC5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Open Sans Regular */....@font-face {.. font-family: 'Open Sans';.. src: url(data:application/font-woff;charset=utf-8;base64,d09GRgABAAAAAGEsABMAAAAAsTAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAABqAAAABwAAAAcbEIkOkdERUYAAAHEAAAAHQAAAB4AJwDwR1BPUwAAAeQAAASiAAAJmCwaFlhHU1VCAAAGiAAAAIEAAACooF6Ikk9TLzIAAAcMAAAAXgAAAGCg5ZlGY21hcAAAB2wAAAGGAAAB2s9AWKBjdnQgAAAI9AAAAEYAAABGE1sNN2ZwZ20AAAk8AAABsQAAAmVTtC+nZ2FzcAAACvAAAAAIAAAACAAAABBnbHlmAAAK+AAATOAAAJGkMGdKhmhlYWQAAFfYAAAAMgAAADYJip5GaGhlYQAAWAwAAAAfAAAAJA9zBj9obXR4AABYLAAAAjcAAAOm2kNYqmxvY2EAAFpkAAABzAAAAdZ4GFVubWF4cAAAXDAAAAAgAAAAIAIHAZduYW1lAABcUAAAAgcAAASAUcWdxHBvc3QAAF5YAAAB7gAAAt15xIzucHJlcAAAYEgAAADaAAABfLpWDR93ZWJmAABhJAAAAAYAAAAG7JdVfgAAAAEAAAAA0WhVmAAAAADJNTGLAAAAANGknRZ42mNgZGBg4AFiMSBmYmAEwpdAzALmMQAADaEBGAAAAHjarZZLbFRVGMf/M51hxoKWqtH4CBoyNrUGjQ1J27GwatpaDZZpi4MOig/iAkJCY0hMExaFgbgwIQYrOTxqCkyh0FmQUpryMkxXLNzhaW3jyuVJV8QFIY6/c9sp4EjVxHz55dw597vf43/OPXMVklSpbn2qSEvru916/rOvenep5oveHTtVv+uTL3droyL4qFiU9/0316GdO3p3K+6vAiIKB2NcoXh
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):24151
                                                                                                                                                                            Entropy (8bit):5.1621785675529
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:ZHbw3tcalAiF0+6ycdaYiY+JiZ0DmrhiWbYM4veoX0qLv5Ms9X+95Synwn2:ZHbw3tcalAiF0+6ycdaYis0DmrhnbB4q
                                                                                                                                                                            MD5:FEF95AACA6FE669CF114CB9E796BD485
                                                                                                                                                                            SHA1:D9B8B9E986031F12519E275D6249A139CBF9F8C1
                                                                                                                                                                            SHA-256:E5FC3A4451EDF51FC28AB4019EA75BE0A4A411DF26FE2BFD2B0BC9F5D7465712
                                                                                                                                                                            SHA-512:0A368EE1F64986DD88D0B5AC470FCAD51E23799779304A457D871DD2380C364537D14EDA23DDD52258B54EDA4D7B83A596FB1AFDB04E61CC8FFCD2611105D625
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Core */..(function (wa) {.. var core = wa.Core = wa.Core || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External;.... //Component.. core.Component = function (name, status, key) {.. this.name = name;.. this.status = status;.. this.key = key;.... this.isIgnored = async function (key) {.. var isIgnored = false;.. var startIgnore = await this.settings.get("startIgnoreDate" + (key || this.key));.. var ignoreDuration = parseInt(await this.settings.get("ignoreDuration"));.... if (startIgnore && ignoreDuration) {.. var today = await this.settings.getToday();.. var startIgnoreDate = startIgnore.parseBasicDate();.. isIgnored = today >= startIgnoreDate && today <= startIgnoreDate.addDays(ignoreDuration);.. }.... return isIgnored;.. };.... this.isInFixGracePeriod = async function (key) {.. var inGracePeriod = false;.. var gracePeriodStart = await this.settings.get("fixGracePeriodStartDate" +
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7998
                                                                                                                                                                            Entropy (8bit):4.696692835387019
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:j8KiNn2zKMXjRIQIeTZmY2OToGF/8OJISRjla0mo9SWLpmUtpdcSbFn4VZ:IKiN2zKgyTeTEZzSRjg0jScmcdvMZ
                                                                                                                                                                            MD5:D9975E21D059E90A256B00C48E4FDD54
                                                                                                                                                                            SHA1:44A68F5CAF5326CD90BAB396C93EBD29BC2CC098
                                                                                                                                                                            SHA-256:CD6D29FFFBDB412347D51D29D27DD7BDECAA05D85B01134BE1FBC2F9BBE4DEB2
                                                                                                                                                                            SHA-512:476AD8B1E514027C0B565D723F606A14B5AAF4E901132698B1BC661C8E73DC2D7170FF258494FA5C2D626CF0EB1DE170D0B7DDD7767DB1C39C47B0E13DEF6B66
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* CheckList UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.... ui.closeDelayTimer;.. ui.CheckList = function (options) {.. var el = {.. $checkListWrapper: $("#wa-checklist-wrapper"),.. $checkList: $("#wa-checklist"),.. $messageWrapper: $("#wa-message-wrapper"),.. $message: $("#wa-message"),.. $messageImage: $("#wa-message-img"),.. $closeWrapper: $("#wa-column-four"),.. $close: $("#wa-close"),.. $logo: $("#wa-column-one"),.. $state: $("#wa-column-three").. },.. checkDomLoadedInterval,.. animateDurationInMs = 400,.. self = this,.... setState = function (options) {.. el.$state.. .html(options.state.template).. .addClass(options.state.css);.. },.... setMessage = function (options) {.. el.$message.. .html(options.message.text).. el.$messageImage.. .html("&#187;").. },.... setBorder = function () {.. el.$checkList.css({..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3536
                                                                                                                                                                            Entropy (8bit):4.494740738337656
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:kZGJ5nzQQenlzN1vylhovKKHNLzpCZjeVBXfoil:kZ8W0v8RHNLlCZjoJfoil
                                                                                                                                                                            MD5:5D2C7932D8D84AD6EF65BEFD0036BD93
                                                                                                                                                                            SHA1:E1AB00696037F650159A8E22311C93FB7B760B49
                                                                                                                                                                            SHA-256:3B752C707A77973161B5746A73CDB59839541A2BEEC7797336981964FA4D9A1B
                                                                                                                                                                            SHA-512:743A3109C00D503B32D93C054532F0FE23506A3D5747E44CDF3294ED9E0F42682E631AE0FD32D2B00E675B5C202F0CFF89C12D7CAF6627276C67A8FBCE2A637B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Dialog UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.... ui.CheckListDialog = function (options) {.. var animateDuration = 400,.. el = {.. $dialog: $("#wa-dialog").. },.... create = function () {.. clearDialog();.. createHeader();.. createContent();.. createButtons();.. },.... createHeader = function () {.. if (options.header) {.. el.$dialog.append(.. $("<div>", {.. id: "wa-dialog-header",.. html: options.header.html,.. tabindex:"0".. }).addClass(options.header.css));.. }.. },.... createContent = function () {.. if (options.content) {.. el.$dialog.append(.. $("<div>", {.. id: "wa-dialog-content",.. html: options.content.html,.. tabindex:"0".. }));.. }.. },.... createButtons = function () {.. if (options.buttons) {.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):18974
                                                                                                                                                                            Entropy (8bit):4.474059874801466
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:BZwBjF3z+j5csy4h11lidEaCa3z4T2EW85xzC2Rvbat2ReY9c8o9OmFfRo:WJyj5csy4DIE3mUTRbzC2RvbaLU
                                                                                                                                                                            MD5:6FA876B654EE2577A67E2F9BAFE775D8
                                                                                                                                                                            SHA1:C84A3C671AE1202EF60E5FA586D5E954EC6053EC
                                                                                                                                                                            SHA-256:C5342CE6CF56B39FE98D72178DC2ED431FEE3FE94116D775E175E473DC74345B
                                                                                                                                                                            SHA-512:9AF6AEDAD9291C38266BA724900FD32A2D9834A6A3EB855984E66AD3950ADB00979B692F2C67ECAEEC3347A1DE42FC8F6C589F3FBFEF491412A06CAA33763B64
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Utilities */..var _langResources_ = {.. checklist: (typeof _lrCheckList_ !== "undefined") && _lrCheckList_,.. options: (typeof _lrOptions_ !== "undefined") && _lrOptions_,.. shared: (typeof _lrShared_ !== "undefined") && _lrShared_,.. uninstall: (typeof _lrUninstall_ !== "undefined") && _lrUninstall_,.. sstoast: (typeof _lrSecureSearchToast_ !== "undefined") && _lrSecureSearchToast_,.. install: (typeof _lrInstall_ !== "undefined") && _lrInstall_,.. webboost: (typeof _lrWebBoost_ !== "undefined") && _lrWebBoost_,.. waiff: (typeof _lrExtensionInstall_ !== "undefined" && _lrExtensionInstall_),.. ut: (typeof _lrUpsellToast_ !== "undefined" && _lrUpsellToast_),.. overlay: (typeof _lrOverlay_ !== "undefined" && _lrOverlay_),.. newTabToast: (typeof _lrNewTabToast_ !== "undefined" && _lrNewTabToast_),.. ssToastVariants: (typeof _lrSSToastVariants_ !== "undefined" && _lrSSToastVariants_)..};....(function (wa, lr) {.. var util = wa.Utils = wa.Utils || {
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):8697
                                                                                                                                                                            Entropy (8bit):4.951690631753836
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:O4n4gMn8LeQ1EU/AsS3zwgPSQyg8qifxE74:p4gMns4sS3znPS08qifxf
                                                                                                                                                                            MD5:AED77490021932F6B70456B419E4EC72
                                                                                                                                                                            SHA1:D9E2FB4DE3CA0BA2E8782DA5B12DE9BA2C87F6EC
                                                                                                                                                                            SHA-256:0A46965A67D037DF02D66FA8159FF59222168C8111FBE47BC2A580FB0AFF80B1
                                                                                                                                                                            SHA-512:53F978177BB2D4EA5217DAB4D4C2B77769829A307E26F271B8690803591DD13E4D66FEF45D563C92785C53E8E313CD38CD9305EDD0B2851CE3B7CEF1730A7C3A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* MWB CheckList Controller */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _tmpl = wa.UI.CheckList.templates,.. _core = wa.Core,.. _window = _core.Window,.. _lrt = wa.Utils.Lang.ResType,.. _l = wa.Utils.Lang(_lrt.WEBBOOST).get,.. _checkList = _core.CheckList;.... ui.CheckListController = function () {.. var self = this;.. var browser = ""; .. var wbShown = "WBShown";.. var wbLastShown = "WBLastShownDate";.. var installDir = "";.. .. this.update = function () {.. _window.ready(async function () {.. var args = JSON.parse(await _external.getArgument("template_args"));.. var isInitial = false;.. browser = await _window.getBrowserType();.. browserCode = await _instrument.getBrowserTypeCode();.. installDir = await _external.getInstallDir();.. if (browser === "FF") {.. wbShown
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2613
                                                                                                                                                                            Entropy (8bit):5.121215845258046
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3Ox0xsUa3l363kKk+kUTkikfE5CYqOcqe5QORDnyJ1:32ExqOcq6Qq61
                                                                                                                                                                            MD5:A9719DF99058DE7B9A3C2532EB09E14D
                                                                                                                                                                            SHA1:C55C96C03CFE3C1C2C4FCF12E5648AAE806A0BAA
                                                                                                                                                                            SHA-256:408CFD06FBA64B9EFCE52CD726D87BF72566E02A5F0303386655EC415DDABBF2
                                                                                                                                                                            SHA-512:993DCD65384820427CE60342BFEC51EAFD5EAA578F14CDDF5EA04A5B3459DEB511784B0C99EA797E274EF9CEB8A725E30ADE067465268E544F12F0604E4902AA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-checklist.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-webboost-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-checklist-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript"
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with very long lines (452), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):23452
                                                                                                                                                                            Entropy (8bit):4.486451361086621
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:CYEzX7WKmfpGz5C6ylu6MJcDoGeDbC95Qm9o:3e7WL8E6+1o
                                                                                                                                                                            MD5:E95C637128E017EA2A4AF08D44B02E66
                                                                                                                                                                            SHA1:84A69536E25FDBE2218C86F2B8B3B821BDAEDA9E
                                                                                                                                                                            SHA-256:F99EB95CF9F86CB0F18A1299370C836CEBCB34E37FF311FF080A7DCD2BD2B181
                                                                                                                                                                            SHA-512:62BD4C127538C0163C33761C9AE99E4EDEC6127BFFFDD09B73173DC8828F792AA68E92EC075A0D857371878D87260E5515A50E4E314753669B7E1B0DD322AAED
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* NPS CheckList Controller */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _tmpl = wa.UI.CheckList.templates,.. _core = wa.Core,.. _window = _core.Window,.. _checkList = _core.CheckList;.. var browserCode = "(unknown)";.... ui.CheckListController = function () {.. var self = this;.... this.update = function () {.. _window.ready(async function () {.. browserCode = await _instrument.getBrowserTypeCode();.. var args = JSON.parse(await _external.getArgument("template_args"));.. if ((await $(window).height()) >= 630) {.. self[args.commandName]();.. } else {.. _window.close();.. }.. });.. };.... this.showNPSSurvey = async function () {.. var html = "";.. html += " <table style=\"border-collapse:collapse;width:450px; height: auto;font-family:Open Sans; color:#53565A;border:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2422
                                                                                                                                                                            Entropy (8bit):5.097939445435896
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3kx0xsUl363kKk+kUTkikCCFqOcqehQORDFqO:OiqOcqiQqJv
                                                                                                                                                                            MD5:EF1F2F2A4F1E96C065B1B0D237291851
                                                                                                                                                                            SHA1:3DA097A79E96CF3162A5503C8647D534180AB62C
                                                                                                                                                                            SHA-256:38576E0580D66E40794BE57ECC724501518B7AD70248DA28EB4D2F27DB9C8537
                                                                                                                                                                            SHA-512:4066145B54767FC1DA99798BA924259EBB344AA1300B1B7781BB5001476910E341E901922964FD590FA2C7178CA33142C450F12E0F36CF207FD548FF8D02931C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-checklist.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-checklist-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\bu
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5551
                                                                                                                                                                            Entropy (8bit):5.146817311828136
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:xs0xQiszL7IsF7IaDNG9ag8sMfgm2bpxu0sHKJxMzuGFqrKEGZI7H3nJaPsC6L3:xsrr5AlNxbbMM5JaUdL
                                                                                                                                                                            MD5:F325FDBFF6093DD39C3810F4FD42D39B
                                                                                                                                                                            SHA1:FAD74E77575EA06EA0CEA03215F99B3547171C90
                                                                                                                                                                            SHA-256:FFCA4F1251360DE3F09303B403B0343EFF5E70A9279EF751CEE74FADCEB0D479
                                                                                                                                                                            SHA-512:99C8C24C3249C5A4144F7B46ED46E3CC572BBF4AAAB34C969F0F706F9A321DB7A47A5277B14C45BB1DC1041F70CFC358950E5711E2EC8C8F19A276ECFBE2662F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Poppins", Arial, Helvetica, sans-serif;.. font-size: 12px;.. outline: none;..}....body {.. color: #212934;.. line-height: 24px;.. user-select: none;..}....#dialog {.. display: flex;.. width: 761px;.. height: 565px;.. background: #fff;.. border-radius: 24px;.. border: 1px solid rgb(0, 0, 0, 0.12);..}....@media only screen and (min-width: 700px) and (max-height: 500px) {.. #dialog {.. width: 730px;.. height: 422px;.. }..}....@media only screen and (max-width: 600px) and (max-height: 350px) {.. #dialog {.. width: 547px;.. height: 306px;.. }..}....#card_layer {.. background: transparent url('file:///[WA_FILES]/mfw\\packages\\builtin\\wa-sstoast-toggle-rebranding-grass.png') no-repeat 0% 100%;.. background-color: #FAFAFA;.. width: 530px;.. background-size: 220px;.. border-radius: 24px 0 0 24px;..}....@media only screen and (min-width: 700px) and (max-height: 500px) {..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2274
                                                                                                                                                                            Entropy (8bit):5.282371415143711
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:5srbbqNax+k+CQ0NVMzWWrVMzLKWrVMzQ0VMzQeVMzQ+k+2VMzQdk+yjVMCpHgke:qaaxily363k3k5kEk2aCNXpGtgSTCw
                                                                                                                                                                            MD5:4B8CE6B0361D3260931A847BD4F1B074
                                                                                                                                                                            SHA1:F4DC5C22B8FD998A02EC41E205EF839BA1286E79
                                                                                                                                                                            SHA-256:757CCD546E4E9D48537EABBC3EB1180090D33413E8BF8A17445D15ECC328184C
                                                                                                                                                                            SHA-512:BC2D11445EC9467612CBF291495F55DB495761BAAD15AF48D019BDF8D8E4F800A469E1DC8CA8895C6F8FD88D1250EBE467298308D11962B7068ADA102597AF27
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>..<head>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link href="https://fonts.googleapis.com/css2?family=Open+Sans:wght@400;600;700&family=Poppins:wght@400;600;700&display=swap".. rel="stylesheet" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/mfw\\packages_web_view\\webadvisor\\edge_onboarding\\edge-ext-toast.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-sstoast-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="fi
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5437
                                                                                                                                                                            Entropy (8bit):5.109883294557674
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:lAGmLlBEdl33zgfgD6vMHEJAbePrENba+wlZXoGc:lAGmLlBEdl33zgfgD6UkuarEM7lZXe
                                                                                                                                                                            MD5:71774B8D7B4F59FDD9082DD5CC733DF5
                                                                                                                                                                            SHA1:F21129E2B6B0366D9F8DC038FDCE21DB1835052D
                                                                                                                                                                            SHA-256:575A60606003382D7DAD2D57B949EF3F21E067837322BB342442AC40B1F85374
                                                                                                                                                                            SHA-512:42ED300968C25B98976BD20A25433D2E8B68D54B9EC9DA13819E23EEE1787F0B580B3B9B7DB26035F6FC3D1463EDB6F3FA39350DB22AF789744E15F9CEC4047A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _instrument = wa.Utils.Instrument;.... ui.accept_extension = function () {.. var toast_variant = 0;.... var newToastDimension = [.. {.. width: "761px",.. height: "565px",.. toast_type: "EdgeOnboardingControlToast".. },.. {.. width: "730px",.. height: "422px",.. toast_type: "EdgeOnboardingLargeToast".. },.. {.. width: "547px",.. height: "306px",.. toast_type: "EdgeOnboardingSmallToast".. }.. ];.... var $el = {.. checkboxInput: $("#set-web-protection"),.. title: $("#title"),.. desc: $("#content p.desc"),.. featureName: $("#feature_name"),.. featureType: $("#feature_type span"),.. featureDesc: $("#feature_desc"),.. doneButton: $("#done_btn"),.. closeIcon: $("#close-icon").. };...... var stringMap = { // check for correct string.. InfoTitle: "S
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1753
                                                                                                                                                                            Entropy (8bit):5.108114143576874
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:VUV7NSU6+ra+pbXa6oNLwghRo7Atzn4XAQj0+NyKVKcEZJ4fFh:VUVC2a63gxtzn20KIp8
                                                                                                                                                                            MD5:51712199DE87F566F578FEF3CB0D90AD
                                                                                                                                                                            SHA1:0F9196E6CAF180D2AA385D81278FA8CAF4CACC58
                                                                                                                                                                            SHA-256:A0688E2DB7902B91E40605BD499AA4370B237B4059A94D812B64EF4970956699
                                                                                                                                                                            SHA-512:6EBBA4DEFFE91B2D6E58F34C06ACE59AA53D2279A92E68A3576D369D244C2B444EB016D6FB4039E8903CB657BE54EFCC863455498FA6F15681BD343015698A30
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:const send_onboarding_event = async function (action_type, ui_type, toast_style) {.. chrome.webview.hostObjects.wa_external.log("edge_onboarding_telemetry.js: send_onboarding_telemetry function");.... try {.. let browserCode = await window.WebAdvisor.Utils.Instrument.getBrowserTypeCode();.. browserCode = browserCode.toLowerCase();.... let isImpression = action_type.toLowerCase() === "impression";.... let closeBtnEnable = await chrome.webview.hostObjects.wa_external.GetSetting(false, "1", "edge_onboarding_close_btn_enable");.... let metadata = "close_btn=" + Number(closeBtnEnable);.... let toast_dimensions = String(await window.WebAdvisor.Utils.External.getScaledWindowWidth()) + "x" + String(await window.WebAdvisor.Utils.External.getScaledWindowHeight());.... let scale_factor = await window.WebAdvisor.Utils.External.getScaleFactor();.. scale_factor = String(scale_factor.toFixed(2));.... metadata = metadata + ",toast_size=" + toast_dimension
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1497
                                                                                                                                                                            Entropy (8bit):5.177183687065216
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:xmp5UEWZR78xQ/0elV7k1Ze+fkMFE1g60q30iTxhxs4P0Fu0xx0j000sT06bw0SX:xmp5UEWZp8xo0uOuHMFYg60q30Mx70Ff
                                                                                                                                                                            MD5:611F755587781C3F7172053EAAF62428
                                                                                                                                                                            SHA1:7A9F9AB01DC784055DE944C783B2EAE4578D25A8
                                                                                                                                                                            SHA-256:08BDDD8B53C03EE7B476219CB6AE4B190390C5933F1C71EB13DF696A0E14BCDA
                                                                                                                                                                            SHA-512:223FBD0C24514977271A67655C58D0E48F008B2A19F4630992F222653F25B7E0E24BA991698D36334AC11BD745CB997A4ACE356C36F4FF6AC726CD1BAB59F5BA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", "Poppins", Arial, Helvetica, sans-serif;.. font-size: 12px;.. outline: none;..}....body {.. color: #212934;.. line-height: 24px;..}.....main-container{.. width: 656px;.. height: 392px;.. flex-shrink: 0;.. display: flex;.. flex-direction: column;.. position: fixed;.. bottom:0;.. border-radius: 24px;.. background: #FFFFFF;.. overflow: hidden;.. align-items: center;.. padding: 0px 35px;.. border: 1px solid #B2B2B2;..}....[class*="flex-item-"] {.. display: flex;.. align-self: center;..}.....main-container .flex-item-1{.. justify-content: flex-start;.. align-self: flex-start;.. margin-top: 32px;..}.....main-container .flex-item-2 p{.. color: #212934;.. font-size: 20px;.. font-style: normal;.. font-weight: 700;.. line-height: 28px;.. margin-top: 14px;..}.....main-container .flex-item-3{.. margin-top: 34px;..}.....main-container .flex-item-4 p{.. margin-top: 32p
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3066
                                                                                                                                                                            Entropy (8bit):5.332471412938537
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:wjRaxDlg+3kKk+kgkaCm5wEsCILQq5wEsCI2A5wEsCIIK17gHx:wjKdsT/dsTdsAjx
                                                                                                                                                                            MD5:157F08E078E9DD766F030F41C790EBE7
                                                                                                                                                                            SHA1:BF3E85E363822B2FBB820C71512CE07DA0AD4906
                                                                                                                                                                            SHA-256:78ADC215E8C7C827770BF57BEFB0F334ABA5088CD91F09F7FB1A9DC755617562
                                                                                                                                                                            SHA-512:3D1A1F4E8233C898B20ECF89AE9C41C870274871E43ED2F7781461960D9DF17D08F72C618A0725344E275ACDA1B3A9BC0583081460A5B4B061957E390A840EBB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>..<head>.. <title>SecureSearch Score Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link href="https://fonts.googleapis.com/css2?family=Open+Sans:wght@400;600;700&family=Poppins:wght@400;600;700&display=swap" rel="stylesheet" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\edge_search\\edge_search_ext_coachmark.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-overlay-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.js"><
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3859
                                                                                                                                                                            Entropy (8bit):4.878022296204829
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:xe04JN7xWXXZ8NQK8E3NQKbk/5XNmsN4qBNINHN4qPdFe2FX1YYtuK1H6ItuNn1w:EPoHvOGX67qPqP2k1xafsmWY06NQj
                                                                                                                                                                            MD5:1DE8953C2AC270FB6F535EB32E9AF1A3
                                                                                                                                                                            SHA1:D50A40A2EBDBBC4A3AE77F3B397D77FE13E34D09
                                                                                                                                                                            SHA-256:9E41A5D6A23999D3694AB0603D49F373F20F7E2D8E3A87AC036735FCD5B09F08
                                                                                                                                                                            SHA-512:962E479515D656EF9961286EFC373774DF1E45020DBAA376B09944D2ACCB4E99919CEC62FB9FAFB97091D0E2687C5F5013C52D911F690CF5674ED04F47CCD549
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* SecureSearch edge monetize phase -2 */..(function (wa,$) {.. let ui = wa.UI = wa.UI || {},.. _instrument = wa.Utils.Instrument,.. _window = wa.Core.Window,.. _external = wa.Utils.External;.... var browserCode = "(unknown)";.. var provider = "Yahoo";.. var windowHeight = 392;.. ui.SecureSearchTooltip = function () {.. chrome.webview.hostObjects.wa_external.log("ready: begin");.. show = function () {.. _window.ready(async function () {.. chrome.webview.hostObjects.wa_external.log("ready: begin");.. .. _window.setWidth("656");.. _window.setHeight(windowHeight.toString());.. .. let lang = wa.Utils.Lang(wa.Utils.Lang.ResType.OVERLAY).get;.. .... chrome.webview.hostObjects.wa_external.log("inside ready");.... var json_to_parse = await _external.getArgument("overlay_data");.... chrome.webview.hostObjects.wa_external.log("after getting overlay data");.... if (!json_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1725
                                                                                                                                                                            Entropy (8bit):5.462790400312901
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:+swDxNxulQeNVMr0+WrVMrLKWrVMrQzVMrQXVMrQdpVMCrNM/QoguKORMEyV8QQQ:NOxNx1/Y+3i3cKc+cGCEQgKy/Gn
                                                                                                                                                                            MD5:3164B1C1FE786BB558D64B2B731FA9AC
                                                                                                                                                                            SHA1:17FD4EF13F15A437F21675EC0F4A668B89F3CB55
                                                                                                                                                                            SHA-256:78036339FA65DD3E227C546D7CECC65732997BE2FFD646FA8501F16F2B3BE4DB
                                                                                                                                                                            SHA-512:0ADBF9FF8C976DFF567006F3B0D7620AD586E0C26BF40F8D1390A7579E294D2BD933DD319628467ECC9F9689BEF9F5760278CDBA25F6DBCF15FC7599AB0D2B86
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\webadvisor\\new-tab-overlay.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-overlay-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4111
                                                                                                                                                                            Entropy (8bit):5.089069563471304
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:T0AmdonK4uoOPV1PixEeB0NufP9SdaQbXkT:AATK4bs/jeCQS9bXS
                                                                                                                                                                            MD5:C0E7D1F5C34B168AF3F023074148C393
                                                                                                                                                                            SHA1:C4ECEEE78EF1575254E88EC8CAA0168A3C561A06
                                                                                                                                                                            SHA-256:F5170E917D7EEC60A2B61B3DB2673E703AA5EAA400325AD0A8DE8E9FDBB81C00
                                                                                                                                                                            SHA-512:0220A34135BB37A62ED5D6953359F5A89ED7A8CF00BB4B962BC690E0A8D1FB84E7B056A6454DB9EC2619D21C9D55D68541C4F4E171B028150ACBC6BF01D27FB7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = (wa.UI = wa.UI || {}),.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument;.... ui.accept_extension = function () {.. var $el = {.. content1: $("#wa-dialog-balloon-content-1"),.. content2: $("#wa-dialog-balloon-content-2"),.. arrow: $(".balloon-chevron"),.. },.... show = function () {.. _window.ready(function () {.. var settings = JSON.parse(_external.getArgument("overlay_data"));.. var overlayType = Number(settings["overlay_type"]);.. var extensionType = Number(settings["extension_type"]);.. .. // Polyfill of isNaN for IE version < 12;.. Number.isNaN = Number.isNaN || function isNaN(input) {.. return typeof input === "number" && input !== input;.. };.... // Validate toastCount is valid;.. if (Number.isNaN(overlayType) || Number.isNaN(extensionType)) {.. _window.clo
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2178
                                                                                                                                                                            Entropy (8bit):5.349457866120589
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:NOxNxj/U3i3cKc+ccWCCFAf2PKqAqIMImqIuap:cUiJJmzTp
                                                                                                                                                                            MD5:2EFE24107B628FAEE2A511BF34E4B606
                                                                                                                                                                            SHA1:935ECF23A55CBFEDFF82596BFCAA66BC103ABE27
                                                                                                                                                                            SHA-256:FA42C8683189A575181694258C07728530515E76249E6FC1B995612E2855DF89
                                                                                                                                                                            SHA-512:532A633CC7B7B60753247B96C7A777F2913D2772B3797FB13399267F330DA98BBB7A94F38D4B6DDC24ECC882992BF4A1B292E734994F1055279ED2EE77A9FAD7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\webadvisor\\new-tab-toasts.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\new-tab-res-toast-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="fi
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3521
                                                                                                                                                                            Entropy (8bit):5.180727388265894
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:m5Y7fVMKxAX955IGIyy8CJ/Z1gu0VKz1hauWSvA8Nb0w4SVzz2eE/NXkfpRC2n:n3AXKffHguIKz1hauWSD0WVf2bXkBjn
                                                                                                                                                                            MD5:E78A327457AB6F478909AE11B6AA398E
                                                                                                                                                                            SHA1:76D2E940CD73ED9B8FD4BEEBC2E607730A03FC67
                                                                                                                                                                            SHA-256:AF69802AB92BCB8ACE0B56A4E0AF914179C370E083E4D2821F5C4A8E9972F25C
                                                                                                                                                                            SHA-512:97059E7855FE3DA5A2FCBB912DFAA4EF91E95FCC6CA810A8F7837682A8EEDD5A1376BAF3F10905345ED57F9FFCC48A49E6C1D649E7B9074AF34B232963D3A829
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = (wa.UI = wa.UI || {});.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _settings = wa.Utils.Settings;.. var _instrument = wa.Utils.Instrument;.. var browserCode = _instrument.getBrowserTypeCode();.... ui.accept_extension = function () {.. var $el = {.. balloonCard: $("#balloon__card"),.. headerText: $("#content__text-header"),.. contentText: $("#content__text-description"),.. acceptBtn: $("#content__actions-accept"),.. declineBtn: $("#content__actions-decline"),.. };.... show = function () {.. _window.ready(function () {.. var payload = JSON.parse(_external.getArgument("overlay_data"));.. init(payload);.... _window.show();.. });.. },.... init = function (payload) {.. var lang = wa.Utils.Lang(wa.Utils.Lang.ResType.NEW_TAB_TOAST).get;.. var toastCount = Number(payload["toast_count"]);.... // Polyfill of isNaN for
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1454
                                                                                                                                                                            Entropy (8bit):5.2497348247434195
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:xmp5UoZRqxQpxVYHhLcY39U0M+mtFl2zZRVchpKIjvVCfnvv/UQsUMmxSlSh:xmp5UoZwxDHF3uBjFloZKY+YfnHcQeUB
                                                                                                                                                                            MD5:A1E5FF65EC605AC3076849A6ED7EAEF2
                                                                                                                                                                            SHA1:D333E828330CBB2327FA768507825E3F7035C059
                                                                                                                                                                            SHA-256:F82FB767EF7DEA81E368C18BDDF7DA2927B177228F654A77C6361973EBB5CCE9
                                                                                                                                                                            SHA-512:414AC9AA25742B7F21625619A756084308FD78BC27491F2319F3D84861A68D877C7AE461226B77E274E7CD710314147B96DA7EE7658E672216CBAF3E461D5AFF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. color: #212934;.. line-height: 24px;..}..../* Parent container */...balloon {.. overflow: hidden;..}.....balloon__card {.. position: absolute;.. right: 55px;.. overflow: hidden;.. box-sizing: border-box;.. background-color: #FFF;.. border: 1px solid #E6E9F0;.. border-radius: 12px;.. height: 200px;.. width: 328px;..}.....card__content::after {.. content: ' ';.. clear: both;..}.....card__content {.. padding: 16px;.. height: 100%;..}.....content__header #wa-logo {.. height: 13px;.. position: relative;.. top: 2px;..}.....content__header #close-icon {.. float: right;.. cursor: pointer;..}.....content__text {.. margin-top: 12px;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-weight: normal;.. font-size: 14px;.. line-height: 20px;.. color: #5A6175;..}.....content__text:last-child {..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1940
                                                                                                                                                                            Entropy (8bit):5.410078627773085
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:+s8xMxdARQXNVMr0+WrVMrLKWrVMrQzVMrQXVMrQdmVMCuedmlOK+uEralXRMSuL:N8xMxtUY+3i3cKc+cjCX6OK+punmQaeu
                                                                                                                                                                            MD5:6F797D96229BE64F47C8813AB3EA57FE
                                                                                                                                                                            SHA1:16062B184CF56864EC259FD67CEC27D4341C4FAF
                                                                                                                                                                            SHA-256:E77D78C0F07B62BA4548E82A3D4D8975688E2CA74D44DF56724EBAAFDCF262EB
                                                                                                                                                                            SHA-512:F41A9879F26E7A705BD3B5602997EBBF3CC781C13E19C1FEFEDBC5F8F7C51644D323FB4CB644732D7EE85015643242E4DED0D5B8D276B82AA7839B6D10A10714
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-ch-store-overlay-ui.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-overlay-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3096
                                                                                                                                                                            Entropy (8bit):5.135378216883125
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:h4D7pOA4nDWFkTpGgWqbV9afhPkDYOEbV3R0GYmk/5LiMCH2qJoNmgxbV9afhPk2:cMA4qOfV9WqxEz0TnMTJoVV9WE6KGXt
                                                                                                                                                                            MD5:0293396E4256CBDCFDE5D5331DC3851B
                                                                                                                                                                            SHA1:9E3CF1DE3467C46FF083B82B945861DE5D7BDDEA
                                                                                                                                                                            SHA-256:23A04AF788D0D9D1A1D801B03610C09B031F35597AC07F13222AEF5C14FD403E
                                                                                                                                                                            SHA-512:DF62BAD0201C81C34796C6FEF8942EEE6B451E1993E2A2F3274CA21BAE9CC14DA06F8DD35BFC6B7F4D7316F0D09517421EA2461CE8371BDEDB687B12DD1C5128
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument;.... ui.accept_extension = function () {.. var $el = {.. contentText1: $("#content__text-1"),.. contentText2: $("#content__text-2"),.. closeIcon: $("#close-icon"),.. };.... let browserCode = "(unknown)";.... show = async function () {.. init();.... _window.show();.... browserCode = await _instrument.getBrowserTypeCode();.... //Send Telemetry 3.0 for dialog balloon.. var screen_flow = browserCode == 'FF' ? 'firefox' : 'introduction';.. var hit_screen_id = browserCode == 'FF' ? '300.1.2.1-windows-onboarding-firefox-webpage' : '300.1.1.1-windows-onboarding-introduction-coachmark';.... var analyticsEvent = {.. _event_name: "wa_onboarding_balloon_impression",.. hit_label_8: screen_flow,.. hit_label_18: "Onboarding
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2368
                                                                                                                                                                            Entropy (8bit):5.135586629622516
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3kx0xsUl363kKk+kUTkiktCCv/enQORDuwJDEk5N:OGv/WQqKw+k5N
                                                                                                                                                                            MD5:8B8A2F738C925E8CF792B97854950F7E
                                                                                                                                                                            SHA1:175BA8DC8CA477A517405CD67FA632F59C1B255E
                                                                                                                                                                            SHA-256:082927BAEAD7385FC7BF98B5497658B405744F9E4421356FECF1312B9D74955F
                                                                                                                                                                            SHA-512:F70C03032489B321767075E8A6761B9EDECBA5012EA583F83B229B14228C3409121075FA16F90E1AD1FA53ED95932AFB8D32A8EFE6DC6E2A6FB40F306D7274F5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-checklist.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-checklist-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\bu
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with very long lines (333), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):17148
                                                                                                                                                                            Entropy (8bit):4.756841654795562
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:cD7PaE5btDT2o1Cm+kYNTth/6x5o+72vY4PWrRd4ZJ2W:Y7PaE5b1T2o1CzksTy5o+7GRP04ZJF
                                                                                                                                                                            MD5:8900B6AB2089AE5774987D76655D8BE6
                                                                                                                                                                            SHA1:69ECD3D2804A851B31DCD0FFB33BBEA16E096D01
                                                                                                                                                                            SHA-256:1D861BB309062425023ADD79D8F8B7AF496A6DC3670D17B63B011DC32128F240
                                                                                                                                                                            SHA-512:0ADBCB7735F1A186D1427EDAC231A109EC7F3F07A0EB5F37A1B4223C0F3BE2ED3DE6C618FD2143B6951336AA8776D63BAA01F1F2B99C484A322DD5960377B2F0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* CheckList Controller */..(function (wa) {.. let ui = wa.UI = wa.UI || {},.. _settings = wa.Utils.Settings,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _l10n = wa.Utils.Lang().checkList(),.. _tmpl = wa.UI.CheckList.templates,.. _core = wa.Core,.. _window = _core.Window,.. _checkList = _core.CheckList;.... ui.CheckListController = function () {.. let threatStateCss = "threat",.. infoStateCss = "info",.. greenStateCss = "green",.. waitImage = "file:///[WA_FILES]/MFW/packages\\builtin\\white_timer.png",.. alertImage = "file:///[WA_FILES]/MFW/packages\\webadvisor\\wa-checklist-risk.png",.. ignore = _l10n("IGNORE"),.. fixNow = _l10n("FIX_NOW"),.. defaultImageCss = "wa-state-img",.. alertImageCss = "wa-state-img-threat",.. keyMap = { "NUW": "WelcomeMessage", "UUW": "UpdateMessage", "CLW": "CryptoLearnWelcome" },.. self = this;.. let browserCode ="(unknown)";.... this.update = fu
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):772
                                                                                                                                                                            Entropy (8bit):5.266152347339336
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:xW/FJLjFUoZdTrh8FwIjEHpbXTfMUGAtf8+IdKjjUK+xe+IqFcF143jhZZwbW8eH:xmp5UoZRqC3dDUUhiLKyFc43bZp7KbEh
                                                                                                                                                                            MD5:2FE491FC40A4004468CD85A09A672406
                                                                                                                                                                            SHA1:76D97997038583C12A70B19461AEB75D12E466CC
                                                                                                                                                                            SHA-256:1F9310A0D7C7646689D719A57DC3FB2D3E41C9AB45ECE5D1BB4529F82D5936BB
                                                                                                                                                                            SHA-512:5624D6520E3095D84BF9755DDC12291FB6EC36362321F74162EF4923E0AA9EC1356E1201F41E11856D893D26AE10AB17C30963FE083D9F64BF54C51466EF902B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. color: #454545;.. line-height: 24px;..}.....balloon-arrow {.. margin-bottom: -6px;.. text-align: center;..}.....balloon-main {.. box-sizing: border-box;.. background-color: #FFF;.. border: 2px solid #E6E9F0;.. border-radius: 24px;.. padding: 24px;..}.....enable-ext-btn {.. background-color: #4989EB;.. border-radius: 4px;.. border: 1px solid #EFEFEF;.. color: #FFF;.. cursor: pointer;.. display: inline-block;.. font-weight: 600;.. padding: 2px 8px;..}..//8BA1828E4F1364FE4C3094A32E88E67157973A4AC83FAA690E4E509ED61CA2E6A3A40D4C268FFD8AF4F836F117F4708D3A7136E237DC9647BE53DE1A63089448++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1831
                                                                                                                                                                            Entropy (8bit):5.443201185141968
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:+swDxMxdI2u5YWrVMrLKWrVMrQzVMrQXVMrQdTMNVMCrnr5OymTQoguT+ORMfrAc:NOxMxG75Y3i3cKc+cdNCzd+TQgT+yA/b
                                                                                                                                                                            MD5:B3A9066BA4F6834CACA76E36CF70A3A4
                                                                                                                                                                            SHA1:D5FDC5A028A6C2BCD31889A36F86ED57046485F8
                                                                                                                                                                            SHA-256:FF683BC097BDEBBF2007D4ADF8AF1B573326B6DA3FFDE4315BBEDA3ABA314D5A
                                                                                                                                                                            SHA-512:A0BB33BD979231397878E895B19AAC8D058F546ED2C604CEC446DF489E5D3CE6F97069EB36BAD2405A60E7831D841B461D9F8B7E085BEF9B2257AA7B440D3F82
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-dialog-balloon.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-dialog-balloon-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-ui-dialog-balloon.js"></script>..</head>.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1617
                                                                                                                                                                            Entropy (8bit):5.267204915883037
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:V2skx0xutt5WrVMzLKWrVMzQzVMzQXVMzQdGVMC8jIYc6/F8dHK:3kx0xi7363kKk+knC8jKSFcK
                                                                                                                                                                            MD5:51ADA7BDB8B119DE4C9DF6A63539B252
                                                                                                                                                                            SHA1:0588C534D5A79CC9E30FE94072DF28884CC68DF8
                                                                                                                                                                            SHA-256:CA35BA7EE03B77DD82C3FD3CD3CE9DF3E83B82999420B9B2807245A81EEECF8F
                                                                                                                                                                            SHA-512:4F73C92ABCE2055AB9ADC4339A8A1BF2951359894DFCCE3C3D49346B0BD46E00AB456FF9940277D811FCFBC6FAE3E3601E9C5F1515699ED4736F612D1B93A4BF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>Download Scanning Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\webadvisor\\wa-dwtoast.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-checklist-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-ui-dwtoast.js"></script>..</head>..<body>.. <div id="wa-dw-toast">.. <div class="heade
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2483
                                                                                                                                                                            Entropy (8bit):5.219173796507417
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:7kxtxC363kKk+knCVr/R+5a5beIwEeIYOzdTsrn:+/Fb1DxTCn
                                                                                                                                                                            MD5:21EE04CC9FD2FFFDA6C2FE1B623F93AA
                                                                                                                                                                            SHA1:0FF796D19542EEA8067AAA8EC659B23A75407C20
                                                                                                                                                                            SHA-256:965A9812B2EB821B736C35D4F0C3229C4EFA2008B963F83B6C905B8F3E259E0B
                                                                                                                                                                            SHA-512:658C4893E8DD2B0C2BEA87461C8FF2EF28B2E716C6FC7C5B119FD1FF3D60D49E47A6F747C92485DE33973ED89DE073326E0A65C146657020DF53964A8B6298BD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>Download Extension Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\webadvisor\\wa-ext-install-toast.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-ext-install-toast-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-ext-install-toast.js"></script>..</head>..<body onselectstart="return false">.. <di
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4885
                                                                                                                                                                            Entropy (8bit):4.835123536475242
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:1zDsTVq7EIkGvTkE0oN6El4iTZTzwuyFDk00JarkM0d7XO:qc7EIXTq06ESGZ37MDa8ryd7+
                                                                                                                                                                            MD5:BAE2CBB5C50B2DE82E238CE4A970C442
                                                                                                                                                                            SHA1:1187B13EAE2FDDBB88D15BA2CF1494A548167236
                                                                                                                                                                            SHA-256:CD116597AEA4DA4DB69CAA54DBCBA16E9EB3BEC49CB7ACAAE0BD8E9B9C3BFAB0
                                                                                                                                                                            SHA-512:B30B3B4F5C5AF4770A498922DCC144F06ED9292A817660B39081039683863E6AC851B868BB81C40223ACDCE3542F8F454B5497E357E56110D922925E6AFCB91D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Download Warning Toast UI */..(function (wa) {.. let ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,.. _instrument = wa.Utils.Instrument,.. _settings = wa.Utils.Settings;.... ui.extension_install_toast = function () {.... let browserCode = "(unknown)";.... show = function () {.. _window.ready(async function () {.. // Set toast window size.. setSize({ width: "485", height: "265" });.... // Get settings data.. let toastCountSetting = "ff_extension_toast_count";.. let toastCount = await _settings.get(toastCountSetting, "0") || 1;.... let lang = wa.Utils.Lang(wa.Utils.Lang.ResType.WAIFF).get;.... // Initialize toast... init(lang, toastCount, document);.... _window.show();.. window.chrome.webview.postMessage("draw_background");.. window.chrome.webview.postMessage("set_focus");.... browserCode = await _instrument.getBrowserTypeCode();.. //
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6769
                                                                                                                                                                            Entropy (8bit):4.974425154516147
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:yH5SvRvxVoY2bZX/o0lhOY52Q5YsYmafFZR9OIv:yH5EvxVD2bJQChOsV5BLaf3yIv
                                                                                                                                                                            MD5:817D9E6AAC3445BE9EDB4E912C4EFFCE
                                                                                                                                                                            SHA1:14AC4215B42332FEDB04D5DD0E7BAB06F96EE38F
                                                                                                                                                                            SHA-256:BAADE101BAFF701219501A1DF90E120B23F19A237CA92E1C953C0589C9CDA741
                                                                                                                                                                            SHA-512:26F74926C22BBD72E2126D7A97F86F9332CE4C14FC8415EB656B3AC613136B3012B5CF370478F54A594ABF0C8AD7C3900F8A5492797D0C58E60683FF4503BBC8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:#bottom {.. bottom: 0;..}....#left {.. left: 0;..}....#left,..#right {.. bottom: 0;.. top: 0;.. width: 2px;..}....#right {.. right: 0;..}....#top {.. top: 0;..}....#top,..#bottom {.. height: 2px;.. left: 0;.. right: 0;..}....#top,..#bottom,..#left,..#right {.. background: #939598;.. position: fixed;..}....#wa-button-donttrust {.. font-size: 26px;.. right: 2px;.. top: 5px;..}....#wa-button-reset {.. background-color: #00AEEF;.. border-radius: 3px;.. color: #fff;.. font-size: 14px;.. font-weight: 700;.. height: 40px;.. margin-top: 12px;.. width: 145px;..}....#wa-button-trust {.. font-size: 24px;.. right: 3px;.. top: 4px;..}....#wa-close {.. padding: 8px;..}....#wa-options-about ul {.. line-height: 23px;.. margin-bottom: 0;.. padding-left: 12px;..}....#wa-options-content {.. font-size: 12px;.. overflow-x: hidden;.. overflow-y: auto;.. padding: 24px;.. width: 550px;..}.... #wa-option
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1561
                                                                                                                                                                            Entropy (8bit):5.436335174224512
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:csY0xtxdJQeNVMznWrVMzLKWrVMzQzVMzQXVMzQdQVMCmFgtHGOSCeO:3Xxtxk/r363kKk+kNCJtH/eO
                                                                                                                                                                            MD5:F752617D495931000B6289C4CB0331A9
                                                                                                                                                                            SHA1:BFF1ABD4967BF5D812FD27FCEF348839294C02DB
                                                                                                                                                                            SHA-256:FE6FF6E6AAC49A1770050DC303B43E112EF3014F980515EA8596B944E3D6721C
                                                                                                                                                                            SHA-512:DCDF94C6280C86509B3D1B12607F1A9EEC67D8EC65AE9BEBF72B50442CD8BA373163D011D9AA346DF12014878B80D528CA769EBF6FAEC9DF5DAA921F591BE449
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=9" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-options.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-options-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/java
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2225
                                                                                                                                                                            Entropy (8bit):5.389102082736705
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:NOxNxS/Y+3i3cKc+cpC3W0PK+ptCHJCER:Y9i2CB
                                                                                                                                                                            MD5:81A5133C79ACDE4F3C65FC850573AE91
                                                                                                                                                                            SHA1:1B93EA110F8786895D9D18FE20DA1951B13080FF
                                                                                                                                                                            SHA-256:BF7A172CD9AF4BF4B66948294277A38D5D5C48E6E01F16759C5E7838BE4E410E
                                                                                                                                                                            SHA-512:B3ADB4E29DD8551814E227D1EA9D18FDD90B86964D8636D8B372F559015703CF5266DCAFF16D391D6AD4A64C372F1C09EB12FB4D001197E25C3304A4C61F95CD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <title>Accept Extension</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\webadvisor\\wa-overlay-ui.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-overlay-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:/
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9619
                                                                                                                                                                            Entropy (8bit):5.244395471568787
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:2Ar/3q1FNFmMtuhVXdeWG3trOpnb+LXB7ZmX7L:7Q8XPG3tyo9UP
                                                                                                                                                                            MD5:34BDC68A46CC4FFA92664C0E8D85B046
                                                                                                                                                                            SHA1:27E2A4B8B72512EA87AC088A8069A6180F566F9E
                                                                                                                                                                            SHA-256:56A8061AC7A7A8C2422B8104723669E3F45A34373CD66CBD06917D50F549A858
                                                                                                                                                                            SHA-512:68D0FB3EC182175919B42E9C093F13C764EC8A7E7BD0303DCCB17399C26AFD0FFA3BBEE79CC91517BAB0F9CE65BC9411E45677DFFDB6BCAFB3FC1CC523678464
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _settings = wa.Utils.Settings;.. var _instrument = wa.Utils.Instrument;.. var browserCode = _instrument.getBrowserTypeCode();.... ui.accept_extension = function () {.. var $el = {.. arrowUp: $("#arrow-up"),.. arrowRight: $("#arrow-right"),.. balloonCard: $("#balloon__card"),.. contentText: $("#content__text"),.. cardImage: $("#card__image"),.. closeIcon: $("#close-icon"),.. waLogo: $('#wa-logo').. };.... var ENABLE_EXTENSION_OVERLAY = 0;.. var INTRO_OVERLAY = 1;.. var SEARCH_WARNING_OVERLAY = 2;.. var SETTINGS_OVERLAY = 3;.. var TOAST_OVERLAY = 4;.... var WA_EXTENSION = 0;.. var SS_EXTENSION = 1;.... var overlay = {.. types: {}.. };.... overlay.types[ENABLE_EXTENSION_OVERLAY + ""] = enableExtensionOverlay; // enable_extension_overlay.. overlay.types[
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2132
                                                                                                                                                                            Entropy (8bit):5.202568131798471
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UGEp5ULZwx7/SMhdIelE5PmE5IeE5YMvubTVO6bvB:72x7aFelgPmgIegYZTVO2J
                                                                                                                                                                            MD5:DE9341556E2C8221926C515B6FDA15A4
                                                                                                                                                                            SHA1:C605E762288F97A0285FD8DDF489583952E66117
                                                                                                                                                                            SHA-256:97A0BA89258FAF42EFBCAABABBC5E50DC6AC05DCC0553FBCAC2C81578F05F0F3
                                                                                                                                                                            SHA-512:570BF4659974D4964E8D5D5FAFFED42C4B04FCD26F88B3FC25495D5233B73B542BA762CBFC8981D1106E62CBDD106C25E538D0D2FC3EEC324680B576BFD0B21A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* CSS file for the new bing rebranding toast that replaces the red SS toast */..* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Poppins", "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. color: #212934;.. line-height: 24px;..}..../* Parent container */...toast {.. position: fixed;.. bottom: 5px;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. overflow: hidden;.. width: 555px; /* Window width is 567px */..}.....card__image {.. display: flex;.. justify-content: center;.. align-items: center;.. float: left;.. width: 150px;.. height: 100%;.. position: absolute;.. background: var(--Grayscale-50-Gray, #FAFAFA);..}.....card__image #green-pc {.. width: 150px;.. height: 150px;..}.....card__content {.. background-color: #fff;.. margin-left: 150px;.. padding: 24px;.. height: 100%;..}.....card__content #info-title {.. color: #343434;.. font-size: 20px;.. width: 100%;.. font-weight: 600;.. line
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1895
                                                                                                                                                                            Entropy (8bit):5.377039973471367
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:Iskx0xdE+QXNVMz3WrVMzLKWrVMzQzVMzQXVMzQdEwrVMCntcIbQSk4CNiebvFU2:Lkx0xEUT363kKk+kHCCnKHYkVQja
                                                                                                                                                                            MD5:2E7631BE009F53F4BC0C4BCAB085E75F
                                                                                                                                                                            SHA1:AE844FF61CFBFA424D533F690F1FF9086E0AAAD0
                                                                                                                                                                            SHA-256:8C8774A11B1A7FB40003F6605298DAE6B02FF60FF778329EB820BEE729945FAF
                                                                                                                                                                            SHA-512:63638EEBA0E5586B903CAEB0DF8D7DB5AED0955D3F06C7597F7A60428E0A0B40B75726AC60534D604823A274EB77FFB78F11E75151B88EA808E44FB690F2E19F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>....<head>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-ss-toast-rebranding-bing.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-sstoast-bing-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\weba
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5141
                                                                                                                                                                            Entropy (8bit):5.110834663201895
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:qATI3xOo49YNYTMhVumnb+iAnZE4wVE8g8BbLHcb+ZOXsa1:qAGxOoKYNMMhvnbcZEDE8g8BbLHcbQOz
                                                                                                                                                                            MD5:2FD635504865420BFDB9EB0FFB0125F5
                                                                                                                                                                            SHA1:D038F72403704565221B0CA62C50120266617128
                                                                                                                                                                            SHA-256:6C7D49F190603FFB148D20D906797BA2C1F70D89BD8F0DE33CE5646414ED1EE5
                                                                                                                                                                            SHA-512:7E3A456CC137CD4930EE85CB040100C4930D89624B3034701968823E55AEE7661F95E5CBB894E7D0B3980365F9A54230C7110D7C9F908D3F96FB2E8287FA591B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _instrument = wa.Utils.Instrument;.. const BUTTON_ACTION = {.. ACCEPT: "Accept",.. DECLINE: "Decline".. }.... ui.accept_extension = function () {.. var $el = {.. cardImage: $(".card__image"),.. cardContent: $(".card__content"),.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. checkboxQuestion: $("#checkbox-question"),.. contentSubFooterText: $("#sub-footer-text"),.. contentbuttons: $("#content-buttons"),.. doneButton: $("#done"),.. declineButton: $("#decline"),.. toast: $(".toast"),.. };.... var langMap = {.. InfoTitle: "SEARCH_TOAST_HEADING",.. InfoText: "SEARCH_TOAST_SUB_HEADING",.. Question: "SEARCH_TOAST_BODY_TEXT",.. SubFooter: "SEARCH_TOAST_SUB_FOOTER",.. ButtonText: "SEARCH_TOAST_YES",.. ButtonDeclineText: "SEARCH_TOAST_NO",.. ToastT
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3234
                                                                                                                                                                            Entropy (8bit):5.155227261928706
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:xmp5ULZwx7/SMhdu/WlE5PmE5IeE5LMs7MFCRPnE5NSubTRqH7xDZK8t3idcjooI:xT2x7aTWlgPmgIegLhcgPgJT0HqGpKp
                                                                                                                                                                            MD5:C94A9247020C241B41D142A338FD4881
                                                                                                                                                                            SHA1:BCA9793666FDE520DD7AA00E0894FB2C310E761B
                                                                                                                                                                            SHA-256:84C636D52F488E71A2130402156F15A5EFD49DB77444B891A536769F4076F940
                                                                                                                                                                            SHA-512:8004EB4733250DE49BB1F15FDC8BA67F26D808FBC22329CC84B5AC2F3BC670CCC51352540A807A07951F949B94CBFCADD0BACBFC4E76673E204F5F22E65FCBB7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Poppins", "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. color: #212934;.. line-height: 24px;..}..../* Parent container */...toast {.. position: fixed;.. bottom: 5px;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. overflow: hidden;.. width: 555px; /* Window width is 567px */..}.....card__image {.. display: flex;.. justify-content: center;.. align-items: center;.. float: left;.. width: 150px;.. height: 100%;.. position: absolute;.. background: var(--Grayscale-50-Gray, #FAFAFA);..}.....card__image #green-pc {.. width: 150px;.. height: 150px;..}.....card__image #mc-logo {.. position: absolute;.. bottom: 16px;.. left: 19px;..}.....card__content {.. background-color: #fff;.. margin-left: 150px;.. padding: 24px 21px;..}.....card__content #info-title {.. color: #343434;.. font-size: 20px;.. width: 100%;.. font-weight: 600;.. line-height:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2721
                                                                                                                                                                            Entropy (8bit):5.322335097429742
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Ekx0xAU6323y3kKk+kOCnK0Qm1jRM3ns2QX8CPfcJol:dm1jRMcfX8C0ol
                                                                                                                                                                            MD5:A4002AA3E3F0E30EF1469C1A84AF73EC
                                                                                                                                                                            SHA1:FD3D841B4B585962B781F1576D1222996544FD1F
                                                                                                                                                                            SHA-256:4AC54B8D6A758524EDA81FE7A5958A06238A95F445AD39A71431F8F170281EF5
                                                                                                                                                                            SHA-512:9129BF5EDA0656B7B787B443C61267813271F14D5AB26C6B04C4C421547FA41860DCD5B106CD85A5C047D30B4656AF35F6DEBD05884E99B85BE90C9231CA9A52
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-ss-toast-variants-rebranding.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-ss-toast-variants-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-sstoast-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\bui
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):10699
                                                                                                                                                                            Entropy (8bit):5.045521916618284
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:cAntBR7h1zIR8p1YVYGl0AV5Y+joOBuooIZEA8g8BbLHcbJOXe:ptP/zIeINl0AV5KOBuooIZ58g8BbLHJe
                                                                                                                                                                            MD5:A33E9E81828BFAA795AD2A1E3801FD57
                                                                                                                                                                            SHA1:233FCE1A4861DE86473C4C984F229888540B8F41
                                                                                                                                                                            SHA-256:A2D6D1E761318360A483B74128CF6DC75FDDE5D7B59E143442189C309EB55E33
                                                                                                                                                                            SHA-512:B2078C444175020176BEC719E235F7E67A837BFF4A3857CFB5AB31AC37EC5B37E81E328253C315CB18B6C541773A9AB3EA4DCBAEA440338BAE78E096136C53FE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:./* Accept Extension UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _instrument = wa.Utils.Instrument;.. var _settings = wa.Utils.Settings;.. const TOGGLE_COUNT = "toggle_count";.... ui.accept_extension = function () {.. var $el = {.. cardImage: $(".card__image"),.. logoImage: $("#mc-logo"),.. cardContent: $(".card__content"),.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. checkboxQuestion: $("#checkbox-question"),.. checkboxInput: $("#set-secure-search-checkbox"),.. checkboxChecked: $("#checkbox-checked"),.. checkboxUnchecked: $("#checkbox-unchecked"),.. setSecureSearchLabel: $("#set-secure-search-label"),.. doneButton: $("#done"),.. toast: $(".toast"),.. secureSearchSwitch: $("#switch-set-secure-search"),.. switchInput: $("#set-secure-search-switch"),.. };.... var variantsMap = {..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2773
                                                                                                                                                                            Entropy (8bit):5.2231906109260615
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:xmp5UoZwx7MdDyTgWfx9gazwPpLDqELO1CX7EnulmlwWW:xA2x7M8TgWfx9ZzwRqzk4wZ
                                                                                                                                                                            MD5:2226BB46CA59E0AC878E6FF97E630D47
                                                                                                                                                                            SHA1:FEF92A5C29DE29265E7E5D7FA12C6340173AB848
                                                                                                                                                                            SHA-256:B9AD6EA414C8575EA1A22CBD380DCA07B70097EC69DE2C4910E6F9FF09A8E381
                                                                                                                                                                            SHA-512:364C20867D36D1FAB09615EF0F2F9135D4809063782FA069B027D009A52F5C0D9F33454D2457B90967F390453B630DBF9A68A96E9FF694AA84C13F95888D96DE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 14px;..}....body {.. color: #212934;.. line-height: 24px;..}..../* Parent container */...toast {.. position: fixed;.. bottom: 0;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. overflow: hidden;.. width: 524px; /* Window width is 530px */.. margin-bottom: 6px;..}.....content__checkbox {.. margin-bottom: 25px;.. display: flex;..}.....card__content {.. background-color: #fff;.. margin-left: 150px;.. padding: 24px;..}.....card__content #checkbox-question {.. font-weight: 600;.. font-size: 14px;.. margin-bottom: 15px;..}.....card__content .button__unfixed__width {.. background-color: #1671EE;.. color: #FFF;.. padding: 8px 16px;.. border-radius: 100px;.. display: block;.. margin-left: auto;.. height: 38px;..}.....card__content .button__fixed__width {.. background-color: #1671EE;.. color: #FFF;.. padding: 8px 16px;
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2556
                                                                                                                                                                            Entropy (8bit):5.3460996927668205
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Ekx0xeexvU2363kKk+kF3CeYYUrOFfp6NnSmsPzI4qJy:5kMOFUNnRs84q4
                                                                                                                                                                            MD5:20DF8C424D9FDC6D9AC7560463CD385F
                                                                                                                                                                            SHA1:BA912CD7E92E522083FE0944F4F61F37FA9959F1
                                                                                                                                                                            SHA-256:4E76CDD5AC54805CB0ED490F5EA2FC282518B041D5260A059E89E1B2C69ACD02
                                                                                                                                                                            SHA-512:8270807EB39F6A301BE40217D9D80C45372E1E39B5A4301F27115702C092F9E20B4B4528A9CD83B3BB59809626C1A738CA15EB3E156C8BC119E60AFE3A1C4012
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>....<head>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\custom-checkbox.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages_web_view\\webadvisor\\wa-ss-toast-variants.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-ss-toast-variants-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_we
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):15860
                                                                                                                                                                            Entropy (8bit):5.045192882623722
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:pBhtOz/WohfMaTGrTaTe1GXoK+iJIZut8g8BbLH5Vj:nOyoiammeYokJIZs8g8BZB
                                                                                                                                                                            MD5:7E5B44F4B207191CAE4F09629B5281F8
                                                                                                                                                                            SHA1:9D71C77C3652125B7867C34344CE9F3730728841
                                                                                                                                                                            SHA-256:949FEF7557748FA0A329B605F23ABD28D08C4C542375FE865B84107CD40609C5
                                                                                                                                                                            SHA-512:B6FF9090000BE937F03E32EACCCA421A16A64D5DD4676AB0B14465B2A4F39116F7D294ADBC13F62A5450F451A54308770BAD0CE349E4EF0304D2B40F3236ADCE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:./* Accept Extension UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _instrument = wa.Utils.Instrument;.. var _settings = wa.Utils.Settings;.. const TOGGLE_COUNT = "toggle_count";.... ui.accept_extension = function () {.. var $el = {.. cardImage: $(".card__image"),.. cardContent: $(".card__content"),.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. checkboxQuestion: $("#checkbox-question"),.. checkboxInput: $("#set-secure-search-checkbox"),.. doneButton: $("#done"),.. toast: $(".toast"),.. setSecureSearchLabel: $("#set-secure-search-label"),.. closeIcon: $("#close-icon"),.. labelDiv: $("#label-div"),.. };.... var variantsMap = {.. // Toast variation phase 2.. 1: {.. InfoTitle: "TOAST_VARIANT_1_TITLE",.. InfoText: "TOAST_VARIANT_1_INFO",.. Question: "TOAST_VARIANT_QUESTION"
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):15991
                                                                                                                                                                            Entropy (8bit):5.052309647002538
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:5B1uHjA9M61F9HRa9nFhxdzzPWQfwGti6+Sjn7:ghi0jn7
                                                                                                                                                                            MD5:D3D2587FDCBD8CF3F8FE881652C68B6A
                                                                                                                                                                            SHA1:5AC86E8BFB1E293882245D4643B2A22116CCCFD7
                                                                                                                                                                            SHA-256:7C4F4F795264026174D9E91FDB8308176EE04931D0DEDFD106444ABCB69F6DD5
                                                                                                                                                                            SHA-512:4BE6AA732893C25F93C543A7030CD6BC848151B6B90EE6C53E1EE3E4783750B59AF998E1DA502847C0168F09723A538EAB342C1FCE07CF05FD06BEB4C9286166
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* version 2 3 */..* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Poppins", "Open Sans", Arial, Helvetica, sans-serif;.. font-size: 12px;.. outline: none;..}....body {.. color: #212934;.. line-height: 24px;..}..../* Parent container */../* version 2 3 */...toast2_3 {.. position: fixed;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. background: #FFFFFF;.. overflow: hidden;.. width: 761px;.. height: 565px;.. user-select: none;..}..../* version 2 3 */...card__content2_3 {.. background-color: #fff;.. margin-left: 297px;.. height: inherit;.. padding-top: 36px;.. padding-right: 36px;.. padding-bottom: 36px;..}.....size_test_card_content {.. background-color: #fff;.. margin-left: 260px;.. height: 100%;.. padding-top: 32px;.. padding-right: 42px;.. padding-bottom: 32px;..}..../* version 2 3 */...card__content .logo2_3 {.. margin-bottom: 8px;.. width: 88px;..}.....card__content .size_test_logo {.. margin-bottom: 16px;
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4291
                                                                                                                                                                            Entropy (8bit):5.123045962254131
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:raaxkly363k3k5kCZhugy1s8FUYoAkZ6tOms8HDDC2eaNS64V2QXDzanW23W:mhutmYo8jtjDheasZVfXDzanE
                                                                                                                                                                            MD5:914FD5A8F27289295D0FAA9296B7CCC2
                                                                                                                                                                            SHA1:03F0C2CBA944132B6543581F6B172824DF8BAD38
                                                                                                                                                                            SHA-256:5838E641647F67228DE00B3473CABBED6D1498FB8D126737BDCDE618B76E3638
                                                                                                                                                                            SHA-512:B03E870D2479648A07561833A9F6ADDF9BD927E1E46C6624625BC2B8B7CF89C8056539E31C0EF3D15AFF848696A7DF1ABBC3E790A114A18EA4BC2C9122B19E36
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>.... <head>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link href="https://fonts.googleapis.com/css2?family=Open+Sans:wght@400;600;700&family=Poppins:wght@400;600;700&display=swap".. rel="stylesheet" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/mfw\\packages_web_view\\webadvisor\\wa-sstoast-toggle-rebranding.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-sstoast-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):20314
                                                                                                                                                                            Entropy (8bit):5.005269775172544
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:nMYsg4KeJ0FpttzjksroBrcIWqXub7m9IrNshzHsX:DsrKMYcsroBrAqXub7m9IrN+2
                                                                                                                                                                            MD5:49D2B3F70DECB62F79587D54B77C161D
                                                                                                                                                                            SHA1:A0EB32BFBEAE91CE408536BF26DA67F59C6E8A36
                                                                                                                                                                            SHA-256:48660300406DD22B43F5F54E3616A5A4ADA407C226C4C2D6A029603055A94655
                                                                                                                                                                            SHA-512:DCE75E0C71AEEE0E5A8AD4C8F599EF76440988BDA5A3FCDB8F6E17170D19907070D3F6AE8CAE31C64ED7759AD5E1E38FE1FA30F0445BF5FEAD737A7017F3312C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _instrument = wa.Utils.Instrument;.. var _settings = wa.Utils.Settings;.. var _misc = wa.Utils.Misc;.. const TOGGLE_COUNT = "toggle_count";.. var browser_code = "";.. var provider = "";.... const toastSizeTestMap = [.. { // 0.. "width": "547",.. "height": "332",.. ToastType: "toggle_toast_ss_toast_size_test_variant_0",.. },.. { // 1.. "width": "625",.. "height": "366",.. ToastType: "toggle_toast_ss_toast_size_test_variant_1",.. },.. { // 2.. "width": "700",.. "height": "416",.. ToastType: "toggle_toast_ss_toast_size_test_variant_2",.. },.. { // 3.. "width": "761",.. "height": "565",.. ToastType: "toggle_toast_ss_toast_size_test_variant_3",.. },.. { // 4.. "width": "352",.. "height": "704",.. ToastType: "toggle_toast_ss_toast_size_test_variant_4",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7437
                                                                                                                                                                            Entropy (8bit):5.10415873127051
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:OW0xXMHRMrola7b6xEgPGquAED+Y8AAoYE9Yl5hpeA8h9Y/5hbqe51E5T9565Cg1:OWlH2zFguf+c9Ug9K7aO9Y1ba
                                                                                                                                                                            MD5:3843340A9BBFE229C6219CA544750446
                                                                                                                                                                            SHA1:812976ECF142D7805F3588176AAC1E4D0F98445E
                                                                                                                                                                            SHA-256:2C1AA93A32169DF0138FD57DF55B8A6DC8937F8E0AF4315B9B68127680111D56
                                                                                                                                                                            SHA-512:7A12BD7C17322742467EBB9C112D0AC64AE5CAC5E4F69BBEFB6A53236417633B2FC8D4D2AB7999962475B90F4DCF4D238036F5762A64930795CA34E54D7DC25B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* version 2 3 */..* {.. padding: 0;.. margin: 0;.. border: 0;.. box-sizing: border-box;.. font-family: "Open Sans", "Poppins", Arial, Helvetica, sans-serif;.. font-size: 12px;.. outline: none;..}....body {.. color: #212934;.. line-height: 24px;..}..../* Parent container */../* version 2 3 */...toast2_3 {.. position: fixed;.. bottom: 0;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. background: #FFFFFF;.. overflow: hidden;..}.....toast2_3_larger {.. width: 761px;.. height: 565px;..}.....toast2_3_smaller {.. width: 761px;.. height: 500px;..}..../* version 1 */...toast1 {.. position: fixed;.. bottom: 0;.. border: 1px solid #ABB2C3;.. border-radius: 24px;.. overflow: hidden;.. width: 524px;.. margin-bottom: 6px;..}..../* version 2 3 */...card__content2_3 {.. background-color: #fff;.. margin-left: 297px;..}..../* version 1 */...card__content1 {.. background-color: #fff;.. margin-left: 150px;.. padding: 24px;..}..../* version 2 3 */...card__content .log
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4045
                                                                                                                                                                            Entropy (8bit):5.136705413245803
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:raaxLly363k3k5kabWZhuvT0/qUYoAxT75CZUea9S64hV2QXDUanjOOR:fbGhYGYoq75Heac7VfXDUanCOR
                                                                                                                                                                            MD5:6DA584055743278D479C9416DBCE7F9C
                                                                                                                                                                            SHA1:2FF6A9EADE6D045708A75EA6D753342FC1E31BD1
                                                                                                                                                                            SHA-256:DF30A6ABE4D7386FAC8EE233F924116DE5EBA6D3DF15FA90B8E3DB1F2AA0D460
                                                                                                                                                                            SHA-512:D0296825A89344A47322712DB56F4A33D3AD532049D31A7CBBC22AB6F2A401EF56524BBFB2C26D3899C0A6D87AED590245BF8768B946B17D1DF3862826C21C1C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:<html>.... <head>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <link href="https://fonts.googleapis.com/css2?family=Open+Sans:wght@400;600;700&family=Poppins:wght@400;600;700&display=swap".. rel="stylesheet" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/mfw\\packages_web_view\\webadvisor\\wa-sstoast-toggle.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\jquery-3.6.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-sstoast-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/mfw\\packages_web_view\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="file:///[WA_FILE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):10410
                                                                                                                                                                            Entropy (8bit):5.144798884804033
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:4MAf3m0aWPwT0JrrvhGzuLIhHQnJs1aW9seo65DhOrE/yIrEz2OlgXe:ef4cGyDJkseoBrdIr0se
                                                                                                                                                                            MD5:1E4D79B80A1F6AD1AB812603F435E723
                                                                                                                                                                            SHA1:1DCAA0916B6ADAF97D7FEF48E3170DD31643C7BD
                                                                                                                                                                            SHA-256:C3F4CBEC65E38AC29C62F34E3A6473F96967EC4EA88BF0B4813D08A9E7232722
                                                                                                                                                                            SHA-512:8E5D6131C65A1F80A057A48415F5CE8ED1ECABCB6D68F55B0628323E07CD3FC4D51AA7928C61FA3CE0D6E997268DF41B3DADB8D7E503FC8909BDC8428A734C1F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {};.. var _window = wa.Core.Window;.. var _external = wa.Utils.External;.. var _instrument = wa.Utils.Instrument;.. var _settings = wa.Utils.Settings;.. var _misc = wa.Utils.Misc;.. const TOGGLE_COUNT = "toggle_count";.. var browser_code = "";.. var provider = "";.. .... ui.accept_extension = function () {.. var $el = {.. version2_3: $(".version2_3"),.. cardContent: $("#card-content"), // different css for different versions.. cardImage: $("#card-image"), // different css for different versions.. featureDisabledSection: $("#feature-disabled"),.. progressPic: $("#progress"),.. contentInfoTitle: $("#info-title"),.. contentInfoText: $("#info-text"),.. expiredSection: $(".expired__section"),.. expiredDivider: $("#expired-divider"),.. expiredLabel: $("#expired-label"),.. expiredName: $("#expired-name"),.. feature1Label: $("#feature-1-label"),.. feature1LabelContaine
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6288
                                                                                                                                                                            Entropy (8bit):4.911633221107463
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:qkKi/9YE82GQyvE7p2Uop1VacAPZnn41/qQNc0:gR4PNYCGc0
                                                                                                                                                                            MD5:CEB9CA0D771CAF69F421B3B722DDA716
                                                                                                                                                                            SHA1:35A67785A3E3DAF2508DED21C10A54407AA7596B
                                                                                                                                                                            SHA-256:52908F8F69C0B3A3AA97BF954F9D0C44F5C05B27721C40B1CBFD718F762907D4
                                                                                                                                                                            SHA-512:E419C3F379D272D24DB5C8BAB1A28D0D2D3B7766F3288D553EBE4290B96635CB3D462A9C8F617024CAFE39FD085004C40DF4634D1750EFCC8B9C209B0CAE31C4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _settings = wa.Utils.Settings;.. _lrt = wa.Utils.Lang.ResType,.. _l10n = wa.Utils.Lang(wa.Utils.Lang.ResType.UT).get;.. .. ui.AvReport = function () {.. var settingUrlBad = _settings.get("upsell_url_bad_scan", "1");.. var settingUrlDefault = _settings.get("upsell_url", "1");.. var url = (settingUrlBad == '' || settingUrlBad == undefined)? settingUrlDefault : settingUrlBad;.. if(url == '' || url == undefined){.. url = 'https://www.mcafee.com/consumer/en-us/landing-page/direct/aff/WA_MTP_StaySafe.html?affid=1523&ccoe=direct&ccoel2=campaign&csrc=wa&cctype=mtp_test5&ccstype=mini_vulnerability_scan_91277'; .. } .. .. open = function () {.. var data = JSON.parse(_external.getArgument("report_data")); .. showReport(data);.. _window.show();.. },.... showReport = fun
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4316
                                                                                                                                                                            Entropy (8bit):4.710661775758201
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:+cAFwUkCqVVPCxEeO0pv1xRsxIE3BXDXjZXGG:hASUrqfjetptxRIXDXjZXGG
                                                                                                                                                                            MD5:576EA20B947CE856A4FC1F3BCA64B7F6
                                                                                                                                                                            SHA1:F63DF63B5DE1F41AA24113D8BDF2B7EEEC99B297
                                                                                                                                                                            SHA-256:7F285CB833C1209D2C02D17D358726462CF1FEF4944FC22196A48B76106C4347
                                                                                                                                                                            SHA-512:957A4BE4D7D2E24D360678F4AC7924BCCEF626681002667287E62B12026F1AE943266BD0DE3C203C9E90DD11740C2A73E8476E2D6352C5D98C5336463058AA84
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Accept Extension UI */..(function (wa) {.. var ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument;.... ui.accept_extension = function () {.. var telBalloonType = '';.... show = function () {.. chrome.webview.hostObjects.wa_external.log("inside show");.. _window.ready(async function () {.. chrome.webview.hostObjects.wa_external.log("inside ready");.. var settings = JSON.parse(await _external.getArgument("overlay_data"));.... if (!settings.balloon_type) return;.... init(settings.balloon_type);.... await _window.show();.... // Send telemetry for dialog balloon showed.. browser_code = await _instrument.getBrowserTypeCode().... //Send Telemetry 3.0 for dialog balloon.. var screen_flow = browser_code == 'FF' ? 'firefox' : '
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:C source, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2708
                                                                                                                                                                            Entropy (8bit):4.976828408398036
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:N45ikP03NTwwiIw0X+Zgleg0q3nwYfwR3AhYeYEfTiNAE1ed1RNADSuM+:RdUl3GsKirE0ShuJ
                                                                                                                                                                            MD5:59AF173A81AA4FC1002AC326EFE62BD6
                                                                                                                                                                            SHA1:AB46FDD81C8CD5322B495D42FD3A0467829CFE0B
                                                                                                                                                                            SHA-256:58737651B1A969FDEDD53D37537EF13F549BC230F46AAEB6BC0E013D91865821
                                                                                                                                                                            SHA-512:065719FF68BBF28D45AC6005395C71A64B01C54EFD908F04A2FFA7F8D859AC7829837BA1C65D54200544F52E24982978860A042829AFB39173549AB2AE5AE054
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Download Warning Toast UI */..(function (wa) {.. var ui = wa.UI = wa.UI || {},.. _instrument = wa.Utils.Instrument,.. _window = wa.Core.Window,.. _dw = wa.Core.DownloadWarning,.. _wa = wa.Core.WebAdvisor,.. _l10n = wa.Utils.Lang().checkList();.... ui.DownloadWarningToast = function () {.. .... show = function () {.. _window.ready(async function () {.. let domain = await _dw.getDomain();.. let fileName = await _dw.getFileName();.... document.getElementsByClassName("logo")[0].innerHTML = (_wa.getProductLogoHtml("file:///[WA_FILES]/MFW/packages\\builtin\\mcafee-logo.png"));.. //$el.status.append(_l10n("PP_STATE_TEXT"));.. document.getElementsByClassName("body")[0].innerHTML = (.. "<p class='content-header'>" +.. "<img width='20' align='middle' src='file:///[WA_FILES]/MFW/packages\\webadvisor\\warning-icon-toas
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):21381
                                                                                                                                                                            Entropy (8bit):3.8681212052565064
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:LravuBFTItTHDiF9ymq4pZpnXEB25hmmvYXOergIKB:PavuBcTHDdmRHpXEB2UEI6
                                                                                                                                                                            MD5:E17CC75340EA8C62160BA8B706CADFB2
                                                                                                                                                                            SHA1:9AB96311356C9045ADF9F8D475567E0DE45B50A4
                                                                                                                                                                            SHA-256:ECDDE28C2752BB014D39ACEACFE08F9502D6E1FFBD2D36B3D18F921A00DD7F0D
                                                                                                                                                                            SHA-512:C41AF41D92D599F2CCC3D1C44FB8119FE863CA33C882D6808712C8280E16DCB7B7AB348A572FD83726E094C461D8089F72C3237EA062D518F641902AEDFC0C58
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Options UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _instrument = wa.Utils.Instrument,.. _settings = wa.Utils.Settings,.. _lrt = wa.Utils.Lang.ResType,.. _l = wa.Utils.Lang(_lrt.OPTIONS).get,.. _core = wa.Core,.. _window = _core.Window,.. _webAdvisor = _core.WebAdvisor,.. _productNameHtml = _webAdvisor.getProductNameHtml();.. _external = wa.Utils.External;.... var OptionsMenu = function () {.. var menuItems = [],.. el = {.. $menu: $("<ul id='wa-options-menu'></ul>").. },.... toggleContent = function (id, delay) {.. $("#" + id, el.$content).. .fadeIn(delay).. .siblings().. .hide();.. },.... itemSelected = function ($item, delay) {.. $item.. .siblings().. .removeClass("selected").. .
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2680
                                                                                                                                                                            Entropy (8bit):5.237427075220709
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3Xxtxc/4363kKk+krCe4T+DSSqor5beIwEeIYuAix7x:O8ztb1/7x
                                                                                                                                                                            MD5:BAC103DB6F861B68E3BFF6B80CC7163B
                                                                                                                                                                            SHA1:F39514FE1BCE1EA0CB1799F416ED328F6635BFEA
                                                                                                                                                                            SHA-256:4C54A5A7DE9A27B39CB5434F7047E8A33767BF6F5B113529D3724A0FEE1A37C7
                                                                                                                                                                            SHA-512:7F41D0A6DDC61352C1A30326B50A0517426E28B3E686413CACD85D214A7C16FC8BD36C3C6BF5F09904671EDADB8E316BC76DACF439A64B13015CF81316ED4EF6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>Download Scanning Toast</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=9" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="file:///[WA_FILES]/MFW/packages\\webadvisor\\wa-upsell-toast.css" />.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-upsell-toast-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/jslang\\wa-res-shared-[loc].js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="file:///[WA_FILES]/MFW/packages_web_view\\builtin\\wa-core.js"></script>.. <script t
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):15043
                                                                                                                                                                            Entropy (8bit):5.1288350061480426
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:+0/PfJTvqz3NbDdvSNOsxyVcNvKTvY6TdR/OsxTtwXMT2OpUF/0Ul:zPfJTvECBxyuNvKTvY6TjBxWcTRK
                                                                                                                                                                            MD5:C75DD64D0805B8CAAD75C26B994D5829
                                                                                                                                                                            SHA1:908943FCF860DEFAF3C8FF65AB38A9A5924A08D3
                                                                                                                                                                            SHA-256:1AA32F82F2BAD433B057BCF7B1D1B97520343DBE5CC40873474456E9CD65400E
                                                                                                                                                                            SHA-512:8C6A5BD24139A794FA0C5B85F1DAE2860BF71C72A5439BEFCA1C988C4D6DC4C4BC23531CD474CCE897261436B142E950352B470321F98A5E4171F86A75F5041B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _window = wa.Core.Window,.. _external = wa.Utils.External,.. _instrument = wa.Utils.Instrument,.. _settings = wa.Utils.Settings;.... ui.createUpellToast = function (toastData) {.. if(toastData.campaign && toastData.campaign !== 'none') return new ui.CampaignToast(toastData);.. .. if (!toastData || (toastData && !toastData.cohort)) return new ui.AvScanToast(toastData);.... switch (toastData.cohort) {.. case 1:.. case 2:.. return new ui.DirectUpsellToast(toastData);.. case 3:.. return new ui.GtiUpsellToast(toastData);.. default:.. break;.. }.. };.... ui.extend = function (Child, Parent) {.. Child.prototype = Object.create(Parent.prototype);.. Child.prototype.constructor = Child;.. }.. .. // ----------------------------.. // Base Toast Object definition.. // ----------------------------.. ui.UpsellToast = function
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5441936
                                                                                                                                                                            Entropy (8bit):6.506710019612722
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:016kzANE8yhtlohyWQ0iMuVjb3yyPZSeACMjWpjMvc7pgHiDj00FLy4JxviqxP1d:M5o2S5CMjyI0DhiAP1QCHom8ti5
                                                                                                                                                                            MD5:B928B80C5DF851A97642E3E97DFF1B6B
                                                                                                                                                                            SHA1:79807701066824CB26924CE448F6425C55D42D22
                                                                                                                                                                            SHA-256:7F1396B074C4D49F8CE7D7FBF9F8905A20B50A03AD6C5FD657CB31DC068B5D42
                                                                                                                                                                            SHA-512:895B9A958A2517A5AFD9A7FB1F8F3D6749A2B2540F44D26C8C643BFAD718ADF2A59137ACBF2836B29B82D13F0374E4698860D6D7206FD7AD7D8F065AD445EA4B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$.......NJ...+j..+j..+j.ASo..+j.U...+j.Un..+j.Ui..+j.Uo.w+j.ASi..+j..^n..+j..To.O+j.ASk..+j.ASn."+j..+j..+j..^n.K+j..^o..+j..+k..)j...o.[+j..Tc..+j..Tj..+j..T...+j..Th..+j.Rich.+j.................PE..d....YWg.........." ...$.N?..........{6.......................................T.....hbS...`A..........................................L.D.....L...... T.p.... Q......&R......0T.8}....G.p.....................G.(.....C.@............`?.......L......................text....L?......N?................. ..`.rdata.......`?......R?.............@..@.data...$.....M.......L.............@....pdata....... Q.......N.............@..@.didat..p.....T.......Q.............@..._RDATA..\.....T.......Q.............@..@.rsrc...p.... T.......Q.............@..@.reloc..8}...0T..~....Q.............@..B................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4109
                                                                                                                                                                            Entropy (8bit):5.532740544042154
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:fDHfl13RqCJ0Q6kQ22E0AOY0T3AiNJI3XVtjjakIXzr9Ml72Yq38lrr/XZ1yiODU:fDIZB1JSt/akIX/SfsuuXA
                                                                                                                                                                            MD5:C03BD6B041B92FBFE8FA15532762A8F9
                                                                                                                                                                            SHA1:2F4DFD37F7FCFA8FB270717A6CB281A4E5EA8B58
                                                                                                                                                                            SHA-256:15FBA1DF5671D8CE05DB40365BAF5A57C9D35230AC74D432058B8CF48BB3A5BE
                                                                                                                                                                            SHA-512:512480E8526EFC1422A9351484E4C53F0D4ABECEB350ECCE7B47652789186C1A95816F4845BF9F3FDB03667EEEFB8B411DFC789A9514703EC32F5632DCBBDCDE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........A.h5.>.5...5...=...5...=...5...5...=...5...4...5...>...=...=...=...5...=...5...=...5...5...=...5...4...5...>...5...>...=...=...=...5...5...=...5...4...5...>...5...>...=...=...=...5...=...5...=. .5.!.=.".5.#.5.$.=...5.%.4...5.&.>...5.'.>...=...=...=.(.5.).5.*.=...5.+.4...5.,.>...5.-.>...=...=...=...5./.5.0.=...5.1.4...5.2.>...5.3.>...=...=...=.4.5.5.5.6.=...5.7.4...5.8.>...=...=...=.9.5.:.=.;.5.<.=.=.=.?.7.@.6.@.L....context_config.contexts....contexts..wa_smart_toast_attributes....setting&context_wa_smart_toast_attributes.handler.SmartToasting.wa_mss_plus....setting.context_wa_mss_plus.handler.MSSpStatus.user_account_id....setting_name,CloudSDK.cache: GET /account/v1/details.key.account_id....settings..handler.AnalyticsWPSSetting....db_name.vso.hash_id.IDENTITY.property_name.accnt_id.handler.WSSSetting....wps..handler.AnalyticsWssWps.setting.context_user_account_id.wss..product_productkey....setting_name1CloudSDK.cache: GET /subscription/v1/details.key.product_key....setting
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1732
                                                                                                                                                                            Entropy (8bit):5.803537322068206
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:AnBciTKqN5+eO96lrbNiFiuUDqKMZO58Aa4Jq7X:ABci+SOMEFsD5MZOs4c7
                                                                                                                                                                            MD5:F95591D0A3A0594302407DF873650871
                                                                                                                                                                            SHA1:FA985B428AD5FC22E30365D4FF0E39D25B2F7D8D
                                                                                                                                                                            SHA-256:78B7D8928C3412B9CB2A0399680F0A87CFEE16BF491C85A880385F5292AD9D4C
                                                                                                                                                                            SHA-512:A6FB50E9B3C5027CE5F3E294E1CFB554FA7D068A924AFBD6248C15CF1012CC49DFAA4CD214FA2A6F817B5AD4A6C1E8AFE6CF6E2E78E0C61AEF43039BE6CFDC36
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........e....X...'...L...6.......9.......B.......X...6...9.......9...'...B...'...L...........X.......X...6...9.......9...'...6.......B...&...B...6.......D...X.2.6.......B...6...9.......9...'.......&...B...6...9.......B.......X...6...9.......9...'.......&...B...'...L...6.......B...H...6...9.......9.......'...6.......B...&...B...F...R...8.......X...'...L...8...6...9.......9...'...6.......B...&...B...6.......D...,AnalyticsWPSSetting: value returned is . = .pairs.NO_WPS_KEY&WPSSetting: JSON parsing error - .decode.json_parser%WPSSetting: wps json setting is .tostring"WPSSetting: wps setting value.NO_KEY.NO_WPS_SETTING WPSSetting: wps nil setting.info.log.core.get_setting.wps_utils.NO_INPUT_SETTING........L...@.......6...-...B...X.......X...+...L...E...R...+...L......ipairs........D6...9.......9...'...B...5...3...'...-...9.......X.$.6...-...9...B...X...9...9...6...9.......9...'.......&...B...6...9.......9...'.......&...B...-...........B...........B.......X.......X...E...R...-...9......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1308
                                                                                                                                                                            Entropy (8bit):5.5549248879182
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:64svoMGnu0xHB1bKNQnuEKSNAdoCsqXRb7UcVzoFsqXRAKJDMOrDYyMyJ1+s9n:1u0xjuE+oeXRJ1oLXRnJDMO3YnyJR9
                                                                                                                                                                            MD5:9F762363448B21B52ED22BEEF55CADB0
                                                                                                                                                                            SHA1:5114D43B90400D2EE8E6DBB0ECA387B4B6B43ABF
                                                                                                                                                                            SHA-256:E7FA982865963C175239D51404B3887FCDE39649677FF283269DD03FA4BF8E93
                                                                                                                                                                            SHA-512:6389B363BFCFB30D61AF3479932B984F4182DB9E00B7AA45475EBB991602F7688AB8601700486BF9DBBD32B7D25099DD5D1EBA377C7F44874B9AA0292DC84BFB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........m-...9.......9...'...B...'...6.......9...B.......X.0.-...9.......9...'...B...-...9.......X...-...9...9.......X...6...'...-...9...9...&...B.......X...9...-...-...9...+...B...9...B.......X.=.-...9.......9...'...B...X.6.-...9.......9...'...B...X./.-...9.......9...'...B...-...9.......X...-...9...9.......X...6...'...-...9...9...&...B.......X...9...-...-...9...+...B...9...B.......X...-...9.......9...'...B...X...-...9.......9...'...B...L.........]AnalyticsWssWps: Expecting wss subconfig and wss handler in context config, but got nil.:AnalyticsWssWps: Nil wss context handler encountered..wss*AnalyticsWssWps: WPS is not installed]AnalyticsWssWps: Expecting wps subconfig and wps handler in context config, but got nil.:AnalyticsWssWps: Nil wps context handler encountered..err.get_context_string.new analyticstelemetry.context..require.handler.wps&AnalyticsWssWps: WPS is installed.is_wps_installed.wps_utils.$WssWps: main get_context_string.info.m_loggerR.......6...9...........B...3...=
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5024
                                                                                                                                                                            Entropy (8bit):5.770690003003992
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:ph4Uw0908YNdY4a8PbjZDoFeuZCkv886A4A7AaAXzAMAwhsGU3JF5uXrK3yWK/8R:/xhdYN8YbuwW6zOJF5uX0yw5QCGIh75
                                                                                                                                                                            MD5:866CC52507CA218A57C37DBC6D1B0F18
                                                                                                                                                                            SHA1:4255A5A017EFCEE25D17184B7100171794016CE0
                                                                                                                                                                            SHA-256:B02F6980B1584CD74BF035C853763AFBB3C790E6A2A4CA3009DA2327938D2467
                                                                                                                                                                            SHA-512:84683E36908F16C787E3BB89F9B86288E694130F15A0EFD0C67882940994470F85BF1C68208D50F0DBA1883637B8644E0931143B0D1AB45B0345411D5F1C5D2B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........(6...9.......9...'...B...5...5...=...5...=...5...=...7...6...-...B...H...-...9.......6...8...9...6...8...9...B...6.......9...+...-.......&.......B...F...R...K..........SetOption.settings.value.key.get_browser_version.pairs.reg_info.ed....value.version.key(Software\\Microsoft\\EDGE\\BLBeacon.ff....value.CurrentVersion.key%Software\Mozilla\Mozilla Firefox.ch....ff..ch..ed.....value.pv.keyNSoftware\\Google\\Update\\Clients\\{8A69D345-D564-463c-AFF1-A69D9E530F96};Inside Browser Information set_browser_version_setting.info.log.core........-6...9.......9...'...B...5...7...6...-...B...H...-...9...6...8...+...B...6.......9...+...-.......&.......B...-...9...6...8...+...B...6.......9...+...-.......&.......B...F...R...K............SetOption.settings"get_supported_browser_version.pairs.browser_ints....ff...ch...ed..CInside Browser Information set_min_max_browser_version_setting.info.log.core........<6...9.......9...'...B...-...B...-...B...5...-...=...6...-...B...H...9.......X...4...<.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):983
                                                                                                                                                                            Entropy (8bit):5.811447092108564
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6J2msRGv1RWv8KD8RY7o7dOfTSOqyKRb9e3C4idAlu9:CR0jD8y85OfTSOqyObZ59
                                                                                                                                                                            MD5:A25D8091FB26EE6A7458652C3C1BF9B8
                                                                                                                                                                            SHA1:FF482DC8A1A5B26431547A51F839486B0BD103AD
                                                                                                                                                                            SHA-256:23230778AB8040779191D967776816727B9FFF3ECEA33D2EA6FB8BAA7E3A2669
                                                                                                                                                                            SHA-512:81C79694AC181B5C4608EDCFCEFB3EE32150943E4F23819982CAF35642E9587606EEC974FE21A300ADFAE1FD2E223F9EC298EBC2DE63832B85DAC218BCB3FB66
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........H4.......X...4...5...>.......X...4...5...>...5...>...5...>...5...>.......'...6.......B...X...6...9...9...9.......)...9...B.......9...B.......X.......9.......B...........X...6.......X...X...E...R...'.......X...6...9.......'...B.......X.......X...6...9.......9...'.......&...B...6.......D....tostringMCould not determine browser version. Returning default value. Browser = .err.log.%d%.%d.match.string.0.0.verion.QueryValue.IsValid.options.root.Registry.Win32.core.ipairs.....options.....root.HKLM....options.....root.HKCU....options.....root.HKLM....options.....root.HKCU....options.....root.HKLM.iej.......'...6.......9...........B.......X...6.......B.......L....tostring.GetCurrentBrowserVersion.utility..........6...'...B...4...3...=...3...=...2...L...."get_supported_browser_version..get_browser_version.mfw.core.Win32Helper.require...//8FC43CD86ADF4C255D43DFF442E6AF1F4BB3F901EDBC2D3217794054192A6CB20C93D1516BE49D8123645F7C275274C167D61D5D2558EA67367D467C5C428385++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):422
                                                                                                                                                                            Entropy (8bit):5.250436371747685
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:6lK3t4LqtAoIulNhWjGWA6q4Tf9q4Tf9qy/jmhSAz9eTWTWXUKWdenWImU+1W1Uy:6I9OuHhWqWBtJjmhzRbaEDGDmQ1UBE
                                                                                                                                                                            MD5:4DD5FF4438678AB1E72D2FCD25608644
                                                                                                                                                                            SHA1:7AED7C79EDD11115A478AE2DBB597855BF4EA7BC
                                                                                                                                                                            SHA-256:D2839001CCD1C7F54048938D7107F0B8DD89F15C3272F58FEA3C5310DA67E05B
                                                                                                                                                                            SHA-512:975D509D422E51B1041010B321FF88E8201EA573F0A7C71398BC646CCD93A7BED234BAB3C55E87F03E9773C89BDB5DF0F3E7DC1B9BAF93ED369E30B7E95752E5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..@.......6...'...B...K...'get_context_string not implemented.error........-...L.................K.....x.......4.......=...3...=...3...=...3...=...2...L.....set_context_config..get_context_config..get_context_string.m_logger;.......4...7...6...3...=...6...2...L.....new.ContextHandler...//3080B3F3C14226C41C47FDBD3F5B14D73EE65B632CE3EAF4D1C1E5818E51DB3A224A6B2FEA110F68D8860A1A0785A0C44213C7D29E188A5E32D600C39C979631++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):897
                                                                                                                                                                            Entropy (8bit):5.5657914963715145
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:68i5J1Gn4Lel9awpSLdVf507iDaXU0XlLRNMSJ1xF7VDG:ti5J1venD4Vf5Coj2RqSJx78
                                                                                                                                                                            MD5:15EFA1987698A34AEE0CD6A4DC3C50F9
                                                                                                                                                                            SHA1:43B47EEE1ED9D2FE0ECAD31A1CCBCC410FCCC663
                                                                                                                                                                            SHA-256:7652C7B9C7A89EF7299DE4EDB39AE0FF0CF74935A836EAA58A514E5A098C5FE4
                                                                                                                                                                            SHA-512:A1BC05E7064B5611A158F398227EB8E86B2CCC28B0BA2D8BBFB0E07F423CBEE888742860F87617D76991A07D9A0BE8DC6544766F76965FC60850CD08462A6589
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........>-...9...B.......X...9.......X...9.......X...-...9.......9...'...B...'...L...6...9...+.......X...9...8.......X...-...9.......9...'...9...'...&...B...6...9...D...........B.......X.......X...-...9.......9...'...9...'...&...B...6...9...D...6.......D.....7) return invalid result. Returning default value...tostring0) does not exist. Returning default value. External utility function (.utility._G.defaultQInvalid configuration supplied to external utility function context handler..err.m_logger.func.default_no_value.get_context_configR.......6...9...........B...3...=...2...L.....get_context_string.new.ContextHandler.........6...'...B...4...7...6...3...=...6...2...L.....new.ExternalUtilityFunction.analyticstelemetry.context.ContextHandler.require...//F11BE6B6083D669E81B3318260DB49C1A6BA6886ABA9AE0B562547EF3DADCCD84B64E5D3EA49856CFA12C71534154BE7476D1A063F866AADDAA2BA393C20A894++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7498
                                                                                                                                                                            Entropy (8bit):5.613792909770243
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:ZjWEqmnipj7pRakfL6HQVS65L6D0Y08N0IVX6Mak6Sj2bA6XCoG3ipGHbFT6Zvv5:RWdmnqRakfOHQVS65OD02N0IVX6MatSI
                                                                                                                                                                            MD5:0CBCBE117A18F9ABED1941BA5DAD6724
                                                                                                                                                                            SHA1:D172160C5746773442053B0D3BAD363506A23DD6
                                                                                                                                                                            SHA-256:156F8108183292BBED329C4F77DB61A773DC53B370C3BF707E480224CAE7012E
                                                                                                                                                                            SHA-512:4E220E5D820F56690F1604035BDF5122FEC482EF1F8A189A2AC97C98AA8B3050FF54893CD51141AF16711DAD37708AB1617A7BDEDA5B5DE393BF675403DD1564
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..V.......-...........-...-...8.......X...-...-...8...-...-...-...8...8...J...K..........d.......4...6...-...B...H...........<...F...R...6...9.......B...)...3...2...L.......sort.table.pairs.........]'...-...B...X.V.'...).......)...M.K.8...9...9...9...9.......X.,.....X.*.....X.(.'.......X...6.......9.......B.......X...'...X...6.......9...........'...B.......6.......9...6.......B...6.......B...A.......X.......'...&...X.......'...&...X...8...9.......X...-...9.......9...'.......'...&...B...X...-...9.......9...'.......'...&...B...O...........'.......'...&...E...R...L........=2) was detected when processing FTF dimension..Invalid information for (.err%) when processing FTF dimension.'Skipping version information for (.info.m_logger.version.0.1.tostring.IsMatch.regex_helper.GetOption.settings.get_setting.wps_utils.wps.setting_source.enablementCriterion.enablementSetting.scope..,.........6...9...........B...6...9...3...3...=...2...L.....get_context_string..FTF_Registry.FeatureTrackingFeatur
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):488
                                                                                                                                                                            Entropy (8bit):5.505647062582451
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6jot8h2HMHGU4iCkSR7zt0GJWJJKvx/JAT8V4JK5yfH:672sHG/wSByGJ1/Vzyv
                                                                                                                                                                            MD5:A0D19CE46D298D28D47F331342797B4E
                                                                                                                                                                            SHA1:DAC13ACF4870EA3737DF06481B735DDF4B11C60C
                                                                                                                                                                            SHA-256:40D623385CBF2B317E52A4DE925DC5DE7E4274BA3B7BE40D248B453AFAD8A9F1
                                                                                                                                                                            SHA-512:1953CC8E6C4F59AAC53E2814CC75E1D35017FC091A5F65EBB069EF0CFD789ED0E0777D310CAC2B713EFDAEB14CF6D00BA328D604CCE94B287CFE588DBFFD2AF7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..O.......6...9...9...9...D...#get_analytics_hashed_device_id.MiscUtils.utils.coreR.......6...9...........B...3...=...2...L.....get_context_string.new.ContextHandler.........6...'...B...6...'...B...6...'...B...4...7...6...3...=...6...2...L.....new.HashedMachineID.logic.MiscUtils.mfw.core.Win32Helper.analyticstelemetry.context.ContextHandler.require...//42289B8895B1C7516C40DE9647D457D33DA846606CEE4E4E1023BCB7D8500F556F540615A20611BB1DF5308BB061071F509368AB30AA0CFB7D9D44E0270727FE++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2001
                                                                                                                                                                            Entropy (8bit):5.683033574229011
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6iSHUuceVdlgG13dShqVJCaZRetV6mclRiXvAZeyUepCGOODGAcncnlMAGJ1LFY:o/c8lgG2qfCasDclRiXv57/7AznlIJc
                                                                                                                                                                            MD5:039A8A6A04B7518B71F13F9CF2E9D2FC
                                                                                                                                                                            SHA1:8F6585AFD091DA5C60A0EDDAC7374D4A600F25A1
                                                                                                                                                                            SHA-256:EAB606A14D5DA138B3F9A84C5E91581ABFAF6E47DE64D1979617E68C5F7A0983
                                                                                                                                                                            SHA-512:4B1F17BD3E170F0B004E9AA950966D9D104C554D5907612AA029A908CFD248A0EDAE2F2EB2E59ECADFB3141185EAA44B8C50934632A7B1015C1A8D16E13C09AE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..k...........9...'...B.......X.......9...'...B.......X.......9...'...B.......X...+...X...+...L....|.&.%%.find........1-.......B.......X...-...9.......9...'.......&...B...+...L.......9...'...'...B.......6...9...'.......'...&...B.......9...'...B.......9...B.......9...'.......&...)...+...B.......X...+...X...+...L........Directory of .find.close.*a.read." 2>nul.dir ".popen.io..\$.gsub%Unsafe directory path provided: .warn.m_logger........*'...6...9...9...'.......)...*...B.......9...B.......X.......9...'...B.......X.......X...6.......D...X...-...9.......9...'...B...'...L...-...9.......9...'...B...+...L..... MSSp not found in registry..version_not_found1MSSp 'DisplayVersion' not found in registry..warn.m_logger.tostring..DisplayVersion.QueryValue.IsValid.HKLM.Registry.Win32.coreYSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\McAfee Security Scan............'...-.......B.......X...'...L...-...9.......9...'...B...+...L.......3MSSp default installation directory not found..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):847
                                                                                                                                                                            Entropy (8bit):5.708275070666962
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6AnfqeIYFxO8waLvpV53SaTMzJ1JSsX3Drp:znfqlY7lwaLvpX3DgzJrFnR
                                                                                                                                                                            MD5:9633786E7B2D8F01C93BED81B46CAF28
                                                                                                                                                                            SHA1:6F5D13B9073941A42AF8DC28ABC03AB0D319C6A9
                                                                                                                                                                            SHA-256:FDA3EB21E2C11ADA68801D7D68FED22631BC1AFE935A9D9B16AA1EFF230FF627
                                                                                                                                                                            SHA-512:9C2A9983F1F0FC0635DDF591D7C8EAD5FB46DAD54C00705DD3DD08D2C79DC279FC72CFC298B991FB2999BA2FB515BDE4FA194273695BC352258F6421B54D74C7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........;)...6.......9...+...'...+...B...6.......9...+...'...)...B...6.......9...+...'...)...B...6.......9...+...'...)...B...6.......9...+...'...)...B...6.......9...+...'...+...B.......X.......X.......X.......X.......X.......X...)...6.......D....tostring.oem_recovery_v2_disabled0*DEFER_SEARCH_MINIMUM_DAYS_AFTER_WA_INSTALL3*DEFER_SEARCH_MINIMUM_DAYS_AFTER_WSS_UNINSTALL4*DEFER_SEARCH_MINIMUM_DAYS_AFTER_WSS_ACTIVATION0*DEFER_SEARCH_MINIMUM_DAYS_AFTER_WSS_EXPIRY.*ShowSearchSettings.GetOption.settings.R.......6...9...........B...3...=...2...L.....get_context_string.new.ContextHandlery.......6...'...B...4...7...6...3...=...6...2...L.....new.SAMRecoverable.analyticstelemetry.context.ContextHandler.require...//47798BE70729F8A1EEFD6036B941C76072E7D2AA74B9DCBE45CA772C9271F8D22A1E1777B9CF55BC242E1D326BD02269E8BE9330CEEC96BA9DB8708760A46ADA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):520
                                                                                                                                                                            Entropy (8bit):5.460800424784102
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6bkleqAuDPPVIVJn1qW9icHJXOefoij4MDrWjJWJJKfmKB+3kEkjN0Zru:6AeqBcn1qW9icp+egTMvWjJ1fWqN+K
                                                                                                                                                                            MD5:8CED50C7DCF9AF1463B742D73D307648
                                                                                                                                                                            SHA1:BC506813F7FDB583A34A6C3F64EB7ED5B2FB09E7
                                                                                                                                                                            SHA-256:81B816CE3A963016ED31CFFBCE98258125EA7ECC81528770241D70636DEB564E
                                                                                                                                                                            SHA-512:8F5BB331E06EC06C3C31FD8BB8203436A47C48C8261B470A5665FD83E121F88DFCD1AB4FCD91D8B16B76D95BA2A3627EE8F91BE86FBF072B30E103B2A4F43C2B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6.......9...+...'...+...B.......X...'...L...6.......9...+...'...)...B...6.......D....tostring context_product_sequence_id.0.*AnalyticsSequencingOn.GetOption.settings.R.......6...9...........B...3...=...2...L.....get_context_string.new.ContextHandlery.......6...'...B...4...7...6...3...=...6...2...L.....new.SequenceNumber.analyticstelemetry.context.ContextHandler.require...//7ED560EC7ED4140568726798C41191271970B2B3A2CA8082D40711DC7A015F3B538C0B6F25B9D40CE2CEC10A9B37B6639B9D5832AF7B155D762D9893E9091CFA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):972
                                                                                                                                                                            Entropy (8bit):5.4279273266494865
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6XWL2ZIiFTncarkwIRwVxneUsqPGGIhOBf49WMmlUJ1pA8GW:WWL+IiFTcarkwIRwVxneUsvGIhM49z7D
                                                                                                                                                                            MD5:43926FBC1D75C72914DC526D8A1F4E5D
                                                                                                                                                                            SHA1:BB85D6E30D1A49B8E7F657700648F25629C86B5C
                                                                                                                                                                            SHA-256:E4B140B78FACE5B057234BA67C5814DB152C69B989C63D4C21186CEA4514F84A
                                                                                                                                                                            SHA-512:100A67368B18A0A4196502C0F76A30CA010D673CE0411D308387F096FF00E16F5DD7484ED9F76DE1D1513E1E74C132BF87FE3C0F28E3EDA87A3D70B5F375CEB4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........../5...6.......9...+...'...'...B...=...6.......9...+...'...'...B...=...6.......9...+...'...'...B...=...6.......9...+...'...'...B...=...6.......9...+...'...'...B...=...6...6...9.......B...C....encode.json_parser.tostring.ml_model_version!smart_toast_ml_model_version.ml_iteration_version.smart_toast_ml_iteration.selected_config_id.smart_toast_config_id.api_configuration_version&smart_toast_server_config_version!client_configuration_version....api_configuration_version..ml_model_version..ml_iteration_version.!client_configuration_version..selected_config_id..unknown&smart_toast_client_config_version.GetOption.settingsR.......6...9...........B...3...=...2...L.....get_context_string.new.ContextHandlerx.......6...'...B...4...7...6...3...=...6...2...L.....new.SmartToasting.analyticstelemetry.context.ContextHandler.require...//618E7BA1E3117C447104D23D8FEEF00B82E662888D67C182F0CE87C845271F7EECE0EAF31D15FB2B2723CD066FE2F2593527F4AC9516E7A093E00A95C77A10F7++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):594
                                                                                                                                                                            Entropy (8bit):5.596923483315471
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6uPWQZbCntmkkkkkaTzorpsV4M7RIJ+K0Ng2Lh085pBVz:6uP9bCngkkkkkNreKMqJ10S8Lb
                                                                                                                                                                            MD5:80BCA5731A602CD79F2A2DA337402C96
                                                                                                                                                                            SHA1:130DFB22FC0C0A3BB981F4CF528DF4D90121BC7A
                                                                                                                                                                            SHA-256:61634B00689F0416EBD55AE68997674C381861926B9DB90926D6CBD01950DAF5
                                                                                                                                                                            SHA-512:F26F763964B0E3E74F52326706F916FAD17FCA17EAC36AF50EC2917B2775FCFF04C047ED156E61D4E0720ED4A76138016A1DE6322781AF77C219F08CA8D04166
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........&-...9.......9...'.......&...B.......6...9.......'...B.......X...6...9.......)...)...B...'...6...9.......)...)...B...'...6...9.......)...)...B...&...L......-.sub.^(%d%d%d%d%d%d%d%d).find.string+SubscriptionExpiryDate: input date is .info.m_loggerI.......6...9...........B...3...=...2...L.....format_output.new.WSSSetting}.......6...'...B...4...7...6...3...=...6...2...L.....new.SubscriptionExpiryDate*analyticstelemetry.context.WSSSetting.require...//08BBB25746BEDB8D6E20EBEC76AE08313EB9543AFD946830A86CF53D60A442475667B8EA9B4382B231C7DE19146F7BA5E838F75C9E6B65A483088B3AE6E505BE++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1106
                                                                                                                                                                            Entropy (8bit):5.524719903516146
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:68K9YrN+Iuz8iWm4CDopXVXHLhN8FlKCzqWb2lLzJJvUJ1o1poO:FKuN+sppLhN87KCz52lLFJ8JGvT
                                                                                                                                                                            MD5:C9DAF06D7876220352BAEF73C942A405
                                                                                                                                                                            SHA1:8BCF45E754780188F7556A89DF5E3C5292FA7804
                                                                                                                                                                            SHA-256:25D5A6478B95AA2812B5B71D0B829B8DD60F04F916E540C3B637DA0BB5498F31
                                                                                                                                                                            SHA-512:52CC2B5E59325CC9B4134AFE2C91B53F3D7404671891613527990F70B7D4EAA706089FF36C3D25102A36DE3CBF22FA426095266ED1C47396AC0690C3156470F2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........J).......X.......X...6...9.......B.......X...6...9.......'...B.......X...)...L...6...6...9.......)...)...B...A...).......X...)...L...6...6...9.......)...)...B...A...).......X...).......X...)...L...6...6...9.......)...)...B...A...).......X...).......X...)...L...6...9...5...=...=...=...B.......L....day.month.year....hour...day..month..year..time.os.sub.tonumber.%d+.match.len.string..4.......6...9...6...9...'...B...C....!*t.date.time.os.........-...9...'...'...B.......X.......X.......X...L...-.......B...).......X...'...L...-...B...'.......X...'...X...'...L..........expired.active..INVALID_DATE.UNSPECIFIED.NO_APP.NO_SUITE.settings.vso.get_sub_db_setting{.......6...9...........B...6...9...........B...3...3...3...=...2...L.....get_context_string...WSSSetting.new.ContextHandler.........6...'...B...6...'...B...4...7...6...3...=...6...2...L.....new.SubscriptionStatus*analyticstelemetry.context.WSSSetting.analyticstelemetry.context.ContextHandler.require...//B23AB20321960D98689F7675
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):538
                                                                                                                                                                            Entropy (8bit):5.533769534729744
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6xnSlRXZQXFcg89rg0lr7JJvUJWJJK8IR6PiiVH6Wkdh:6M1aOPDlnJJvUJ1WiuHg
                                                                                                                                                                            MD5:C95DAAEA59951DE6DA7198F68FADF0DF
                                                                                                                                                                            SHA1:76C384BF454AB2196AD781D7ED581611218083FF
                                                                                                                                                                            SHA-256:A03587A466C47394325A3AE0EA6564B6EE7781ACDA52DBFB10FDD27F24B15596
                                                                                                                                                                            SHA-512:BFEE79901D005E04839174ECAB6C70CBDA02235A403D9261D6C3E59114028FC5A9D9CB04FC15D7A40A5F8E4167DDBDEFB6C595F8C06B2742688E96D6783AD0D0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..l.......-...9...'...'...B...'.......X...'...X.......X...'...L......paid.0.1.free.trial.vso.get_sub_db_settingq.......6...9...........B...6...9...........B...3...=...2...L.....get_context_string.WSSSetting.new.ContextHandler.........6...'...B...6...'...B...4...7...6...3...=...6...2...L.....new.SubscriptionType*analyticstelemetry.context.WSSSetting.analyticstelemetry.context.ContextHandler.require...//11EF221A65A8089498DFA65ABA8462CA418FBA7BD92C7F7DB9F4579FA226B34A88F3ED0E7EF1811D41C3BC7BAF0C60E4040249C986F94027FC1851E720355E7F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):857
                                                                                                                                                                            Entropy (8bit):5.605404148897678
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6K2KHgolfJ+6HmReFYfaHSSTXy6/ynul82t/CCGfOzmik2lrDQxL30GJWJJKyudf:6LSgolbGXSPyKOq8s/le2l4xAGJ1O2jP
                                                                                                                                                                            MD5:603393BD8D0BCB5264BB142C09E4B0C4
                                                                                                                                                                            SHA1:B5F29709DEA7649807C5865F272A4274B4874E77
                                                                                                                                                                            SHA-256:16EC82174D4D3681E3D9CF35193DAA0CEC0AF6E78CDC70C068D66D8CE160A6FE
                                                                                                                                                                            SHA-512:AA716B29E1BA8079F3F281CF4DDF60D043CE8F6E138CBB839C655FAF401E004F63D5F6C93D15B177B0CAED4C47356614CB8512EFC9ECB2DDB4AD7BE366A962A7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........&)...6...9...9...'...'...)...*...B.......9...B.......X.......6.......9...+...'...+...B.......X.......6.......9...+...'...+...B.......X.......6.......D....tostring.*Freemium.*Orphaned.GetOption.settings.IsValid5SOFTWARE\McAfee\MSC\Settings\ApplicationInfo\MSC.HKLM.Registry.Win32.core......Y.......-...9...B...6.......B...........X...+...L...+...L......tonumber.get_suite_status..&.......-...9...D......get_suite_status.........6...9...........B...3...=...3...=...3...=...2...L.....get_context_string..is_suite_installed..get_suite_status.new.ContextHandler.........6...'...B...6...'...B...4...7...6...3...=...6...2...L.....new.SuiteStatus.mfw.core.Win32Helper.analyticstelemetry.context.ContextHandler.require...//D62E179CA9F974ADA822EE17391FDFE2DB517C1F6813ECF1706058473BD8BFE9177D7862D5EF6109598C14026F7F41E96B0C820F28150A65432AEBBC84D4DF05++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):472
                                                                                                                                                                            Entropy (8bit):5.5653649919561845
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6YkglNLnYklpsvcRu3U4M4rJ0NRu3pKFDHWlXb8h:6JglN7YkleZ35MSJ0NRu3k2oh
                                                                                                                                                                            MD5:2A3473A5C4CFEF019E934480007F9F20
                                                                                                                                                                            SHA1:9ADB42E46C3773630526AF9445E9997334D47CC1
                                                                                                                                                                            SHA-256:44468A6FFE1B3EC0B7675294A5FDF0B46A53602E3F8961A04A4EA2D63F2BE4D7
                                                                                                                                                                            SHA-512:BDCB4828078FAF8D7E7F2411D76F2C251B99F7D7B71034DADA31AD77F7E9B0CBA26F59BD6AF79E8C1C9F944D1A766507E083422EFB50F8E2324B86FDD403E356
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..m.......6...9.......'...B.......X...6...9.......)...)...B.......L....sub.^(%d%d%d%d)-(%d%d)-(%d%d).find.stringR.......6...9...........B...3...=...2...L.....format_output.new.AnalyticsWPSSetting.........6...'...B...4...7...6...3...=...6...2...L.....new.WPSSubscriptionExpiryDate3analyticstelemetry.context.AnalyticsWPSSetting.require...//87D046D26C7DAED16B25681CBE5E60A60A7DDF56F91176923720189008293AF6DA7AFDD1C98C84758AC2BE8E2111149CF7F32E06244607B383081B978BF56970++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):582
                                                                                                                                                                            Entropy (8bit):5.585042877052748
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:67k+e+rvD2xZBzroBWpsvcRu3I4Mv1J0NRu3pKWTdhA2qTC:6hVvD+ZB4BWeZ3NMv1J0NRu3kGqTC
                                                                                                                                                                            MD5:ABB076906A20B54903AB7E03979D0F29
                                                                                                                                                                            SHA1:6E288784662F4CAB02DF225899EF261B89035F0A
                                                                                                                                                                            SHA-256:AAD6C1E611CDFE275D8D708ABBACE0B1F6FEB4F6FA6E509AEFF4B7D6D5C610A8
                                                                                                                                                                            SHA-512:B86497766AA7E4C4EDAABFCCA612DB2C32C19908D0F22467F337F1365F310A2B6059EAB979298F0EF9D332E44B8B169E69D490EA5F33371552DDF2B307D57D6F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...............X...L...6...9.......B...5...5...6.......B...X.......X...'...L...E...R...6.......B...X.......X...'...L...E...R...L....expired.active.ipairs.....trial-expired.paid-expired.....trial-active.paid-active.lower.stringR.......6...9...........B...3...=...2...L.....format_output.new.AnalyticsWPSSetting.........6...'...B...4...7...6...3...=...6...2...L.....new.WPSSubscriptionStatus3analyticstelemetry.context.AnalyticsWPSSetting.require...//3EDABBBFF1370903FE86FBF74ED65B089A8ADCA584AD7ABA40788E4DF778A1DB9BBB5BFEBC323BBED49CFD3C03BBBD003EF9B5A00DCE710E742D4D8BF0CFE72D++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):576
                                                                                                                                                                            Entropy (8bit):5.590487718848391
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6/kx+rvDcoK29ppsvcRu3m4M2YJJJ0NRu3pKcYipivfRCxQQ8Au3:6/kmvDdPpeZ3XM2WJJ0NRu3kcY+YfRCM
                                                                                                                                                                            MD5:42521526124AA6D77D4115EBA907F000
                                                                                                                                                                            SHA1:3BA7CA231758D4174A709250DD6506C257C85CDB
                                                                                                                                                                            SHA-256:4A4B8E1A965CE846A3A9E69F03DF45AC99BE319C1A7612BAD86AB6FB18198399
                                                                                                                                                                            SHA-512:64A644A236232E02DC903293A490E649766C28615FE8A27BE9BD7BBCB2026BA64D7826292D3A226359D97C7F0E7944B99888848DFFFDA3EC2A02B00098B15DF3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...............X...L...6...9.......B...5...5...6.......B...X.......X...'...L...E...R...6.......B...X.......X...'...L...E...R...L....paid.trial.ipairs.....paid-active.paid-expired.....trial-active.trial-expired.lower.stringR.......6...9...........B...3...=...2...L.....format_output.new.AnalyticsWPSSetting.........6...'...B...4...7...6...3...=...6...2...L.....new.WPSSubscriptionType3analyticstelemetry.context.AnalyticsWPSSetting.require...//BDE5DC05FE6A42D5F6E58E62E92580FCC150A2A8517874E86447691279B3B88A7F242E05CEE69EB6C73ACEFFB87B3F0F8F123456A87A8F5655E54E0EDCA5EA79++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1244
                                                                                                                                                                            Entropy (8bit):5.804731252510459
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6x6wckmg85AjHwRf8FlNXqzngq4YlP+rYWbemAENhRVtBmwJMUJmT0LhcYF:Y6wK5AzCU7ZuglvAElVtBmw+UJTLf
                                                                                                                                                                            MD5:75D07C1C909A665D1A5C343A51F969DE
                                                                                                                                                                            SHA1:45F38DCAB0450BD6CB84CDAA0CB9A0AFCB043BFF
                                                                                                                                                                            SHA-256:4A79D42E9FAE445195459A33DD27365EE3A1B282E6C8902EF86B0FD5060439F5
                                                                                                                                                                            SHA-512:AA3012D30C588FFDEF10B9D64E715A9C878DD1B01075AACFDB71690C30380D6A76615D329B2B9F08D51E4A3CF46E4B179B4E0640041B1D5918E83D3ECE75CEBB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........L...........='...-...9...B.......X...9.......X...9.......X...-...9.......9...'...B...L...-...9...9...9...B.......X.......X.......X.......X...9.......X...9.......X...6.......9.......B...........X...-...9.......9...'...B.......-...9.......B.......6.......D......tostring.format_output?MD5 function incorrectly hashed data. Using default value..MD5Hash.utility.MD5.hash_id.UNSPECIFIED.NO_APP.NO_SUITE.get_sub_db_setting>Invalid configuration for the WSSSetting context handler..err.m_logger.property_name.db_name.get_context_config.UNKNOWN........('...-...9...B.......X...'...L...6...9...9...'...'...)...*...B.......9...B.......X...'...L...6.......9...........B.......X.......X...'...X...6.......B.......L......tostring.UNSPECIFIED.GetProperty.subdb.NO_APP.IsValid#SOFTWARE\McAfee\MSC\SubManager.HKLM.Registry.Win32.core.NO_SUITE.is_suite_installed.............6...9...........B...3...=...3...=...3...=...2...L.....get_sub_db_setting..get_context_string..format_output.new.SuiteStatusr.....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):644
                                                                                                                                                                            Entropy (8bit):5.652130140454056
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6Ox2oFtgLNzzPYXxFvO/cQTlr7A01JzKYAGMGuqi:6ZoFeLhzPQxFczTlZ1JmRini
                                                                                                                                                                            MD5:53D0C97359B37EBD03D53099EABA7518
                                                                                                                                                                            SHA1:B0C3CD4892A4414F3D628055EA9CB53101ED8AB3
                                                                                                                                                                            SHA-256:2FE36EB967BA08195BD1CD26194CA3897CB95CACBE5BCFAF619E253B934CD3B6
                                                                                                                                                                            SHA-512:4ED75E085631D7CA1EE647F7D21D7BF0C79BA0CE8F284AEAE11F484323BF9A36A201007D1487257D8DAFBC7930BFD89A9AECBDCF47BC791EA6814616B849EA5F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........#-...9...B.......X...'...L...6...9...9...'...'...)...*...B.......9...B.......X...'...L.......9...'...B.......X.......X...'...L...6.......D......tostring..ReleaseName.QueryValue.no_ver.IsValid.SOFTWARE\McAfee\MSC.HKLM.Registry.Win32.core.no_suite.is_suite_installed...O.......6...9...........B...3...=...2...L.....get_context_string.new.SuiteStatus.........6...'...B...6...'...B...4...7...6...3...=...6...2...L.....new.WSSVersion.mfw.core.Win32Helper+analyticstelemetry.context.SuiteStatus.require...//E1AB425AC221CB94D9BE0A4D5DD6E5564817DC3184E7E5D97497B00335F5E9C95AF28F59D56F465C7D1E20C580344EF0EE8687F7379A9917A5D5417545DC946C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2311
                                                                                                                                                                            Entropy (8bit):5.607016714665769
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:mkeaI12J4DXRBQJwyXJ/eJVMTbzscly3AZEhV6oEkiJAOtX2ihZFZ:m3BdrQtXdeyrscw3FV6oEkyAOtX2sZFZ
                                                                                                                                                                            MD5:D5B01276FA721A4744C79F1D7990B0E0
                                                                                                                                                                            SHA1:F97234C015E996E46B7263F6480AA52A5F25CCA0
                                                                                                                                                                            SHA-256:FCD95A9124D220F8ACCBC16F89128B68459E2F43101F3FD3C524EB476C570698
                                                                                                                                                                            SHA-512:F41FBA96C32246080BE584CC846A49D7AA1061EBB9023E4E1BA18B7A9B501D7F2AD07A0889F4C7915AAB2BD9EF7B7AAA9D6764901A75F44A1C54A11C9AF8A3A4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........'...6.......9...+...'...'...B...........9...'...'...B.......6...9.......'...B...X.......X...+...L...E...R...+...L....([^,]+).gmatch.string.%s+.gsub.analytics_deny_list.GetOption.settings.........M6...9.......9...'...B...6...'...B...6...9.......9...'...B...6...9...B...H.7.-...9.......9...'.......&...B.......X.%.9.......X.".9.......X...6...'...9...&...B.......X...9...-...9.......B...9...B...6.......9...+...9.......B...X...-...9.......9...'...9...&...B...X...-...9.......9...'.......&...B...F...R...K.....4Invalid configuration supplied for the context #Nil handler found for handler .err.SetOption.settings.get_context_string.new analyticstelemetry.context..setting.handler.Processing context .m_logger.contexts.pairsgIn AnalyticsEventHandler's process_context_attributes before for .. pairs(context_config.contexts)6analyticstelemetry.context.analyticscontextconfig.require:In AnalyticsEventHandler's process_context_attributes.info.log.core........-...L.................K...........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):8124
                                                                                                                                                                            Entropy (8bit):5.407648093940651
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:74/aZONpo7az5gqKcgF9D5aVF2Jl+PLIO:74CupGaz5gqKcgfD5aV0Jl+Dz
                                                                                                                                                                            MD5:0434B934FA55C30022B59F58EE0FA261
                                                                                                                                                                            SHA1:D5A6C5F4A0C729EFE9D9812F3FAC4307C751443F
                                                                                                                                                                            SHA-256:789EF271CAD1744AF73D7267B78B957A6FCF354FFC09ED9059C870BA702992B6
                                                                                                                                                                            SHA-512:486C385DAC6402E25E5C78BC635F8EE7064972F06E031185111F14A393C736C41CD21A422D14C74F0D0AC42DBC70FBB1EE916824F3E27AE433C993D309D9E218
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...>.........5...5...5...=...5...=...5...=...5...=...5...=...5...=...5...=...5...=...5...=...5...=...5...=...5...=...5...=...5...=...5...5...=...4...5. .>...=.!.=.".5.#.5.$.=...4...5.%.>...5.&.>...5.'.>...=.!.=.(.5.).5.*.=...4...5.+.>...=.!.=.,.5.-.=...5./.=.0.5.1.=.2.5.3.=.4.5.5.=.6.5.7.5.8.=...4...5.9.>...5.:.>...5.;.>...=.!.=.<.5.=.=.>.5.?.=.@.5.A.5.B.=...4...5.C.>...5.D.>...5.E.>...5.F.>...=.!.=.G.5.H.5.I.=...4...5.J.>...5.K.>...5.L.>...=.!.=.M.5.N.5.O.=...=.P.5.Q.5.R.=...4...5.S.>...=.!.=.T.5.U.=.V.5.W.=.X.5.Y.=.Z.5.[.=.\.5.].=.^.5._.5.`.=...4...5.a.>...=.!.=.b.5.c.5.d.=...4...5.e.>...=.!.=.f.5.g.=.h.5.i.=.j.5.k.=.l.5.m.=.n.5.o.=.p.5.q.=.r.5.s.=.t.5.u.5.v.=.w.5.x.=.y.=.z.5.{.=.|.5.}.=.~.5...=...5...=...5...=...5...=...5...=...5...5...=...4...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...5...>...=.!.=...5...=...5...=...5...=...5...=...=...7...6...L....events_config.events...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):439
                                                                                                                                                                            Entropy (8bit):5.430304555816182
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6IWlL3uknxUyPpPD4M9CCDiEiMJsYJJKq43JCO:6bL3uu3P6M9HDiEvJsP7n
                                                                                                                                                                            MD5:A24DC4B2C5942DDFBC216372AD3005EE
                                                                                                                                                                            SHA1:742ED4AB2A4F4BA5E0D173913131DB32E63B7A01
                                                                                                                                                                            SHA-256:42046CA4BCC5A3C9AE63CB3C0FAED0B285FD2E451313EDD6B54B8D7763BC58FC
                                                                                                                                                                            SHA-512:2FB594DEFD2F4E6BC182CA1EDB743625B4A0DD9F57777F74937A72BFD15A4755E4DFE4B9F6CB314CFDAE4836A3870FF8F9FFD8CE2E8A4D0CD28416CCE7CAA27D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..>.......6...'...D...)handle_on_navigation not implemented.error_.......6...9...............B...3...=...2...L.....handle_on_navigation.new.AnalyticsEventHandler.........6...'...B...4...7...6...3...=...6...2...L.....new.AnalyticsHandleOnNavigate4analyticstelemetry.events.AnalyticsEventHandler.require...//DAE8FB8DBFC7B08C4AA8C548C3A9DE382C3ACD00B3123B98F6787D3A2922AA2039919A250A062B7EA31E7B15728BAB2E825DB50A3B3EAC834C99EF7E5858A0AD++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2050
                                                                                                                                                                            Entropy (8bit):5.674368122563602
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:3K1O3RnzJe0E/+dvxd4xzyA9JG0JbXS9mf+ZS9oFGtQt6MjG+VkJLrTmHC:Vex/0+fRiYd+QFuk1faC
                                                                                                                                                                            MD5:1543285A5B33D0EABD10FC958BDE7136
                                                                                                                                                                            SHA1:F455B99AE46422FF116AE192EB2364491CD7CC35
                                                                                                                                                                            SHA-256:0C8E7B105016154A353432AD17B4D0F97A6AC67B4B10D47D636AD3135D07DA31
                                                                                                                                                                            SHA-512:314F2A4FBF80C2A6CC26802DA05939F8037126F99F43F22152C98BC676493F37281CCD09C7F7088F2AEBC89183AEA08B8395336BA4D70764BEF27EBD64A76F64
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........66...9...8.......X...8...L.......9...'...B.......X.......9...'...B.......X...'.......&...6.......9.......'...B.......X.......X...+...<...L...6...9...)...B...'...6.......B...&...6.......9...)...9...9.......B...+...L....currentline.short_src.Log.utility.tostring%Failed to load package. Error: .getinfo.debug..include.external.mfw..^core%..^mfw%..find.loaded.package......!...6...9.......9...'...B...6...9.......X...6.......X...6.......X...6...9...)...B...'...6.......9...)...9...9.......B...)...L.......X.......X...6...9.......9...'...B...)...L...6...9.......9...'.......&...B...6...9.......)...+...B.......X...6...9.......9...'.......'.......&...B...)...L.......X...9.......X...6...9.......9...'...B...)...L...6...9...9...8.......X...6...9.......9...'...9...&...B...)...L...9.......X...6...9.......9...'...9...&...B...)...L...6...'...9...&...B.......X...6...9.......9...'...9...'...9...&...B...)...L...9...6...9...........B...9...B.......X...6...9.......9...'. .9...&...B...)...L...)...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2153
                                                                                                                                                                            Entropy (8bit):5.703014440133593
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Oe7guhyIJ6flj14j6Q6ARRhQ00MuhXuS5g+i3BJ0sPJQ7:Oe1FqjWbdRRC0ns3di330sPM
                                                                                                                                                                            MD5:056744ECEA4B7360AC01351866B61C3D
                                                                                                                                                                            SHA1:A7950CE3BE6118E33697ED22C95D6DA6C69A0143
                                                                                                                                                                            SHA-256:C89C6258D669F50DB8E95D66EA26DC66A90CFB2464ACD8D77D785A325DA1DED3
                                                                                                                                                                            SHA-512:2592AF53E62D260127EFAB58505DD500D3BFB9C8CF81C2AB244F74A37087119E061B134BC58D230CE3CD526AB8B7041C4BDEEF4D1A88793323A476AD2185FAFF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6.......9...+...'...)...B.......6.......9...+...'.......D....SetOptionInt"*AnalyticsCounterPagesBlocked.GetOption.settings.........%+...6.......9...+...'...+...B...........X...+...L...9.......X...9.......X...6.......9...'...D...X...9.......X...6.......9...'...D...X...+...L...K....msad.ads.blocked.Frame.msad.sites.blocked.PublishMessage.wssEventSender.Top.level.Typosquatting._event_name.*AnalyticsSendWss.GetOption.settings......).|-...9...B.......X...-...9.......9...'...B...+...L...9.......X...-...B.......X...-...9.......9...'...B...-...-...B.......X...-...9.......9...'...B...9.......X.(.'...=...9.......X...'...=...9.......X...'...=...9.......X...'...=...9.......X...'...=...X...'...=...9.......X...'...=...X...9.......X...'...=...X...'...=...X...'...=...'...=...9.......X...'...=...X...'...=...5...9...=...9...=...9...=...9...=. .9...=...9.......X...9...=.!.9...=.".9...=.#.9.%.....X...'.&.=.$.-...9.'.....B...-...9.(.D............transmit_analytics_event.set_analytics_event.de
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2034
                                                                                                                                                                            Entropy (8bit):5.619001010095783
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UsDTHkRkQtT4vdeR6oJdULzkDeJe7gujLMsHiKfJJ5MJ30cbJfF7n:Us/HVQh4vyALzkDme1j/C0JJ5A30cbJZ
                                                                                                                                                                            MD5:1F53FFA42A301E65B399C0021AC9D85F
                                                                                                                                                                            SHA1:A8090738A676C7563964690F4A3A92F66CD42B8C
                                                                                                                                                                            SHA-256:3B22238152C23349CA96AF7105650CB6DEC67C683DF8BF2C26CAC0C5385F61C2
                                                                                                                                                                            SHA-512:FF2995B57460E6F3DD0F3532DB3C808930B09D020A7C3F906B3F629C95FD8B11A10805135A33C9B820F8183CB7E72DF9886CFD64688866F7A7B984639751E8FD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........*6...9.......9...'...B...-...9...B.......X...-...9.......9...'.......'...9...&...B...+...L...9...-...9...........B...9...B.......X...-...9.......9...'.......&...B...L.....'Failed to handle analytics event: .handle_on_navigation.new.handler. Handler: BBrowser Navigate handler does not exist for analytics event: .err.m_logger.get_analytics_eventIIn Analytics BrowserNavigate Handler's process_registration function.info.log.core........06...9.......9...'...B...6.......X...-...9.......X...-...9.......9...'...B...K...6...6...9...B...H...+...9.......X...6...'...9...&...B...........X...9.......X...-...5...=...=...<...F...R...K........config....handler..config..handle_on_navigation.analyticstelemetry.events..require.handler.events.pairseA global analytics configuration mapping analytic events to event handlers has not been defined..err.m_logger.g_analytics_configSIn Analytics BrowserNavigate Handler's build_navigation_registrations function.info.log.core.........6.......9...+...'..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1419
                                                                                                                                                                            Entropy (8bit):5.79482391332802
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6NpCk+enQBwRdS0ZSF2j5G6n8VGLoL9m/eB+kJRiuWeTSKUZSFgT46A3zh6fTZ2m:qCvenawRdS0ZSw1F8VGLZGB+2CKUZSmd
                                                                                                                                                                            MD5:24079788DC3C924FD3BFE6C5724F4E81
                                                                                                                                                                            SHA1:C6AE7F3E466866CA55B4610BBFED214BE1810949
                                                                                                                                                                            SHA-256:0FB28CBFCE9A25007E85E54CD839D6195EFE3FD91D431BA70C53C9B281087186
                                                                                                                                                                            SHA-512:7C27B87E24696E2AF8115DE2B4E0ADF4B13771A534C125A0AABDCCBD56DCF017C9E6A69CDF636B21804EAFBCA47CEBAE19296538632D608BC6D0C4938869C00F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...9...8.......X...8...L.......X...+...6.......9...............B.......X.......X...+...<...L...6.......)...B...K....error.include.external.loaded.package.........6...9.......9...'...B...5...'...6.......B...X...6...6...........B...E...R...K....requireFromLogic.pcall.ipairs.\logic\.....MiscUtils.providers_selector.base_provider.ss_logic.oem_business_logic.type_tag_utils=Inside Analytics's CommonLogicLoader's requireLogicFiles.info.log.core........]6...9.......9...'...B...'...6.......9...B.......&...6...9...'...)...B...6...9...'...B...6...9...9.......'...&.......B...9.......X.5.6...9...:...9...B...).......X.-.U.+.....9...'...'...B...6...9.......9...'...........&...B...6...6...........B.......X...6...9.......9.......B...6...9...9...........B...........X...6...9...:...9...B.......X...X...6...9.......9...'...B...K....loadSSProvidersCode end.FindNextFile.err.requireFromLogic.pcall.Loading script: ...luc.gsub.cFileName.string.handle.*.luc.FindFirstFile.Win32.WIN32_FIND_DATA[1].n
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2671
                                                                                                                                                                            Entropy (8bit):5.863752214121039
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Nv/cUjFEmVSJhJ2TqHsZHNJGoXWpFs9hEi20hjXVFOI0B2gzZ9i5JEpJmhL:Np2h4TqH4zGRpKTbj/Vga/EpK
                                                                                                                                                                            MD5:5C8DF7C70B138ECB45611F1C99CDF879
                                                                                                                                                                            SHA1:0B37D4EA4E269D4959BC81A3115E348A4D5627B5
                                                                                                                                                                            SHA-256:83FF1310D76F529F9BC6512E29F75F27B191026342E0CAAB35656404532F8072
                                                                                                                                                                            SHA-512:0994475671831EF29CBB77A8757E5B8005699C9D94B20616C4C243D3D5365B424EE707316269D6C9645E2A5D9D6D1FB9A07A1FC82DB80F89D784E03B80B9B963
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........d6...9.......9...'...B...-...9...B.......X...9.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...-...9...B...+...)...'.......X...-...9.......X...-...9.......9...'...B...+...L...9.......X...9...9.......X...9.......X...+...9.......X...6...9...B.......6.......9...........'...9...'...6...9...9...B...&.......B.......6.......9...........'...9...'...6...9...9...B...&.......B...+...L......SetOption.lower.string._.GetOption.settings.tonumber.default_no_value.in_context.prefixQAnalytics Daily counters handler called with an invalid event configuration..Analytics_DailyCounters.get_analytics_configBAnalytics Daily Counters handler was passed an invalid event..err.m_logger.triggerType.browser.get_analytics_event;Inside Analytics Daily Counters handle_analytics_event.info.log.core.......%...6...9.......9...'...B...-...9...B...+...)...+...'...5.......X...9.......X...9.......X...9.......X...9...........X...-...9.......X...-...9.......9...'...B...+...L...9.......X...9..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2592
                                                                                                                                                                            Entropy (8bit):5.570588287292458
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:q8RJ0a2Qh6wIHQB9NoCZJdxrLz+vFBLRN9Wh2h9lSeXXfRzjF3JKRjd+PJlOJ6yY:q8/AQh6+LNJZZLz+9dpSe/pjfKPKlO0Z
                                                                                                                                                                            MD5:5BCB480176060509A8F25D89458128DB
                                                                                                                                                                            SHA1:6277D5A16C6BAF28724AF14B30C799E9B8882115
                                                                                                                                                                            SHA-256:91487D6FA7401AAF7D639FE3D19E12C7E82C8E2093BF42E4517CB6056D62CCDF
                                                                                                                                                                            SHA-512:98EF1BDC00E6193E375C9A83CACF10597C19C3F9F82C8E256ADFD1287A845ED03CC967AA8B2BE4084D254CCA30BA86D2637B1EEE3C538B5AB2F73042DA3606D1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........(-...9...B.......X...-...9.......9...'.......'...9...&...B...+...L...5...9...-...9...........B...9.......B...-...<.......X...-...9.......9...'.......&...B...L.......XTelemetry 3.0. Daily Ping's process_registration failed to handle analytics event: .send_on_ping.new....metric_value..extra..handler. Handler: CTelemetry 3.0. Send on ping handler does not exist for event: .err.m_logger.get_analytics_event.........4...6...-...B...H.......X...9.......X...9.......X...9...8.......X...9...9...<...F...R...L......metric_value.ping_metric_id.pairs.........6.......X...6...9.......X...-...9.......X...-...9.......9...'...B...K...6...6...9...B...H...+...9.......X...6...'...9...&...B...........X...9.......X...-...5...=...=...<...F...R...K........config....config..handler..send_on_ping.analyticstelemetry.events..require.handler.pairstTelemetry 3.0. A global analytics configuration mapping analytic events to event handlers has not been defined..err.m_logger.events.g_analytics_config........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1145
                                                                                                                                                                            Entropy (8bit):5.896058509059003
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6UUM9qnTXtfq2BeVhrhjClvVvgP0VvAqScukUJdI3GgVv+vJ/vJ5508Ht+z:TOHEVhMEAAqSDdc3vcJXJAzz
                                                                                                                                                                            MD5:C9C350BDA2597A50FA2AB170BA780E5A
                                                                                                                                                                            SHA1:7DDF190329C5C549B85D8FB961B887B32CBF32F8
                                                                                                                                                                            SHA-256:53BE02E74F7E94C261A4EAE6FCA5D0F42FA33E32CAD5B1E1DF80BA533B9E012C
                                                                                                                                                                            SHA-512:30FB4B8042CF5C14BB1AF8DA2C6F18C75D5A044162778708A9D2FFF8F939B67FDC32FDE768BADE2C234B333653A1A702229963A7E9F22854730C4423E01BDC41
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........?6...9.......9...'...B...-...9...B.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...4...6...-...B...H...6.......9...+...6.......&...)...B...<...6.......9...+...6.......&...)...B...F...R...9...=...6...6...9.......B...A...=...+...L........encode.json_parser.tostring.metric_value.ping_metric_id.SetOptionInt4ANALYTICS_BROWSER_NAVIGATION_COUNT_TODAY_PREFIX.GetOption.settings.pairs\Analytics DailyPingBrowserNavigationCount handler called with an invalid configuration..err.m_logger.ping_label.get_analytics_config:Inside DailyPingBrowserNavigationCount's send on ping.info.log.core.........6...9...............B...'...7...5...3...=...2...L.....send_on_ping.....ch.ff.ed4ANALYTICS_BROWSER_NAVIGATION_COUNT_TODAY_PREFIX+Analytics_BrowserNavigationCountToday_.new.SendOnPing.........6...'...B...6...'...B...5...7...6...3...=...6...2...L.....new$DailyPingBrowserNavigationCount....send_on_ping./analyticstelemetry.events.SettingsDBLookup)analyticstelemetry.events.SendOnPi
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1385
                                                                                                                                                                            Entropy (8bit):5.647811771424218
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6CelnIXFF/xolSVxjGJUkEdWyJYlvV3HVEguLuSE8GJV6vJ/vJ5H6hIm/Fch:70IXn8IGy6eHLucbJXJdy/k
                                                                                                                                                                            MD5:8254A852D48CCB91AEE447BA5358DC05
                                                                                                                                                                            SHA1:AEEE33315A653283EA929F68895580AF1885A47A
                                                                                                                                                                            SHA-256:DB505E7F28335D556C377DD845042C0D40B07538E6038D81C15CE3A8C8547073
                                                                                                                                                                            SHA-512:D561F92E71DEDD99B75B4FE1A0FB6E292C8F0B0A130B6FADDA947650ED246581F428CC5CB1FAFFCE72D25DA71CCC6F6F2FB07518D752F40D9776DA652208E2D8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........'6...9.......9...'...B...6...9.......B.......5...7...6.......9...6...8...B.......X...6...9.......9...'.......&...B...+...L...-...9...+...-.......&...+...D........get_setting$Process is running for browser .IsProcessRunning.utility.browser_processes....ch.chrome.exe.ed.msedge.exe.ff.firefox.exe.lower.string9Inside DailyPingBrowserUsed's get_browser_used_today.info.log.coreD.......6.......9...+...-.......&...+...B...K......SetOption.settings........36...9.......9...'...B...-...9...B.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...4...6...-...B...H...-.......B...<...-.......B...F...R...9...=...6...6...9.......B...A...=...+...L............encode.json_parser.tostring.metric_value.ping_metric_id.pairsNAnalytics DailyPingBrowserUsed handler called with invalid configuration..err.m_logger.ping_label.get_analytics_config/Inside DailyPingBrowserUsed's send on ping.info.log.core.........6...9...............B...'...5...3...3...3...=...2...L.......send_on_ping....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1533
                                                                                                                                                                            Entropy (8bit):5.591046055711385
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6qZ0GoJPeM2Q+ycfXlvVulvDJNn7IBTbWcB5f396BBqmkctcXlvV54SGXjuZwiJn:t0GoJWM2Q+yHJNnWbv96G1kSGa5JjFJ/
                                                                                                                                                                            MD5:5481A7F0DB5E38C2E0B4D487ADA34CFA
                                                                                                                                                                            SHA1:0BC321BD4CC8DC159967B5F522CDAD180EC648EE
                                                                                                                                                                            SHA-256:E30194B320783BEE0646634015D1A944380277765C1FB976374FAA19380C62B3
                                                                                                                                                                            SHA-512:AA4458E7D1A708F985CBB936296C600970F6F29AFECD0D36990B3C1617B25F40CDEDF5E3ED3EC8B34736DF4631FA912E3EC8D2BE4C9E80719F1A85F5B0F50A50
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........C-...9...B...+...)...6...9.......9...'...B.......X...9.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...9.......X...9.......X...+...9.......X...6...9...B.......6.......9.......9.......B.......9.......X...9.......X...9...6.......9.......9.......D......SetOption.max_value.GetOption.settings.tonumber.default_no_value.in_contextSAnalytics DailyPingMetricCounter handler called with an invalid configuration..err.m_logger.setting_name.ping_metric_idAIn Analytics DailyPingMetricCounter's handle_analytics_event.info.log.core.get_analytics_config.........O-...9...B...+...)...+.......X...9.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...9.......X...9.......X...+...9.......X...6...9...B.......9.......X...9.......X...+...6.......9.......9.......B...9.......X...9.......X...9...9...=...=.......X.......X...6.......9.......9.......D...X...+...L...K......SetOption.metric_value.max_value.GetOption.settings.reset_count.tonumber.default_no_value.in_co
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4617
                                                                                                                                                                            Entropy (8bit):5.830734673267187
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:GQEBjpEGPxKTKVUhwq6avqws1aoibd6IKloknBNlMveTGXryHeEnvxJwFvOcgQS6:GQOEGPxKTK6WaNs4Vd5Kl1bEdbREJWlH
                                                                                                                                                                            MD5:5675171C0D8D4695A4E2C75BF56D4487
                                                                                                                                                                            SHA1:CEA4EC1801BA52D8D31EDC3E3CE234CCBE09B169
                                                                                                                                                                            SHA-256:4DD4426315AA9B87979C7A1CC3355159D3A1539DDF65AFB8969BD4B01B4EB680
                                                                                                                                                                            SHA-512:866A19877D5EBEDF6CDF105C2839D3A245C852CDF536176D9DD26B8821D2A718BD4679E88D4B3777963A2DAC510F58EEB629D2CC7F3C0D728401BDF19434B30C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........5...=...=...=...L....hit_label_21.hit_label_20.hit_label_19....hit_label_21.._event_name.wa_domain_membership.hit_label_20..hit_label_19.^.......-...............B...9.......B...9...D......transmit_analytics_event.set_analytics_event........$6.......9...+...-...)...B...6.......9...+...-...)...B.......X...-...9.......9...'...B...+...L.......X...-...9.......9...'...B...+...L...+...L.........EAnalytics DomainMembership ver_to_send < ver_sent so not sendingEAnalytics DomainMembership ver_to_send = ver_sent so not sending.info.m_logger.GetOption.settingsg.......6.......9...+...-...)...B...6.......9...+...-.......B...K........SetOptionInt.GetOption.settings........<4...6...9.......B.......X...-.......9...'...6.......B...&...B...L...6.......B...X.$.6...9...........B.......X...-.......9...'.......'...6.......B...&...B...X...-...8.......X...'...5...=.......X...'...=...=...6...9...........B...E...R...L........insert.table.type.value..name....value..type..name..unknown.: .Error getti
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3032
                                                                                                                                                                            Entropy (8bit):5.870910964820613
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:IWmazRGpYrvwvziT45n1y27j6F01AwQS0ZBdJgGlKqdA/kvUgZDf2jCHJJ1mjA:IU4pWczlN7jUQPQSggkKqdAIZDf2GHJN
                                                                                                                                                                            MD5:2C8911B3980EEF3A29CE473B4CD9217A
                                                                                                                                                                            SHA1:F139C36C58654B67B49CD9207A1899E40ABE0F57
                                                                                                                                                                            SHA-256:E3BC027E22AB082BD1331AF8527DB62369D72D573A7F33A3E0DC1F9B8654CEBD
                                                                                                                                                                            SHA-512:7DD6CF875534AAF205D9BE680734BDD50F4637FC8AE310877FB5730221DD92290359EEE0D1827684078308F6034639D3E7AEA25B1546749617FA27B19BB91E38
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..n.......6.......B...H...6...9.......9...B.......X...9...L...F...R...+...L....domain.urlMatch.match.string.pairs........+...L...........=-...9.......9...'...B...-...9...B.......X...9.......X...9.......X...-...9.......9...'...B...+...L...+...)...-...9...-...B.......X...+...L...6...9...-...'.......'...9...&...B...6.......9...............B.......6.......9...............B...+...L............SetOption.GetOption.settings._.lower.string^Analytics Domain Navigated Counter handler was supplied a malformed event for processing..err.url.browser.get_analytics_eventOEntering Analytics Domain Navigated Counter handler's handle_on_navigation.info.m_logger.........D-...9.......9...'...B...+...)...+...5...).......)...M.4.)...-.......)...M...6...9...-...'...-...8...9...'...8...&...B...6.......9...............B...).......X...5...-...8...9...=...8...=...=...-...9.......B...-...9...B.......X...6.......9...............B...O...O...+...L..........SetOption.transmit_analytics_event.set_analytics_event.hit_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1661
                                                                                                                                                                            Entropy (8bit):5.6353792956433075
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:oeQDKesU4NION1YmRj2AZGrZ+8JHlDiJelgJxV:oeXeN4NpRRjY40dyeSJ
                                                                                                                                                                            MD5:A5EF78E0F756F9435BF466F4699494E2
                                                                                                                                                                            SHA1:222D52D9293B97166D3C30BC96DCCD76389029C4
                                                                                                                                                                            SHA-256:3104A3FCF530FA3503BCF18352E464716C6D461CA8BC44572EA0DBDD9DD34F6D
                                                                                                                                                                            SHA-512:7FD8FD52148917CF69E9E8974F20FF7C3575294B252383EBBD7AD7E0AD8F3C9F20C3913EAF4C1A77F3267EFCD8C28ACDC7E99EDF9FBBF72F0ABC83792E379F8C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..X.......6.......9...+...'...+...D...&*DownloadScanSendProcessTelemetry.GetOption.settingsU.......6.......9...+...'...+...D...#*DownloadScanSendFileTelemetry.GetOption.settings........7'...+...9.......X...9.......X...6.......9...'...B.......X.......L...X.$.9.......X...9.......X...'...6.......9...'...B.......X...6.......9...+.......)...B.......6.......9...+...........B.......X.......L...X...+...L...K....SetOptionInt.GetOption.settings.msad.files.blocked&*AnalyticsCounterDownloadsBlocked.Blocked.msad.files.safe.PublishMessage.wssEventSender.AcceptRisk.interaction_type.DownloadBlock.name..........B-...9...B.......X...-...9.......9...'...B...+...L...-.......B.......X...-...9.......9...'...B...9.......X...-...B.......X...'...=...9.......X...-...B.......X...'...=...4...9...=...9...=...9...=...9...=...9...=...9...=...9...=...9...=...-...9.......B...-...9...D............transmit_analytics_event.set_analytics_event.ui_type.hit_label_24.colour.hit_label_23.hit_label_22.hit_label_21.browser.h
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2427
                                                                                                                                                                            Entropy (8bit):5.734071337426371
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:6/W/iBelQ1lYQ0M7atJAaPpJ5JjWJHZF8ko8jVpPUmQrWDJXRgAn3JusvOi:jlQlAJHJSD8k9jWa1XSg3t
                                                                                                                                                                            MD5:A125C112C55E27E0FDDD2E541480EE53
                                                                                                                                                                            SHA1:5FC3996D4205DD73544E4FE80A1916AB3EC569D8
                                                                                                                                                                            SHA-256:FBD236FAB0A1A641C46DFCE6CB173491474A9CBD3173C77BC33509C115953886
                                                                                                                                                                            SHA-512:DA1F328764D4E4891463960CFDBD8710D01AC6698B43DD4A5D1AC9F1F2BAFAF50A7D25F111351CC47B6893CD554CAF741AFB8F216D28A3ADEAA2CB83CD399A61
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........#...6...9.......9...'...B...-...9...B.......X...9.......X...9.......X...9.......X...9.......X...-...9.......9...'...B...+...L...-...9...B.......X...-...9.......9...'...B...+...L...+...9.......X...9.......X...+...'...9.......X...9...6.......9...+...-...+...B.......X...-...9.......9...'...B...+...L...6.......9.......-.......B.......X.......X...'...X.......'...&...'...9.......X...'...9...'...&...'...9.......X...'...9...'...&...'...9.......X...'...9...'...&...'...9.......X...9.......X...9...'...9.......X...9...'...9.......X...9.......X...'...9...'...&...'.......'.......'.......'.......'.......'.......&.......'. .....'.!.&...6.......9.".....-.......B...+...L..........SetOption.}.{.,"metadata":.,"line_number":.,"error_code":.,"error_type":.,"function_name":."file_name":.metadata.error_code.".null.,.[-HeronErrorsLog heron telemetry disabled..GetOption.settings.default_no_value..in_contextGHeronErrorsLog handler called with an invalid event configuration..get_analytics_configPAnalyt
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1361
                                                                                                                                                                            Entropy (8bit):5.7222381194006
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6iagPrR/Jr3yCJOxTnZBCjsVudecYHfxQ6FF9K6FXyvjocu/yYXl3JB1J5ZzGBeN:hPrP3BsZBCjocBqK3joD/yYXbvJB
                                                                                                                                                                            MD5:9AC09FB2FE4AB5D79A8823E8E56C9BB4
                                                                                                                                                                            SHA1:F800A112729815F419DA876E0E87FC0DB50B0BBE
                                                                                                                                                                            SHA-256:C4A499FEA4EE42E78FFA0996B3DA2D6150023C4BCA326B7A9FE80D3B16906227
                                                                                                                                                                            SHA-512:B11CABF05F7AF0028475EE1BE4DF6597A9644DAA5ABDF0A8150DB8E18F6E224615D675D119E2B2A00B6369939476053978D1AAC8DC49EACE9B2CBB5B408D3356
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........+...L...........V-...9.......9...'...B...6.......9...+...-...)...B...6...-...B...H.B.6.......9...+...-.......&...)...B.......X...-...9.......9...'.......B...X./.6.......9.......B.......X...-...9.......9...'.......B...X. .-...9.......9...'.......'.......&...B...5...=...=...=...-...9.......B...-...9...B.......X...6.......9...+...-.......&.......B...F...R...K............SetOptionInt.transmit_analytics_event.set_analytics_event.hit_label_21.hit_label_20.hit_label_19....hit_label_21.._event_name.wa_installed_extensions.hit_label_20..hit_label_19.. is *extensions json payload for browser: ANil installed extensions payload so not sending for browser .get_extensions_info.browserSettings8Ver_to_send <= ver_sent so not sending for browser .pairs.GetOption.settingsHEntering Analytics InstalledExtensions event handler's send_on_ping.info.m_logger.........6...9...............B...'...'...5...3...=...3...=...2...L.....send_on_ping..handle_telemetry_event....CH...ED..1Analytics_Installed_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3307
                                                                                                                                                                            Entropy (8bit):5.672005510352201
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:p9hLYo14yWoUDkcqroiepVs+5ahLiD70tWQrdkI1:9PTWoUDDXD7Kdl
                                                                                                                                                                            MD5:5A35BF4618BFCEAB37688CB5A8511FA3
                                                                                                                                                                            SHA1:62E09C8AC3C5A9603E0793A444DFE4A19B48B04C
                                                                                                                                                                            SHA-256:539F34F12F104A2B32CE52E9FBB3642BB0CD48E2F5598681EE9287215BD3CD60
                                                                                                                                                                            SHA-512:CCA0106170395258F6B1FAAF23BB2B9D6BE742391CD915124E25391B0E15580C41F4C0623B2C01E928D5FE7DF1D99B69705CAF2A9C1E877E7E2B4F775C3F17CD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........0...6...9.......9...'...B...'...6...6.......9...+...'...)...B...A...6...6.......9...+...'...)...B...A...6...9.......9...'.......'.......'.......&...B.......X...6...9.......9...'...B...K...6.......9...+...'...+...B...6.......9...+...'...+...B.......X...'...X.......X...'...6...9.......9...'...6.......B...'...6.......B...'.......&...B.......X...6.......9...+...'...)...B...6...9.......9...'...6.......B...&...B.......X...6.......9...+...'...)...B...6...9.......9...'...6.......B...&...B...6...6.......9...+...'...)...B...A...6...9.......9...'.......&...B...6...6.......9...+...'...+...B...A.......X...K...6.......B...6...9.......9...'...6.......B...&...B...6...6...9...'. .....B...A...6...9.......9...'.!.....&...B...5.".=.#.=.$.=.%.=.&.=.'.6...9.......9...'.(.B...-...9.).....B...6...9.......9...'.*.B...-...9.+.....B...6...9.......9...'.,.B.......6...9.......9...'.-.....&...B...6.......9...+...'.......B...6...9.......9...'./.B...K.....9send_low_search_user_targetting_telemetry() exitin
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1396
                                                                                                                                                                            Entropy (8bit):5.560263627552033
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6j+e/agXgQCWpI4M6JUhheWdJs1bWWSAJWIKY7jJw8JNHuuZJvJZHrRO2vJsKH4L:u+e/vPNMEUhhfdcb3VA7Y3Jw8JzZJv32
                                                                                                                                                                            MD5:B6555ECDDF3AE6C3F7207673E9DFEC54
                                                                                                                                                                            SHA1:601D2A773577A56E823BF13A2544F27DF122519E
                                                                                                                                                                            SHA-256:25C34EBF0EF869FE78E293563719F2C36C4DD4EB53EB7B2FD954E35D9C491F98
                                                                                                                                                                            SHA-512:26BD9959A208FDC9C8890B6B8FFE87B4CCBD92C9DE2295B4624D34EB437D4C52D2F36BB268FE37F1B7D9DC530B41B1645B984B241CAC220CB7D93FE6B6E46244
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........M6...9.......9...'...B...-...9...B.......X...9.......X...6...9.......9...'...B...+...L...6...9...9...B...7...6.......9...+...-...6...&...+...B.......X...6...9.......9...'...B...+...L...6.......9...+...-...6...&...)...B.......6.......9...+...-...6...&.......B.......X...6...9.......9...'...B...+...L...+...L.........aNavigatedToday Telemetry 3.0 handler unable to increment BrowserNavigationCountToday setting.SetOptionInt.GetOptionXNavigatedToday Telemetry 3.0 handler unable to set BrowserUsedToday setting to true.SetOption.settings.lower.stringXNavigatedToday Telemetry 3.0 handler was supplied a malformed event for processing..err.browser.get_analytics_eventAIn Analytics NavigatedToday Handler's handle_analytics_event.info.log.core..........6...9.......9...'...B...-...9...D......handle_analytics_event?In Analytics NavigatedToday Handler's handle_on_navigation.info.log.core.........6...9...............B...'...'...3...=...3...=...2...L.....handle_on_navigation..handle_analytics
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3033
                                                                                                                                                                            Entropy (8bit):5.6445036663431125
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:REIVPXKEKVUIc7JExkuuajjtBjqb87lzXdM2LCkPTbxY4eSZrlMWuar7uLnU/XaM:REGPXKEKVUN8uoBjk8XMCCovbeK5MxnE
                                                                                                                                                                            MD5:CB3840772AA5D70D563B31E6E6D5BED4
                                                                                                                                                                            SHA1:FBC3D845B022E0A3E38DC01E832D11A2F813778B
                                                                                                                                                                            SHA-256:148F560CDC77D62088B201D549C866D488E6D7EBB0547CE1E7F4B46B777B5A13
                                                                                                                                                                            SHA-512:B8764F8C09DF899665060CA268BF630A00854F0A484D543FDC99AD7C0E36D4CFE1C48D178AFE0C5A851895396AD6050842274304CA2621A1D07B08420B109349
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........$6.......9...+...-...)...B...6.......9...+...-...)...B.......X...-...9.......9...'...B...+...L.......X...-...9.......9...'...B...+...L...+...L.........EAnalytics PushNotification ver_to_send < ver_sent so not sendingEAnalytics PushNotification ver_to_send = ver_sent so not sending.info.m_logger.GetOption.settingsg.......6.......9...+...-...)...B...6.......9...+...-.......B...K........SetOptionInt.GetOption.settings.........'...6.......B...X.......'...6.......B...'...&...E...R.......X.......9...)...)...B...........'...&...L....].sub.",.tostring.".ipairs.[........()...4...6.......B...X.......9...'...B.......9.......B.......9...'...B.......9...).......B...........X...6...9...........B.......E...R...-.......B...........J......insert.table..:.sub.//.find.ipairs..........5...=...=...=...L....hit_metric_0.hit_label_21.hit_label_19...._event_name.wa_push_notifications.hit_metric_0..hit_label_21..hit_label_20.ch.hit_label_19.^.......-...............B...9.......B...9...D......transm
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1355
                                                                                                                                                                            Entropy (8bit):5.59101889177688
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6JO8dwKfhwo8uuGEE0eVEKvRRMjjgOvEW4d5Z+S69gxuuHJjMfJsPHUxn:ADDfhCuDEE0eHRMjjTu+gx9HJQfJ5xn
                                                                                                                                                                            MD5:DB20AA1CD1B6E51D8D5BE03DE5C8BF87
                                                                                                                                                                            SHA1:F041DE9EA9B6ADEC749448232A3B8C84EF1BC3FD
                                                                                                                                                                            SHA-256:66BDADE4994B6045BED335BE31A7F9AB0B4FDB2F01818C95D624F97B00D58503
                                                                                                                                                                            SHA-512:1E67BB6971A4FFB120ACEA3DCF58FDC12F7EDC6913591D5EF5751945B02B9CE2CBCDF5FD98CBD92D4C09B35173B690E35B3D1A216388E620363A3DFB7EE4F98E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ............-...9...B...-...9.......X...-...9.......).......X...6...9.......9...'...B...+...L...9.......X...9...=...4...-...9.......X...-...9.......X...9...=...9...=...9...=...-...9...........X...9.......X...-...9...:...=...X...-...9...:...=...-...9.......X.:.)...-...9.......)...M.4.-...9...8...........X...6...9.......9...'...B...+...L...-...9...8...:...8.......X...-...9.......X...-...9...8...:...'...<...X...6...9.......9...'...B...+...L...X...-...9...8...:...-...9...8...:...8...<...O...-...9.......X...-...9...=...-...9.......B...-...9...D........transmit_analytics_event.set_analytics_event.hit_screen8Malformed event passed into RemapAttributes handler.default.set_default_for_not_mappedNRemapping part of config passed into RemapAttributes handler is malformed.remapping._event_name.Impression.browser.hit_label_20.hit_label_19.name.hit_label_18.as_is.interaction_type.action_type9Malformed config passed into RemapAttributes handler.err.log.core.event_names.get_analytics_event..a.......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3387
                                                                                                                                                                            Entropy (8bit):5.518921565811051
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:+cEGPlKkKVUr0/VjzpzRILXFfj2NIWjRN5RlDk9w03ngpYjRI26VNPNBYwixtPmn:PEGPlKkK6gRzpzu05Pu91nY7HWU
                                                                                                                                                                            MD5:8E6128F8F2A9F879C6306590A8D5177B
                                                                                                                                                                            SHA1:146103A6B4E2B54A4814780DDA0FC58082A443EE
                                                                                                                                                                            SHA-256:EE3DEE8BC57ADDE2453A4C96278587CBD80129DAE0EC3B17E6F6BDC8EBB64C22
                                                                                                                                                                            SHA-512:8C6B4F52A7C57B3E35E9C220768962EEFABD791B601CCBD25D836EE3D0C3F599B048069DE64BBBC0CA26F24B6BFAA4D41736074C40633B6F1BDB207A12726C3D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...9...6...9...'...B...A...6.......9...+...-...)...B...).......X...)...L...!...L......GetOption.settings.!*t.date.time.os........$6.......9...+...-...)...B...6.......9...+...-...)...B.......X...-...9.......9...'...B...+...L.......X...-...9.......9...'...B...+...L...+...L.........<Running processes ver_to_send < ver_sent so not sending<Running procceses ver_to_send = ver_sent so not sending.info.m_logger.GetOption.settingsg.......6.......9...+...-...)...B...6.......9...+...-.......B...K........SetOptionInt.GetOption.settings..........-...9.......9...'...B...6.......9...+...-...+...B.......X...+...L...-...9...B.......-...9.......X...6...9...6...9...'...B...A...6.......9...+...-.......B...6.......9...+...-...)...B...+...L...6.......9...+...-...)...B...-...9.......9...'.......&...B...-...9.......9...'...-...9...&...B.......X.O.-...9.......X...-...9.......X...-...9.......X.C.-...B...).......X...-...9.......9...'...B...+...L...'...-...B.......X...6.......9...B...........X...-.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1653
                                                                                                                                                                            Entropy (8bit):5.796504876010033
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:JDSzV16a2/zAij2Hacz8SDAJJEyJ/QQN4:JuzV1BMrj2/8W0JEySY4
                                                                                                                                                                            MD5:71FFCE9BE0676300990DB112319B18EA
                                                                                                                                                                            SHA1:4A7B0BC0A058D21AD3DF2719D0A3B41B1D027C99
                                                                                                                                                                            SHA-256:0861A21D2679E49EF9E1202C6F90E29FA73AD66518CEAE8943F95707F718BFF5
                                                                                                                                                                            SHA-512:3499CB79844B6D341397CE896119FD7A418324D45AA4E6E171E2B07C8AAB064DBA496A9403621AE15336DBC3D4A6679EF9733A16B24B78411DEEE4D438846B76
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........A-...9.......9...'...B...-...9...B.......X...9.......X...9.......X...9.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...+...)...6...9...-...'...9...'...9...'...9...&...B...6.......9...............B.......6.......9...............B...+...L........SetOption.GetOption.settings._.lower.stringHAnalytics SearchSuggest Counter handler was passed an invalid event.err.search_type.interaction_type.browser.name.get_analytics_eventDEntering Analytics SearchSuggest Counter Handle Telemetry Event.info.m_logger.........J-...9.......9...'...B...+...)...+...5...5...5...).......)...M.8.).......)...M.3.).......)...M...6...9...-...'...8...'...8...'...8...&...B...6.......9...............B...).......X...5...8...=...8...=...8...=...=...-...9.......B...-...9...B.......X...6.......9...............B...O...O...O...+...L........SetOption.transmit_analytics_event.set_analytics_event.hit_metric_0.hit_label_21.hit_label_20.hit_label_19...._event_name.wa_search_suggest.hit_metric_0..h
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5468
                                                                                                                                                                            Entropy (8bit):5.684573016098276
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:vEc6Kr6/joo1pKtk8LhEPeL4wM9IKV1BkU+DdZdggkqJtzLULlPT:vBZr6cq8txNMKKrOU+RZdjJBLMZ
                                                                                                                                                                            MD5:3778F3C22BF093A34BB5692A9B4DA2C6
                                                                                                                                                                            SHA1:97D933306ADDD6D6359EC3753721ECCFD9CCE583
                                                                                                                                                                            SHA-256:B724C5CD2F574A01A88ED238DDDE988A440AD027F9190ADDDF345AF8D188CA93
                                                                                                                                                                            SHA-512:F095FDC6F063824231C2380DF76E0B7788F18D30B638383097F0E193F90C110B5AD7850E0816FEB285A527AB9C00445D27D559EC205A2DD9324FE9BC82A69409
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..8.......6...9...6.......)...B...C....tonumber.char.string+...........9...'...-...D......%%(%x%x).gsubc.......6.......B...H...6...9.......9...B.......X...L...F...R...+...L....urlMatch.match.string.pairs........06...9...........B...7...7...6...9.......6.......B...6...9.......'...B...7...7...6.......X...6...9.......)...6.......B.......-.......B.......6...9.......'...'...B.......6...9.......B.......L......lower. .+.gsub.first2.last2.&.sub.first.last.find.string.2.......-.......-...8...9...D........firstIndicator........F'...6.......B...X.>.+...6...9...B...X...+...6.......B...X...6...9.......'.......'...&...B.......X...+...X...+...X...E...R.......X...+...X...E...R.......X...6...9...B...X...6...9.......'.......'...&...B.......X...+...X...E...R.......X.......X...9...X...9...'.......&...E...R...L.... .category.exclusion.%f[^%w_].%f[%w_].match.string.inclusion.ipairs.........+...L.............-...9.......9...'...B...-...9...B.......X...9.......X...9.......X...-...9.......X...-...9.......9.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):8197
                                                                                                                                                                            Entropy (8bit):5.709606313879427
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:UD2A/mLB7AVWy/c9AbQLW/rNwGYF3B6YfX:gPAUVWyc9AbBeGYtfX
                                                                                                                                                                            MD5:3F35B8392D1798597572ACDDEE5C3120
                                                                                                                                                                            SHA1:F5DB76148679A62E1615EF8BFFA87109841A9E80
                                                                                                                                                                            SHA-256:165B85E77E30395DD43C0B979A82E895BA0522F133538DAC1AE02D4224959D10
                                                                                                                                                                            SHA-512:17431A9A7A00D35DFC00F7F191FD313A04F4C50A6EAFD4EF8471EDA7F41DADEA30B467A16069AA7C7F06DE04CB01260A2EE370BECBE3A559A1C9641F9AA871DB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...6.......9...+.......)...B...A...6...9.......9.......'...6.......B...&...B.......6.......9...+...........B...K....SetOption.tostring. - count: .info.log.core.GetOption.settings.tonumber.........$6...9.......9...'.......&...B...9...9... ...).......X...U...........X...6...9.......9...'.......'.......'...9...&...B...5...=...=...9...=...L.......month..year..day..day., day: ., month: /Secure search hit add_month result, year: .month.year-Secure search hit add_month, num_month: .info.log.core..........!6...9.......9...'...B...6...9.......B...6...9.......B...6...9...........B...6...9.......9...'.......'.......'.......&...B.......L...., difference:., target_time: /Secure search hit days_until, start_time: .difftime.time.os!Secure search hit days_until.info.log.core...........~6...6.......9...+...'...)...B...A...6...9.......9...'...B.......X.f.6...9...'.......B...-.......)...B...-.......)...B...6...9...-...........B...A...6...9...-...........B...A...6...9.......9...'...B...6...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2753
                                                                                                                                                                            Entropy (8bit):5.78394166018439
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:5sSiaIqULiwOSJJWkGqCq+RkvjjQH7UjULso2X16RYDQJ8v029vJPbtD:5sRaIqx9gJWkGqH+Qjc3L6IYDk8v029n
                                                                                                                                                                            MD5:8237CA728FE9B37944D872D8AA34D726
                                                                                                                                                                            SHA1:1CA63A24AFBB2BE70766D915EC34163C63E53155
                                                                                                                                                                            SHA-256:1C2A9D2D80B9A406F7956F778CF70102AB4DD4CF4F688F93D366F1C6C6A8C02A
                                                                                                                                                                            SHA-512:76E339E13FFB4DC10702B25D2F715AEFFC749F0D24FB0AECF2DFA56DDA45C03E771BD55E67C1608E9442CF79ED2862BAD6D0F9BDF968FEC2D46A23118D4888A2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........@...-...9...B.......X...9.......X...9.......X...9.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...'...'...9.......X...9.......X...9...9.......X...9.......X...9...9.......X...6.......9...+...-...9...&...9...B...X...9.......X...9.......X...9.......X...6.......9...+...-...9...&...'...B...=...6...9...B...-...9.......9...'...6.......B...&...B...6.......9...+...'...+...B.......X.A.6.......9...+...'...)...B...)...'.......X.#.6...9...!.......B...6.......9...+...'...)...B...-...9.......9...'...6.......B...'. .6.......B...&...B.......X...-...9.......9...'.!.B...'.".....X...'.#.....&...X.......'.$.'.#.....&...-...9.......9...'.%.....&...B...'...9.......X...6.......9...+...'.&.)...B.......X...6...9...!...B...).......X...6.......B.......6.......9...+...'.&.)...B...X...6.......9...+...'.&.....B...5.(.9.'.=.'.9...=.).9...=.*.9...=.+.9...=.,.=.-.9.......X...6.......B...=...6.......B...=./.-...9.0.....B...-...9.1.B...'...9.....2.X...'.3.X...9.......X...'.......X...6.4.9
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):571
                                                                                                                                                                            Entropy (8bit):5.368387435739017
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6t5LzIKSSj3d2k0uknxFJ+PF4MVIRMJsYJJKHLrdas5MHS:6t5Pj3MbuuHJjMVtJsPHLxas5eS
                                                                                                                                                                            MD5:C79B4D9ABAB7F9088963396633373130
                                                                                                                                                                            SHA1:138EDF86F524355BD7E037FC1E21DCB1D6AC077B
                                                                                                                                                                            SHA-256:31C8327F3757FE4A889D6BFC13E8B778A9CD09119FED103F8B60DDB10B7270E2
                                                                                                                                                                            SHA-512:E762F3A14D737C26B94524120F0BD65613DD1BAB3E1877F588B9579C2A67CFDDEF973A4D50A78BF886ADB67398F1974A20B77310EFEBA690F3B06AD55384595E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........-...9...B...9.......X...+...=...9.......X...+...=...9.......X...+...=...-...9.......B...-...9...D......transmit_analytics_event.set_analytics_event.flags.timeout.analyticsSDK.get_analytics_eventa.......6...9...............B...3...=...2...L.....handle_analytics_event.new.AnalyticsEventHandler.........6...'...B...4...7...6...3...=...6...2...L.....new.SendImmediately4analyticstelemetry.events.AnalyticsEventHandler.require...//5AF2B3F30CA2477B8884BB0D801B1721C9FC6976C639E9179DE8ECBB599B8CA365CD6F815DF94702B8EF29344880D003B55FE2897CE4189C2F8870D5FFB199E9++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):407
                                                                                                                                                                            Entropy (8bit):5.443442104534436
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6AWHuknxcW7NPl4MXFQMJsYJJKV7gehAoiljaDq:6FuuOMXFZJsPtBOoU0q
                                                                                                                                                                            MD5:E8DF367056FE2ABFE9304728B0181C4E
                                                                                                                                                                            SHA1:7D1D9096FD18F373FF19DDB5406C8D4176A50461
                                                                                                                                                                            SHA-256:DFC8D29D6C889BC0A5700446E389197DE191EF1B5CFDBA64CF2167E8334C3FEE
                                                                                                                                                                            SHA-512:23D4D5C28F8B2D3F3242BE50DE34B8E54FCDADB78D2DF8E20D0FE26ACCE27506CF9E364434EA614F5B7B80C215DC6B98101C5EC2A94003DC93B0A30C33CAA2D0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..6.......6...'...D...!send_on_ping not implemented.errorW.......6...9...............B...3...=...2...L.....send_on_ping.new.AnalyticsEventHandler{.......6...'...B...4...7...6...3...=...6...2...L.....new.SendOnPing4analyticstelemetry.events.AnalyticsEventHandler.require...//21398B440EA28FAF8D99DD7EA2BD636471BA9D882AE2E076332081F8193BDFD81EC66AC532DD528EEA1411464872F558A57639C30F53475D3F51EA51B5001805++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):405
                                                                                                                                                                            Entropy (8bit):5.508156056649387
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:67klvhpCl2IWm7RYvfOH6eaA0lbDPeX3t7/:6EeJViWH6blbLq
                                                                                                                                                                            MD5:A288B56AD5CE337137C0A3B8F600F5C3
                                                                                                                                                                            SHA1:B9D7D321EA5B63355C10BEC920E4231F35E70490
                                                                                                                                                                            SHA-256:87B778D9AEE383BBF5D607B9F6FBFD6788C48E87BD673B0F4F3EA682A9DDB1E8
                                                                                                                                                                            SHA-512:955FFEC02DDB6E6C9998B570031FE8169657D1C8454AD0FB6A17B9DA6C0051DAD058C6B7C800F307C74BE613979317CE320B85EA6A4CC9A265140230B147AA3B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........'.......X.......X.......X...6...9.......9...'...B...X...6.......9...............B...........X...'...6.......D....tostring.GetOption.settingsAInvalid parameters supplied for get_setting helper function..err.log.core.(.......4...3...=...2...L.....get_setting...//2F60F4770EC82BE45FE951736A149B465D3E892E3CA2FFC2A21C625294129A5F4E4AEF90C0A32469DA9727A56B1BA8853AE964C8267917CB5AA0FF71CBC4BC88++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1675
                                                                                                                                                                            Entropy (8bit):5.812628804473798
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CiDSFhorowIgf3Nah9LbjM1qj+IQdXoiz8SDAJJKrkJcOahg:PujxRgfE7bjM1qjYdXz8W0JKYSXg
                                                                                                                                                                            MD5:F1530A4A72D6FC8A138963122A592426
                                                                                                                                                                            SHA1:28012084AD424E7E45498BD34B46DC6C4894CB85
                                                                                                                                                                            SHA-256:2C5CAA83B99DFF814D665F8615F9CC6F6C0C4E91A9DD9BE54032B49305C0B591
                                                                                                                                                                            SHA-512:CDFA76E2B91E3B753E6529D2624917B213459A6143985D8DC7733C0AD074BC145E886631F3CA1A7A5E44E3726F9C736FCEE907EFB2CF2A68C6848579CF552EE5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........C-...9.......9...'...B...-...9...B.......X...9.......X...9.......X...9.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...+...)...'...6...9...-...'.......'...9...'...9...&...B...6.......9...............B...9... ...6.......9...............B...+...L........SetOption.GetOption.settings._.lower.string.defaultFAnalytics SMA Reputation Counter handler passed an invalid event..err.count.color.site.browser.get_analytics_eventEEntering Analytics SMA Reputation Counter Handle Telemetry Event.info.m_logger........Q-...9.......9...'...B...+...)...+...5...5...5...5...).......)...M.>.).......)...M.9.5...8...=...8.......9...B...=...+...).......)...M.".6...9...-...'...8...'...8...'...8...&...B...6.......9...............B...8...<...).......X...+.......X...6.......9...............B...O...-...9.......B.......X...-...9...B...O...O...+...L........transmit_analytics_event.set_analytics_event.SetOption.GetOption.settings._.lower.string.hit_label_20.upper.hit_label_19...._event
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2284
                                                                                                                                                                            Entropy (8bit):5.688225802861164
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:QZmvjPkSALczlpJbZ1ef/czmg2bRTHZ1IJWvD8PJD99nJlQXB:QZmvAZoJ7bmg2bRTPsWvDo59ne
                                                                                                                                                                            MD5:C29B48B46920AB4EAD3A21EEB77D1A00
                                                                                                                                                                            SHA1:7F075528E4F14A5AB87D4EA8034307CD978B3876
                                                                                                                                                                            SHA-256:E4C90BDFFA953F6D93BDCE6DCCD1E960F369C5FE514CCEB4263D31E6BB690B5E
                                                                                                                                                                            SHA-512:3DBEE74CE0A17FA8AF1A10C158321000AF1D4AC31609A695970CCD0F0B2A5A30D981C85EEA3FEDE58134C8276B0591394CCFC9DBD0E374364961B38CB1B8F5F1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..#.......-.......'.......&...L......_w.......-...........B...6.......9...+.......)...B.......6.......9...+...........B...K......SetOption.GetOption.settings.>.......6.......B...X.......X...+...L...E...R...+...L....ipairs........i6...9.......9...'...B...-...9...B.......X...9.......X...9.......X...-...9.......X...-...9.......9...'...B...+...L...5...-...=...6...9...B...X...4...<...6...-...B...X...-...........B...6.......9...+.......)...B...8...<...6.......9...+.......)...B...E...R...E...R...4...=...6...-...B...X...6.......9...+...-.......&...'...B...9...<...6.......9...+...-.......&...'...B...E...R...9...=...6...6...9.......B...A...=...+...L..............encode.json_parser.tostring.metric_value.ping_metric_id.None.Last_Failure.SetOption.GetOption.settings.ipairs.Schema_Version....Schema_Version.IAnalytics ToastCheck send on ping called with invalid configuration..err.m_logger.triggers.ping_label.get_analytics_config0Inside Analytics ToastCheck's send on ping'.info.log.core........U6..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):767
                                                                                                                                                                            Entropy (8bit):5.4781836322079815
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6kQ5GlsglzZ7GlsggGlN6W0oHQp3JhEJ9AnuyzRu+nGpIjbDckndhhlSJg0qNPPO:6N5VglN7VggGl1QTSJ9AnuZ+nzDcunhc
                                                                                                                                                                            MD5:813010E03F53082949F857AB3AD34D0C
                                                                                                                                                                            SHA1:2C0AEB8AD7C01A7B0C4CCC7E6E8889CCD1AA72DD
                                                                                                                                                                            SHA-256:C5AF7F0E7FCC80D0A2F47DED1F8665F7AC0969E9F722B8AD89013F90B36FB33F
                                                                                                                                                                            SHA-512:08A435E9ED068E072D689955CCDE370D6690D15EBC3A03EEDC9E1093C8079943F9A20B2A05068E4BEBB8CDF8E669CDBC173D5D188F3B91C72911817D31A94207
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........#-...9...B.......-.......X...-...9.......9...'...B...+...L...-...-...9...8.......X...-...9.......9...'...B...+...L...6.......9...-...9...D..........PublishMessage.wssEventSender>Invalid message passed to WSS Analytics analytics handler.messageQEmpty analytics telemetry information returned when processing WSS Analytics.err.m_logger.get_analytics_event.........6...9...............B...5...3...=...2...L.....handle_analytics_event....msad.files.safe..msad.sites.safe..new.AnalyticsEventHandler}.......6...'...B...4...7...6...3...=...6...2...L.....new.WSSAnalytics4analyticstelemetry.events.AnalyticsEventHandler.require...//CAB46F8B4979A9367CD8CC9D65DE914508BF352E34B41B25FF46C215AEE55DE9481C9C8B7B95518D8C91B46ECB0154E69B12E21F660EA42EC64BF3F864536427++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):616
                                                                                                                                                                            Entropy (8bit):5.509919989918288
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6Tkq5GlsgyP26WfEFyi9AnuyzRu+nGpIjbk0uknxFJ+PF4MaoMJsYJJK9M64UcV3:6X5VgyP2cyi9AnuZ+nzbuuHJjMaRJsPI
                                                                                                                                                                            MD5:33255E585532FAD946CFA0C6C30D1805
                                                                                                                                                                            SHA1:FA0C203AAA2D0CFE0E241081FE116BD8706540B9
                                                                                                                                                                            SHA-256:7A1C49F3197F47A2DFA2B9A612C238CD248B3C4F60C8A83217ACEEB13759D32C
                                                                                                                                                                            SHA-512:D45E3C14E15758679313407C1A2F7AC16C5CC9BA6A391109E0959D216061C35FD67F0CFA3AD0EF9DE2001E664EE89A4C8E4FEA9DD5CB348E149DDBA4E45B5783
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........-...9...B.......-.......X...-...9.......9...'...B...+...L...6.......9...-...9...D........message.PublishMessageRaw.wssEventSenderQEmpty analytics telemetry information returned when processing WSS Analytics.err.m_logger.get_analytics_eventa.......6...9...............B...3...=...2...L.....handle_analytics_event.new.AnalyticsEventHandler.........6...'...B...4...7...6...3...=...6...2...L.....new.WSSAnalyticsRaw4analyticstelemetry.events.AnalyticsEventHandler.require...//4C5EF8E50932A718928AC60DE5F3A3091AA4F2F5662105885F24C1C87AC0E7C510992B1F2E63BE4D10838A77FB022A976EA602993EE8EA650CFBAE6F4D302649++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3931160
                                                                                                                                                                            Entropy (8bit):6.517200498178353
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:viT3zh7BuogehP0Dm+ItKnrLCzWUNCY1x9CH1S5j8QaAqZHLzee6dy:yuogeRd/S+jRaA6Gy
                                                                                                                                                                            MD5:CA79242AD42B4477057E398550249B54
                                                                                                                                                                            SHA1:6145A551BFE7014EE23AB9AEAB4CAFE177B315CF
                                                                                                                                                                            SHA-256:146BC884337E506A0473149D28F84528301759FF31086A033865EFB1E44B2720
                                                                                                                                                                            SHA-512:29BAEE39940B7688C40E57587F77E4490A364970C8E6CA2DE55709DE19352F2B3E5D91A8B3E3188C1B4953EB471817716F6B359B0F1A6D04DFFF2E59C9869C42
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$......./..Pkd..kd..kd.. ....d......yd......ad.......d.. ...fd.. ...vd..q...jd......yd......jd.. ...xd.......d..kd...e......:d..q....d..q.#.jd..q...jd..Richkd..................PE..d...'YWg.........."....$..,..........P%........@..............................>......S<...`..................................................*7.......=......0;. )...L;.......=..t...N4.p....................O4.(....g1.@............ ,.X...8$7......................text.....,.......,................. ..`.rdata...*... ,..,....,.............@..@.data...$....P7..h...<7.............@....pdata.. )...0;..*....8.............@..@.didat.......`=.......:.............@..._RDATA..\....p=.......:.............@..@.rsrc.........=.......:.............@..@.reloc...t....=..v....:.............@..B........................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5985656
                                                                                                                                                                            Entropy (8bit):7.997073443075553
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:98304:T+PQByUNM+wti12AJyTJs6mEzHohlciWocwyJ6TW9TFIfvxzNfuTeaFfPzemlu:i4ByU6+JyTKbEDoXciWoSdF+vhNf4TeV
                                                                                                                                                                            MD5:EFADC0D22983A99516DDBFBA3FD6F1A5
                                                                                                                                                                            SHA1:A64D75E07B8535FC7F71F33684CEB852E6784FA9
                                                                                                                                                                            SHA-256:B4F29215D91B81325283EA358CB73753D53392874637C501F3009F0718091461
                                                                                                                                                                            SHA-512:479F98D3D2C868F7189F09669A92F941979679F60525229F917F8B351BFCDEC8873E8D69D3153515F660A80D666E5F4A0DF8CC00F59EC1B423AE1DFD48C8B6E8
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:PK............................app_launcher.js|Uak....._1..?.,r\...x.4.B.>..O.R......2;.+\.........Z.v.sfV^..... ...ww......Ow.........>.....{..-C^......<.7......#...!..j.:...G...`..........h....k.s.B...@q..@...HV...M.a'..~."E,'.N].."%.9[.O.R.O.....h@.j...,o',.9...../.^bLR.0i3.'.....)D........=K..M.V...B.;1.#`.Ta......3;;va...Hq..N...E..<.d.O%<...XX.2..`....FI.+W.H.t...`l3Fc.v6me.E....!1.5...O.e..c..]w.L.M........N.c.B.U...6.`..H...H.<D..&.S...1L."t. ..Q3zVg..k..A.-.X.....i'h.Y$..p:l..i/=. Y.i$B.]....Is&U.......H...I.....J.l....Q`.x.Gh......H.l..n|.!<u.....5...]b..T....F..W....u.7'......|-<s,.....p}.....&.?...;. ....@..%%T...v.[.jz........Tk..p.UA..T.P.jvu..T..**....:SU.|..2....../..4.X...\....w-.^;\...y.bPTR.Rz&.K..f...C._.v..|~....0Y.y...W......u......fC.~..}..i.vL.]...+.cS.s..s.(.P...Cxm..?.4.c..:j..\>..9Iz.\-...}.\!pT.,...W..Fw..K..*p(..P.}9..E.(..Hf..*M.UP'.\.OC._.rm..y.P.....~.....;.8....a...O.,.Xe:S\(.r.%..."y...Ynu...G...@..#VY.(.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):358
                                                                                                                                                                            Entropy (8bit):4.783729084285157
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:3FF2b4FPeee/KabRVdUvFFyFlLulkNCZDZKMjeQoFeNCBHu4H4WsNCHERN2l7Y:1YJKadislLAj+9QoFdBOKjkRN2l7Y
                                                                                                                                                                            MD5:4BCE68B8CBF044EB70958BC6018D0F01
                                                                                                                                                                            SHA1:46B4482884D6062CF15E618B8035BD1E675A3EA9
                                                                                                                                                                            SHA-256:FE5A9A409388CD8E5D6AF76E3FC8E8708F697F2577886BC3B826B4D591CB4306
                                                                                                                                                                            SHA-512:0F3E86AEB29E202E2E36E4E1859AFED3F17CE65246E90291CA8413287B94798A42309EB27E5CFB67A0B48A8C6D14174FBFC3F36EBE25B7BD8D7800BB78671047
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "name": "siteadvisor.mcafee.chrome.extension",.. "description": "webadvisor",.. "path": ".\\BrowserHost.exe",.. "type": "stdio",.. "allowed_origins": [.. "chrome-extension://fdhgeoginicibhagdmblfikbgbkahibd/",.. "chrome-extension://dbghilognjpbmkdcpjgodiieiflmlaeb/",.. "chrome-extension://iiloambhgijcaodolaknfhmcficdnaca/".. ]..}
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):357
                                                                                                                                                                            Entropy (8bit):4.7907114893123115
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:3FF2Eas4FPeee/KabRVdUvFFyFlLulkNCZDZKMjeQoFeNCBHu4H4WsNCHERN2l7Y:17aWJKadislLAj+9QoFdBOKjkRN2l7Y
                                                                                                                                                                            MD5:BEEC1609B6AA63B29247C7C4805CBF32
                                                                                                                                                                            SHA1:A9AF06A9D648857FDFBB8BD0D1B6A49840FF0232
                                                                                                                                                                            SHA-256:BFFE531435235BF8801946B9BC8654A79727FD6D591DBB7BE173BE9A55FC6974
                                                                                                                                                                            SHA-512:36BBB47F67D2B112AF77759E637318CD79560156B3B5A1007FEE0CB0A9FDE3E26C99D980D2160DF0A730304A43D3D16D2F28742E44A5303B81C0FEAE78A176FA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "name": "webadvisor.mcafee.chrome.extension",.. "description": "webadvisor",.. "path": ".\\BrowserHost.exe",.. "type": "stdio",.. "allowed_origins": [.. "chrome-extension://fdhgeoginicibhagdmblfikbgbkahibd/",.. "chrome-extension://dbghilognjpbmkdcpjgodiieiflmlaeb/",.. "chrome-extension://iiloambhgijcaodolaknfhmcficdnaca/".. ]..}
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.478002392539657
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLPbKq8GLfrCt:7rrSOX8BC0Bj5dXEC0BjyKS0b/8oCt
                                                                                                                                                                            MD5:3410423B9D7B023BA74C63F07F99235D
                                                                                                                                                                            SHA1:5109BA37F63F1FF50C07F925FBB4F81B4D304A10
                                                                                                                                                                            SHA-256:BECD6B3499F92B282494A55D59C826E2CC293119D04164E7FF586AF13E436D8E
                                                                                                                                                                            SHA-512:2D7858B7E603666FBC6BBE29E36E62EB8DDDF4308F5D0AFADBFC3631D5A5C916F79FD15818226F4382548C6B97EE4C82E9D429E3F3CE0B3C07AEC274AA7189B1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//170C272373DD9D70DD07D3078B003D50C1703FC86F85DAA23AD470B978AF27482F6639AD74CEFC108CAD71CF5282E7443B9659D3F66218FECB7BF63D25FDA524++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.45820186251319
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLRinpsFkS6dxq:7rrSOX8BC0Bj5dXEC0BjyKSoFkvq
                                                                                                                                                                            MD5:2CE0087562892070D641D509DB32DD54
                                                                                                                                                                            SHA1:7D9ECFBB816010CFFB98627FD39A86D371E117AE
                                                                                                                                                                            SHA-256:A624B6BFC871D5E57FD7E1AF5B0328DBAF7723C9D7192021B08673EA4F079A26
                                                                                                                                                                            SHA-512:C70C4B74237C077877D436B2C7B6B2B1E7B7B22C4955B5A19352F4768A4D21AA7F76E5C8FD43B571DCB008FAA22C2080F0F509795D83DDEC6B17310E8FE35F21
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//DE4789EFC404036F254F89D75AB1E47C57D3CA6A942662C9EC6F89BC6DB6A0D7B1DFA6DA422823197A9FEF248699D117FF9A2764D737AE5996DA82C2FA1AD905++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.4461883658600305
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynL2TdEhuGhwVbj:7rrSOX8BC0Bj5dXEC0BjyKSREhWVbj
                                                                                                                                                                            MD5:61C640F0D948B87E20F9FBFFEB77A330
                                                                                                                                                                            SHA1:9F5ABDA83E0C7F0F3D83170E3339A7AF2912C7B5
                                                                                                                                                                            SHA-256:992438959C209FD4517A0E7023436301425CC6D27757F26783FE360D7422E0B5
                                                                                                                                                                            SHA-512:5BF2939DF94222647EC27DB611EF50D4C6AB6B571F327A38572518A9A414869A08343DBF2BBE3F939D62A8FEB48E7CD621FE8BC2DAE9FDB97046E70F7454D705
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//EFC1EE5B000C51F38E99D71E91304386AC8C570D5DD9CDC91758712E81CDB04BCEA17EB3C7D3EDC62DA96FACAE8331434DC71D1A739FBF611C48686DB31A7A8B++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.463440158175525
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLxThs/VgKX29QO:7rrSOX8BC0Bj5dXEC0BjyKSa1s/SBX
                                                                                                                                                                            MD5:AB213B8B678499E34545107A3F29DD6D
                                                                                                                                                                            SHA1:69C9B45E6D29DAC2B8C13FDBEF0F61B9404F8B03
                                                                                                                                                                            SHA-256:230237CD0094158BC14ACD53455E1DA1FB0D6F66A8C22660993A8BD1A2F7EFD4
                                                                                                                                                                            SHA-512:A6D1E6D065F3F933C7E383A658E206CA0E7F21FCD9E32D197EA73F51B7EA6191B5E9F24ABF501FE07193DB77F417BEA69B9620A8DA8014A8C84E41566159EBD1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//8C8EDC53C2A798D8B8D350BAFC5F57DEA5A52F21A530381F8E0EF1CF522FEBFC114D3245A62C07CD059D1F3543A380539D4C9D7D5467F3632256E4A4E8E72368++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.467789482393415
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLV/KWsFFNrk3Pn:7rrSOX8BC0Bj5dXEC0BjyKS1TdMPn
                                                                                                                                                                            MD5:4B4F53A26CC390BD46AA5E2F788E3EA3
                                                                                                                                                                            SHA1:62BC3F2752C7311B2C8790A864AD13E1DF1B6F4C
                                                                                                                                                                            SHA-256:9E8D7F02744939ED1E6A1B4B6CD2EA1B23D3982B288A481A5A376F8160352806
                                                                                                                                                                            SHA-512:D5E3480CB2FE8F27B700E9CCADBE73DE4A35757601743421576D8DC34EB54A9E949276C9C44355DA63CD0416C0A1C6DA37E41DE80027394014638DED4334A3EB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//33A26F8AB0BDA7AB05E99D60F4F621817338ED5758F0C32F0F619D96E500D1FAF0C6475E53F482DADF1A8C68C9FBB46B7C5F4825EDCD821555BF2A2FF44E5E6F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.448414128170323
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLcfO8ANNC4g:7rrSOX8BC0Bj5dXEC0BjyKSZA64g
                                                                                                                                                                            MD5:C1D503621E5A9C14287289E37F9EA3BB
                                                                                                                                                                            SHA1:D28E3CA01EAC333BFEFF8A058F4CFCDE60EEF482
                                                                                                                                                                            SHA-256:3E3BBCA2FFC1C3C906AA3890E9F820A014C46825BEBE31478F9543154001F58C
                                                                                                                                                                            SHA-512:823A503277ABBA0BCADA5472F17A09587C6C805E21485FC307BCC7AAD7A1D6DE492AE511CC152B6053551CA67646F797A90085F046C6352AE6506F1046702CCA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//800E8484F6D0DA03B1160E6ACBCE9316EFD8E385323AE0EFAEC6A52BFFA61413A9FDBA5B65C4E03B788EE0E35709753347D51AA8196900CD480E183B3B4697FF++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.465072364155408
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLSUEsiYqLzg34:7rrSOX8BC0Bj5dXEC0BjyKShxBLzg34
                                                                                                                                                                            MD5:9D5D3C1DDE30DE91108EBB542CAB5600
                                                                                                                                                                            SHA1:DF459112D06C18206E861E7FC5B03A42FD990961
                                                                                                                                                                            SHA-256:E455B5D287F20CB26839DE4BD471D55BD85F033FCB0BD67C2AD31E6FB82D7B06
                                                                                                                                                                            SHA-512:4DD1210E6F86B2F9282B391E08E741AC74B48BA2CCED440D6888361BAB6963E8775876C462F43E1439DEA8F42C004087941D779284C4E7F8D84C6EDDF07730C3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//197E502E240A4CA940A10248DDC7B457E66B1914812253E76922527458780623CEBB4355839FAA94A8AC20E4AA84E2D3E4F05034C99B545573140DF684051FF7++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.450475785026495
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLppMK1JGNrOu+AV9T:7rrSOX8BC0Bj5dXEC0BjyKSwp93s7+i
                                                                                                                                                                            MD5:4CA33ADF377846302AA9DAA2AAE4E1BA
                                                                                                                                                                            SHA1:D203BC3DB5801DBB3D71DF8E75915390A3DDEB3E
                                                                                                                                                                            SHA-256:402CCF67CE7A9951D946564F5E226446EB96DBF94497F163BFD24E798DD9B661
                                                                                                                                                                            SHA-512:1E89577B1D2FD48B228724F82842A883D2AF3097663E15F468A43BBF409C7B91E854C2FE746EA7418CFACA68BD07B32FFE4A9485F1520C24777A2EC907A139D2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//9F617C02EB2854E54701D6C82A1DCDAACADD1D378E21B16805111FBEAA77599CB9A3674789A71AA3E5F3E1878243417CD515BB3708A13B3C0DA9DE3F13F295D1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.481524147070895
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLmeMRrM:7rrSOX8BC0Bj5dXEC0BjyKSY
                                                                                                                                                                            MD5:9766BF4631C38C443F90A96BF2AB8850
                                                                                                                                                                            SHA1:4F0377CE71C77B6B3428B321DB9337C0FA99F7D7
                                                                                                                                                                            SHA-256:3751DDC1CE3D2B012A05F3964CE95C41F4A5768DD72F989AF104ACEF3732B970
                                                                                                                                                                            SHA-512:FAA42E18C39937CCE6473C0BC8CBB0AC3A4ECCD3BECC9DC8FE698C18591AF6BBE486B22319D709FCA69AE18FF0E1E3B22D2BD8A8A0708AAB107A3F5B9EC4C3E1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//67E264B2CB7B527F0921289C594BD303A45323BF11ADF4C68EC7DD65C01420A8E25FF931FE23816796C416E81C7627DFD3D557614DD0BF8D9F829DA7A0FFDF72++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.47132080555524
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynL3zw+6e6VR3S2Zl:7rrSOX8BC0Bj5dXEC0BjyKSqzcpRCOl
                                                                                                                                                                            MD5:ACC4ED97C4563B2E64DEFCD44D78B8B8
                                                                                                                                                                            SHA1:B42881266236C3634850B775AF19340D44DC9EE7
                                                                                                                                                                            SHA-256:B93E215A6B95B7D4251812A8696C70E3C61B4D5E8E7FA4CDDF67976E6443A50C
                                                                                                                                                                            SHA-512:45B58202CEB8DDCA14A77E04A670973D877E5A295AF887FE0E2FEDFC1ABA5AA573B7CB4A3C90A1B4259FADC8BCBB3CE10DB18294CC68D009B92F51BCEBA6C7C4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//DBBE25382AA6DF542447F36EB6CE5902E2511B186C63DB0ACDD352D5B50D848DD6F0E4A0936BD5301F0B550E79CFF7DC112145C505B12589C745F7BDF32A29F6++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.487560968790192
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7rrSOX8BC0Bj5dXEC0BjyKSC9n0O1oS5xR:um8BC0d5dXEC0dyKSC9H35
                                                                                                                                                                            MD5:20D85274B90D12ABD222AB115EF43214
                                                                                                                                                                            SHA1:F5E71C94568574379C1D6BBAE3A643BDCFBD0857
                                                                                                                                                                            SHA-256:DDD51A060019E5C31B78EECC00B6E950EE3BE5DD26242035995AE766B6724E3B
                                                                                                                                                                            SHA-512:3C5E81224EB3FED271D6529638DFABA434700F70226845A4AC169BA4B478AAAEC004409D696DF7073F1FDEB09CCEC8F390E3CBEC9341F24004DE4F3EF3C0D89C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//25A992B7398B877194795B5694213D623B4A022693F7884E49A475C730D91943CABDB60F10EF1EFF6B546C8577D3A889DFAAC46B6330F3190002C0C170217C52++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.480787895471054
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLGFG1BVmCu:7rrSOX8BC0Bj5dXEC0BjyKSBGnc
                                                                                                                                                                            MD5:C70C36B511E82B847C7DC46F327E47A5
                                                                                                                                                                            SHA1:05FF8B9392EB32493F7A286F384A1EF78DE62910
                                                                                                                                                                            SHA-256:34C21790DB18BB71E35076C11AA6E2E78115889985B9BAA9034B77DE32BC414D
                                                                                                                                                                            SHA-512:24E7D0F6D2BB3D360553BE8EB52761F72C2E75CDA53AE1AF26D69A9D97AE7E1FD70423BCAD9BD06E12EC60B7B70A979B79BC61AE9E4A906024EB6523B7C021DA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//0796F1E4B93F54298FD1A8B639684DF0641E3B6D0B13BE63E69299747C749117CF4208D1F60D5AEAFA50699DD05F9816334037A7B528BC3E6C43199311D74D8C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.462903513812164
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7rrSOX8BC0Bj5dXEC0BjyKSESpeMLc1VP:um8BC0d5dXEC0dyKSPppcT
                                                                                                                                                                            MD5:8697DF2F89C4CFED17AF75E933248049
                                                                                                                                                                            SHA1:5BE052DC7DD91B28A592587336A92B4811B635D7
                                                                                                                                                                            SHA-256:F8FC5B6F79C3377A361677A141AD9AF9C5EAC136E18FDD841CB3A7FE64037914
                                                                                                                                                                            SHA-512:2C91638962B1C47492E5E24821994592BEC0E0B092560E4A4D689C1465781A5220333BFC7984CA120CD5D4047B4993EBF09C44F28895187C62E0D4A52AD841D0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//771FA244E7D097EA223ECD7BF9A2B9DD2F8371E2CF00479AFB61FC86CF275850B4FA3FC056087776EAA15B2A52F5CFDCC0C8251E0C68411C689AB4D6BB121B19++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.451823404854838
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLsvGcPd3:7rrSOX8BC0Bj5dXEC0BjyKSTd
                                                                                                                                                                            MD5:CC177FD362B9B177DAD1EE258BB5985A
                                                                                                                                                                            SHA1:38E916023D033A20D2F087DE9D3DD955CFF42FAC
                                                                                                                                                                            SHA-256:7733DF6E8715ACFEC2BE7998D4846756E00AFE9C78318BEBB8A4D229E36A00D3
                                                                                                                                                                            SHA-512:021B2395B81568797A45E1A8112F15DB41625CA8D7548A8F3EFC47FEBD27B72B6B5FF6CAE0D335F3779098F5EF83402B6C3FE086B3C1A724CDBADF6370079074
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//D9CF9F78740E0EC220CDA03ECA26E011AE407F902C5717BE3B9D3C80D0107189805A795D1B42126A26EDF0C7B146AA4BDB2D4E1CA7EAED4F2BB3C3C9F6D43285++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.459097531412527
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7rrSOX8BC0Bj5dXEC0BjyKSxsD8ddFSop:um8BC0d5dXEC0dyKSx/doop
                                                                                                                                                                            MD5:87EC7329B9A2504FD57665DCD93EA440
                                                                                                                                                                            SHA1:3481CADB9557E568ED8264A3DDA382EF1AD627E0
                                                                                                                                                                            SHA-256:0DEA84250C30C1DF133C1B04785DBF556263685FE8B13F69E7B0D8950F6261E9
                                                                                                                                                                            SHA-512:1CD7E5A363909A712BD925686F306709B5D6A93B91AE124C790AB2BF009B8337D3B273AFEEE4360F48DDE1F3129DD0531A2730E08BBBCD3D3CCF06E8E14B98C9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//E4B753978D948C3BCBB586B78060C1C908BF014C730ECDC5BAC9BC50C638D3C89383F2ACFB67E8DB7B0D3C45D4C3475C4650DAAAC70876854587BE88B88092D5++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.471152494094452
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLTgjMYTE:7rrSOX8BC0Bj5dXEC0BjyKSEoMYw
                                                                                                                                                                            MD5:BC0ABA9C4CE9E942493C40DF9A238949
                                                                                                                                                                            SHA1:C567B6F511B9EE761E69E0F4463FB2AF60BBB721
                                                                                                                                                                            SHA-256:560151438028B1E5F20D439A0150E6EC1444F7667312B0542473E0725DE48790
                                                                                                                                                                            SHA-512:7B124700B8CBFA16F53F77789F2436E809BF5578A3D74C9E6008F4E13819A4E2E3AE72890F1BCA41989B466F73574A956742C09D3641AD95D50D8D8ACFE058FE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//238C493BC13C059A7590D647A34B0E8C16A127C95CEAAF28B45B8CB38430FB02EB7DD11740D2FFA9B8784D3B128F59E05DAC3CF5451DF6611ABB6199310FAA20++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.450746110524956
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynL9Gi3Wj/lSBk:7rrSOX8BC0Bj5dXEC0BjyKS8n3kNAk
                                                                                                                                                                            MD5:8F53E40982BCAC8D45A5F639B7EF7AA2
                                                                                                                                                                            SHA1:59F456D1F9E5A87839C6C360A5F928EA23A3DA66
                                                                                                                                                                            SHA-256:D6FB842ADFA2B5CF16827F8F8BBBD73563F699E48197442BAEFEFBAFE9463A17
                                                                                                                                                                            SHA-512:6855EC2A8D9657B37620ED1E8FA87467B4C90DF79EDA35B86B0A0AC3E69690E692CA724F1B0CAB9AC41F0BE3A379CCD090B6539783AE6AC53CDB4F0DA8073D4A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//5DAC1438231AF6188CB4EDF6E96DB68E01EF46AA2546A36037386015AE0C1E9661D9AE8408389F6F23C3B908A19BDDB83D1C0F3450B1B2ABECE8DB65D8C24F89++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.459480754994661
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7rrSOX8BC0Bj5dXEC0BjyKSouykPkylZb:um8BC0d5dXEC0dyKSou3PkqN
                                                                                                                                                                            MD5:0B30C3F64A2BFA1B9B4016A6C845190C
                                                                                                                                                                            SHA1:68A15807719324798679D041AB036890F73F8672
                                                                                                                                                                            SHA-256:5D3B4E4D7A3AC77C03E4DFF314DC24BDFAB76D20E2D216DBAD8213954FC918A4
                                                                                                                                                                            SHA-512:7DAE4E5ACD4983822F48E49E48DE47B8AFDD47D4616158B517F8925034D7412A016FD68657BDEEC732B46354AE429741D9C00B8BFCF621B506A3453C9F6FD9EE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//1034E1EF549D1DCDC233A68773E4A7D137C12BC7C0EEFA8A3C282506887B337765BE6E304F3E17A4A63559A7270957B5A37DD7BF291D898BFEF2CF1DE383991F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.4578715329046235
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLI7ktDT988fL:7rrSOX8BC0Bj5dXEC0BjyKS7+DjL
                                                                                                                                                                            MD5:9F7DC1ACE7B73892EE50A6545DFA83CC
                                                                                                                                                                            SHA1:6EB701564900B80AEC333E7978DAF803302D2DBB
                                                                                                                                                                            SHA-256:8772F8019C8E43238FD3CC8245252ADAED691173B576C11CE2AB9F7AB6A9CD6E
                                                                                                                                                                            SHA-512:19894199EA7B99CBECCEAC50ECDC878029F4637D112A4AADE0A1443283A7410840354978BE9207C78B89F16C7AAE35B4CCFF53A5A6C6A8EC6CEB8F7D3C3ADA44
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//67DC12E3E58036558E2EA7EB6197C862C7C8879BBB3C05EFE202D72CC023C73236E70655FB44B135D99BEA9CEFA325BCF779BC9D7663CB53B533E93F0D2FF624++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.452713758915027
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLsLdhv6ktsw:7rrSOX8BC0Bj5dXEC0BjyKSZLdEw
                                                                                                                                                                            MD5:056B6616A05E445D3FA7D9E9C37A47A3
                                                                                                                                                                            SHA1:DD78B3BBB306B9A4EA182E002C56C618E8A3A254
                                                                                                                                                                            SHA-256:FB8CF477130D5BBF99DFE38C418CC533B66FCD6EBFBEB03821F13227C35FF294
                                                                                                                                                                            SHA-512:177E3D758F1C3A2B06B90704E95D216BC668DADBF5F06710DDF23B08D0C473EEE0A84EF77E41B2C6F30B619016A2862A8BE0CD2E5E4A9AEE6C448924C5B30514
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//CDBB8A3CCBA0269F2197E46FD682E1B59A9A1061B8AA26978188C2069ACB1179019D014B34890ADC9B0AC825494B21BE841446BA0E8734B678178816D549CB56++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.473380197780306
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLkpxgQjT6hn:7rrSOX8BC0Bj5dXEC0BjyKS5ptjT6hn
                                                                                                                                                                            MD5:DB43C21F2271B397D7B5909A53FE38C1
                                                                                                                                                                            SHA1:E9F022DB0ECEC8C5642B0B7C3551AC666DF92D76
                                                                                                                                                                            SHA-256:CE7395F2238B5603C7382AC1915D1FC581AF24D729930E7D7A2145AD791517CE
                                                                                                                                                                            SHA-512:15698CCBE6969776EE0FA6D44C1C617BE490281362E457FA3F9DCF0DD0D863458B3D659378B32D790F45CA6DC4D8046DC581F8C5BFF837713E1ABBD1FB5FF4BB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//86F7645CC88253D58957AC5933573C7246547A7549D8F6E71E7486FE351F82C9FAF2F6974D771329EB0477FEBEECA2D8F606D6DF66DC96293B335B1C86DB9ED8++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.461249326785134
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLQcjHfJiS7:7rrSOX8BC0Bj5dXEC0BjyKSghiq
                                                                                                                                                                            MD5:435A9C4F81763B978ECBB1C99B3693A2
                                                                                                                                                                            SHA1:48C8BDDA74C684D968C361C9964FC572A65EB795
                                                                                                                                                                            SHA-256:64B73C84508FF05EC83EC446B7878E044FC831ADF2FAA8F7B47E858BE43B865B
                                                                                                                                                                            SHA-512:DD24DD4E8F908E4647EE466603F219A4162086E7EAB528AFC5B0867A9EBA4C106DF7406C2F74014AF76A83262D5897A2A9D76F848A7DB4A6D964440C586CC57C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//2C6565085DA6F74A6EB5A92F2E1D22CEB3CC9BD312E056B0BB1A0B2755FCF705AD13F8507E2CB381C81570640DB6E4BE57278E7F7BCD4F4D1E1529F60FB841E9++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.446820266860203
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynL6f1OeEv0C8ccsEOO:7rrSOX8BC0Bj5dXEC0BjyKSbOoccsO
                                                                                                                                                                            MD5:F8CCC13B0166600BD5B77E424A0B5C50
                                                                                                                                                                            SHA1:1CFA3E02B2176B29D7FD3CF1303272F4AFF82F1E
                                                                                                                                                                            SHA-256:C69850853289B66E722D1553451D5B3F46900C1D488A1EF654EAAA1366BFB8AA
                                                                                                                                                                            SHA-512:DF62E02C67D3DCBE81D001C1224ED84579D38FB2C1B7D6DEF19B244B5EAFF5B65F3B58937674423A5E32A7F4B212779C7439F98C1A0926E1BACE3D759A30ABBF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//473DBA04D8A20814BBA01FDAB002E47772A45021A1BB9566C1AD149C18DC5CDD8D13826CF4DEB30D7A7D1C2BECE0D7315ACEFFD29481D1EC8B2AB18960B5574B++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.461095188089534
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLoj4bhEx5U2C:7rrSOX8BC0Bj5dXEC0BjyKS/4bho5U3
                                                                                                                                                                            MD5:674F615000BC5A8BCA213B7FE45505F1
                                                                                                                                                                            SHA1:A33318EB56BDDB9E9C6415673318D3E51E5CAAA6
                                                                                                                                                                            SHA-256:137EAD881360C9C563FF6C708D50D1928B2C0519ADFD31F52B923D53E3AA2257
                                                                                                                                                                            SHA-512:4B930F27914DC67D8C46759C74D241973F2110C208A09026052E59631381ADF494B094C60FE42FB5DABDCC09AED0B79758950864E4182E017F996EC1FE3DD72D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//7BCBF56649B8A8DE9694C97C2D7DBB07C8F6392C54EC30E598227A755D8AEA8E23741C801EA17290197F912CFA572BD7DF2FCCCF3D2B2D9251D31116271EB21F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.470616512102546
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynL61lpcFBmLcAdQbun:7rrSOX8BC0Bj5dXEC0BjyKSFPQBmNQu
                                                                                                                                                                            MD5:6ED11FBEC9DB6C8739E7A999D4B74EB0
                                                                                                                                                                            SHA1:4F4DD5958816438DC62EFC514A4CCDED75743747
                                                                                                                                                                            SHA-256:299CB08BE417FDF9B909EDC16FEB09B43F668D6BBB99A3BFFCAA2C2CD8773DDB
                                                                                                                                                                            SHA-512:41E6DA0D4778F1213325B3FFCE3CFE71A8137037773347EA6CE5414A5436B2AF5045CB8F47F8E780B9B568424C9305B11BFC2AA5589D14CDF9CB8B65E1A034A1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//A6207980C064E27FC18791F5067AE2C3E6E429D262D83E374468377510A78D67579390BCA7F1BA3CE34A49C17912FBA13F856449914C30428AF6617214694C7A++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.458089036751079
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLU/uQcj2ODKhMt:7rrSOX8BC0Bj5dXEC0BjyKSWlt
                                                                                                                                                                            MD5:8C6DBC15A46106D53D1B6983A825F733
                                                                                                                                                                            SHA1:B7B959D2D883DF827C6F4E01AA3AAD3D96A88A85
                                                                                                                                                                            SHA-256:1B455928749E3FA51A9CC77A145E8B4DCA202EA71EF36BA80DEFCE30476329D9
                                                                                                                                                                            SHA-512:A87727A936D8FDD2A9E636B7F4470AC9BB911D972835130276FC26522A61C8BD31621C6E41653D4916151470558A42188E28BC74573B5484713D0179E06161EC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//AFC878D4EEA1BAF07247E23665CE59E698D580CCAB718DF6E608074DDAE4529DBDC4FA41234D9EDD8C31F9132E5DC116DC41C6B22AB4D322A19315330381BB04++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):803
                                                                                                                                                                            Entropy (8bit):5.457116068891303
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7rBDjl+6mOX8BCNaBz3dumdjjECNaBz3duuqRcrSjynLCU1ZanxqMghmh:7rrSOX8BC0Bj5dXEC0BjyKSPXnDCmh
                                                                                                                                                                            MD5:62FC9B1A76459A938CF523484ACD3D71
                                                                                                                                                                            SHA1:EC4A823C94D30DAF6F44C10B3F911F9DC3C36D72
                                                                                                                                                                            SHA-256:CE6C27A84437D9125409085561D28FF93DDA8DFD7D43520987B20D4C96A522DC
                                                                                                                                                                            SHA-512:7D680A571D7992AB37CAAE9E249A5A2A3DD90A2854A31D998492677CE3E7EA99784086101BBBB7CA6612014AD7F792103DD4D549C58BA73F6A6A407FE259F083
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrNewTabToast_ = {.. NEW_TAB_EXTENSION_HEADER_VARIANT_1: "New tabs just got safer",.. NEW_TAB_EXTENSION_HEADER_VARIANT_2: "A safer way to browse",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_1: "With industry-leading security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_CONTENT_VARIANT_2: "With McAfee security on every new tab, you can bank, shop, and browse with confidence knowing which sites you can trust.",.. NEW_TAB_EXTENSION_TOAST_ACCEPT: "Add extension",.. NEW_TAB_EXTENSION_TOAST_REMIND_LATER: "Remind me later",.. NEW_TAB_EXTENSION_TOAST_DECLINE: "No, thanks"..}....//E04E6AC99547F41386BF9B5FE2D956F687FB85AE9689642B49AD5D35E825F8FA7FB1E94AD52C7ACDE0AFE8B827DF731489B4CCD17EFC2463524E4F80BBE6F14D++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5377
                                                                                                                                                                            Entropy (8bit):5.641095543119768
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:WQVBazY8QxuorbT6roQ/CZwmBrqtXNMDUaGCrW+NlaVy98ZDcT7ek81qh:WQvaz3AumireG6HYVygDcTqh1G
                                                                                                                                                                            MD5:19B3AA71508DC95387C4E1EF9E037BB3
                                                                                                                                                                            SHA1:D446E27B6AF4D4222EB5AEE99E3B9863DE8CDC85
                                                                                                                                                                            SHA-256:261B1918501A029BD8AC4CCDCFC93AF069F3F79AF20657E68A17C238DB7C28B7
                                                                                                                                                                            SHA-512:2CD7FB984A63950E01A0AC5C8A81B755164F874404D58A8054F6CEDDA94C5E7E94D67135B992C2F2D365348C09C8972FA159B67B284408B6FDACCFB60803615B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Prob.h. skenov.n..",.. DL_SCANNING_MESSAGE: "Soubor, kter. chcete st.hnout, pro jistotu skenujeme.",.. DL_BLOCKED: "Zablokovan. stahovan. soubor",.. DL_SCANED: "Skenovan. stahovan. sooubor",.. SS_ON_STATE: "Bezpe.n. vyhled.v.n.",.. SS_FIX_MESSAGE: "V.born.! Tyto zm.ny provedeme p.i p...t.m restartov.n. prohl..e.e.",.. SS_OFF_STATE: "Je vy.adov.na akce.",.. SS_OFF_MESSAGE: "Upozorn.n.! Ka.d. des.t. hled.n. obsahuje nebezpe.n. odkaz.",.. SS_OFF_DIALOG_HEADER: "P.idejte k v.sledk.m hled.n. hodnocen. rizika",.. SS_OFF_DIALOG_CONTENT: "Ov..te bezpe.nost odkazu d..ve, ne. na n.j kliknete.",.. SS_SEARCH_OPTION: "Nastavit slu.bu Bezpe.n. hled.n. jako v.choz. vyhled.va.",.. THREAT_OFF_STATE: "V.straha zabezpe.en.!",.. THREAT_OFF_MESSAGE: "Po..ta. je vystaven hrozb.m, ale m..eme v.m pomoci.",.. AVFW_DIALOG_HEADER: "Antivirus a br.na fire
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5126
                                                                                                                                                                            Entropy (8bit):5.34166175614958
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:uZb3Bdp2fhG5TrVo8Ybuoo/tFCld/lwrYeCEUVlku/TzmV9S9hSFmUihKV:QCfhwrrYbuoG4Z+VchgmKV
                                                                                                                                                                            MD5:79FC174B1449981FA52792ACC4566681
                                                                                                                                                                            SHA1:BE4453DB3F3DACACC1979E3AF55E71878D269E12
                                                                                                                                                                            SHA-256:F4EB9444621C2524ED7D351297814DD1166CF56793F47402242315640D373402
                                                                                                                                                                            SHA-512:2B10F8C22863C76D66F226EE5C359BAADE8F85575867F5F12B56B5E9D1E7E7A134DF1532F13FFB71F75DB968A41B13C7790F3EF95B91882A895F665853029406
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Scanner .",.. DL_SCANNING_MESSAGE: "For en sikkerheds skyld scanner vi overf.rslen.",.. DL_BLOCKED: "Download blokeret",.. DL_SCANED: "Download scannet",.. SS_ON_STATE: "Sikker s.gning",.. SS_FIX_MESSAGE: "Fint. Vi foretager disse .ndringer, n.ste gang du genstarter browseren.",.. SS_OFF_STATE: "Der skal udf.res en handling.",.. SS_OFF_MESSAGE: "Advarsel: 1 ud af 10 s.gninger indeholder et farligt link.",.. SS_OFF_DIALOG_HEADER: "F.j risikobed.mmelser til dine s.geresultater",.. SS_OFF_DIALOG_CONTENT: "F. at vide, hvor farligt et link er, f.r du klikker p. det.",.. SS_SEARCH_OPTION: "Brug Sikker s.gning som standards.gemaskine",.. THREAT_OFF_STATE: "Sikkerhedsadvarsel",.. THREAT_OFF_MESSAGE: "Din computer er i fare, men vi kan hj.lpe.",.. AVFW_DIALOG_HEADER: "Antivirussoftwaren og firewallen er ikke sl.et til",.. AVFW_DIALOG_CONTENT: "Ca. 864 millioner stykker personlige oplysning
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5366
                                                                                                                                                                            Entropy (8bit):5.342945535147279
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:F20O91pUKtemTKjnkGzgUIzeRF9DQ8YMLOeaTkHzp1E9Cm6uUUZA:F29CKteQKjnkGzwzeRN8hA1EEtBaA
                                                                                                                                                                            MD5:582E51D1B634F961CD005FA07D631413
                                                                                                                                                                            SHA1:76DC23A47487555D7211222823F60866DE9AF3DC
                                                                                                                                                                            SHA-256:CB370D85C7844B2A7762D1FAA1A3FC265C15D60DB8A066A7C216270D4021AC03
                                                                                                                                                                            SHA-512:7E0366642F65F1D48E1569EC81CB382DAFF86AD2167D7F6FA5F1EE306A14D0147BE39385298E64E01B371F48BCB85057DA1796FCEEE5B1B44429F67DA3A65B81
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Scannen...",.. DL_SCANNING_MESSAGE: "Wir scannen den Download zu Ihrer Sicherheit.",.. DL_BLOCKED: "Download blockiert",.. DL_SCANED: "Download gescannt",.. SS_ON_STATE: "Sichere Suche",.. SS_FIX_MESSAGE: "Sehr gut. Die .nderungen werden .bernommen, sobald Sie Ihren Browser das n.chste Mal starten.",.. SS_OFF_STATE: "Handlungsbedarf!",.. SS_OFF_MESSAGE: "Warnung! In 1 von 10 Suchergebnissen ist ein gef.hrlicher Link enthalten.",.. SS_OFF_DIALOG_HEADER: "Risikobewertung f.r Ihre Suchergebnisse hinzuf.gen",.. SS_OFF_DIALOG_CONTENT: "Erkennen Sie gef.hrliche Links, bevor Sie darauf klicken.",.. SS_SEARCH_OPTION: "Sichere Suche als Standardsuchmaschine festlegen",.. THREAT_OFF_STATE: "Sicherheitswarnung!",.. THREAT_OFF_MESSAGE: "Ihr Computer ist ungesch.tzt, aber wir k.nnen Ihnen helfen.",.. AVFW_DIALOG_HEADER: "Ihr Virenschutz und Ihre Firewall sind deaktiviert",.. AVFW_DIALOG_CONTENT: "Seit
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):8385
                                                                                                                                                                            Entropy (8bit):4.965325304098503
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:BYz3hNXL4xrlON0pOqxptk2xgthUE6wfOhLQvTK:ULXUlObqTC2xgwmOhcvTK
                                                                                                                                                                            MD5:CAEE0E4BF0E9EE5AE6B55AB4865B11AA
                                                                                                                                                                            SHA1:869533109A2FE7F2F2B10A803D99944A27602236
                                                                                                                                                                            SHA-256:154C0A969BA4A31A249C07697101EF26D5692CEC115043A13DF90BB2243B7B3E
                                                                                                                                                                            SHA-512:6DEBE5D175E54DBB8DBC7F9F65AE4EA223D0E435BC7762B32BBFEDA1DDB9D088849B275000E05419B69C3453EC7BF2B99A98EA291AADC591E48B8E4AC69B810B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: ".........",.. DL_SCANNING_MESSAGE: "......... .. .... ... ... ...... ..........",.. DL_BLOCKED: ". .... ............",.. DL_SCANED: ". .... ........",.. SS_ON_STATE: "....... .........",.. SS_FIX_MESSAGE: "......! ..... .. ....... .. ........... ... ....... .... ... .. .............. .. ......... ...........",.. SS_OFF_STATE: ".......... .........",.. SS_OFF_MESSAGE: ".......! 1 .... 10 ........... ........ .......... .........",.. SS_OFF_DIALOG_HEADER: "........ ............. ........ ... ............ ..........",.. SS_OFF_DIALOG_CONTENT: "...... .... ........... ..... .... .........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4755
                                                                                                                                                                            Entropy (8bit):5.330213437300072
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:uU3x9/eMjflrS5xsyoBkXqLB+Qz/Q1wU9pYOosphMx:3x9Jjf2Kkm8GQ1NPjVqx
                                                                                                                                                                            MD5:D464C590EAA58D0D74502C46629A4B3E
                                                                                                                                                                            SHA1:880E2AC7F43D30E4691C96955376164A1A3E9C85
                                                                                                                                                                            SHA-256:FD21C09C996BD82D952D9F4DF60AF993921840311AC98F263BB9AE9F5047212D
                                                                                                                                                                            SHA-512:D4078BF1D859DA34E9386F1A390DDA19750C12FB8FCB6B8E3E393E2DFED7647D9FB9B673A8E3E5FB467C96BE48D1DF953CB1D9C6406E743651451443B9F9A6AA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Scanning...",.. DL_SCANNING_MESSAGE: "We're scanning your download just to be safe.",.. DL_BLOCKED: "Download blocked",.. DL_SCANED: "Download scanned",.. SS_ON_STATE: "Secure Search",.. SS_FIX_MESSAGE: "Great! We'll make these changes the next time you restart your browser.",.. SS_OFF_STATE: "Action needed!",.. SS_OFF_MESSAGE: "Warning! 1 in 10 searches contain a dangerous link.",.. SS_OFF_DIALOG_HEADER: "Add risk ratings to your search results",.. SS_OFF_DIALOG_CONTENT: "Know how dangerous a link is before you click on it.",.. SS_SEARCH_OPTION: "Make Secure Search my default search engine",.. THREAT_OFF_STATE: "Security Alert!",.. THREAT_OFF_MESSAGE: "Your computer is exposed, but we can help.",.. AVFW_DIALOG_HEADER: "Your anti-virus and firewall are off",.. AVFW_DIALOG_CONTENT: "About 864 million personal data records have been compromised through data breaches since 2005.<br/><br/> Don't browse
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5193
                                                                                                                                                                            Entropy (8bit):5.30018704737383
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:dRey5rMscODKKai5iihhi6VnRSyLK3yAEK9WOM0CKAXTs9:dUWr+ODhai5SknRSkNKPM0VP
                                                                                                                                                                            MD5:B794B207632AD4CBEF74E695A9AC82CD
                                                                                                                                                                            SHA1:3451678023A25CB3F94BE03F8B2EB14A69B1523C
                                                                                                                                                                            SHA-256:6EA61F211D5ED1C5EFBFA5585C1B3ABE8BEB42B4E349102B795A8EB50E4F0CD9
                                                                                                                                                                            SHA-512:E311960012E329A390183461C7522B5950940F6219A22EA1D2AB07C045C5EAAC62AF5A2758758D1B491E907F1D86FA00BFD604C6CBECA9A5FDF9241F72445741
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Analizando...",.. DL_SCANNING_MESSAGE: "Estamos analizando la descarga por motivos de seguridad.",.. DL_BLOCKED: "Descarga bloqueada",.. DL_SCANED: "Descarga analizada",.. SS_ON_STATE: "B.squeda segura",.. SS_FIX_MESSAGE: ".Genial! Aplicaremos estos cambios la pr.xima vez que reinicie el navegador.",.. SS_OFF_STATE: ".Debe tomar medidas!",.. SS_OFF_MESSAGE: "Advertencia: 1 de cada 10 b.squedas contiene un v.nculo peligroso.",.. SS_OFF_DIALOG_HEADER: "A.ada calificaciones de riesgo a los resultados de sus b.squedas",.. SS_OFF_DIALOG_CONTENT: "Conozca el nivel de peligro de un v.nculo antes de hacer clic en .l.",.. SS_SEARCH_OPTION: "Definir B.squeda segura como motor de b.squeda predeterminado",.. THREAT_OFF_STATE: ".Alerta de seguridad!",.. THREAT_OFF_MESSAGE: "Su equipo est. expuesto a riesgos, pero podemos ayudarle.",.. AVFW_DIALOG_HEADER: "El antivirus y el firewall est.n desactivado
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5216
                                                                                                                                                                            Entropy (8bit):5.317560654565851
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:zyErLx7VO33aiG/qshhi6VnRfylmDiP2QuyMLii9j0OsKbY7:zXrXO33aiiMknRfyp/Haiitfz87
                                                                                                                                                                            MD5:B928738E0F210A88173A518E7CD21352
                                                                                                                                                                            SHA1:5124FC124D459481C889F0F7B8E2D53C5453C8B7
                                                                                                                                                                            SHA-256:CE02DBA270472727C12B273CE27B967744FFD9AE5220C045BBF6B3C84683CAE6
                                                                                                                                                                            SHA-512:15BCA76C6709490DE139D09CE4ED520FB0A4DBF0AED11778622D83D39722CFE7B6C92740DC81BF601B77328FBEEC3B56B58E796BF66189F9E6AC2B3A03F125E7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Analizando.",.. DL_SCANNING_MESSAGE: "Estamos analizando la descarga por motivos de seguridad.",.. DL_BLOCKED: "Descarga bloqueada",.. DL_SCANED: "Descarga analizada",.. SS_ON_STATE: "B.squeda segura",.. SS_FIX_MESSAGE: ".Excelente! Aplicaremos estos cambios la pr.xima vez que reinicie el navegador.",.. SS_OFF_STATE: ".Se requiere acci.n!",.. SS_OFF_MESSAGE: ".Advertencia! Una de cada diez b.squedas contiene un v.nculo peligroso.",.. SS_OFF_DIALOG_HEADER: "A.ada calificaciones de riesgo a los resultados de la b.squeda",.. SS_OFF_DIALOG_CONTENT: "Conozca el nivel de peligro de un v.nculo antes de hacer clic en .l.",.. SS_SEARCH_OPTION: "Establezca B.squeda segura como motor de b.squeda predeterminado",.. THREAT_OFF_STATE: ".Alerta de seguridad!",.. THREAT_OFF_MESSAGE: "Tu computadora est. expuesta, pero podemos ayudarte.",.. AVFW_DIALOG_HEADER: "El antivirus y el firewall est.n desac
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4959
                                                                                                                                                                            Entropy (8bit):5.317878966620111
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:5ZZ4vNUD1ns7pqxqkRKk/eFt+2jiLRQoYWzZ0pu96M1ckY:PZ4vNlq4kRKkGSRcpuw4s
                                                                                                                                                                            MD5:4B49DB5828AC292E3F4126918B7567D4
                                                                                                                                                                            SHA1:B5793159E583B314019086E7226818E9E250D14F
                                                                                                                                                                            SHA-256:8F1C0F2B67B88DE8CDE93E533A89E8D8D576149D8F0C5C766935354D84A5B869
                                                                                                                                                                            SHA-512:F744355F146F7096583C4579ABB739005167A1513796E1FA69ABA4CF483AF302283D246A5732582F4BFAC6C99624E4BFE73CCCC44ACF1606EAFF21B6EB95B226
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Tarkistetaan.",.. DL_SCANNING_MESSAGE: "Lataamasi tiedosto tarkistetaan varmuuden vuoksi.",.. DL_BLOCKED: "Lataus estetty",.. DL_SCANED: "Lataus tarkistettu",.. SS_ON_STATE: "Suojattu haku",.. SS_FIX_MESSAGE: "Hienoa! Muutokset tulevat voimaan, kun seuraavan kerran k.ynnist.t selaimen.",.. SS_OFF_STATE: "Toimia vaaditaan!",.. SS_OFF_MESSAGE: "Varoitus! Joka kymmenes haku tuottaa vaarallisen linkin.",.. SS_OFF_DIALOG_HEADER: "Lis.. hakutuloksiin riskiluokitus",.. SS_OFF_DIALOG_CONTENT: "Luokituksen avulla n.et ennen linkin napsauttamista, onko se vaarallinen.",.. SS_SEARCH_OPTION: "Aseta Suojattu haku oletushakukoneeksi",.. THREAT_OFF_STATE: "Tietoturvavaroitus!",.. THREAT_OFF_MESSAGE: "Tietokoneesi on alttiina uhille, mutta voimme auttaa.",.. AVFW_DIALOG_HEADER: "Viruksentorjunta ja palomuuri ovat pois k.yt.st.",.. AVFW_DIALOG_CONTENT: "Noin 864 miljoonaa yksityist. datatietuetta on jout
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5692
                                                                                                                                                                            Entropy (8bit):5.302908789339375
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:0MxyhGiDkpQQrrENOqplZuFfrYnWv6HScq48Ky6o9Q+W55fTsujG:0ZhGVQQrrENOqYIH2V6o/W5a
                                                                                                                                                                            MD5:336E2EA07CD3577F75620D2976563A07
                                                                                                                                                                            SHA1:BF98A5000A7535254DC436CCBBD4B2E9379E8FC7
                                                                                                                                                                            SHA-256:C5166CFA2CCD93C23FE690740354032ACC1335886684457AE2D87278D0C7E101
                                                                                                                                                                            SHA-512:0C94DE545128DFDFCA6DCF6BAC83F8D72C2841C321C23FEE77A4F50F0B8CB85F30E36FE929E060FB6CC59DEC81436C55D027ADC2C385152F56FA0BFF56622144
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Analyse en cours...",.. DL_SCANNING_MESSAGE: "Nous analysons votre t.l.chargement par simple mesure de s.curit..",.. DL_BLOCKED: "T.l.chargement bloqu.",.. DL_SCANED: "T.l.chargement analys.",.. SS_ON_STATE: "Recherche s.curis.e",.. SS_FIX_MESSAGE: "Tr.s bien! Nous appliquerons ces modifications la prochaine fois que vous red.marrerez votre navigateur.",.. SS_OFF_STATE: "Intervention requise!",.. SS_OFF_MESSAGE: "Attention! 1.r.sultat de recherche sur 10 comporte un lien dangereux.",.. SS_OFF_DIALOG_HEADER: "Ajoutez des cotes de risque . vos r.sultats de recherche",.. SS_OFF_DIALOG_CONTENT: "Connaissez le niveau de dangerosit. d'un lien avant de cliquer dessus.",.. SS_SEARCH_OPTION: "Ajoutez Recherche s.curis.e . mon moteur de recherche par d.faut",.. THREAT_OFF_STATE: "Alerte de s.curit.!",.. THREAT_OFF_MESSAGE: "Votre ordinateur est vuln.rable, mais nous pouvons vous aider.",.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5621
                                                                                                                                                                            Entropy (8bit):5.318278974154098
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:yp99a4ffmtaCS1mELq47byJXGUmytipUS22d9h+/ijfTEQY:yXAaCpELq4Fr2c/2ijY
                                                                                                                                                                            MD5:146272CD85FECAB892122F01C0D3690D
                                                                                                                                                                            SHA1:E4457EFAC92906A8B36D041F30468729BAA368B7
                                                                                                                                                                            SHA-256:1F4317974E332E9E2482D5355E46237A491BBAFF4E614D771A4E14FDF9E11DC0
                                                                                                                                                                            SHA-512:F1EDAAC5A80DABDCFB707F54EB8B9B54D5C83A1EF237E3014302763EA2E034742FF0F871097AF759C48F25550DB9BC52FFA79A00F0A68903604049A3BA49BEC7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Analyse en cours...",.. DL_SCANNING_MESSAGE: "Par pr.caution, nous analysons votre t.l.chargement.",.. DL_BLOCKED: "T.l.chargement bloqu.",.. DL_SCANED: "T.l.chargement analys.",.. SS_ON_STATE: "Recherche s.curis.e",.. SS_FIX_MESSAGE: "Tr.s bien. Nous effectuerons ces modifications au prochain red.marrage de votre navigateur.",.. SS_OFF_STATE: "Mesure . prendre.",.. SS_OFF_MESSAGE: "Attention.! Une recherche sur dix contient un lien dangereux.",.. SS_OFF_DIALOG_HEADER: "Ajouter l'.valuation des risques . vos r.sultats de recherche",.. SS_OFF_DIALOG_CONTENT: "Prenez connaissance du danger que repr.sente un lien avant de cliquer dessus.",.. SS_SEARCH_OPTION: "D.finir la recherche s.curis.e comme moteur de recherche par d.faut",.. THREAT_OFF_STATE: "Alerte de s.curit..!",.. THREAT_OFF_MESSAGE: "Votre ordinateur est expos. aux menaces, mais nous pouvons vous aider.",.. AVFW_DIAL
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5041
                                                                                                                                                                            Entropy (8bit):5.416211301758333
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:W82DDbczNyMnf3MeFH+JDxk/zay9SIhFO8DF84sSbuoU0zDub9FONkd3V/oWRT:W34zwMfceFHSDxa1FcZbLONslgGT
                                                                                                                                                                            MD5:D3A0326AD337FA5B081C7AFF4E4BDFB4
                                                                                                                                                                            SHA1:4793AC98638429A732C67E6ED7D15004633F70CD
                                                                                                                                                                            SHA-256:7EC80830E9514A585DF452A683B44569EA1CE3EBB0EFF141871E51E438F26710
                                                                                                                                                                            SHA-512:1DE5CEEC1626769A89ECE44460328E2A68B313B9D0536C9E61AEFD1C5EA352B97C78ADF45B1DF3694E8B255ECEBF3F7F4270D71D838F1861908AF0D6B67979AA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Pregled...",.. DL_SCANNING_MESSAGE: "Pregledavamo va.e preuzimanje za svaki slu.aj.",.. DL_BLOCKED: "Preuzimanje je blokirano",.. DL_SCANED: "Preuzimanje je pregledano",.. SS_ON_STATE: "Sigurno pretra.ivanje",.. SS_FIX_MESSAGE: "Sjajno! Ove .emo promjene uvesti sljede.i put kada ponovno pokrenete preglednik.",.. SS_OFF_STATE: "Potrebna je akcija!",.. SS_OFF_MESSAGE: "Upozorenje! 1 od 10 pretraga sadr.i opasnu vezu.",.. SS_OFF_DIALOG_HEADER: "Dodajte ocjenu rizika rezultatima pretra.ivanja",.. SS_OFF_DIALOG_CONTENT: "Saznajte koliko je veza opasna prije nego .to kliknete na nju.",.. SS_SEARCH_OPTION: "Postavi Sigurno pretra.ivanje kao zadanu tra.ilicu",.. THREAT_OFF_STATE: "Sigurnosno upozorenje!",.. THREAT_OFF_MESSAGE: "Va.e je ra.unalo izlo.eno, ali mo.emo vam pomo.i.",.. AVFW_DIALOG_HEADER: "Isklju.eni su antivirusna za.tita i vatrozid",.. AVFW_DIALOG_CONTENT: "Oko 864 milijuna z
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5401
                                                                                                                                                                            Entropy (8bit):5.531960464670316
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cDlYr1MDbtVqXiZgRRGXtsXPG8sZT15INx7h6X9mwu9Dvymc+cE0AHmt:hZYHqXiL8y5WzN6gwuBKmzP5Hmt
                                                                                                                                                                            MD5:2F948E205E01DBA3E5E52FC66516A421
                                                                                                                                                                            SHA1:FA3DABAEBC4CCB2283993086BD537FFDEC6F20E5
                                                                                                                                                                            SHA-256:2B5609EE8D4A5748963DED07B9E4BACD925BF41BE2BF5BD4A2388BD34CF7C245
                                                                                                                                                                            SHA-512:B5A9B2C12A6EA6B0BBA28EC1A19A3C79A30A45A0FF965CBC61C1F4542EFF809B54337066E764684BFF724D961CC330CF1F35919B2C80EE79147D8BE374C6FB8C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Vizsg.lat...",.. DL_SCANNING_MESSAGE: "Biztons.ga .rdek.ben .tvizsg.ljuk a let.lt.tt f.jlt.",.. DL_BLOCKED: "Blokkolt let.lt.s",.. DL_SCANED: "Megvizsg.lt let.lt.s",.. SS_ON_STATE: "Biztons.gos keres.s",.. SS_FIX_MESSAGE: "Rendben. A b.ng.sz. k.vetkez. .jraind.t.sakor v.grehajtjuk ezeket a m.dos.t.sokat.",.. SS_OFF_STATE: "Beavatkoz.sra van sz.ks.g!",.. SS_OFF_MESSAGE: "Figyelem! Minden tizedik keres.s vesz.lyes hivatkoz.st tartalmaz.",.. SS_OFF_DIALOG_HEADER: "Vesz.lyess.gi besorol.sok megjelen.t.se a keres.si eredm.nyek mellett",.. SS_OFF_DIALOG_CONTENT: "Ismerje meg a hivatkoz.s vesz.lyess.gi besorol.s.t, miel.tt r.kattintana.",.. SS_SEARCH_OPTION: "A biztons.gos keres.s legyen az alap.rtelmezett keres.motor",.. THREAT_OFF_STATE: "Biztons.gi riaszt.s!",.. THREAT_OFF_MESSAGE: "Sz.m.t.g.pe sebezhet., de seg.thet.nk.",.. AVFW_DIALOG_HEADER:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5110
                                                                                                                                                                            Entropy (8bit):5.2250614647799924
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:ZDrBAuuEnhYJMxwmH77265IcUNspZPBDNMTix+wwyHTd9H7pmC2z/xR:drLnhYJ2wmHf2MIcUYQw1HJR74FxR
                                                                                                                                                                            MD5:613F88C68D2809F97F9FD6F87DB97F02
                                                                                                                                                                            SHA1:C0E86B3D76F630487A6A0C73DD1D49406D206EFF
                                                                                                                                                                            SHA-256:6F44EBC3163E3EFD327E2C5022102EF7EE733C309E6A21D885192A2FC111D9E1
                                                                                                                                                                            SHA-512:F4EBC8EE49D8FA677F8398F24121D0962E4DA78B53F8CBFF1B10A7B20AD4218B085EF9517DD15869AA4EB554A53DC8E49E663FAFD60CA2871151527E3BBC030F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Scansione in corso...",.. DL_SCANNING_MESSAGE: "Stiamo eseguendo la scansione dei download per verificare che siano sicuri.",.. DL_BLOCKED: "Download bloccato",.. DL_SCANED: "Download scansionato",.. SS_ON_STATE: "Ricerca sicura",.. SS_FIX_MESSAGE: "Perfetto! Apporteremo queste modifiche al riavvio del browser.",.. SS_OFF_STATE: "Intervento richiesto.",.. SS_OFF_MESSAGE: "Avviso. 1 ricerca su 10 contiene link pericolosi.",.. SS_OFF_DIALOG_HEADER: "Aggiungi le classificazioni dei rischi ai risultati di ricerca",.. SS_OFF_DIALOG_CONTENT: "Conosci la pericolosit. di un link prima di accedervi.",.. SS_SEARCH_OPTION: "Imposta la ricerca sicura come motore di ricerca predefinito",.. THREAT_OFF_STATE: "Avviso di sicurezza.",.. THREAT_OFF_MESSAGE: "Il computer . esposto a rischi, ma possiamo aiutarti.",.. AVFW_DIALOG_HEADER: "Antivirus e firewall sono disattivati",.. AVFW_DIALOG_CONTENT: "Dal 2005, circa
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6573
                                                                                                                                                                            Entropy (8bit):5.7257577861051265
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:NTUsvaiozLJ9h9yY4smsT7h0O71Kw1JFe:esv4J9HyY4smsT7h0O7PvE
                                                                                                                                                                            MD5:7970DCCF2A75017322A8A0D30FB86AA3
                                                                                                                                                                            SHA1:468EEDB0167833CCB3095D10DA3CD4E6C6174B67
                                                                                                                                                                            SHA-256:1042DD9E402EA14B9E210736B6CC829E1A0C27644F12EBF824D73711BCE64F8E
                                                                                                                                                                            SHA-512:A86B6F3086E17A8F8CAD0B011540700A9D28E9C28B8E8273996E6D2017D78188F14F49A402236393BF9E7799F2BC3D2BD64AEA83BE9AF3E009771DCA406254F0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "........",.. DL_SCANNING_MESSAGE: "..................................",.. DL_BLOCKED: ".............",.. DL_SCANED: "............",.. SS_ON_STATE: ".....",.. SS_FIX_MESSAGE: "....................................",.. SS_OFF_STATE: "..........!",.. SS_OFF_MESSAGE: "... 10 .. 1 ......................",.. SS_OFF_DIALOG_HEADER: "...................",.. SS_OFF_DIALOG_CONTENT: "..........................",.. SS_SEARCH_OPTION: ".......................",.. THREAT_OFF_STATE: ".........",
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5497
                                                                                                                                                                            Entropy (8bit):5.847978360180218
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:A4T4OfEAmKkUvLS/fDa8s9If8LNaSkXLwjk2XEgvR6z0O739OBqKkLHtNi:Bff7Jk3a8iNaSEKtODYBqKoNNi
                                                                                                                                                                            MD5:7B107B89F270CDFBE68D065104D3410E
                                                                                                                                                                            SHA1:15FECC05C253ADEE9973A583E743CF4D6026811B
                                                                                                                                                                            SHA-256:5C885A2108E53417E3C33FD28CC32C1EC83EBCCA64E5D043C330628AB6DAC447
                                                                                                                                                                            SHA-512:3E46BED37CA260521BE6F084EA14B3D2878A70315B0BA80DC8C28A1BF87AB1C2D85FF3CAAC4096CA2626E38F4185DEAA10817636EC91DA98094380377128181A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: ".. ....",.. DL_SCANNING_MESSAGE: "... .. ..... .. .....",.. DL_BLOCKED: "... ....",.. DL_SCANED: "... ....",.. SS_ON_STATE: ".. ..",.. SS_FIX_MESSAGE: "....! ..... .. .... .. ... ......",.. SS_OFF_STATE: "... .....!",.. SS_OFF_MESSAGE: "..! .. .. ... ... ... ... .. 1/10....",.. SS_OFF_DIALOG_HEADER: ".. ... .. ... .......",.. SS_OFF_DIALOG_CONTENT: ".... .. ... .... .. .......",.. SS_SEARCH_OPTION: ".. ... .. .. .... ..",.. THREAT_OFF_STATE: ".. .....!",.. THREAT_OFF_MESSAGE: "... .... ...... McAfee. .... . .....",.. AVFW_DIALOG_HEADER: "...... .
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4937
                                                                                                                                                                            Entropy (8bit):5.338664370900008
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:iith6b8IIs/ySd0vgZwxwud8eWgwbYeCCVKduaN3z559JBhoAsUnxUbE:J36nR1swuD8boN951hvsUnxYE
                                                                                                                                                                            MD5:908B64646BE9EA860FF28CA62CEA259D
                                                                                                                                                                            SHA1:511549293C2C332C506E1518C0BE2DBEA3D99C46
                                                                                                                                                                            SHA-256:EE6AA51B79C56B237DBD65BD2DD0A364A219294D178CC7293921543EEAD327D0
                                                                                                                                                                            SHA-512:BD7D9055FE87817B3D32383C3E245CD02BFD42EA6925A443B273ADCEA69806807AA0944A65DCD384044C60D8327DA51B3803C369625CA6CAEB7FEB12F52C6A0F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Skanner..",.. DL_SCANNING_MESSAGE: "Vi skanner nedlastingen for . v.re p. den sikre siden.",.. DL_BLOCKED: "Nedlasting blokkert",.. DL_SCANED: "Nedlasting skannet",.. SS_ON_STATE: "Sikkert s.k",.. SS_FIX_MESSAGE: "Flott! Vi skal gj.re disse endringene neste gang du starter nettleseren.",.. SS_OFF_STATE: "Handling kreves!",.. SS_OFF_MESSAGE: "Advarsel! 1 av 10 s.k inneholder en farlig kobling.",.. SS_OFF_DIALOG_HEADER: "Legg til risikovurderinger i s.keresultatene",.. SS_OFF_DIALOG_CONTENT: "Vit hvor farlig en kobling er, f.r du klikker p. den.",.. SS_SEARCH_OPTION: "Gj.re Sikkert s.k til standard s.kemotor",.. THREAT_OFF_STATE: "Sikkerhetsvarsel!",.. THREAT_OFF_MESSAGE: "Datamaskinen din er eksponert, men vi kan hjelpe deg.",.. AVFW_DIALOG_HEADER: "Antivirusbeskyttelsen og brannmuren er av",.. AVFW_DIALOG_CONTENT: "Omkring 864 millioner oppf.ringer med personopplysninger har havnet
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5046
                                                                                                                                                                            Entropy (8bit):5.29923659608503
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:IHFRCH1qpecUFhzJizV+kE1XGwRZYzg0u0Qu2OOkMCJuzXvu9odS+daUmh4:IHFRCVqpAFh4zV+kol56Q1EJ2vufCaL4
                                                                                                                                                                            MD5:0A0CD532F6553B3D545538405118FE96
                                                                                                                                                                            SHA1:6D0D4723131FE762BF5F8385AA943FA6AB4EF500
                                                                                                                                                                            SHA-256:1DFA69BA967AB4ADF08C4440523CAC4B9430227A7668A0A1AA0FC333775E16EA
                                                                                                                                                                            SHA-512:6A423AFA53F6A3EE7D9C1DC7CC89C26E9A9AD676D93DBD99C1FCD395A1B4B7A5AD92DD510F31B1AF48B1BC9787443B211FAD4F0E2285F827DE12EAE5349E8EB8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Scannen...",.. DL_SCANNING_MESSAGE: "Uw download wordt voor de veiligheid gescand.",.. DL_BLOCKED: "Download geblokkeerd",.. DL_SCANED: "Download gescand",.. SS_ON_STATE: "Beveiligd zoeken",.. SS_FIX_MESSAGE: "Fantastisch! Deze wijzigingen worden ge.mplementeerd wanneer u uw browser de volgende keer opnieuw start.",.. SS_OFF_STATE: "Actie vereist!",.. SS_OFF_MESSAGE: "Waarschuwing! 1 op de 10 zoekopdrachten bevat een gevaarlijke link.",.. SS_OFF_DIALOG_HEADER: "Voeg risicoclassificaties toe aan uw zoekresultaten",.. SS_OFF_DIALOG_CONTENT: "Weet hoe gevaarlijk een koppeling is voordat u erop klikt.",.. SS_SEARCH_OPTION: "Maak Beveiligd zoeken mijn standaardzoekmachine",.. THREAT_OFF_STATE: "Beveiligingswaarschuwing!",.. THREAT_OFF_MESSAGE: "Uw computer is blootgesteld, maar wij kunnen u helpen.",.. AVFW_DIALOG_HEADER: "Uw antivirus en firewall zijn uitgeschakeld",.. AVFW_DIALOG_CONTENT: "Sinds 2005
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5241
                                                                                                                                                                            Entropy (8bit):5.554898483368969
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:qUIwsXVPIcXdt1qJZHybN1qfWl9my9bpE3TiYv5YTKSjzxj4dsd9DFsxee7G6T9:q1wsXVgcHoZHu2OlqukURj4di5te7F
                                                                                                                                                                            MD5:36A6295576043C8E8265AE0B293F0278
                                                                                                                                                                            SHA1:71C85F04D2BB8A6EB4E1A44DFE0694E8D4CF9784
                                                                                                                                                                            SHA-256:F2A53E12CD5B1E7F5414C7BA50BE1C0E194FF8B24F441468F7B2DBE34F992F0A
                                                                                                                                                                            SHA-512:34E00B00652F486EE4618B7268E7DA31DF4B122983FF80DC6C9FAA3EE6A05FD1AECBD63F178BD739C11A5BF6261606D3EA29A93C9828B1CBD55473CA8DAC280F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Skanowanie...",.. DL_SCANNING_MESSAGE: "Na wszelki wypadek skanujemy pobierany plik.",.. DL_BLOCKED: "Pobieranie zablokowane",.. DL_SCANED: "Pobieranie przeskanowane",.. SS_ON_STATE: "Bezpieczne wyszukiwanie",.. SS_FIX_MESSAGE: ".wietnie. Zmiany zostan. wprowadzone po ponownym uruchomieniu przegl.darki.",.. SS_OFF_STATE: "Wymagane dzia.anie.",.. SS_OFF_MESSAGE: "Uwaga! 1 na 10 wyszukiwa. zawiera niebezpieczne ..cze.",.. SS_OFF_DIALOG_HEADER: "Dodaj oceny ..czy w wynikach wyszukiwania.",.. SS_OFF_DIALOG_CONTENT: "Dowiedz si., czy ..cze jest niebezpieczne, zanim je klikniesz.",.. SS_SEARCH_OPTION: "Ustaw Bezpieczne wyszukiwanie jako domy.ln. wyszukiwark.",.. THREAT_OFF_STATE: "Alert zabezpiecze.!",.. THREAT_OFF_MESSAGE: "Komputer jest nara.ony na zagro.enia, ale mo.emy Ci pom.c.",.. AVFW_DIALOG_HEADER: "Antywirus i zapora s. wy..czone.",.. AVFW_DIALOG_CONTENT: "Od 2005 r. bezpi
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5076
                                                                                                                                                                            Entropy (8bit):5.3456641309639785
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:hzqsY64tGeMe1EjJDQYz8VMntBYv4tBg9Wq90QuG:hWnjE7e1iJl44BgD9Z
                                                                                                                                                                            MD5:29C37461266F5EC54C912892D7DEA5BB
                                                                                                                                                                            SHA1:2027257CCEA215C5B26AC43556313A869ED9793F
                                                                                                                                                                            SHA-256:2D6742EFC60C9F941DD63D606C67415F98352F626DE4DCC21F9AD906C0634E65
                                                                                                                                                                            SHA-512:4184F473F42C1A5F255E755566B64F010B86D144D033DB6A2291DAD22967A2CE4F9954AE9CBD4FEA25DA25A2AC19A66A39AF7858D0C721C7B4668AB74A072E3A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Varrendo...",.. DL_SCANNING_MESSAGE: "Estamos varrendo o seu download apenas por seguran.a.",.. DL_BLOCKED: "Download bloqueado",.. DL_SCANED: "Downloads varridos",.. SS_ON_STATE: "Pesquisa segura",.. SS_FIX_MESSAGE: "Excelente! Implementaremos essas mudan.as na pr.xima vez que voc. reiniciar o navegador.",.. SS_OFF_STATE: "A..o necess.ria!",.. SS_OFF_MESSAGE: "Aviso! 1 em 10 pesquisas cont.m um link perigoso.",.. SS_OFF_DIALOG_HEADER: "Adicione classifica..es de risco aos seus resultados de pesquisa",.. SS_OFF_DIALOG_CONTENT: "Saiba qu.o perigoso . um link antes de clicar.",.. SS_SEARCH_OPTION: "Tornar a Pesquisa segura meu mecanismo de pesquisa padr.o",.. THREAT_OFF_STATE: "Alerta de seguran.a!",.. THREAT_OFF_MESSAGE: "Seu computador est. exposto, mas podemos ajud.-lo.",.. AVFW_DIALOG_HEADER: "Seu antiv.rus e sua firewall est.o desativados",.. AVFW_DIALOG_CONTENT: "Cerca de 864
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5194
                                                                                                                                                                            Entropy (8bit):5.346110251487307
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:L60E2K+GRZAEbZoyh5Mj+WkfVptFa9GqDXyImC:L6SKhDAmlk+bVLFaXDz
                                                                                                                                                                            MD5:74A1FEF9FD994E5C29BCD75A5D10A1FE
                                                                                                                                                                            SHA1:0405794450F059415289FA709D1EAC5798F4D893
                                                                                                                                                                            SHA-256:67137ADF5237EAF8D9676D1076FF52875F65F98EC0FE91930B3AD1D79B063F76
                                                                                                                                                                            SHA-512:C4F7A61292BAED702B1536E1D74791F8B6BE89F9D3886A2579DFF3B76667795DCCD001B2724658D822C09007500815B8BB05B3EE8BD9B26DDBE1A397D2E8CD41
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "A analisar...",.. DL_SCANNING_MESSAGE: "Estamos a analisar a sua transfer.ncia para garantir a m.xima seguran.a.",.. DL_BLOCKED: "Transfer.ncia bloqueada",.. DL_SCANED: "Transfer.ncia analisada",.. SS_ON_STATE: "Pesquisa segura",.. SS_FIX_MESSAGE: ".timo! Aplicaremos esta altera..es quando reiniciar o browser.",.. SS_OFF_STATE: "A..o necess.ria!",.. SS_OFF_MESSAGE: "Aten..o! 1 em cada 10 pesquisas cont.m uma liga..o perigosa.",.. SS_OFF_DIALOG_HEADER: "Adicione classifica..es de risco aos seus resultados de pesquisa",.. SS_OFF_DIALOG_CONTENT: "Conhe.a o n.vel de perigo de uma liga..o antes de clicar.",.. SS_SEARCH_OPTION: "Tornar a Pesquisa Segura o meu motor de pesquisa predefinido",.. THREAT_OFF_STATE: "Alerta de seguran.a!",.. THREAT_OFF_MESSAGE: "O seu computador est. desprotegido, mas podemos ajudar.",.. AVFW_DIALOG_HEADER: "O seu antiv.rus e firewall est.o desativados",
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7499
                                                                                                                                                                            Entropy (8bit):5.002826493531936
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:J8/c1QuytDV2s488V+TtWHkWUIU9RyVto:J8/c1Qu+DwgWlUf9AVm
                                                                                                                                                                            MD5:0B00B4F1DF53D7869D97AE55F5FD9F30
                                                                                                                                                                            SHA1:B9828063943585D69A78C0A5163816F9749882C3
                                                                                                                                                                            SHA-256:2D41BB850FEE8E3AF133D204ED946BA2383888017AE50326F2BA716F390DADD7
                                                                                                                                                                            SHA-512:1E21CB4033310B38CEF36FC18A5D10ED6A251F47EF5EBDD40C4E2777125E32E90AABCFDD10D6E2EE69CBA583C8400E498B40A64BDAAA93CCF5DD9C5D9F837015
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "...........",.. DL_SCANNING_MESSAGE: "........... ............ .........",.. DL_BLOCKED: "............. ........:",.. DL_SCANED: "......... ........:",.. SS_ON_STATE: ".......... .....",.. SS_FIX_MESSAGE: ".......! ......... ..... ....... ... ......... ........... .........",.. SS_OFF_STATE: "......... ........!",.. SS_OFF_MESSAGE: "......... . ........... ....... ........ ...... .... ....... .......",.. SS_OFF_DIALOG_HEADER: "........ ....... ..... . .......... ......",.. SS_OFF_DIALOG_CONTENT: "..... ......... .. ...... ......., ......... ... .......",.. SS_SEARCH_OPTION: "....... ........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5398
                                                                                                                                                                            Entropy (8bit):5.643833908825308
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:jTm1b9h9okCKuoXx9byC6n+Ih6hXV7ILNadt6rDSczFk9HVXrfj6n:jTob/9SKuqbyC6nYhScSicBk5Bfj6n
                                                                                                                                                                            MD5:3655FD9C38BBE8F3A1FFD73062DD9FE2
                                                                                                                                                                            SHA1:B40F7125588BD8A3196840F93B683A54FF6651FF
                                                                                                                                                                            SHA-256:9CF3E0F6E0E4CF5CD638AB02AD388B9234F7ED4FF2FAFDE45CCE62A69D1ACBB1
                                                                                                                                                                            SHA-512:7498900E9B263C2AC9F48162B99F3191F16F8E936D074E91A62CCA9B961F2753DE3F8EB4CB91E8F49C9388E69C9ED1814D25C4E63B88BEF6715B3E5F9760ED17
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Kontroluje sa...",.. DL_SCANNING_MESSAGE: "Stiahnut. s.bor sa kontroluje, len pre istotu.",.. DL_BLOCKED: "S.ahovan. s.bor bol zablokovan.",.. DL_SCANED: "S.ahovan. s.bor bol skontrolovan.",.. SS_ON_STATE: "Zabezpe.en. vyh.ad.vanie",.. SS_FIX_MESSAGE: "Skvel.! Zmeny sa uskuto.nia pri najbli..om re.tartovan. prehliada.a.",.. SS_OFF_STATE: "Treba kona.!",.. SS_OFF_MESSAGE: "Upozornenie: 1 z 10 vyh.ad.van. obsahuje nebezpe.n. odkaz.",.. SS_OFF_DIALOG_HEADER: "Pridanie hodnoten. rizika k v.sledkom vyh.ad.vania",.. SS_OFF_DIALOG_CONTENT: "Sk.r ne. kliknete na prepojenie, mali by ste vedie., .i je nebezpe.n..",.. SS_SEARCH_OPTION: "Nastavi. slu.bu Zabezpe.en. vyh.ad.vanie ako predvolen. vyh.ad.vac. n.stroj",.. THREAT_OFF_STATE: "Upozornenie zabezpe.enia:",.. THREAT_OFF_MESSAGE: "V.. po..ta. je v.ohrozen., ale m..eme v.m pom.c..",.. AVFW_DIALOG_HEA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5115
                                                                                                                                                                            Entropy (8bit):5.416583517368563
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:a7um49Rmkzg/G5dK+J8tkaUnSlBS2DFA4s+roJGEUuzvYb9NKNvt3w/yTK:3VNzgOWS8ttFFV/b3KNlgqTK
                                                                                                                                                                            MD5:1256512BE1EFBDC68E879DC97D4FA564
                                                                                                                                                                            SHA1:DB86F80BA7CDFC48EE4D69745258CB2C197814E7
                                                                                                                                                                            SHA-256:46A31754958D949387AFB60C5E454C797D0958A58965C7E429C528F140A7C42C
                                                                                                                                                                            SHA-512:1195A75953C0A3031C37EEB33441057AC3689CD108EC29B25A024C90B9EB64E6A90309A8A6C12A722E149C88A356AADB48D17AE37D741149290DB0A5A0052ECA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Skeniranje...",.. DL_SCANNING_MESSAGE: "Skeniramo preuzeti sadr.aj radi va.e bezbednosti.",.. DL_BLOCKED: "Blokirano preuzimanje",.. DL_SCANED: "skeniranje preuzimanja",.. SS_ON_STATE: "Bezbedna pretraga",.. SS_FIX_MESSAGE: "Odli.no! Ove izmene .e biti unete kada slede.i put pokrenete pregleda..",.. SS_OFF_STATE: "Potrebno je preduzeti odre.ene korake!",.. SS_OFF_MESSAGE: "Upozorenje! Svaka deseta pretraga sadr.i opasnu vezu.",.. SS_OFF_DIALOG_HEADER: "Dodajte ocene rizika u rezultate pretrage",.. SS_OFF_DIALOG_CONTENT: "Saznajte koliko je neka veza opasna pre nego .to kliknete na nju.",.. SS_SEARCH_OPTION: ".elim da bezbedna pretraga bude moj podrazumevani pretra.iva.",.. THREAT_OFF_STATE: "Bezbednosno upozorenje!",.. THREAT_OFF_MESSAGE: "Va. ra.unar je izlo.en pretnjama, ali mi vam mo.emo pomo.i.",.. AVFW_DIALOG_HEADER: "Antivirusni program i za.titni zid su isklju.eni",.. AVFW
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4882
                                                                                                                                                                            Entropy (8bit):5.406741594701944
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:fl+hIZSmigy7tw5va0ZPYVhH9lSIkMKJU9xIGRQtVRW:d+hIZC7twtn8HQJJUQGRIW
                                                                                                                                                                            MD5:ED90CCC22D94259863411386C6DE31D9
                                                                                                                                                                            SHA1:5215A30E75B0B24B1C346FDE2E1841A85FA16F4D
                                                                                                                                                                            SHA-256:C014BF7588A24566A02ADC04E7BC656CAA655F374E61AE97C4A4C581716F660E
                                                                                                                                                                            SHA-512:1A377928F0DE59F1999D0745412C6786C06471A29E32892DC52C43748513A80BF269E343177CD686C56E62DF9B4F6C6824D2F4F21A35E91F0044B1BA1CA275C4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Genoms.ker...",.. DL_SCANNING_MESSAGE: "Vi genoms.ker h.mtningen f.r s.kerhets skull.",.. DL_BLOCKED: "H.mtning blockerad",.. DL_SCANED: "H.mtning genoms.kt",.. SS_ON_STATE: "S.ker s.kning",.. SS_FIX_MESSAGE: "Perfekt. Vi utf.r .ndringarna n.sta g.ng du startar om din webbl.sare.",.. SS_OFF_STATE: ".tg.rd kr.vs!",.. SS_OFF_MESSAGE: "Varning! 1 av 10 s.kningar inneh.ller en farlig l.nk.",.. SS_OFF_DIALOG_HEADER: "L.gg till riskklassificering i dina s.kresultat",.. SS_OFF_DIALOG_CONTENT: "Du f.r veta hur farlig en l.nk .r innan du klickar p. den.",.. SS_SEARCH_OPTION: "V.lj S.ker s.kning som standardalternativ f.r s.kmotorer",.. THREAT_OFF_STATE: "S.kerhetsvarning!",.. THREAT_OFF_MESSAGE: "Datorn .r utsatt f.r risk, men vi kan hj.lpa till.",.. AVFW_DIALOG_HEADER: "Antivirus och brandv.ggen .r inaktiverade",.. AVFW_DIALOG_CONTENT: "Cirka 864 miljoner personliga da
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5273
                                                                                                                                                                            Entropy (8bit):5.486084661941598
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:THxCtJRQDY8NoBGZOpo/n2ovqXm/IwjfdZ1zT4x9hEKHCnAzvjUB:7xCtANoBGnR/TdZJ4xEsvU
                                                                                                                                                                            MD5:16DD9886CC8A8E2D47F02CF6B5963C3F
                                                                                                                                                                            SHA1:B05E5AF94B50984FC4BF4285FA3D61CB3ABA881E
                                                                                                                                                                            SHA-256:4F35D4163571622E74B655567B6AA0A3716D2DAC09653F57C873504BFFCD8B90
                                                                                                                                                                            SHA-512:7C8A194D5ACFA94ADAA7B3C5C3F45A40E13EA1515D2D105774E759630263472EA96962F741440CCFA896184DC42786420DB8109F5EE7E6535377C0948EED3DBD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: "Taran.yor...",.. DL_SCANNING_MESSAGE: "Her ihtimale kar.. indirmenizi tar.yoruz.",.. DL_BLOCKED: ".ndirme engellendi",.. DL_SCANED: ".ndirme tarand.",.. SS_ON_STATE: "G.venli Arama",.. SS_FIX_MESSAGE: "Harika! Taray.c.y. bir sonraki sefer ba.latt...n.zda bu de.i.iklikleri uygulayaca..z.",.. SS_OFF_STATE: "Eylem gerekli!",.. SS_OFF_MESSAGE: "Dikkat! 10 aramadan biri tehlikeli ba.lant. i.erir.",.. SS_OFF_DIALOG_HEADER: "Arama sonu.lar.n.za risk de.erlendirmeleri ekleyin",.. SS_OFF_DIALOG_CONTENT: "T.klamadan .nce bir ba.lant.n.n ne kadar tehlikeli oldu.unu bilin.",.. SS_SEARCH_OPTION: "G.venli Arama'y. varsay.lan arama motorum yap",.. THREAT_OFF_STATE: "G.venlik Uyar.s.!",.. THREAT_OFF_MESSAGE: "Bilgisayar.n.z savunmas.z ancak size yard.mc. olabiliriz.",.. AVFW_DIALOG_HEADER: "Vir.sten koruma ve g.venlik duvar. kapal.",.. AVFW_DIALOG_CONTENT: "2005'ten
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4673
                                                                                                                                                                            Entropy (8bit):6.276205522230196
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:THIWI0hyh/2vKsPMP0VIQUuGOPpBM9Yc81vzNcS:T5Qh/Yq9joBMGz1p3
                                                                                                                                                                            MD5:E66D37AAB885C74B33FD5071D791AE2E
                                                                                                                                                                            SHA1:339AD07D34524474667AF8E6986BEECE43EA4521
                                                                                                                                                                            SHA-256:632988C5A468576BECF2BC1C48EF2BDD22CA44B64001A7BB8273E36F5E2C46F6
                                                                                                                                                                            SHA-512:61BCC0A4989CD0A290CBF78A05144781DFFCA7695E77D1151446CF4DAB2470275764A48CFE203990EC4474268810773FF1242EEABA7AA74293200BDAE0ED8ECB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: ".......",.. DL_SCANNING_MESSAGE: "..................",.. DL_BLOCKED: "......",.. DL_SCANED: "......",.. SS_ON_STATE: "....",.. SS_FIX_MESSAGE: "...! ....................",.. SS_OFF_STATE: "....!",.. SS_OFF_MESSAGE: "...1/10 ............",.. SS_OFF_DIALOG_HEADER: "...........",.. SS_OFF_DIALOG_CONTENT: "...................",.. SS_SEARCH_OPTION: ".............",.. THREAT_OFF_STATE: ".....",.. THREAT_OFF_MESSAGE: "...................",.. AVFW_DIALOG_HEADER: "............",.. AVFW_DIALOG_CONTENT: ". 2005 ....... 8.64 ..................<br/
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4704
                                                                                                                                                                            Entropy (8bit):6.287282072477445
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:+54tUIE58+sUHLz4111bAmwqkFvHOVJXBxC7RP9LX9Qom/6tTh:+utkVAdAm8uf0X6/StV
                                                                                                                                                                            MD5:0D802B12B61EB7530F3D7A4D422E8D58
                                                                                                                                                                            SHA1:9E1345A686E7418E769315A31526FE80062AFE23
                                                                                                                                                                            SHA-256:FC46CFEC7591898641E8BA53D247F6DAEBD01432AA65ABD9DD48B41BA9E3D9A7
                                                                                                                                                                            SHA-512:D448CDBCA3F4387370E08218BAB8670D22DB73E7D013743374053D8F903FCC9235B6DAE5E6C91CE1C71FE91CE35F9B2BEE0B6CDEDF8DAB2772D65AB5CB84D542
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrCheckList_ = {.. DL_SCANNING_STATE: ".......",.. DL_SCANNING_MESSAGE: "..............",.. DL_BLOCKED: ".....",.. DL_SCANED: ".....",.. SS_ON_STATE: "....",.. SS_FIX_MESSAGE: ".......................",.. SS_OFF_STATE: ".....",.. SS_OFF_MESSAGE: "...10 ..... 1 ........",.. SS_OFF_DIALOG_HEADER: ".............",.. SS_OFF_DIALOG_CONTENT: "..................",.. SS_SEARCH_OPTION: "...............",.. THREAT_OFF_STATE: "......",.. THREAT_OFF_MESSAGE: "...................",.. AVFW_DIALOG_HEADER: "...........",.. AVFW_DIALOG_CONTENT: ". 2005 ...... 8 . 6 . 4 ...................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1510
                                                                                                                                                                            Entropy (8bit):5.7308486902000615
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTt2GGq0IQDhhlGGqg4o1GGGqUdVkrN0/Fq9eA0dmQAjaha:w3q0Fhl3qg71G3qUvkrNeq9f0dm7Ca
                                                                                                                                                                            MD5:952AC00977A6A75229831F51439FBED3
                                                                                                                                                                            SHA1:D0CD40469B603D1880B6C40D187D98620E3D9F3E
                                                                                                                                                                            SHA-256:9132DD6D4BA0C2911D90E7E3FBD6F2E09422CC861C3D85DDB0492E4E717002CD
                                                                                                                                                                            SHA-512:72B546181A83EAC8D29864456B19237FE9B0EECEA09AF63C7100B3463F157027F4BACA6F85FDF279625E3158508F7A1E97F45EB4FA88A37293B26A40FD2F8356
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Z.skejte bezplatnou ochranu p.i proch.zen. internetu od spole.nosti McAfee kliknut.m na mo.nost {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Povolit roz...en.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "Pomoc. mo.nosti {0} zapnete tyto funkce vy... ochrany: Bezpe.n. hled.n. McAfee., Blokov.n. reklam a Blokov.n. sledov.n..",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Povolit roz...en.",.. ADBLOCK_SEARCH_WARNING_CONTENT: "Pomoc. mo.nosti {0} budete d.le chr.n.ni online d.ky t.mto funkc.m vy... ochrany: Bezpe.n. hled.n. McAfee., Blokov.n. reklam a Blokov.n. sledov.n..",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Ponechat zm.ny",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "Pomoc. mo.nosti {0} programu McAfee. WebAdvisor zapnete tyto funkce vy... ochrany: Bezpe.n. hled.n. McAfee., Blokov.n. reklam a Blokov.n. sledov.n..",.. ADBLOCK_PERMISSION_ADDED_CONT
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1414
                                                                                                                                                                            Entropy (8bit):5.5444424224442725
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTEz6tBWYCISc5ciWzCISNOFBWYCISrrVpz92w56WYaF4glU8:U4nCISc5cvCISNOFnCISrxRmWnF418
                                                                                                                                                                            MD5:7CCDD6A86B6C29F577C45DD7821028EE
                                                                                                                                                                            SHA1:EE43BAA8BC9579B3885DB7F256E5F3B3E6534FC3
                                                                                                                                                                            SHA-256:CF42402BCCA3F4B9D934C26076995CE51AF247CB737F5A1FFB624581F36752F4
                                                                                                                                                                            SHA-512:DBB7C3D54A8120B48E89A938FBC2B39A11B5CCDEAD2533BFF8E3AD0B1D7A8BC000DD73844B826115E22191C09778AE2A500BF8E21CA754E2C24FE76D9DA899F8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Hent den gratis webbeskyttelse fra McAfee ved at klikke p. {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Aktiv.r udvidelse",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} for at sl. disse ekstra sikkerhedsfunktioner fra McAfee. til: sikker s.gning, blokering af reklamer og blokering af sporingsfiler.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Aktiv.r udvidelse",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} for fortsat at v.re beskyttet online med disse ekstra sikkerhedsfunktioner fra McAfee.: sikker s.gning, blokering af reklamer og blokering af sporingsfiler.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Behold .ndringer",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor for at sl. disse ekstra sikkerhedsfunktioner fra McAfee. til: sikker s.gning, blokering af reklamer og blokering af sporingsfiler.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Tillad",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Ak
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1494
                                                                                                                                                                            Entropy (8bit):5.514748469930225
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTjZ+CqIYh/aCCqIYVdQvTMzTIAc7HQmKnCqIY4DMEIWljVnARzSQd:zZ+lxVlxVebMzTEQmKnlx4DO+JnXQd
                                                                                                                                                                            MD5:222E72A8FD24B4BD56C3B83756348D44
                                                                                                                                                                            SHA1:D67E9B10B0B4D008B96615F8FB5AEF86300E414B
                                                                                                                                                                            SHA-256:ACC453C349AE57B5073CA8F30C6707EC99B52F21E81F11B941D8FEC9DB62ED15
                                                                                                                                                                            SHA-512:AC1EFD688C437214B245EF08583AEED49B117101BC293FC3FA01D33F80CC9CBDA534D6C27CA0E0F3F1B8224D25D8909721C2A03C8A896BB5CC3EB8FEFB63FA49
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Nutzen Sie den kostenlosen Web-Schutz von McAfee, indem Sie auf "{0}" klicken.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Erweiterung aktivieren",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "Klicken Sie auf "{0}", um die folgenden Funktionen des zus.tzlichen Schutzes zu nutzen: McAfee. Sichere Suche, Ad-Blockierung und Tracker-Blockierung.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Erweiterung aktivieren",.. ADBLOCK_SEARCH_WARNING_CONTENT: "Klicken Sie auf "{0}", um weiterhin mit den folgenden Funktionen des zus.tzlichen Schutzes online gesch.tzt zu bleiben: McAfee. Sichere Suche, Ad-Blockierung und Tracker-Blockierung.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: ".nderungen beibehalten",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "Klicken Sie f.r McAfee. WebAdvisor auf "{0}", um die folgenden Funktionen des zus.tzlichen Schutzes zu aktivieren: McAfee. Sichere Suche, Ad-Blockierung und Tracker-Blockierung.",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2138
                                                                                                                                                                            Entropy (8bit):5.217917771128103
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTYCoYrWTMeJ3P/oYeITMeJ3Pq2dnzgWTMeJ3P+PPvKoYC0EDdX0y2wyilhXphz:TWRpEIRpq2dzgWRp+Pt0EDdZhB
                                                                                                                                                                            MD5:F480CAFB6E6AB3C73664518C7F6DCE08
                                                                                                                                                                            SHA1:BA22771FA3F1CA35A9E41CC9BECD0C1768FCC3A1
                                                                                                                                                                            SHA-256:CC51D88615DA148FBF5396B2A98B3195BC709536C9DA6812A9C330D4B326CE59
                                                                                                                                                                            SHA-512:EE17EE494FAEDB59D22F4D543BA1521637B460D39B82B2EE00452DACB56DA529694FC5747DE300155C5ACEFCC3462B04F628A5B6C4E87B4F198A8362FCF7DF93
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "......... ...... ......... ... .. McAfee ........ .... ... {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "............ .........",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} ... .. .............. ..... ... ........... ......... ..........: ....... ........., ........... ........... ... ........... .......... ... McAfee..",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "............ .........",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} ... .. ........... ........ online .. ..... ... ........... ......... ..........: ....... ........., ........... ........... ... ........... .......... ...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1249
                                                                                                                                                                            Entropy (8bit):5.490467303745762
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTBv4lHkVKlHNEAkulHrRH/T5fLCOPmK:V4lHkVKlHNpkulHrRH/ht
                                                                                                                                                                            MD5:BB4BB22B690B376D8929C2CC25BF2B12
                                                                                                                                                                            SHA1:14E7C6B2EDCEF13331C60FA6DE88F42A431C9EB0
                                                                                                                                                                            SHA-256:5D4B6883689465D1D2535FEC8177B798DCC34743AFE22DB065C37FB43C5F1BBF
                                                                                                                                                                            SHA-512:196B700246267E0ABD861566232A698BD3F2B82CDB2EF4CA42EEA7F81B376A3B02983AC4841B489A125EBB9B0262ECEBA570601A30A39E824AA86B9821AEB645
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Get your free web protection from McAfee by clicking {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Enable extension",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} to turn on these Added Protection features: McAfee. Secure Search, Ad Blocker and Tracker Blocker.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Enable extension",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} to continue staying safe online with these Added Protection features: McAfee. Secure Search, Ad Blocker and Tracker Blocker.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Keep changes",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor to turn on these Added Protection features: McAfee. Secure Search, Ad Blocker and Tracker Blocker.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Allow",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Enable extension",.. CHROME_ENABLEMENT_GUIDE_CONTENT_1: "to finish setting up WebAdvisor.",.. CHROME_ENABLEMENT_GUIDE_C
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1447
                                                                                                                                                                            Entropy (8bit):5.489080845620684
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT81my6MaXBldRzVenBldR+MQOAz/HQ2BldRiud91QHIc0x81mHkysdN:M1m/MaRlXVeBlKMQOAz/HZleudEr0O1H
                                                                                                                                                                            MD5:F5976C18C8AB9C484A9FB7FA7B785EDE
                                                                                                                                                                            SHA1:318CF0881E841E3154F8A82CCC6E682E28B5C87D
                                                                                                                                                                            SHA-256:7B3A200EC1EBEFB6433B4E1F6CDFC53AA9E232379B2765714EC9DA7F3EC727E1
                                                                                                                                                                            SHA-512:CDDFDFB566446CD2DBB4B5BC457B4C42BD87B699A26ECC2A186BE0BEDC7830D123FB1023D42340FF7451F2F0B45246AF646D90BE5E592DC6E2E1B308862E0A04
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Disfrute de la protecci.n web gratuita de McAfee haciendo clic en {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Habilitar extensi.n",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} para activar estas funciones de Protecci.n a.adida: B.squeda segura, Bloqueador de anuncios y Bloqueador de rastreadores de McAfee..",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Habilitar extensi.n",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} para seguir estando protegido en Internet con estas funciones de Protecci.n a.adida: B.squeda segura, Bloqueador de anuncios y Bloqueador de rastreadores de McAfee..",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Conservar cambios",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} WebAdvisor de McAfee. para activar estas funciones de Protecci.n a.adida: B.squeda segura, Bloqueador de anuncios y Bloqueador de rastreadores de McAfee..",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Permitir",.. CHR
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1434
                                                                                                                                                                            Entropy (8bit):5.478348436291751
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTBWmy6caQmDdJVe9mDdsMQOAzdmDdQ0a0yLh1mH3/:Em/caQs/Ve9s6MQOAzdsuPRLh1mH3/
                                                                                                                                                                            MD5:347D21A367591A956DDD60421EC6F9D1
                                                                                                                                                                            SHA1:E7DD98B8B423C4FF845F0791D850AB37F7147A05
                                                                                                                                                                            SHA-256:CC3318BF5006AFEB6462820BC4EF081908200C76E929F1DB7B066AD1437708A7
                                                                                                                                                                            SHA-512:73DCFAD2F11DD6097A0657BB4A455C09370A02CFB4524B33DE27018712AF6CC0056A067DE891EF4EB5201EFFCF1693A182D84C28AB7567E57DD4E635BC5027C4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Obtenga su protecci.n web gratuita de McAfee haciendo clic en {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Activar extensi.n",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} para habilitar estas funciones de Protecci.n Adicional: B.squeda segura de McAfee., Bloqueador de anuncios y Bloqueador de rastreadores.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Activar extensi.n",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} para continuar seguro en l.nea con estas funciones de Protecci.n Adicional: B.squeda segura de McAfee., Bloqueador de anuncios y Bloqueador de rastreadores.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Conservar cambios",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor para habilitar estas funciones de Protecci.n Adicional: B.squeda segura de McAfee., Bloqueador de anuncios y Bloqueador de rastreadores.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Permitir",.. CHROME_ENABLEMENT
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1371
                                                                                                                                                                            Entropy (8bit):5.523574079075182
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTigoQ6AHPXTSgVCPP3TOcJ9PgTKTSzogH07RQuzSZCsQJwzimvd:PZtXbVQ3qcJt3+zVUVXXN2mq
                                                                                                                                                                            MD5:2BD1EFE6A5E9A74308673F6A3E391584
                                                                                                                                                                            SHA1:D928B2C7863AB95F81A3BEE96EDA913E92FE3417
                                                                                                                                                                            SHA-256:E7119B544C60B9A506393749ADB8705591F95886282D0537875A954C3AD39F37
                                                                                                                                                                            SHA-512:BB9BC19573534ED30D489A33CE2718DF92568EE565A55BEA8A8E453AE40A6498A7A4AF8325FBDD51EBFB8E751B1C68D084B794192C82D59E124A2029C5551EFE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Hanki McAfeen verkkosuojaus maksutta napsauttamalla {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Ota laajennus k.ytt..n",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0}, jotta voit k.ytt.. n.it. lis.suojausominaisuuksia: McAfeen. suojattu haku, mainosten esto ja seurannan esto.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Ota laajennus k.ytt..n",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0}, jotta pysyt jatkossakin turvassa verkossa n.ill. lis.suojausominaisuuksilla: McAfeen. suojattu haku, mainosten esto ja seurannan esto.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "S.ilyt. muutokset",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0}, ett. McAfee. WebAdvisor ottaa n.m. lis.suojausominaisuudet k.ytt..n: McAfeen. suojattu haku, mainosten esto ja seurannan esto.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Salli",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Ota laajennus k.ytt..n",.. CHROME_ENABLEMENT_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1453
                                                                                                                                                                            Entropy (8bit):5.47242197014462
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTBU39MC7soZ8JyVt0oZ8JVuh6oZ8JTm6Tb41mgEyNlThDn+:S7BasV3aT6HahmKU1PXThD+
                                                                                                                                                                            MD5:9A6724E82BD656390E9B94EBDC18DA14
                                                                                                                                                                            SHA1:D3F5E2C9E392BF0BBCE501144AF230A748B20A1F
                                                                                                                                                                            SHA-256:CFD4418961A4257D0A082198CDD6E82B1ACB274B93C2BE17436B8EFBDE5CD759
                                                                                                                                                                            SHA-512:6C94DFE2ACA585C1DE0C2D365D6D660D55E0757CC9B6614E2E090EC2B40A49ABABCB60BBF5D59D70AB74A0504E098146627B42C682840BA01B8108EE9F79CD4B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Obtenez votre protection Web gratuite de McAfee en cliquant sur {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Activer l'extension",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} pour activer ces fonctions de protection accrue: recherche s.curis.e McAfee., Bloqueur de publicit. et Bloqueur de localisateur.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Activer l'extension",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} pour continuer . .voluer en ligne en toute s.curit. gr.ce . ces fonctions de protection accrue: recherche s.curis.e McAfee., Bloqueur de publicit. et Bloqueur de localisateur.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Maintenir les changements",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor pour activer ces fonctions de protection accrue: recherche s.curis.e McAfee., Bloqueur de publicit. et Bloqueur de localisateur.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Autoriser
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1510
                                                                                                                                                                            Entropy (8bit):5.50151203088086
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTCKMC7mZ8yHVt2ZGNZ8ysMQu0Z8yQjSFbV+bzFtWrkzkIRah:yq7ma0VwSa7MQu0apeFMpmcR0
                                                                                                                                                                            MD5:9B2A8AB4F1BAE9902B78E0F3F5D4E232
                                                                                                                                                                            SHA1:E7189231932D2D0ED26074EBADCA8A8FF08B9EBB
                                                                                                                                                                            SHA-256:ABF2D6A213F3B0C28AE5397727E1CAEA4A7C54FC63CEE72C89E8428458E04D88
                                                                                                                                                                            SHA-512:0E5ACF8F48C5FAB0FC39F6BA4B2FA4F419C22E10B190DC272EA32A1EBFCE5F509636A2C78DE31EE21CDC0A439C5C4AC402602774AC5D95EF5EE2ABC8270B00B5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "B.n.ficiez de la protection web gratuite de McAfee en cliquant sur {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Activer l'extension",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} pour activer ces fonctionnalit.s de Protection renforc.e.: Recherche s.curis.e McAfee., Bloqueur de publicit.s et Bloqueur de trackers.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Activer l'extension",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} pour continuer . .tre prot.g. en ligne avec ces fonctionnalit.s de Protection renforc.e.: Recherche s.curis.e McAfee., Bloqueur de publicit.s et Bloqueur de trackers.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Conserver les modifications",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor pour activer ces fonctionnalit.s de Protection renforc.e.: Recherche s.curis.e McAfee., Bloqueur de publicit.s et Bloqueur de trackers.",.. ADBLOCK_PERMISSION_ADDED_CONTENT
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1402
                                                                                                                                                                            Entropy (8bit):5.615778989371223
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HThh5mCPPDSIuREwP3ycRCCPPDmetuqELFbiFCsr1:Rh5mCPPDSI6xP3ycRCCPPDm6pELFOFhR
                                                                                                                                                                            MD5:13B4643F485BA6D7CEA00A60F19494C2
                                                                                                                                                                            SHA1:809DA37950B3908776DFFEA07AA923885CB99E00
                                                                                                                                                                            SHA-256:6E6A185CF72F5553AC9F4671351967CB241E5289AEAD350D664859A961C4E0FD
                                                                                                                                                                            SHA-512:EFF88C2DEE3A0C7A74A7C458EBE1AFA67B8D133EFFF1FC2E4FCD396B723A3D720ED03F05DD08CCD8D9E6673410492F38B27583E19B72865A57A5BF3EE78A1112
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Dobijte svoju besplatnu web za.titu od McAfee-a klikom na {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Omogu.i pro.irenje",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} da biste uklju.ili ove funkcije za dodatnu za.titu: McAfee. Sigurna pretraga, Blokada oglasa i blokada alata za pra.enje.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Omogu.i pro.irenje",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} kako biste nastavili biti sigurni na mre.i s ovim dodatnim zna.ajkama za.tite: McAfee. Sigurna pretraga, Blokada oglasa i blokadu alata za pra.enje.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Spremi promjene",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. da biste uklju.ili ove funkcije za dodatnu za.titu: McAfee. Sigurna pretraga, Blokada oglasa i blokada alata za pra.enje.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Odobri",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Omogu.i pro.irenje",.. CHROME_E
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1518
                                                                                                                                                                            Entropy (8bit):5.680219099732828
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTt3WD/Pwd03L7mtPsJePwd0kYGc8hQwde/WCpeT4zAsjWE+p71:5EP20bStUwP20kYGcIQ2e/JYeAsyE+Z1
                                                                                                                                                                            MD5:CDA34B94F6482896BE2433B1FE169230
                                                                                                                                                                            SHA1:013647E9561364278A9BC63702CD816D0581A9E0
                                                                                                                                                                            SHA-256:26089964398D8A35A393AA3E3558D6F640FBEC25D9B60C543D20AFF2BFCBA5BF
                                                                                                                                                                            SHA-512:8A47BE0BFE1E2BD7D845FFDC98495AEB29AD1FE81930C4741B87CB5988EB7A2FA2493A8EB0AD764139076E8B3778E8E70DEAAB07882C412B9F4ACED9CB9961EB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "A McAfee ingyenes webes v.delm.nek ig.nybe v.tel.hez kattintson a(z) {0} elemre.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "B.v.tm.ny enged.lyez.se",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} a tov.bbi v.delmi funkci.k, a McAfee. biztons.gos keres.s, a hirdet.sblokkol.s .s a k.vet.blokkol.s bekapcsol.s.hoz.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Enged.lyezze a b.v.tm.nyt",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0}, hogy tov.bbra is biztons.gban legyen online a tov.bbi v.delmi funkci.k, a McAfee. biztons.gos keres.s, a hirdet.sblokkol.s .s a k.vet.blokkol.s r.v.n.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: ".rizze meg a m.dos.t.sokat",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0}, hogy a McAfee. WebAdvisor bekapcsolja a hozz.adott v.delmi funkci.kat a McAfee. biztons.gos keres.st, a hirdet.sblokkol.st .s a k.vet.blokkol.st.",.. ADBLOCK_PERMISSION_ADDE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1405
                                                                                                                                                                            Entropy (8bit):5.465869446781161
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT1z0nFTVKnrpGpcJVKnrpGNG7FTVKnrpGrjQDej2lDuzgx:Fz0FTYrpGpcJYrpGNGBTYrpGrjQCj2lv
                                                                                                                                                                            MD5:66A94E7B4E31892F28A39C5C21EDFA29
                                                                                                                                                                            SHA1:A0AF983CCE61A29F051654B8B8BEA9F854BF505B
                                                                                                                                                                            SHA-256:4F1AD7E17605DB5AA697B12F20992B0680C281365C2A57DC38B653697D3B9A2F
                                                                                                                                                                            SHA-512:BF094A38258435E0CE112928DA1E8A1CDCFB0706576F29686AA4C5DD2189AA27DFB4665010D9707B576E1C73ED97E89DE978720CD5DFD74E993967FD0C1EEE88
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Ottieni la protezione Web gratuita McAfee facendo clic su {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Attiva l'estensione",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} per attivare queste funzionalit. di protezione aggiuntiva: Ricerca sicura McAfee., Blocco della pubblicit. e Blocco dei tracker.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Attiva l'estensione",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} per restare protetto online con queste funzionalit. di protezione aggiuntiva: Ricerca sicura McAfee., Blocco della pubblicit. e Blocco dei tracker.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Mantieni i cambiamenti",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} a McAfee. WebAdvisor di attivare queste funzionalit. di protezione aggiuntiva: Ricerca sicura McAfee., Blocco della pubblicit. e Blocco dei tracker.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Consenti",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Attiva
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1682
                                                                                                                                                                            Entropy (8bit):5.755218080478307
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:x8H0vGRwMvNaRw8CvrbQRwA8vxvovyZWKzAFV3:a2UwuewDrWwA+pyqWKMFF
                                                                                                                                                                            MD5:BC463EE3DA1F25CE1DD7B76E9CA05E2C
                                                                                                                                                                            SHA1:A87F7C887D8FAB4191687AF39AEEA2297A2A1EB3
                                                                                                                                                                            SHA-256:A8A56277FFD79EB42ED1170652D84F193917412160FD8529836DA3265753AC77
                                                                                                                                                                            SHA-512:EEC3CB2B0EE92E05375638A728E1BB491AE97E1474AB6397441449D97CCAF81E33278C64D4CD7910AFC755205E2940F34652B60CA93F3C3D4888944869ED32A9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "{0}................. Web ............",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "............",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0}.......... .... ..........................................",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "............",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0}.......... .... ..........................................................",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: ".......",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "...... ..........{0}.......... ...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1350
                                                                                                                                                                            Entropy (8bit):6.006146131137553
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT5dVhbu+vNh0/p7OvmksBv01I+vqNhGjB+Xx2ZZBju0p:pXvkJOvmdBvAvq5B2ZZB60p
                                                                                                                                                                            MD5:06702AF578E6B22482A75FA51B843965
                                                                                                                                                                            SHA1:FA2AE0343264EF1DBF4B579E29192A08AD7CC2ED
                                                                                                                                                                            SHA-256:286BA24428AC4ECC198BA77B2A58943451CDC3BD1F205718C0C1EE52280FC244
                                                                                                                                                                            SHA-512:E3E002E02B9AE44F51753D2694CF95224C4DC7FFD3E030CFA8E3D6910B9B7CC0B94E8BD393816521ABD3A4090F0E5BAD38243E5BCA7E31FC37365D9B1A7C6EFA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "{0}. .... McAfee. .. . ... .....",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: ".. ..",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0}. .. .. .. .. ... .... McAfee. .. .., .. ..., .. ...",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: ".. ..",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0}. .. .. .. .. .... ... ... ... ..... McAfee. .. .., .. ..., .. ...",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: ".. .. ..",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "McAfee. ....... {0}.. .. .. .. ... .... McAfee. .. .., .. ..., .. ...",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "..",.. CHROME_ENABLEMENT_GUIDE_BUTTON: ".. ..",.. CHROME_ENABLEMENT_GUIDE_CONTENT_1: "..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1389
                                                                                                                                                                            Entropy (8bit):5.562698623437252
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT7bqCaYyGIG3aYEgdXCCaYIRSPuA9/3QFYKDOVh:rWCaPQ3a3gdXCCa1oPuAN3Kbq
                                                                                                                                                                            MD5:17CFA17F85DF05A9623708D6159DAE42
                                                                                                                                                                            SHA1:88128E5BF8DF4830B1EA3EB6175279A7488EDD38
                                                                                                                                                                            SHA-256:73C4F22C1EC7440DA09B3370F01264A28FB660EA99488D9937147DAD229714B2
                                                                                                                                                                            SHA-512:30D18EF68DFA53348B0490ED053356199B28FE511DC44023961055110EF9F0606DD2B26AA53CC09C6A88C6E5DA05DEC03BB297B3CB3235172614F45148350354
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "F. kostnadsfri webbeskyttelse fra McAfee ved . klikke p. {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Aktiver utvidelse",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} for . sl. p. disse funksjonene i Ekstra beskyttelse: McAfee. Sikkert s.k, Annonseblokkering og Annonsesporingsblokkering.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Aktiver utvidelse",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} for . f. uavbrutt nettsikkerhet med disse funksjonene i Ekstra beskyttelse: McAfee. Sikkert s.k, Annonseblokkering og Annonsesporingsblokkering.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Behold endringer",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor for . sl. p. disse funksjonene i Ekstra beskyttelse: McAfee. Sikkert s.k, Annonseblokkering og Annonsesporingsblokkering.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Tillat",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Aktiver utvidelse",.. CHROME_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1362
                                                                                                                                                                            Entropy (8bit):5.488513290813395
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT+2CwmVpm7KECQc6WpV6LqKECh6zhpTnKECZ6BMcpS3KfwDwzxFU5qu:ulHXQc6CVsph6znTCZ6BMIS3KQAxFU5V
                                                                                                                                                                            MD5:4FEC3D3013AE3960661692481D4EDB83
                                                                                                                                                                            SHA1:EB94F6848879D5C40B34C4CDCE9C075051FB820A
                                                                                                                                                                            SHA-256:F4E6730E587783080569765A77A785382751900C2ED5B6272D020DAEF43B85F6
                                                                                                                                                                            SHA-512:A6154C22506833208B9DEE8839362E6A0DFBBC14023E7E9686E6FF33531F5EB16525B1CD6B4F4D739EDA3B58F66126AB313376023C1C6779D5164D2CE20D17E0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Activeer uw webbescherming van McAfee door op {0} te klikken.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Extensie inschakelen",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} om deze functies voor Extra bescherming te activeren: McAfee. Secure Search, Advertentieblokkering en Trackerblokkering.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Extensie inschakelen",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} om online veiligheid te handhaven met deze functies voor Extra bescherming: McAfee. Secure Search, Advertentieblokkering en Trackerblokkering.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Wijzigingen behouden",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} dat McAfee. WebAdvisor deze functies voor Extra bescherming inschakelt: McAfee. Secure Search, Advertentieblokkering en Trackerblokkering.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Toestaan",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Extensie inschakelen",.. CHROME_ENAB
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1445
                                                                                                                                                                            Entropy (8bit):5.692269550840036
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HThG9K7qoBXUUyTNHyAoBXs0W17ZGoBXQLVTEaWjNwc4u2Hs:xG99IXnkHyAIXs0W17ZGIXQLVoaKNwcf
                                                                                                                                                                            MD5:43192C8FC49E340A87336605440CE8B8
                                                                                                                                                                            SHA1:3FFEE3CD20B1AD2FD89069B1A78E307F3D039275
                                                                                                                                                                            SHA-256:81EE335AA99A98334D55E38836706FC2ED29716BF8A346F4C176D4007FAC49A0
                                                                                                                                                                            SHA-512:6983C41D20C456227AD37107720B4BE3655C605DFFDD8EE4AC66B6D8DBA1E1769A4B5B952B3DECE12F256EC03D86EA672CBF793A1AA85F95F4E93A0954F20A8F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Otrzymaj bezp.atn. ochron. w sieci Web od firmy McAfee, klikaj.c {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "W..cz rozszerzenie",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0}, aby w..czy. funkcje Dodatkowej ochrony: Bezpieczne wyszukiwanie McAfee., Blokowanie reklam i Blokowanie .ledzenia reklam.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "W..cz rozszerzenie",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0}, aby zachowa. bezpiecze.stwo w Internecie dzi.ki tym funkcjom Dodatkowej ochrony: Bezpieczne wyszukiwanie McAfee., Blokowanie reklam i Blokowanie .ledzenia reklam.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Zachowaj zmiany",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} programowi McAfee. WebAdvisor na w..czenie funkcji Dodatkowej ochrony: Bezpieczne wyszukiwanie McAfee., Blokowanie reklam i Blokowanie .ledzenia reklam.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Zezw.l",.. CHROME_ENABLEMEN
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1387
                                                                                                                                                                            Entropy (8bit):5.506991556456199
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTBsKJqk3NnebNgHbrxkHjFRt7Siu47VfMnOA/+O:yaqk3NnebNg7rxCFq4ynOAWO
                                                                                                                                                                            MD5:FBE39EC0DBFE2816B42BB68887D3B030
                                                                                                                                                                            SHA1:B82CF4E6B4A5C3E74CB1E2DECCB94DDE56330142
                                                                                                                                                                            SHA-256:910C7854052E7CB18154EC9FD2DC1C743291D8917034F27006F6CE1681FBA084
                                                                                                                                                                            SHA-512:95D68E16B68CDBA3266DE12ECA52C44AE174F7A1DFDAA9FEACDD274A518F801ED8F648471EB04A49E56BCEB6E95E19EC0173366F77533DFB9B8BB842B686441B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Obtenha sua prote..o gratuita na Web da McAfee clicando em {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Ativar extens.o",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} para ativar estes recursos de Prote..o adicional: Pesquisa Segura, Bloqueador de an.ncio e Bloqueador de rastreador da McAfee..",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Ativar extens.o",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} para se manter seguro com estes recursos de Prote..o adicional: Pesquisa Segura, Bloqueador de an.ncio e Bloqueador de rastreador da McAfee..",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Manter altera..es",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} o McAfee. WebAdvisor para ativar estes recursos de Prote..o adicional: Pesquisa Segura, Bloqueador de an.ncio e Bloqueador de rastreador da McAfee..",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Permitir",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Ativar extens.o"
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1439
                                                                                                                                                                            Entropy (8bit):5.517413148992093
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTBV0k3gQWF3+be0GQWF3+hgoQQWF3+vxkHjJYPJW11wgQdg:D0k3gQWObe0GQWOhgvQWOvxCJuW8gQdg
                                                                                                                                                                            MD5:4AF297B7BE41DFA4EB86EF803461EB18
                                                                                                                                                                            SHA1:9AC16E6A1D01A324010204054F678641EFC3FC92
                                                                                                                                                                            SHA-256:9ED643E393BC88F631B0F68A640F71E077305F1577A11290FB26E2E95706DD79
                                                                                                                                                                            SHA-512:5ECA544EE9D6A1A43E8A33FCD9A8AC1916120ECD209FA23DB8A9F421D6368A1F26EA6E5E7A7C60603CEFA7342F6131A8CCA55B7014C261058870ACA5CCA16C80
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Obtenha a sua prote..o Web gratuita da McAfee clicando em {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Ativar extens.o",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} para ativar estas funcionalidades de prote..o adicionais: Pesquisa segura da McAfee., bloqueador de an.ncios e bloqueador de monitorizadores.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Ativar extens.o",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} para se manter protegido online com estas funcionalidades de prote..o adicionais: Pesquisa segura da McAfee., bloqueador de an.ncios e bloqueador de monitorizadores.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Manter altera..es",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} que o McAfee. WebAdvisor ative estas funcionalidades de prote..o adicionais: Pesquisa segura da McAfee., bloqueador de an.ncios e bloqueador de monitorizadores.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Permitir",.. C
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2030
                                                                                                                                                                            Entropy (8bit):5.254060167581995
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:cjVIb3DoC64sVmb3D1tazjVIb3DzImiLvyxvMwSO:QVi3Z2VM3enVi3v2vyfR
                                                                                                                                                                            MD5:09128BA6C4A2812132FD41727A02E40B
                                                                                                                                                                            SHA1:B3F8731DA4FDC9CE05D3B7CC07F4440173EDDCCC
                                                                                                                                                                            SHA-256:C44010F0FD357E46AD0D250CD55E5735B23FBDE8D2A086C4719DE926C6C09FEF
                                                                                                                                                                            SHA-512:4FEAA71EB155A97200B1A10379230E114E9D598DD2FB38FCDFC994356FEDCC761A4A6DC2A32C7FF003FA22F3BA171A24CB052A8241785D56849983D8A7B90B8C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "........ .......... ...-...... .. McAfee, ..... {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "........ ..........",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0}, ..... ............ ......... ....... .............. ......: .......... ..... McAfee., ........... ....... . ........... .........",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "........ ..........",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0}, ..... .......... . ............ . ......... ......... ............. ......... .............. ....... ......: .......... ..... McAfee., ........... ....... . ........... .........",.. ADBLOCK_SEARCH_W
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1420
                                                                                                                                                                            Entropy (8bit):5.798786258877509
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT/iSRyjWeDvEPpRK2NF1I5DyjePD+hCf3c4kc+QF9IAAPE:P3YSeYpccF1Ic6Chm3j+o9Ivc
                                                                                                                                                                            MD5:FACAA2C2A3350F1443A87605DA328AF0
                                                                                                                                                                            SHA1:A6CD0F183589885006C239D045A4C89058615A2F
                                                                                                                                                                            SHA-256:6B4E3ED3367672335686B40AD3949C38D1A3E8897EBFB2D1B78EEFD705D387F2
                                                                                                                                                                            SHA-512:E50B018B9116249D39ABFB9D9FD51BAF15A6314796B9A5E8018FB684AA1E393A2E06E02FBD52474DEE9BA29703A5379EABFD796A7320E6994F50D70881B7D5C7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Z.skajte bezplatn. webov. ochranu od McAfee a.kliknite na mo.nos. {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Zapn.. roz..renie",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} a.aktivujte funkcie zv..enej ochrany: zabezpe.en. vyh.ad.vanie McAfee., blokovanie rekl.m a.blokovanie sledova.ov.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Zapnite roz..renie",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} a.nestra.te ochranu online v.aka funkci.m zv..enej ochrany: zabezpe.en.mu vyh.ad.vaniu McAfee., blokovaniu rekl.m a.blokovaniu sledova.ov.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Ponechajte zmeny",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor a.zapnite funkcie zv..enej ochrany: zabezpe.en. vyh.ad.vanie McAfee., blokovanie rekl.m a.blokovanie sledova.ov.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Povo.te",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Zapnite r
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1338
                                                                                                                                                                            Entropy (8bit):5.6423626000899
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT4eGvvtCawa+dCIHrFwa+Npp1mCawa+rUoDOGnDkpJcdqQ2y:IeCvtCawa+dCIBwa+NVmCawa+rUoDOGB
                                                                                                                                                                            MD5:ECF03F3BD3F117CCA572E4115F895708
                                                                                                                                                                            SHA1:91DCE729E254520F77FCA79CB3E70754562E9152
                                                                                                                                                                            SHA-256:DDD74FF9C6E80A9F283D248325D47316EA5ED2E5E00B641F35E08B0DABCE7C27
                                                                                                                                                                            SHA-512:95A4631E5DEE63D056621C40AC2CC304317187D94DE05FEC741ABABC3FFA8ADD2A3C3EA2318B7132464C45C3E2298195AE4BCC45733CD9A098129335613C327D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "Ostvarite besplatnu veb za.titu kompanije McAfee klikom na {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Omogu.ite ekstenziju",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} da biste uklju.ili ove funkcije Dodatne za.tite: McAfee. Bezbedna pretraga, Ad Blocker i Tracker Blocker.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Omogu.ite ekstenziju",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} kako biste ostali sigurni na mre.i uz ove funkcije Dodatne za.tite: McAfee. Bezbedna pretraga, Ad Blocker i Tracker Blocker.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Zadr.ite promene na",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor da biste uklju.ili ove funkcije Dodatne za.tite: McAfee. Bezbedna pretraga, Ad Blocker i Tracker Blocker.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Dozvoli",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Omogu.ite ekstenziju",.. CHROME_ENABLEMENT_GUIDE_CONTENT_1: "da zavr.it
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1361
                                                                                                                                                                            Entropy (8bit):5.638807761088261
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT7ecjfypbD4qpbD02gVpbDYX/P33zMc2LUF:rDOpbD4qpbD0JVpbDYX/P33zd2LUF
                                                                                                                                                                            MD5:A7C892B18D262BC145A2DE0971AD1830
                                                                                                                                                                            SHA1:E8A072A5D33735F35656D9D6DF28A5EADAE2A0A9
                                                                                                                                                                            SHA-256:CC46652252D575B63859ED5BCFE4AC1F9D4639B0021DC86805500856B45D5733
                                                                                                                                                                            SHA-512:BC0982D7B38CCAF90F779594DEE9ACF43CAF05498FEDB9737CCA7E0D47D3DAFC4EE27B90592FB577E71E585073E5A45A4A379D46209105E5015A3482B45AFAF7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "F. kostnadsfritt webbskydd fr.n McAfee genom att klicka p. {0}.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Aktivera till.gg",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} f.r att aktivera Ut.kat skydd-funktionerna: McAfee. S.ker s.kning, Annonsblockering och Blockering av sp.rare.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Aktivera till.gg",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} f.r att forts.tta h.lla dig s.ker online med Ut.kat skydd-funktionerna: McAfee. S.ker s.kning, Annonsblockering och Blockering av sp.rare.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "Beh.ll .ndringar",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor f.r att aktivera Ut.kat skydd-funktionerna: McAfee. S.ker s.kning, Annonsblockering och Blockering av sp.rare.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "Till.t",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "Aktivera till.gg",.. CHROME_ENABLEMENT_GUIDE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1404
                                                                                                                                                                            Entropy (8bit):5.668672857602126
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HT3Nd7QUN3Z/UVXMJgYZ/v94oIuZ/Nc7I4dBng5cFEicvX6j:tBQUNGVcDxBc7HTFR
                                                                                                                                                                            MD5:3285945713F8099A491E5910E9F5CDD8
                                                                                                                                                                            SHA1:18C8E215A29E6151DE39DE2F98F352815053B1CA
                                                                                                                                                                            SHA-256:C0544A7D705ED5D777D72383D72DE8756C1F1B022CD01AC66FA1DCCAC34A75CE
                                                                                                                                                                            SHA-512:37B7EF1009098EF11A0B90CFC05E5361162E8515F947D87999D663AF750C420A62BC8B9377C2B37A81A1D61964C47693BC1DA5ABE0D67D13E567F0DDDADEB1D9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: "{0} .zerine t.klayarak McAfee'den .cretsiz web korumas. edinebilirsiniz.",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Uzant.y. etkinle.tir",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "A.a..daki Ek Koruma .zelliklerini a.mak i.in {0}: McAfee. Secure Search, Reklam Engelleyici ve .zleyici Engelleyici.",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "Uzant.y. etkinle.tir",.. ADBLOCK_SEARCH_WARNING_CONTENT: "Bu Ek Koruma .zellikleri ile .evrimi.i g.vende kalmak i.in {0}: McAfee. Secure Search, Reklam Engelleyici ve .zleyici Engelleyici.",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "De.i.iklikleri kaydet",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "A.a..daki Ek Koruma .zelliklerini a.mak i.in McAfee. WebAdvisor'. {0}: McAfee. Secure Search, Reklam Engelleyici ve .zleyici Engelleyici.",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: ".zin Ver",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "WebAdvisor kurulumun
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1303
                                                                                                                                                                            Entropy (8bit):6.289340282266
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTjjZ8CKz+1CaxNs/CthZvG7qXdW4mUs/nbSCH:pQzaxmahZv9rm3bSY
                                                                                                                                                                            MD5:80C4177F291119F669C2157B39E4758D
                                                                                                                                                                            SHA1:23613E210FDE5BE4FDB87F0B2D67806056D072B7
                                                                                                                                                                            SHA-256:3D8B6BB483F86B553CA719D38A8DB7187CBDB02D5F593A4128EEE6B4D0F3FC36
                                                                                                                                                                            SHA-512:73166AEEF02ED6EE0317EC0746063CF05581C377DA46548F2B6A5BB9013D3F2EF8CDFB7CF7DB07293A44F8F347E2954C882BA89E161D9A2B3D1B42E12587105B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: ".. {0} .............",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "....",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0} .................. .....................",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "....",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0} .................. ..............................",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "....",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} .... ...................... .....................",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "..",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "......",.. CHROME_ENABLEMENT_GUIDE_CONTENT_1: "......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1249
                                                                                                                                                                            Entropy (8bit):6.299966282396261
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HTAOzmcPZeSlGkyTDnZZeSlGCGtDcPZeSlGW17/10lQZ0S04CdugElO:dzmkCkyTDn/CCGtDkCW1aZKU
                                                                                                                                                                            MD5:F8B54967B08380ED852C72726B751D6E
                                                                                                                                                                            SHA1:D5161619125D555189F557F7F94433F4F6CCBE09
                                                                                                                                                                            SHA-256:8E0EAC94E355504F9BE57467FE91ED19F76113F49C602BBE3F8AEF7228EAD877
                                                                                                                                                                            SHA-512:91066ED2105321CA85EE03F7ADB5938D896746B48F90B0E40662FC3705F895AED12192B4C71F4385C86E60C8DB3810FF89C18F3A680AF28D02D053C0955BF6A8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. ACCEPTANCE_EXTENSION_CONTENT: ".. {0} ..... McAfee Web ...",.. ACCEPTANCE_EXTENSION_CONTENT_STRONG: "......",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT: "{0}............McAfee. ....................",.. ADBLOCK_ACCEPTANCE_EXTENSION_CONTENT_STRONG: "......",.. ADBLOCK_SEARCH_WARNING_CONTENT: "{0}....................McAfee. ....................",.. ADBLOCK_SEARCH_WARNING_CONTENT_STRONG: "....",.. ADBLOCK_PERMISSION_ADDED_CONTENT: "{0} McAfee. WebAdvisor ...........McAfee. ....................",.. ADBLOCK_PERMISSION_ADDED_CONTENT_STRONG: "..",.. CHROME_ENABLEMENT_GUIDE_BUTTON: "......",.. CHROME_ENABLEMENT_GUIDE_CONTENT_1: "... WebAdvisor ...",.. CHROME_ENABLEMENT_G
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1048
                                                                                                                                                                            Entropy (8bit):5.760018493827392
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGY406vV41eK+59CpMSqKBgvtdUeniGdZIVOEF3CR:24e+59YMdZZENs
                                                                                                                                                                            MD5:E505B63A2F328822A3457CE03843F8DD
                                                                                                                                                                            SHA1:A2E82758DBFEF138D8B536A71088AF52671A2C49
                                                                                                                                                                            SHA-256:2A0E957EC208B9CE5E39E0EFAFF9880D45D2C8C64FFEE40295D1156287CE7DC0
                                                                                                                                                                            SHA-512:D2F9049AB97F03359B9A276FEC7BEDDA3B3ECA66B4F2C8C26675BAAC66629FE65076CEFBDB9B73F118FDF360F637DC8EE185033F7148BA1DB94EAC62BFB40EBE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Zajist.te si ochranu v digit.ln.m prost.ed.",.. WAIFF_TOAST_DESC_1_COHORT_1: ".kolem n.stroje McAfee. WebAdvisor je chr.nit va.e osobn. .daje, aby se nedostaly do nespr.vn.ch rukou.",.. WAIFF_TOAST_DESC_2_COHORT_1: "A. ji. nakupujete, vyu..v.te bankovn. slu.by nebo proch.z.te web, na.e bezplatn. n.stroje v.s pom.haj. chr.nit . a kyberzlo.inci nebudou m.t .anci.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor je bezplatn. n.stroj, kter. chr.n. va.e osobn. .daje, aby se nedostaly do nespr.vn.ch rukou.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Povolte n.stroj WebAdvisor a zajist.te si ochranu p.ed viry, malwarem a dal..mi hrozbami pro va.e online zabezpe.en..",.. WAIFF_BUTTON_ACCEPT: "Zajistit ochranu",.. WAIFF_BUTTON_REMIND_LATER: "P.ipomenout pozd.ji",.. WAIFF_BUTTON_DECLINE: "Ne, d.kuji"..}..//2D7CC7931A39F234558A33CAD3765970C45ECEEBFC60F421404D6FD52805E367D7FEF22B9BD2546776
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):986
                                                                                                                                                                            Entropy (8bit):5.435709474604912
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uG92vXRwV/YIehPFXc9vLfcRwV/YIeSP/GIi7dZMVIxvvBe9WuZ:nVYC9rVYttZdBAWuZ
                                                                                                                                                                            MD5:8DD44453A825D8504CD91FEF29030128
                                                                                                                                                                            SHA1:16CEF0BFC6428B38C5488A03401C632DEE21E585
                                                                                                                                                                            SHA-256:10DB66E4B9B2F8D3DE626F7BB96C01195FC1E687376000882367434350690628
                                                                                                                                                                            SHA-512:0C93254EDBD114167FF665DEC67725CCC1E620997A3B6F8E6BA97EE38EAF72C6EA3901E7FDB0ADCFC5CD68A6E9FFA0C6B5D80A6E4801B834B89F8C921C73ED47
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Beskyt dit digitale liv",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor beskytter dine personlige oplysninger og forhindrer, at de falder i de forkerte h.nder.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Uanset om du bruger internettet til at shoppe, g. i banken eller bare surfe, holder vores gratis v.rkt.jer dig i sikkerhed og beskytter dig mod cyberkriminelle.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor er et gratis v.rkt.j, der beskytter dine personlige oplysninger og forhindrer, at de falder i de forkerte h.nder.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Aktiv.r WebAdvisor for at beskytte dig selv mod virus, malware og andre onlinetrusler.",.. WAIFF_BUTTON_ACCEPT: "F. beskyttelse",.. WAIFF_BUTTON_REMIND_LATER: "Sp.rg mig igen senere",.. WAIFF_BUTTON_DECLINE: "Nej tak"..}..//1532520A68DAC3FF2BEAFC834A0932CA2D053A2667AA7FC3F3FD2FD43200A638DFACB3FB2FBD41D63D9452CA737886EE9F1A89E9CCF76158CB1CC2393F59AF1D++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1026
                                                                                                                                                                            Entropy (8bit):5.441717163928068
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uG+QvxOeGg/OA9kNlv1VOe3F0Sui7xQd/y/QVZNfmKn8vWwn:QWX9GftF0SJxMa/uNOKnRwn
                                                                                                                                                                            MD5:B8AB88AD26362724B3AA05E44B1D8AA7
                                                                                                                                                                            SHA1:31F8AFFB3DD03BF3B71A1C0FDFE19F5B0C53DD25
                                                                                                                                                                            SHA-256:3BB32AFCBE6FA6DFE6C3043FDB7494B4F5431CAE2B22BD4916950310CE553098
                                                                                                                                                                            SHA-512:EA3382B0E4634061FF6542B81F6394EDDCB0593157B7E67806FED5552474616652F9A53644A947A2592603C84D77A769E06075AC2F9B953EBFE25F2ADCA03E40
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Sch.tzen Sie Ihr digitales Leben",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor hilft Ihnen, zu verhindern, dass Ihre pers.nlichen Daten in die falschen H.nde gelangen.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Ob Sie nun im Internet einkaufen, Bankgesch.fte t.tigen oder surfen: Unsere kostenlosen Tools helfen Ihnen, sicher zu bleiben, damit Cyberkriminelle keine Chance haben.",.. WAIFF_TOAST_DESC_1_COHORT_2: "Das kostenlose Tool McAfee. WebAdvisor hilft Ihnen, zu verhindern, dass Ihre pers.nlichen Daten in die falschen H.nde gelangen.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Aktivieren Sie WebAdvisor, um sich vor Viren, Malware und anderen Bedrohungen Ihrer Online-Sicherheit zu sch.tzen.",.. WAIFF_BUTTON_ACCEPT: "Schutz einrichten",.. WAIFF_BUTTON_REMIND_LATER: "Sp.ter erinnern",.. WAIFF_BUTTON_DECLINE: "Nein danke"..}..//9073A30F9664CF09836F767851BB037E22FDA60D15A5634B8E39A2A3D0A6E6AD959A0A27A26F31E6697A26BA09FD6F70BD14A721
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1606
                                                                                                                                                                            Entropy (8bit):5.12079517663386
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGwvlT6DePnEHleEnM+na8cEseDrXHrRvu1QGRXePoEHlesD3ir3rwqDijGduaX:4HEHXnjKEXDrXrgKeEHXbirDduDAnyXW
                                                                                                                                                                            MD5:DFA837AC4D05F6CE45A354E6D5CFA8B7
                                                                                                                                                                            SHA1:D5CE22779221CEF597991AE73B082BCD5E74A995
                                                                                                                                                                            SHA-256:64F170EFCDD20FDC04B172A6F1B13C0700CDDB9862D5064CEABEB9732008273F
                                                                                                                                                                            SHA-512:D7FAA1DC24D8D63EE1EBCD52773F623CF6E0E7FD41E4435E73E77EDBF5A0F43887466B23FDDCE02B4073EBA3C151668F53EAD526A161C97BC74EED2DE4B92735
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "......... ... ........ .... ...",.. WAIFF_TOAST_DESC_1_COHORT_1: ".. McAfee. WebAdvisor .... ..... .. ... ......... .... .......... ........... ... .. ...... .. ..... ......",.. WAIFF_TOAST_DESC_2_COHORT_1: ".... ............... ......, .......... .......... . ........... ... web, .. ...... ........ ... ....... .. ... ......... .. ........... ........ ... .. .......-........... ... .. ..... ..... ........ .. ... ...........",.. WAIFF_TOAST_DESC_1_COHORT_2: ".. McAfee. WebAdvisor ..... ... ...... ........ ... ........... ... .......... ........... ... ... .. .. ...... .. ..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):915
                                                                                                                                                                            Entropy (8bit):5.48084822062607
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uG/4Iv74Ge+uVfWMhCHJHvU0hGecZrD5i9dwdS/VF2Wp:l4guUMgHJM06ZSdsSr1p
                                                                                                                                                                            MD5:D7C523A4330183ECDFB3ED016E957B67
                                                                                                                                                                            SHA1:25602D1FCAC86AF4145D6ECE96C92783B5C6FC7A
                                                                                                                                                                            SHA-256:F02BC806DF57949524FC7D48397812447814F69C0594E3F7E6A17D94F030C83B
                                                                                                                                                                            SHA-512:E2A795A4613E5AC3273DDCAEB36C900CAE514694E9849D361484EDEE6B2D3FBA8066E068F5FE6165F6C169092784CEAD23671D2767F5FA1A4E4C3422A8C0A21A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Protect your digital life",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor works to safeguard your personal info from falling into the wrong hands.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Whether you shop, bank, or browse the web, our free tools can help keep you safe -- and cyber criminals won't stand a chance.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor is a free tool that safeguards your personal info from falling into the wrong hands.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Enable WebAdvisor to protect yourself against viruses, malware, and other threats to your online security.",.. WAIFF_BUTTON_ACCEPT: "Get protected",.. WAIFF_BUTTON_REMIND_LATER: "Remind me later",.. WAIFF_BUTTON_DECLINE: "No, thanks"..}..//1EFBD8890FBB6202F25E76BFB37BED3655C526CA13A6C39F091FF77FCDE1E74DE3D6E0E418634F157714134E83372490132403F9CAFE4ADDD0BAD0869BB246A7++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):965
                                                                                                                                                                            Entropy (8bit):5.430144610649704
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGKvMwKimzpe4sTtkAFvZxR/mzpeWLdvRYjiOdSXkHVovcZQn/:V/RcKkxspJYbSXkCvT/
                                                                                                                                                                            MD5:3C86994A03EFD552740F47DFF61F2632
                                                                                                                                                                            SHA1:84C2DF7247E0D593AA125FB1BE6ACB5B2ACC7255
                                                                                                                                                                            SHA-256:77027DF4446456D0CAC8ECF2DC179A9B52C87D8879B04845C5BF4BD25EB7314C
                                                                                                                                                                            SHA-512:323B8CA7FF2F276313186115952B958FF46C4D4F0099E3C81D53477595DFC4798BE577FE60D00026B889C7CE6315AEF98AB640D0B4A7226AA3B438B007013CAA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Proteja su vida digital",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor est. pensado para evitar que su informaci.n personal caiga en malas manos.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Nuestras herramientas gratuitas pueden protegerle al navegar, realizar compras y gestiones bancarias. Los ciberdelincuentes dejar.n de ser un peligro.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor es una herramienta gratuita pensada para evitar que su informaci.n personal caiga en malas manos.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Active WebAdvisor para mantenerse a salvo de virus, malware y otras amenazas para su seguridad en Internet.",.. WAIFF_BUTTON_ACCEPT: "Protegerme",.. WAIFF_BUTTON_REMIND_LATER: "Record.rmelo m.s tarde",.. WAIFF_BUTTON_DECLINE: "No, gracias"..}..//5CADD3F77C0E66E7E9C653CCDB6068983600027CDC981F2BF04A7CCED5F75255DAC5D9EDCFA397981228886DE827C6389075ABD3EDB8965F01DCAB9895E54148++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):938
                                                                                                                                                                            Entropy (8bit):5.466446767836645
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGSvyUpep4n0OlvZxxzpeWLZV2iadSXkHVhZdUR1OMUn:R4nHxP9KSXkLj61ZU
                                                                                                                                                                            MD5:E581CCEAC4CBDE3C8B591F5D9BA9CB61
                                                                                                                                                                            SHA1:C4CE35FAFB92B301340F90BB72C30D1329DEC944
                                                                                                                                                                            SHA-256:E72C1ADD92CFFF72470A7C7A5C93927E1A62AEB71179D1C75D10B6F773BB51E9
                                                                                                                                                                            SHA-512:D9E539813884E88EAD2918516E0DB348EB7F842C1BAAB963DE51C7AADC0583AA04F68FAA071F8FBF06700534EB382CDD0C1ECA9B0132AA76EBDF8E0A5EDE2AF4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Protege tu vida digital",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor trabaja para evitar que su informaci.n caiga en malas manos.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Sea que compre, haga operaciones bancarias o explore la web, nuestras herramientas gratuitas ayudan a mantenerlo seguro, y a derrotar a los cibercriminales.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor es una herramienta gratuita para evitar que tu informaci.n personal caiga en malas manos.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Active WebAdvisor para protegerse contra virus, malware y otras amenazas a su seguridad en l.nea.",.. WAIFF_BUTTON_ACCEPT: "Prot.jase",.. WAIFF_BUTTON_REMIND_LATER: "Record.rmelo m.s tarde",.. WAIFF_BUTTON_DECLINE: "No, gracias"..}..//986CBE9BB839AD7FD0E82EC24863593924C4EE5FA0089D72CAFC5214B0C0143744585021A2195EF66F2D533D7E457C70505EAAC87A7947EA44848B60C4F68D78++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):992
                                                                                                                                                                            Entropy (8bit):5.529748026711536
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGrvpj8feM9FkTJ/XvQEbJjZjeX3EliRDd8tmQVatYBN:3qF4Z59lQEmdpYP
                                                                                                                                                                            MD5:B11BD16225904F9E4333E265D8C85A3E
                                                                                                                                                                            SHA1:EB68585E42DC33FCCDBCB0D8C79A25A1ED675AB5
                                                                                                                                                                            SHA-256:E3CCEC953211A2967B5F3C47259FC7F3CE647E1D5E28A385B843A4E3EF867BBB
                                                                                                                                                                            SHA-512:233C7BE4DDAFD2817022B52ED313FF911BAF8378A7197D0DAA82CBB53E60762F0EB46295902E46C3D232105B7F371AB2BA71CEEE65E8FA2791B4520F52C6FB3D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Suojaa digitaalinen el.m.si",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor pyrkii est.m..n henkil.kohtaisten tietojesi joutumisen v..riin k.siin.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Miten tahansa viet.tkin aikaa verkossa . ostoksia tehden, pankkiasioita hoitaen tai sivustoja selaillen . pysyt turvassa maksuttomien ty.kalujemme avulla. Kyberrikollisilla ei ole mit..n saumaa.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor -ilmaisty.kalu est.. henkil.kohtaisia tietojasi joutumasta v..riin k.siin.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Ota WebAdvisor k.ytt..n suojautuaksesi viruksilta, haittaohjelmilta ja muila tietoturvauhilta.",.. WAIFF_BUTTON_ACCEPT: "Hanki suojaus",.. WAIFF_BUTTON_REMIND_LATER: "Muistuta my.hemmin",.. WAIFF_BUTTON_DECLINE: "Ei kiitos"..}..//011BB8325FD03891334C8279A0470C6FE648B32EDA959849E0B181B27B45DF5922C170AF6702EC0A93C784541171E4C1BACED490D804C949C7F19324AA2F2E0A++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1082
                                                                                                                                                                            Entropy (8bit):5.443278347494329
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGNwvlMmlPcePzFzW0AvZrONq2lPce+XRKjwihGyAdCVqRoj:SMmlxpq0YrR2lkRKRUoj
                                                                                                                                                                            MD5:9588E1A8FD12FDCE77EA9AC50535E92E
                                                                                                                                                                            SHA1:563F0C9C4AD63303F1027538E18318F4CE3B925A
                                                                                                                                                                            SHA-256:D10B9731734772743B91181FC3D17D7F2A48738542292403068E524B1F52BC8B
                                                                                                                                                                            SHA-512:00EB21616DAD4450A1BBB24CD7C04A40C06EE29BE78962C7306AB63D54CD8B1BC2A8309AFD45F8EE46911B930AA9193ED907590789D1A96417E7D35729AEF4C8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Prot.gez votre univers num.rique",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor oeuvre . s.curiser vos donn.es personnelles et les emp.cher de tomber entre mauvaises mains.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Quand vous magasinez, effectuez des op.rations bancaires ou parcourez le web, nos outils gratuits contribuent . votre s.curit. -- et les cybercriminels n'ont aucune chance contre vous.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor est un outil gratuit qui s.curise vos donn.es personnelles et les emp.che de tomber entre mauvaises mains.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Activez WebAdvisor pour vous prot.ger contre les virus, les logiciels malveillants et d'autres menaces pesant sur votre s.curit. en ligne.",.. WAIFF_BUTTON_ACCEPT: ".tre prot.g.",.. WAIFF_BUTTON_REMIND_LATER: "Me le rappeler plus tard",.. WAIFF_BUTTON_DECLINE: "Non, merci"..}..//0CEC8C4DAF3307B881207E579211632EA67F6D72001BE860
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1128
                                                                                                                                                                            Entropy (8bit):5.397343027672221
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGmowvBtNhlFsceiA/6FVFzupllnF4vZrJ5NhlFsce+XvJ+wiZQdqVqDFGkp5W:eNhllA/6FVFOlOrJ5NhlNUMxFGkpQ
                                                                                                                                                                            MD5:225BC263E2FF4DF711EBD4B608BC17C0
                                                                                                                                                                            SHA1:2FB1AD94092F412A17B93268B51904BA47E2EA2C
                                                                                                                                                                            SHA-256:3DF8B95C3CB6739F3A3B7587C9D221BFFD14F6F7890390A1079FC091FC63FBA8
                                                                                                                                                                            SHA-512:590ACE282A74FEBD09613D8AE57DA9E459E10DB6DBAE52DB64B4D913A549472159F93EB112F801D53A5001D0C1BFB28D5EE07B6EFF2FFBA96DAF3A714D0451C9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Prot.gez votre vie num.rique",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor s'efforce de prot.ger vos donn.es personnelles pour les emp.cher de tomber entre de mauvaises mains.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Que vous fassiez des achats en ligne, effectuiez des op.rations bancaires ou naviguiez sur le Web, nos outils gratuits vous aident . rester en s.curit..: les cybercriminels n'auront aucune chance d'arriver . leurs fins.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor est un outil gratuit qui prot.ge vos donn.es personnelles pour les emp.cher de tomber entre de mauvaises mains.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Activez WebAdvisor pour vous prot.ger contre les virus, logiciels malveillants et autres menaces pour votre s.curit. en ligne.",.. WAIFF_BUTTON_ACCEPT: "Obtenir une protection",.. WAIFF_BUTTON_REMIND_LATER: "Me le rappeler ult.rieurement",.. WAIFF_BUTTON_DECLINE: "Non, merci"..}..//C0
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):970
                                                                                                                                                                            Entropy (8bit):5.5335623778383525
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGjvA5v/6FewAv/dHvav/6Fe0QhJ4Mmi6dwVmGbxFdFvO:S5vyAvlSvSG2M0hO9vO
                                                                                                                                                                            MD5:E589CCA4574BE9C31479BB5F884426F5
                                                                                                                                                                            SHA1:694479FCD6530106F7AB9165250FFB53EE8A847D
                                                                                                                                                                            SHA-256:EF54BAC483A824E52C05090A5310164A99475ADCA91FA88E9D598F7A66BFFBE0
                                                                                                                                                                            SHA-512:C2DD95276DE0E90E260B7AE0EC9FEA5C3ECAFDB96D8E00DAF7858C62F7517DF81D7EAA3ABFBB9F60335D18DE2FD69C998ABE6C24B8AAFD65056D977480EC5394
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Za.titite svoj digitalni .ivot",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor djeluje kako bi za.titio va.e osobne podatke od pada u pogre.ne ruke.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Bez obzira da li kupujete, bankarite ili pregledavate web, na.i besplatni alati mogu vam osigurati sigurnost - a cyber kriminalci ne.e imate .ansu.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor je besplatni online alat koji .titi va.e osobne podatke od pada u pogre.ne ruke.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Omogu.ite WebAdvisor kako bi se za.titili od virusa, zlonamjernog softvera i drugih prijetnji va.oj internetskoj sigurnosti.",.. WAIFF_BUTTON_ACCEPT: "Za.titite se",.. WAIFF_BUTTON_REMIND_LATER: "Podsjeti me kasnije",.. WAIFF_BUTTON_DECLINE: "Ne, hvala"..}..//B7D9D738B85EFDD8629EBABF36A768FADF1CC54EA171C1EBECBDA4FAEB03A547E1C1A4359FDC52074496C5BD99C3F78A7F74ED451BD698363059BE0794076EDB++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                            Entropy (8bit):5.601373452697428
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uG7bmvSr5Mycde/FsuaVvQG2Qe5MycdefYasTyrikPId7r6QVbTzV3ms:RTUju5UJ3TyVE7NzV2s
                                                                                                                                                                            MD5:C334EA1C53721513A8175D592F74282F
                                                                                                                                                                            SHA1:496D139F91706805D93C7B3CFCAF66AEFFCDCD98
                                                                                                                                                                            SHA-256:806CE13BB964B56733855FDFBDD6B7D750B2678A59132609399CE2348F15562C
                                                                                                                                                                            SHA-512:7B16FB9FDC4B9BEA6B702403FC9137D5514131C4A6CCE0AE0AE12D3E7A86A431777F1BD820A075BD96E06402FCDEE01F6169BA53CDFE3367CE3B9CCAB3FE93F6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Gondoskodjon digit.lis .let.nek v.delm.r.l",.. WAIFF_TOAST_DESC_1_COHORT_1: "A McAfee. WebAdvisor megakad.lyozza, hogy szem.lyes adatai illet.ktelenek kez.be ker.ljenek.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Ak.r v.s.rol, banki .gyeit int.zi vagy b.ng.szik online, ingyenes eszk.zeink gondoskodnak v.delm.r.l, hogy az internetes b.n.z.knek es.ly.k sem legyen.",.. WAIFF_TOAST_DESC_1_COHORT_2: "A McAfee. WebAdvisor egy ingyenes eszk.z, amely megakad.lyozza, hogy szem.lyes adatai illet.ktelenek kez.be ker.ljenek.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Enged.lyezze a WebAdvisor funkci.t, hogy biztons.gban legyen a v.rusokkal, a k.rtev. programokkal .s az egy.b vesz.lyforr.sokkal szemben, amelyek online leselkednek .nre.",.. WAIFF_BUTTON_ACCEPT: "Gondoskodjon a v.delemr.l",.. WAIFF_BUTTON_REMIND_LATER: "Eml.keztessen k.s.bb",.. WAIFF_BUTTON_DECLINE: "K.sz.n.m, nem"..}..//F8C3CE8799AF89B1814
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):978
                                                                                                                                                                            Entropy (8bit):5.359773111268553
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGKk2vkvtdeLny8MK9GEreLYvl6lvtdeVHD/ikdCeitVt6lVH:tBQxMK7eLjYCelH
                                                                                                                                                                            MD5:404D11F879ED6E62D18F660F4F1011C8
                                                                                                                                                                            SHA1:C6E242DA3C3065DFE036D13672AB621C9E0A3FB3
                                                                                                                                                                            SHA-256:C2B18461D35D0C0C0A1BB900EC807E301446400E4B8B5BA59C49A5E28CC15626
                                                                                                                                                                            SHA-512:5690CEC6EBC4D81279BDD0DA79AA1E6685E357C850A7C3E612065DFFAAAAEA197D77BE5431D463DC5B47824A32C02977BDFF735BF139225463260C3710F59808
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Proteggi la tua vita digitale",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor impedisce alle tue informazioni personali di finire nelle mani sbagliate.",.. WAIFF_TOAST_DESC_2_COHORT_1: "I nostri strumenti gratuiti ti aiutano a restare protetto e tenere alla larga i criminali informatici quando fai acquisti, esegui transazioni bancarie e navighi in Internet.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor . uno strumento gratuito che impedisce alle tue informazioni personali di finire nelle mani sbagliate.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Attiva WebAdvisor per proteggerti da virus, malware e altre minacce alla tua sicurezza online.",.. WAIFF_BUTTON_ACCEPT: "Proteggiti",.. WAIFF_BUTTON_REMIND_LATER: "Visualizza in seguito",.. WAIFF_BUTTON_DECLINE: "No, grazie"..}..//EAC9F80E8618CDBC45FC85134AE6F861DE735D32C594F841A6913BC2359239D28AE4C338C666E7F3FCA841B52B3DD9AA4556DC92DCEA42213C1F6218023D5030++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1220
                                                                                                                                                                            Entropy (8bit):5.7286091836828925
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uG7QvTYRFqOqeEnckuxTvlRFqOlesuhxkOQihdPvIVb7ShxE/L8:ZQYRFqkZrRFqcuzBvPv3TSw
                                                                                                                                                                            MD5:9A461AD6044F77B3FB4376D329C5BDC3
                                                                                                                                                                            SHA1:856F5181B0DD3E37D75BA56508BCF4E6B94BB72D
                                                                                                                                                                            SHA-256:CEF79F28B5A658337EF6781F138900A7780DE9611060F9F7FC9BD67C165C83D4
                                                                                                                                                                            SHA-512:A02983E2C3CD19F0D9F016F620322EE54FE7948982F47F9449309872B68F8EFAC6538D93EA6CE7848507AFA645C0F8DC8F61A48C7E230EDDADAD263A77974DCB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: ".... ...........",.. WAIFF_TOAST_DESC_1_COHORT_1: "...... ......................................",.. WAIFF_TOAST_DESC_2_COHORT_1: "..... ............ ................................................................",.. WAIFF_TOAST_DESC_1_COHORT_2: "...... ............................................",.. WAIFF_TOAST_DESC_2_COHORT_2: "..........................................................",.. WAIFF_BUTTON_ACCEPT: ".....",.. WAIFF_BU
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):986
                                                                                                                                                                            Entropy (8bit):6.006191144297644
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGqSv513heSk6BcSVpFrhjvG13DaJe/MhCowW/irdijVAJv4PCi/xd:0cdFvrhqD0QRPii43/xd
                                                                                                                                                                            MD5:826BE52F97F182988B05316488896FF5
                                                                                                                                                                            SHA1:7ECFF3C6EC7E04EFBAED0C7172193443FDBCDACD
                                                                                                                                                                            SHA-256:39803F96BD52CFD1783B3D59651405FC5868D974CDA0769378B54E878D0E32DF
                                                                                                                                                                            SHA-512:A7527B4679C750D4524F4AB6CC61C73D94F82EF5EE8C5EF55310EF2A4FB2217A5B79D662ACC6AAE370BD27D586EA72A6255B28712F0E89B3D3C47515B9D5C437
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "... ... ..",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. ....... .. ... .... ... ......",.. WAIFF_TOAST_DESC_2_COHORT_1: ".., .. .. . .. . .. ..... McAfee .. ... ... ... .... ... .... ... ... . .....",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. ....... .. ... .... ... .... .. ......",.. WAIFF_TOAST_DESC_2_COHORT_2: "....... .... ...., ... . .. ... .. ...... ......",.. WAIFF_BUTTON_ACCEPT: "....",.. WAIFF_BUTTON_REMIND_LATER: "... ..",.. WAIFF_BUTTON_DECLINE: ".. . ."..}..//587D3BC96BBFCC814561D97E8453CB0AA16E3850F8CA4F313F9E917704B7B7BE0D47DD925B20EFF0278E462D4371B194AE6E5C8194F2C0A1940626C13627FAB6++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):962
                                                                                                                                                                            Entropy (8bit):5.4851247359255595
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uG9IvAh1IerDGuH9tvIzzh1IeLkGAlIi7dkVpJOs:fLd+LtkHtSJOs
                                                                                                                                                                            MD5:6A418F95DC477538E975D5FA06B67D31
                                                                                                                                                                            SHA1:B6669B0ED075CD62A1EDD9C144E7D1487A490E71
                                                                                                                                                                            SHA-256:16D78592AFA39C8E51087B7DF3FE0584C4973FCA831CEE01CDB76995F44102C2
                                                                                                                                                                            SHA-512:12100EB96D123ECF1230F2A5A3107E32E2035E7770A98B98B2A305292409F52A5DE3F1FC5D4E880FDE6F58013259309E3889C22FB570E08B19306C6D4BCDD975
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Beskytt det digitale livet ditt",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor bidrar til . forhindre at personopplysningene dine havner i gale hender.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Enten du handler, bruker nettbank eller surfer p. nettet, kan de kostnadsfrie verkt.yene v.re holde deg trygg . og nettkriminelle har ingen sjanse.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor er et kostnadsfritt verkt.y som bidrar til . forhindre at personopplysningene dine havner i gale hender.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Aktiver WebAdvisor for . f. beskyttelse mot virus, skadelig programvare og andre nettrusler.",.. WAIFF_BUTTON_ACCEPT: "F. beskyttelse",.. WAIFF_BUTTON_REMIND_LATER: "P.minn meg senere",.. WAIFF_BUTTON_DECLINE: "Nei takk"..}..//DB9B06E543A7D137F0775CA6C99756428AD6717442517548A6524AC1D0C9887199CB6C406B21DE58E38301D461A720E5B0B0BB1F0E7E6F9561C594B8216B5B53++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1008
                                                                                                                                                                            Entropy (8bit):5.386460388121823
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGCbQvNQ/JHeGLwpBgvNTHUQ/JHeHgjQui8QydMiQVF4NUGaUA:wbE+JjwpMU+JeaQuHx1NU/p
                                                                                                                                                                            MD5:E4ED67F4730ABD3EEC0E5171C84536D9
                                                                                                                                                                            SHA1:CB2CB6D491A06306D9D764AC20791F95C3F1B66A
                                                                                                                                                                            SHA-256:A64FFA688D3FD408B4C991392DADC2430F02C3C1D9F0031DF9121899EACF81F2
                                                                                                                                                                            SHA-512:C8FAD5C3ED40735BD371CE9D929BFACF59018AE213395B16BE82CAC5F3E6044742F219FC18ED689DF69750253E46EEB347D4ED871FBF8E47058F3BD115AB729A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Bescherm uw digitale leven",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor beschermt u door te voorkomen dat uw persoonlijke gegevens in de verkeerde handen vallen.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Of u nu online winkelt, bankiert of surft, onze gratis tools kunnen u helpen om uw veiligheid te handhaven. Cyberciminelen maken geen schijn van kans.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor is een gratis tool waarmee u kunt voorkomen dat uw persoonlijke gegevens in de verkeerde handen vallen.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Schakel WebAdvisor in om uzelf tegen virussen, malware en andere bedreigingen van uw online beveiliging te beschermen.",.. WAIFF_BUTTON_ACCEPT: "Zorg dat u beveiligd bent",.. WAIFF_BUTTON_REMIND_LATER: "Help mij herinneren",.. WAIFF_BUTTON_DECLINE: "Nee, bedankt"..}..//C5D45099576EED60AFBECB14D26E8D2C1629A279844ADD8FAEDE5747B146DB4093111E0661F9FA1703E51BD8FEBA14CFA32A3B6665D2E0463A209FC334
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1093
                                                                                                                                                                            Entropy (8bit):5.663628249038643
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGVNFvLnLYFCeTKTv0vmNGHKZYFCeoVmPbYCjisi2d8VVNocIfLRC:PnLaKTvdckXVmPbvUO89IfLRC
                                                                                                                                                                            MD5:FC235094E605D87760AFA4E6EC715AE7
                                                                                                                                                                            SHA1:BC40F8B434E2DE0E9F6F2D27E14DBFB91B930585
                                                                                                                                                                            SHA-256:82E58C663F63B5BBC24B18CED6D297756DF12FA5F0279F760BADC189E7DC6AD3
                                                                                                                                                                            SHA-512:796863ECC0E2A8E683B91455D469DF1923084DBE3BA86765E0BEF1953F76B440350467FF6A11CFE73962AC0DFC66D16068C0E9CEB0B8F1404C8D2E36170783A0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Bezpiecze.stwo w cyfrowym .wiecie",.. WAIFF_TOAST_DESC_1_COHORT_1: "Rozszerzenie McAfee. WebAdvisor dzia.a w celu zabezpieczenia Twoich danych osobowych przed wpadni.ciem w niepowo.ane r.ce.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Nasze bezp.atne narz.dzia pomog. Ci. zabezpieczy. przy zakupach, korzystaniu z bankowo.ci lub podczas przegl.dania Internetu . cyberprzest.pcy nie maj. szans.",.. WAIFF_TOAST_DESC_1_COHORT_2: "Rozszerzenie McAfee. WebAdvisor to bezp.atne narz.dzie chroni.ce Twoje dane osobowe przed wpadni.ciem w niepowo.ane r.ce.",.. WAIFF_TOAST_DESC_2_COHORT_2: "W..cz rozszerzenie WebAdvisor, aby chroni. si. przed wirusami, z.o.liwym oprogramowaniem i innymi zagro.eniami dla bezpiecze.stwa w Internecie.",.. WAIFF_BUTTON_ACCEPT: "Skorzystaj z ochrony",.. WAIFF_BUTTON_REMIND_LATER: "Przypomnij mi p..niej",.. WAIFF_BUTTON_DECLINE: "Nie, dzi.kuj."..}..//5E79AD27360576221417C36C122517D930CE2
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1007
                                                                                                                                                                            Entropy (8bit):5.486847787876765
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGWvGqe4TqfWHvxYLqeo3L9iGdtHVA2uVbWua:JsTmLA3LNt+1bba
                                                                                                                                                                            MD5:F7483FAA42194C903BEB4E79D0757822
                                                                                                                                                                            SHA1:B2101BA0D20E7F79749E103272279897EDA1CBBE
                                                                                                                                                                            SHA-256:FC9D8BBA5C75F318ECF6040449F40A06DEC59860B94EB855CBC7440416B030C0
                                                                                                                                                                            SHA-512:BF4CE34990B1D75FB3260BDDE7EC7012108336DCBF1417F3C9413DA5D61B8E05D78E80184A99778D8519225FA42357669FF5FDD9A512CCB5C7F2A7F26811AAF0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Proteja a sua vida digital",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor trabalha para impedir que suas informa..es pessoais caiam nas m.os erradas.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Seja para comprar, fazer transa..es banc.rias ou navegar a Web, nossas ferramentas gratuitas podem ajud.-lo a manter-se e seguran.a -- e os criminosos cibern.ticos n.o ter.o a menor chance.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor . uma ferramenta gratuita que impede que suas informa..es pessoais caiam nas m.os erradas.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Ative o WebAdvisor para proteg.-lo contra v.rus, malware e outras amea.as . sua seguran.a online.",.. WAIFF_BUTTON_ACCEPT: "Proteja-se",.. WAIFF_BUTTON_REMIND_LATER: "Lembrar-me mais tarde",.. WAIFF_BUTTON_DECLINE: "N.o, obrigado"..}..//05EF87C124705522A44094E03E10AD13384C7B6C2E9C009D7021E950DB1F14D10BAC436E43C26B4AAC1BBBA33D80DBA4AE4942AB3F0F65F63DFDA88F84C
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1038
                                                                                                                                                                            Entropy (8bit):5.450247041256477
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGWvXqemtvxo8lo8Fv0YYqeorp9i7d0HVn1WN45:munlVYArpm0/WN45
                                                                                                                                                                            MD5:B40D10BBE04592B1EAFEA00BC24F677F
                                                                                                                                                                            SHA1:0389D3CA31A8387AB9A307B5914D7936A32A858A
                                                                                                                                                                            SHA-256:4788FD904E4EFF99BC2232F7ED0306B99AB52078F6006FB2E4CF24750BA509AD
                                                                                                                                                                            SHA-512:86B5B5255A0448C1362DF890BF4F21C29702AA2C976C868542F8B42DA2FA37D091AFDB357575D5048212ACEFF3DA73BF3F78DDD51918F6E3D117EAD19BB02D3E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Proteja a sua vida digital",.. WAIFF_TOAST_DESC_1_COHORT_1: "O McAfee. WebAdvisor trabalha para impedir que as suas informa..es pessoais caiam nas m.os erradas.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Caso fa.a compras, realize opera..es banc.rias ou navegue na Web, as nossas ferramentas gratuitas podem ajud.-lo a manter-se em seguran.a, e os cibercriminosos n.o v.o ter qualquer hip.tese.",.. WAIFF_TOAST_DESC_1_COHORT_2: "O McAfee. WebAdvisor . uma ferramenta gratuita que trabalha para impedir que as suas informa..es pessoais caiam nas m.os erradas.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Ative o WebAdvisor para se proteger contra v.rus, malware, e outras amea.as . sua seguran.a online.",.. WAIFF_BUTTON_ACCEPT: "Obter prote..o",.. WAIFF_BUTTON_REMIND_LATER: "Lembrar mais tarde",.. WAIFF_BUTTON_DECLINE: "N.o, obrigado"..}..//FDED51B6B9F9B5E6200E35ED5D2B59F11193BB163D1928B19013A1D4F42BB69F3997029516A8D18E0A2EE7ABB7C9
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1396
                                                                                                                                                                            Entropy (8bit):5.236803505318647
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGgmLHv4r6HeS0WPHH7XQfOc5TwvFovr6HeyHiM7avIixQd3ImlV4JBjc6hTSF2:amMm7Uh2zaq43jLSF2
                                                                                                                                                                            MD5:848AEE666CB1351F3980A29D3AF7A1D4
                                                                                                                                                                            SHA1:0D3838743B9C4EFF15F4305960B94D427D380FDE
                                                                                                                                                                            SHA-256:49AD1FAB3C4EDD993D85BA4E3D0FFE5A7F155CAB64FB0A838723F2A03E856EF3
                                                                                                                                                                            SHA-512:787F4FD5D021C06B72446B38EC29B0F300D22677B108255A9DE066D1BB8888978D0C97253EF6853E04D2AE9E108FC11F41F29EBBDF6A7B8069B1E127A45B810A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "........ .... ........ ...",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor ............ .................. ..... ...... .......",.. WAIFF_TOAST_DESC_2_COHORT_1: ".......... .. ...., .......... .. .. ......., .......... ........ ... .............. ...-........, .... .......... ........... ....... .......... .... ...... .. ..... . ..................",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor . .......... .........., .............. .................. ..... ...... .......",.. WAIFF_TOAST_DESC_2_COHORT_2: "........ WebAdvisor, ..... ........ .... .. ......., ........... .....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):954
                                                                                                                                                                            Entropy (8bit):5.789596697093949
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGqvUTke2+u4Z2M2vtd2keuEAvECuiFdCVtxdvGi5:s2OvpQdvGi5
                                                                                                                                                                            MD5:4C44491023BCACE71B5B5670F01A82A7
                                                                                                                                                                            SHA1:BC9972C3BDBF6899B18FB4ECF0C1E3CE9400624A
                                                                                                                                                                            SHA-256:C2C62F53C1E694275AA783F1F88C4D92124ACE06371767F675F1D59DE1AD04CA
                                                                                                                                                                            SHA-512:014D4E1053D6DF17CABDE226FF95BEF3697022F0B0309A664E6AD1571FF16AD39674D5B7C1B2C1B8CE75A2478887842AEF6B0A4001667FB7295A6EB6FAAD42FF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Chr..te svoj digit.lny svet",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor v.m pom..e ochr.ni. osobn. .daje pred ne.iaducimi osobami.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Na.e bezplatn. funkcie v.s ochr.nia pri nakupovan. online, elektronickom bankovn.ctve alebo prehliadan. webu a.nedaj. .ancu kyberzlo.incom.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor je bezplatn. n.stroj, ktor. ochr.ni osobn. .daje pred ne.iaducimi osobami.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Zapnite WebAdvisor a.ochr..te sa pred v.rusmi, malv.rom a.in.mi hrozbami, ktor. na v.s ..haj. online.",.. WAIFF_BUTTON_ACCEPT: "Z.ska. ochranu",.. WAIFF_BUTTON_REMIND_LATER: "Pripomen.. nesk.r",.. WAIFF_BUTTON_DECLINE: "Nie, .akujem"..}..//8A1B5EE10C8E25E733EAE75F94326C9EBD06FD2B2389C9F90E47F60863FA165375EF6841B40C92DF512BB6A46DF74CC134266F4854A6411B030135D935C6CBDA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):962
                                                                                                                                                                            Entropy (8bit):5.575857341922756
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGjvY4FembeVgtvKSFe0WLmLTlwFi1dAVOtrK4Di:mlQJnlH7vDi
                                                                                                                                                                            MD5:3DCE958EEE4B291C1374E4CE48C8CFC0
                                                                                                                                                                            SHA1:6F35CEB254B50FD23119E250FBF5DB8BC6D29DE5
                                                                                                                                                                            SHA-256:72A5A13B2FF562300BD16973D4F7568141EFA434C913A170659C34D8DC0771A3
                                                                                                                                                                            SHA-512:90E3375E253E34698466C1FEB79DDCD8F2DB8F23F44ACF75F6800A9ECE441CCE0FA54850D51503DA673AF148B4997FFC1EC53B3C56E1BE873B29BC978475977F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Za.titite svoj digitalni .ivot",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor radi na .uvanju va.ih li.nih informacija od padanja u pogre.ne ruke.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Bez obzira da li kupujete, koristite bankarske usluge ili pretra.ujete veb, na.i besplatni alati mogu sa.uvati va.u bezbednost-- a sajber kriminalci ne.e imati .anse.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor je besplatan alat koji .uva va.e li.ne informacije od pada u pogre.ne ruke.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Omogu.ite da vas WebAdvisor za.titi od virusa, malvera i drugih pretnji po va.u bezbednost na mre.i.",.. WAIFF_BUTTON_ACCEPT: "Za.titi me",.. WAIFF_BUTTON_REMIND_LATER: "Podseti me kasnije",.. WAIFF_BUTTON_DECLINE: "Ne, hvala"..}..//6DFEACC2836F5543D2955E6A9A48708DCAA122531C0857F611AD5F38A9149EA8E949381DD2CCB4B54C8FA540FE331E657EC77F617F084D9215FCAC3A8288F922++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1002
                                                                                                                                                                            Entropy (8bit):5.520357138204716
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGKlvc49IeIuZR6/Otvo6WT8E9IehgNMxi72dUVIE40TMCO:Y9au+2M8E9nqMSOk40Tu
                                                                                                                                                                            MD5:53291E841F78133612D2CEED35493ED5
                                                                                                                                                                            SHA1:FCB7CC3152F472EAD955E6F97A3E77B671F29FE7
                                                                                                                                                                            SHA-256:91C7B0C5EFDB5F40020B33EE626DA0850037CA3FD2617C6C6E4B3379E764DB6B
                                                                                                                                                                            SHA-512:EC705FD1EC2CED44D3DFF507A31FB2A9C68B0A898A89436A16D07E1DAAA1E646A5176826B2A0A8D3DD099D9EB0F507B3E3EB31D6E3B2E89329FB3A08461B3DC8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Skydda ditt digitala liv",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor jobbar f.r att f.rhindra att din personliga information hamnar i fel h.nder.",.. WAIFF_TOAST_DESC_2_COHORT_1: "Oavsett om du shoppar, utr.ttar bank.renden eller surfar p. internet kan v.ra kostnadsfria verktyg hj.lpa till att h.lla dig s.ker -- och n.tbrottslingarna kommer inte ha en chans.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor .r ett kostnadsfritt verktyg som hindrar att din personliga information hamnar i fel h.nder.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Aktivera WebAdvisor f.r att skydda dig mot virus, skadlig programvara och andra hot mot din s.kerhet p. internet.",.. WAIFF_BUTTON_ACCEPT: "Skydda dig",.. WAIFF_BUTTON_REMIND_LATER: "P.minn mig senare",.. WAIFF_BUTTON_DECLINE: "Nej tack"..}..//C5DD8703598B1C9479B775D8F6F05687A39282CD92FB6A023340F583B775703103F997B78EE840C68B0AC8E9E096424BAAF8638993526AE0DF63021E560A88CA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1061
                                                                                                                                                                            Entropy (8bit):5.631821293910584
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGS2QvNaIeIse0jz0CtBsvzCOvje4DFkNHiNQd1NHVcdVQDV:PaahjzHtWbnZMH2QR
                                                                                                                                                                            MD5:AB0BCF641E9CB622F5D3741D36A5F4E4
                                                                                                                                                                            SHA1:72E37992E0C57E0AD44E0D03472D134898C10139
                                                                                                                                                                            SHA-256:C2BF08768A67C13DDB703BE667E1A4BFFA71B724D1E7A4E70BF7E09135B0AADB
                                                                                                                                                                            SHA-512:2EE897FF17F8CD91E4D47AB275CD00F8FF36921E6E70E67EB67C2D57ECA329C8996E059EF0D4798F77A4E4011A53C9AED97279E9788D7BDEFAA229FEE2CC1BEC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "Dijital ya.am.n.z. koruyun",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor ki.isel bilgilerinizin yanl.. ki.ilerin eline d..mesini engeller.",.. WAIFF_TOAST_DESC_2_COHORT_1: ".ster al..veri. yap.n, ister banka i.lemi ger.ekle.tirin, ister web'de gezinin, .cretsiz ara.lar.m.z g.vende olman.za yard.mc. olur; siber su.lular.n hi.bir .ans. kalmaz.",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor, ki.isel bilgilerinizin yanl.. ellere ge.mesini .nleyen .cretsiz bir ara.t.r.",.. WAIFF_TOAST_DESC_2_COHORT_2: "Kendinizi vir.slere, k.t. ama.l. yaz.l.mlara ve .evrimi.i g.venli.inize y.nelik di.er tehditlere kar.. korumak i.in WebAdvisor'. etkinle.tirin.",.. WAIFF_BUTTON_ACCEPT: "Kendinizi koruyun",.. WAIFF_BUTTON_REMIND_LATER: "Daha sonra hat.rlat",.. WAIFF_BUTTON_DECLINE: "Hay.r, te.ekk.rler"..}..//4733763885A4F0CBE71F154E1732926C5B3F517B835BE9F1FFED7C084CC221CD03B64
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):917
                                                                                                                                                                            Entropy (8bit):6.338078767595641
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGFvQsaInleBd82wvxsnInlehoyliIodS8Vqwr7KFTiX:RaI4i2ZnI9b77X
                                                                                                                                                                            MD5:E31EA455A252A16AE63F571F2558F351
                                                                                                                                                                            SHA1:85A4C98F9EE863BD0693BF4F8DAF3DE9754232A6
                                                                                                                                                                            SHA-256:F6B8C644C71CDEFB6036915531C3D328E73F0A149980C7862005B61B55329315
                                                                                                                                                                            SHA-512:A38C87841714CC7AE187982563FCDA2E20EDB8D1158E3E49E6DBDF82EEDD0E2386C778D8A0C3E9C7E32EE419F6164BF4B530BFA4C75A0AC16112E39BA01F8B15
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "........",.. WAIFF_TOAST_DESC_1_COHORT_1: ".... ...................",.. WAIFF_TOAST_DESC_2_COHORT_1: "........................................................",.. WAIFF_TOAST_DESC_1_COHORT_2: ".... ............................",.. WAIFF_TOAST_DESC_2_COHORT_2: "................................",.. WAIFF_BUTTON_ACCEPT: "....",.. WAIFF_BUTTON_REMIND_LATER: ".....",.. WAIFF_BUTTON_DECLINE: "...."..}..//08C118F48DCB5DD454C97A1A4508971B7DCFF3A730E987EB761E4D2B0CFF573C8B2488DF2CD9622F41BDAAE55C8B681BAF049B42077D685BB3AA3920153EA4F0++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):915
                                                                                                                                                                            Entropy (8bit):6.381419326448278
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7uGYvJeiCCpqKvZeedNsyinkdSgVq4YNj1IL:GJRNxJL
                                                                                                                                                                            MD5:068397E779297050800B9E8653111EAA
                                                                                                                                                                            SHA1:ECFDC61B0C92DEE9A9432FEE1CCBC4427D99E1EA
                                                                                                                                                                            SHA-256:9EBDDD6060785D2F9272D288B3B92FCDF97C83F55BE7F6070D9EB037CE223EF3
                                                                                                                                                                            SHA-512:EF531CC79F85AA9801EFF83D4E67658B45DCDCE3BE94DD6BBCF276EF5045353D82FAD0183ECD19A9E7A2384B0FF69AE53E37623EB5F2945DA78ACD107696F92E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrExtensionInstall_ = {.. WAIFF_TOAST_TITLE: "........",.. WAIFF_TOAST_DESC_1_COHORT_1: "McAfee. WebAdvisor .....................",.. WAIFF_TOAST_DESC_2_COHORT_1: "...............................................",.. WAIFF_TOAST_DESC_1_COHORT_2: "McAfee. WebAdvisor ..........................",.. WAIFF_TOAST_DESC_2_COHORT_2: ".. WebAdvisor ...........................",.. WAIFF_BUTTON_ACCEPT: "....",.. WAIFF_BUTTON_REMIND_LATER: ".....",.. WAIFF_BUTTON_DECLINE: "......"..}..//44005B08579073257891516EF9EBDA28F27E9BB3644446D2278395347CEF382BE2D68259C9C47D7D7DE5BFDBC55C4E42BCEB91C5ECE4F45970626C57B3F613BD++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4962
                                                                                                                                                                            Entropy (8bit):5.646884833588854
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Ht5PSpPUGEAopoM4odOR9EPH1h1bTzUXToCnqIK92n4laxOQDgu+:rqpcGEAQ54ROdhlTCTXqIKM4lansu+
                                                                                                                                                                            MD5:4E27D3782D712E0D08FEC2F9775ADA9D
                                                                                                                                                                            SHA1:AE9D9012D8021A1D0D2D42C8C31C5F3E6D367BB1
                                                                                                                                                                            SHA-256:628FDB0502503B8AA055E24C2D156FED737ACD8F48F3B5E1CD9DB9DC6FB7C233
                                                                                                                                                                            SHA-512:F70122D10100CAB9B549F3FC573356845AB9EC2DEBD209088CB70780BBE88DA7A8670E1DA540087AE03997500A484B254C8C5443A41C48A748DF0D9927725EBE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Dokon.ete svoji ochranu na internetu . ZDARMA!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Jen tak d.l!",.. OEM_TOAST_VARIANT_INFO: "M..ete se na internetu c.tit mnohem bezpe.n.ji. P.idejte zabezpe.en. vyhled.v.n., abyste dokon.ili ochranu p.i proch.zen. internetu McAfee a zv..ili sv. bezpe.. na internetu.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Aktivov.n.m zabezpe.en. vyhled.v.n. jste dokon.ili nastaven. ochrany p.i proch.zen. internetu McAfee.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Zku.ebn. verze antivirov. ochrany McAfee",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Ochrana internetov.ho prohl..e.e",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Ochrana prohl..e.e je va.e linie obrany proti nebezpe.n.m webov.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4454
                                                                                                                                                                            Entropy (8bit):5.394761777553124
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Hud7h5xpL1yuPQacJspPbkwriNTSwcvEFyFQFgvQ:M7hTpByuodJspPbrriNmwcvkZFg4
                                                                                                                                                                            MD5:A659B76FE11F00CB564DE596F0123016
                                                                                                                                                                            SHA1:C70CA0AF3D7DBAE353635B8BA1D386D31397B828
                                                                                                                                                                            SHA-256:0A13969EEDBD963E86564D087DFF16C7ED3FE55872F1CB0468AFEAE0D85C2848
                                                                                                                                                                            SHA-512:9BE6B449A761B1919C2EF07EFE7117C242F1260DDC5DE535F814F1BAD7FAAADBDD4C4950ABD46FB574429A8CC267E3B654694A54F2C7E4CC57AF51701DD37E6E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "G.r konfigurationen af din onlinebeskyttelse f.rdig . GRATIS",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "S.dan!",.. OEM_TOAST_VARIANT_INFO: "Du kan have en endnu bedre beskyttelse online. Tilf.j s.gebeskyttelse for at g.re konfigurationen af McAfee Web Protection f.rdig og forbedre din sikkerhed online.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Du har afsluttet oprettelsen af din McAfee Web Protection ved at aktivere s.gebeskyttelse.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Pr.veversion af McAfee Antivirus",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Online browserbeskyttelse",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Browserbeskyttelse er din f.rste forsvarslinje mod usikre websteder, links, downloads, malware og meget mere.",.. OEM_TOAST_VARIA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4525
                                                                                                                                                                            Entropy (8bit):5.357913243879113
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Hu7HbtZh8r8XUawmvah/R70a0+PNIk02+qjdLcSpQk86B:yHbF8rbme/RRpOk02+QtcSuk86
                                                                                                                                                                            MD5:1784B37BB34D9318CF61BB12542473BB
                                                                                                                                                                            SHA1:8A419D0B5CD92F8EA7A6DD501833EB932533FD28
                                                                                                                                                                            SHA-256:B13B2FDF8304A8FFE6FA74AFDFA066B1B7191E9D6C0A4B51CB24299032EFEB4E
                                                                                                                                                                            SHA-512:8D0CA8C3B407937505DF6F7E374AB1C8CB375D750F7920A9968B22625E504D7465D34618CE864FCD34D9627F13D610CD3E6A2397578FCF82F4641110D7A2FD1C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Komplettieren Sie Ihren Online-Schutz . KOSTENLOS!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Sie nutzen nicht alle Funktionen!",.. OEM_TOAST_VARIANT_INFO: "Ihr Online-Leben k.nnte noch viel sicherer sein. F.gen Sie Online-Suchschutz hinzu, um den McAfee-Webschutz zu vervollst.ndigen und Ihre Sicherheit im Internet zu erh.hen.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Sie haben den Suchschutz aktiviert . der McAfee-Webschutz ist jetzt vollst.ndig eingerichtet.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "McAfee-Testversion",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Browserschutz",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Der Browserschutz ist Ihre erste Abwehrreihe gegen unsichere Websites, Links, Downloads, Malware und mehr.",.. OEM_TOAST_VARIANT_F
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6944
                                                                                                                                                                            Entropy (8bit):5.098772797667829
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HwrU5F9ob1w9r4vQZEiH/MkCyf9Wxi8+cw2tV9fnozQRfQ7oRvt:QrU5FixMrp/MksxbhtV91I7oRvt
                                                                                                                                                                            MD5:38A0E4A175309DB73A17985840ECB41E
                                                                                                                                                                            SHA1:0EC458BDBED8B956044710CDE092D5104B8BCBC9
                                                                                                                                                                            SHA-256:492BBCB89A9DCF4D33E173632CC93FD85CAD46542F9C4136E11531089870A1D9
                                                                                                                                                                            SHA-512:531BD90BE6AC65954F34FA5E199F39C1DDF171BD5D5279CA7CAAFD3786B5590EC063BAF8C06928E83DA835DF12C640C79BBA57669BFFDC35A0FA38F374D197BC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "........... ... ........... ... ......... . ......!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "......!",.. OEM_TOAST_VARIANT_INFO: ".... ........ .. ..... ... ........ ... .......... ......... ... ......... .......... ... .. ............ .. ........... ... ......... McAfee ... .. .......... .. ........... ... .........",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "............ .. ....... ... ............ ... .......... McAfee .............. ... ......... ...........",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "...... McAfee Antivirus",.. OEM_TOAST_VARIANT_FEATURES_ENABL
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4727
                                                                                                                                                                            Entropy (8bit):5.36476564696804
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HVm7IJTUE/c0dnhD6HaTKz+cfItWHMtDJHRLWyk7mEQheM0FP:IYUcno6mpbONH5Wt7mPheMCP
                                                                                                                                                                            MD5:D93BD044D71235CD5B1D2126B1A5FD68
                                                                                                                                                                            SHA1:239D7C744E60871D825505B9B559527741BB65BC
                                                                                                                                                                            SHA-256:635CC2808EAA48CC3D6FBBD71135858542DDC257B48DD4A4EE99BFAF44FEEA91
                                                                                                                                                                            SHA-512:DBE1474B9733D6EB0BD54E0A3E6A7D0C81B8B4C8C81B1EC22B67E23D508EDC525EB47C5063B3DC8B9F6A6ECE87D18603EB4EDF32DFB02D991767BE4A0B6AF25B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Refuerce su protecci.n online GRATIS",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: ".Muy bien!",.. OEM_TOAST_VARIANT_INFO: "Puede navegar con mucha m.s seguridad. A.ada una capa de protecci.n a sus b.squedas en Internet con McAfee Web Protection.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Ha terminado de configurar McAfee Web Protection con la protecci.n para las b.squedas.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Versi.n de prueba del antivirus de McAfee",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Protecci.n para navegar por Internet",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "La protecci.n del navegador es su primera l.nea de defensa frente a sitios web, v.nculos y archivos de descarga poco seguros, adem.s del malware y otras amenazas.",.. OEM_T
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4645
                                                                                                                                                                            Entropy (8bit):5.372840787353813
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:H+uLpSRLUr0y8YDhD5MkLb6kyoRV41uRyrF4QVP2q:euLiQgu4kLbLyqMuRAFjVPX
                                                                                                                                                                            MD5:A394E17B5CA626ABAAA6467077B3E5DF
                                                                                                                                                                            SHA1:DAB7412F54533E5345D0458468DA19FC6E5BD101
                                                                                                                                                                            SHA-256:340F71C8D0C4CE43CB6194F1387968363696FB6F3CB57643993CAF498FFFB578
                                                                                                                                                                            SHA-512:FB9EA9016FD929604412B7C3059900A378A7C7CF274F997825466963C1E148E09C78AAFDF728BC191891A3CA7E85809EA003E7E9B04E7DB6E03B95C3FC7BAC79
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Completa tu protecci.n en l.nea. .GRATIS!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: ".Fant.stico!",.. OEM_TOAST_VARIANT_INFO: "Puedes estar mucho m.s seguro en l.nea. Agrega la protecci.n de b.squedas para completar McAfee Web Protection y mejorar tu seguridad en l.nea.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Has completado la configuraci.n de tu McAfee Web Protection activando la protecci.n de b.squedas.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Prueba de McAfee AntiVirus",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Protecci.n del navegador en l.nea",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "La protecci.n del navegador es tu primera l.nea de defensa contra el malware, los sitios web, las descargas y los v.nculos inseguros, y mucho m.s
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4369
                                                                                                                                                                            Entropy (8bit):5.382012747965098
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HCY1buqqISrqXmaENWWAyROr+DTVgjifdQhdM:i2bURGOAlyROrWgjCCha
                                                                                                                                                                            MD5:67318590DD6DCF9C9FDEB28CBD2B08B3
                                                                                                                                                                            SHA1:D60B883105C993EED5C3BB48C043BB89B67F6277
                                                                                                                                                                            SHA-256:3BE92620EAC468E3550D908D89514979A3EC0F37260DD771DC5922A90D0391A0
                                                                                                                                                                            SHA-512:1DF0CEE261A720F7DFA11A4736301404C4DFAC1952E135766475E4E7DB886B2EFA3EBDF32D2EFDC5DF9360BA7DE6AAE3FB2506CBD05646CAE5C73A2FDB1BC2FE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "T.ydenn. verkkosuojauksesi . MAKSUTTA!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Hienoa!",.. OEM_TOAST_VARIANT_INFO: "El.m. verkossa voi olla turvallisempaa. T.ydenn. McAfeen verkkosuojaus hakujen suojauksella ja paranna turvallisuuttasi verkossa.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Viimeistelit McAfeen verkkosuojauksen ottamalla hakujen suojauksen k.ytt..n.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "McAfee Antivirus -kokeiluversio",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Selaimen suojaus verkossa",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Selaimen suojaus on ensimm.inen puolustuslinjasi muun muassa vaarallisia verkkosivustoja, linkkej., latauksia ja haittaohjelmia vastaan.",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_NAME: "Hakujen suojau
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5002
                                                                                                                                                                            Entropy (8bit):5.3618244169536
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HZzGKZjPEluOR2wzvjc8/MWaAE+XZKn3mTvARBdphbmbQQQJA3jqtQjQ7cjUgLn:lVEzx/Zk3uvAdfdJo1jzTn
                                                                                                                                                                            MD5:6A3D4851DB8F6174B5B39B11ADD93574
                                                                                                                                                                            SHA1:700B972FA021989DE003E925683A5F80D5ED495D
                                                                                                                                                                            SHA-256:88DB68AB507E55379EEEA8411B174C649E878BED65D021F355BC6CCD76270FED
                                                                                                                                                                            SHA-512:49E4F91CDFE623BA29D6FAD87188F5015A0E885DAA6E9B7502DD29B3D37F5A9D3944A83AF4988249375405DCF107D5C27B2C5C55AC911D084ED82BC1D6313B4A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Compl.tez votre protection en ligne - GRATUIT!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Quelle bonne d.cision!",.. OEM_TOAST_VARIANT_INFO: "Vous pourriez .tre beaucoup mieux s.curis. en ligne. Ajoutez la recherche s.curis.e pour compl.ter la protection Web McAfee et pour renforcer votre s.curit. en ligne.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Vous avez compl.t. la configuration de votre protection Web McAfee en activant la recherche s.curis.e.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: ".valuation gratuite de l.antivirus McAfee",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Protection du navigateur en ligne",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "La protection du navigateur est votre premi.re ligne de d.fense contre les sites Web, lie
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4951
                                                                                                                                                                            Entropy (8bit):5.368494552125785
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:H1dQtHATWE0/hUcGNyFmjjc8md8QPSsnRxKGF7juyNmYSff9j5rQgFSS:VKtrE0pIUL6sR727FBygFSS
                                                                                                                                                                            MD5:056063BDD96CE5802216A7249606D273
                                                                                                                                                                            SHA1:6C34DA5D6E8EE775472DD0740249DDF612C01264
                                                                                                                                                                            SHA-256:0B1C31A69CD1D5C9EF04D5DB7460B63F5109A6CEAD5D94659B19D8887188A11F
                                                                                                                                                                            SHA-512:CBE2BF3AF47CC40F441A9FC2B41756A37DA6C2D658F1D2FE8B29E3B56631B1B8BB038DDFA119AB7BB4F796FCC7A731469790378D8059B1015124361F8D685B1D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Terminez la configuration de votre protection en ligne . GRATUITEMENT.!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Bravo.!",.. OEM_TOAST_VARIANT_INFO: "Vous pouvez .tre beaucoup mieux prot.g. en ligne. Ajoutez la protection des recherches pour compl.ter votre protection web McAfee et renforcer votre s.curit. en ligne.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Vous avez termin. la configuration de votre protection web McAfee en activant la protection des recherches.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: ".valuation de l'antivirus McAfee",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Protection du navigateur en ligne",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "La protection du navigateur constitue votre premi.re ligne de d.fense contre les sites
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4651
                                                                                                                                                                            Entropy (8bit):5.4634190327462555
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HCsNsKVqer5TZNOZG9OBhwMsvA0+Ovho6rQYBoF:zNsiqsZ4cM6A0+Ove60YiF
                                                                                                                                                                            MD5:8780E1A0A4EC2CF2FC79819AC33B409E
                                                                                                                                                                            SHA1:19CA2AC32060FB749041CECC15CD28458E7FD07A
                                                                                                                                                                            SHA-256:388719F06F56B3B99ACF659127F76A968EF22F46DA3F4BCA540C613BCAF12AD8
                                                                                                                                                                            SHA-512:FA9F7697ACF3B815760152349DDC1B01D0AC1F10AB19B91E6411486E0A0E2AF3B1A310FD260286CC8B57D927824AAE6876D3D6FFBE4CE728DEAB8A7CB69B5F22
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Dovr.ite svoju online za.titu . BESPLATNO!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Tako treba!",.. OEM_TOAST_VARIANT_INFO: "Na mre.i mo.ete biti puno sigurniji. Dodajte za.titu pri pretra.ivanju kako biste dovr.ili McAfee Web Protection i pobolj.ali svoju sigurnost na mre.i.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Dovr.ili ste postavljanje svoje McAfee Web Protection omogu.avanjem za.tite pri pretra.ivanju.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Probna verzija McAfee Antivirus",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Za.tita preglednika na mre.i",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Za.tita preglednika va.a je prva linija obrane od nesigurnih web-mjesta, poveznica, preuzimanja, zlonamjernog softvera i jo. mnogo toga.",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4620
                                                                                                                                                                            Entropy (8bit):5.543617473209933
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HfqjRDpi/v3XWyYNDX5XcmPcnrW2S6CatskM0QlH7ct:/q7gGFDX5dorWKskCF7q
                                                                                                                                                                            MD5:8C673408D8CA2ECC2C413D6E1DBBCD92
                                                                                                                                                                            SHA1:3CA8B4AFF0D8B913A6B4DF15801BAC1CBB8810F9
                                                                                                                                                                            SHA-256:18BCD1DB9FD5A0D472EE8126A777EB88888BADE3C309FD50865D3BFCA229ABA4
                                                                                                                                                                            SHA-512:814B71BE326D93E7402ABF685AAF6D5CA8A6DC954934FE40AE6F3C4A923620C6456667B281FD61E5EED9347E1092563D2778B7DD43D7D85586CF5DCAD1DBD544
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Eg.sz.tse ki online v.delm.t . INGYEN!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Nagyszer.!",.. OEM_TOAST_VARIANT_INFO: "M.g nagyobb biztons.gban lehet online. Enged.lyezze a v.dett keres.st, hogy teljess. tegye a McAfee webes v.delmet, .s n.velje online biztons.g.t.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "A v.dett keres.s bekapcsol.s.val befejezte a McAfee webes v.delm.nek be.ll.t.s.t.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "McAfee v.rusirt. pr.baverzi.ja",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Online b.ng.sz.v.delem",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "B.ng.sz.je v.delme a frontvonal a nem biztons.gos weboldalak, hivatkoz.sok, let.lt.sek, k.rt.kony programok stb. elleni biztons.g ter.n.",.. O
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4608
                                                                                                                                                                            Entropy (8bit):5.24552695607158
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HQj/oecik1Rs8CwrTww7Jr6QdIBOG1XY4RO2YC+qQAjx2:4/obl1VnUw7Jr6QdIh1XY4RO2YC+pCw
                                                                                                                                                                            MD5:5868296FE9E4C2686EBA44ACC7736D37
                                                                                                                                                                            SHA1:083037480237422BA7042B443B9B8EDCDC91E1AE
                                                                                                                                                                            SHA-256:612726B0CBFF2FC22923ED4AF818328F1322679C2680B7D7278AE77FEB4F5344
                                                                                                                                                                            SHA-512:0E1830C3AEE62177D48C70998E25AADA0F9DF3EFABB93351336C0894FE9FF91117FF1D6A46C1E299C75B8AB8A2F2F8A4D1E880592E7E36E79FAE9718338276BA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Completa la tua protezione online - GRATIS",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Ottimo!",.. OEM_TOAST_VARIANT_INFO: "Puoi migliorare notevolmente la protezione online. Aggiungi la protezione delle ricerche per integrare McAfee Web Protection e migliorare la tua sicurezza online.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Hai completato la configurazione di McAfee Web Protection attivando la protezione delle ricerche.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Prova di McAfee Antivirus",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Protezione online del browser",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "La protezione del browser . la prima linea di difesa da siti Web, collegamenti e download non protetti e dal malware.",.. OEM_TOAST_VARIANT_FEATURES_DISAB
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5215
                                                                                                                                                                            Entropy (8bit):5.859003972604919
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HaYG+SPT4mep9K9B95H1bccLyf/9f71bYwNKiVEVH9skXbrbQCQ6L2nKQKUGC:q+SPT4mnh5d/KVYwNZiZ9RrOJ6C
                                                                                                                                                                            MD5:A541AF3628C6487A87229D6ED38970FE
                                                                                                                                                                            SHA1:259D22A54D1694ACEE13888FF0982BA325E142A7
                                                                                                                                                                            SHA-256:2C5CB26A55EA781490D1FECE3F78535711BA884B4E899DA5B3F7C731890BE86C
                                                                                                                                                                            SHA-512:0D7056DE6AD94E30ADE7EFC671C54EE5A81E4910A6B7922A71423A8260624EE2BFC3F6FCBC00E83A84439389BD6C5CC6B874D6CB060443C21D84B426DE03C6E5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "................. - .....",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: ".......",.. OEM_TOAST_VARIANT_INFO: "............................... McAfee Web Protection ..........................",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: ".............McAfee Web Protection ...............",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "..... .............",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: ".........",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4770
                                                                                                                                                                            Entropy (8bit):5.834460120265474
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HNby+JvldshnPhOVGUZoI+0MYAT2T1eHEzdaVQkwpSMH:tGk3sNhxHI+0cUKu06kTMH
                                                                                                                                                                            MD5:80CD4DA8CD225A78DDF3E73CBE51EABD
                                                                                                                                                                            SHA1:334ECADEBD1686FB1465CA4BA38FB29652F0EC54
                                                                                                                                                                            SHA-256:1334BEC9DC21AA478DEA12A868AA7FDAF1A95990C1015019DDBE6B90907BBA65
                                                                                                                                                                            SHA-512:581CE2F5BDE668724560657C0FD577ECB28361D3EDBC31A53E125EC06E4D0334C941120E424F4365F3BDE92316191F59F4741EB3280565B33FEA206E3917AD6F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "... ... ... ... ......",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "......!",.. OEM_TOAST_VARIANT_INFO: "... ... ... . ..... .. ... .... ... McAfee . ... ... ... ... ......",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: ".. ... ..... McAfee . .. ... .......",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "McAfee ...... ...",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "... .... ..",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: ".... ... .... .. . ..., .., ...., ... .. .. ... ... ......",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4467
                                                                                                                                                                            Entropy (8bit):5.38161829670382
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HqSH3f2pqCBDGeE36ZmcQf5xPCN1LeCYrWbVhYqeQGE/MSbIY:KmW4eClJ/PCN1LXYr2LYqdGE/xbR
                                                                                                                                                                            MD5:86593197A71C0F209DBE3A68004CB7C9
                                                                                                                                                                            SHA1:6509AD251FE7DEF618F906752413A5AE514BD5CF
                                                                                                                                                                            SHA-256:7F7CDDF4F4E42063B3E81598D9879E0B7DE40F496573E0DE47BF184AAEFD1C90
                                                                                                                                                                            SHA-512:44221D254012DF747CB82A727F98C8B029AF4681CB0348A9CC60898D17D27BEB061987934255F490FA000CB93B24EBF53E42D65C84570E7A6A3FECEADDCF000A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Gj.r nettbeskyttelsen din komplett . KOSTNADSFRITT!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Ikke verst!",.. OEM_TOAST_VARIANT_INFO: "Du kan bli mye tryggere p. nettet. Legg til s.kebeskyttelse for . gj.re McAfee nettbeskyttelse komplett og forbedre nettsikkerheten din.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Du fullf.rte konfigureringen av McAfee nettbeskyttelse ved . aktivere s.kebeskyttelse.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Pr.veversjon av McAfee antivirus",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Nettleserbeskyttelse",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Nettleserbeskyttelse er ditt fremste forsvar mot usikre webomr.der, koblinger, nedlastinger, skadelig programvare med mer.",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_NAME:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4299
                                                                                                                                                                            Entropy (8bit):5.379409348781231
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:H2AwS9S9NzRHuSpGikmkH4XRgPKvpR1E1B2azPDcF2g+FeksVMkgR1pfQ55C:WAweeN9hGikmkHDKpRS1EaTDw2g+Ffs8
                                                                                                                                                                            MD5:C2AB04CD7E5E26640BB7A66E7B3EFDA5
                                                                                                                                                                            SHA1:C0448971C5B43F92FB83436E7391B995BFF941BB
                                                                                                                                                                            SHA-256:549457A9156FCBD81D5B46844D6DCC85FD983E44A25F510B4BDF8A60A0A52346
                                                                                                                                                                            SHA-512:ED59892217E479264C8AE724A0CE254D5DF74862BF2033F947E7535F9E1E0ED32BDB3BA1FD0C98CAC15499CE60A7057B7B841BDF427DA518C0CEFB3B685E2B0A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Voltooi uw online bescherming . GRATIS!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Goed gedaan!",.. OEM_TOAST_VARIANT_INFO: "U kunt online veel veiliger zijn. Voeg zoekbescherming aan uw McAfee-webbescherming toe en verbeter uw online veiligheid.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "U hebt het instellen van uw McAfee-webbescherming voltooid door zoekbescherming in te schakelen.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Proefversie van McAfee Antivirus",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Online browserbeveiliging",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Browserbeveiliging is uw eerste verdedigingslinie tegen onveilige websites, koppelingen, downloads, malware en meer.",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_NAME: "Zoekbescherming",.. OEM_T
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4749
                                                                                                                                                                            Entropy (8bit):5.577135253793333
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HeH6Ry8L5clQB1MuoIbuNO8Q2STtWQLpXsJi6jiTZ/80zthQX2w+:+Ht8tclQB1AnO8Q2STtWQLpXsJrEZ/8Y
                                                                                                                                                                            MD5:6B0584C8750221C9B143AD8E4851F97E
                                                                                                                                                                            SHA1:BAF3739AB3EB0EC8D737B0CDD7019D9770B26540
                                                                                                                                                                            SHA-256:A129819ED747FABDE12841BFB9B25DEC69CF9FF4E25E96BCB73E5AE58400E560
                                                                                                                                                                            SHA-512:7491F8665167EC0E4F56F66313769EF894BD8D77DFBED027AB15A2C16297EA81287D79265E25DC4A11CF2C6B3A19F24F9EBD8134738EA37CDF263A63C4F3F56A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Wzmocnij swoj. ochron. w Internecie . BEZP.ATNIE!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Dobra robota!",.. OEM_TOAST_VARIANT_INFO: "Mo.esz mie. znacznie wi.ksz. ochron. w Internecie. Dodaj ochron. wyszukiwania, aby wzmocni. ochron. funkcji McAfee Web Protection i zwi.kszy. swoje bezpiecze.stwo w Internecie.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Uko.czono konfiguracj. funkcji McAfee Web Protection poprzez w..czenie ochrony wyszukiwania.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Wersja pr.bna programu McAfee Antivirus",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Ochrona przegl.darki w Internecie",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Ochrona przegl.darki to pierwsza linia obrony przed niebezpiecznymi witrynami, ..czami, pob
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4556
                                                                                                                                                                            Entropy (8bit):5.392364845070507
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Hlahgzv62PaQaLuR89CrPnzGS77lq+XQsnaS:FaqvFL7R89MPnzGS77U+AsaS
                                                                                                                                                                            MD5:E620EE0E71FD5179379A8C1D4FCA2405
                                                                                                                                                                            SHA1:9ECC0BEDF394A26462DAAA0A8339A5A2116E6BB2
                                                                                                                                                                            SHA-256:B857F08E6793D3A7D1F7FCAB2CC03729864929D40890AC508CAA9C163C8C401F
                                                                                                                                                                            SHA-512:E51CCBB50DFC2050608EA7CD9250061D7DD09E34CDA9B0966F2E8EE3833D4A76C4C0312F1A3AEBA825568BA5A85726BD81BF32470A0B1C2A4ECD5E0FB9919E2A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Conclua a sua prote..o on-line GRATUITAMENTE!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: ". isso a.!",.. OEM_TOAST_VARIANT_INFO: "Voc. pode ter muito mais seguran.a on-line. Adicione prote..o de pesquisa para completar o McAfee Web Protection e aumentar sua seguran.a on-line.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Voc. concluiu a configura..o do McAfee Web Protection ativando a prote..o de pesquisa.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Avalia..o gr.tis do antiv.rus da McAfee",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Prote..o do navegador on-line",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "A prote..o do navegador . sua primeira linha de defesa contra sites, links e downloads inseguros, malware e muito mais.",.. OEM_TOAST_VARIA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4478
                                                                                                                                                                            Entropy (8bit):5.365427676170518
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HI2q8anq+9cCh9FcTVvtObxsp0R1vsfYRq+XQwgac:o38eq7CTWRvtO6pe1vsfYg+Awdc
                                                                                                                                                                            MD5:1FFACA84AB047522238575D26444B1C1
                                                                                                                                                                            SHA1:E3A08051A07F92F334B6DE958336F1C3A503BCC9
                                                                                                                                                                            SHA-256:F669083F2800C6CC1BE35B992CDA2922B55A493A6076260782D088524DB56DF8
                                                                                                                                                                            SHA-512:3DF57FB94FBA7BD6E33381DF5F150AE3D7E49FA655283EDA272F371AE2267D599C10CC442EFD3D3BF960F739B293B2B3F1CE4705ACCE8187EEC3203FED3109E7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Complete a sua prote..o online . GR.TIS!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Boa!",.. OEM_TOAST_VARIANT_INFO: "Pode estar muito mais seguro online. Adicione a prote..o de pesquisa para completar o seu McAfee Web Protection e aumentar a sua seguran.a online.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Terminou de configurar o seu McAfee Web Protection ao ativar a prote..o de pesquisa.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Avalia..o do antiv.rus McAfee",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Prote..o de browser online",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "A prote..o de browser . a sua primeira linha de defesa contra Web sites inseguros, transfer.ncias, malware e muito mais.",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_NAME: "P
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6441
                                                                                                                                                                            Entropy (8bit):5.191712551362283
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:H3P3dV2BQF3iK4ttHiUWB3E4L2bLrrDSiaA1oSUd0BSO+Vft1ZQpmvfRYWc:v/2Bo3L4iPdMPnSvA1UQbGf6pMfRc
                                                                                                                                                                            MD5:17601027BE0E1941274EC8AA97DA3F37
                                                                                                                                                                            SHA1:4BE73FA80DB484EC1712BCD56D356CAA57C8687E
                                                                                                                                                                            SHA-256:A4FE46EBD30F700AF434F14DBF0D9B9D803BB671A4175130AA1271736C84E0B4
                                                                                                                                                                            SHA-512:33C99E1E4B601AF85F1DD4435481FE06A93CB779660F31B4DDE8EA50376F620B978C78DE2C675513340B3E825AE40AC34FDA3D71A437A063F8D0C25B63045677
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "......... .... ...... . ......... . .........!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "... .......!",.. OEM_TOAST_VARIANT_INFO: ".. ...... ........ .... ............ . .......... ........ ...... ......, ..... ......... McAfee Web Protection . ........ .... ............ . ..........",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: ".. ......... ......... McAfee Web Protection, ....... ...... .......",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "....... ...... McAfee AntiVirus",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "...... ........ . .........",.. OEM_TOAST_VARIANT_FREE_LABE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4713
                                                                                                                                                                            Entropy (8bit):5.639633098055761
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Hu/cMHiS0zIB64Vb8JmdTv6zInPVO+mMQ90P:2c+iE64xTdTvPVng90P
                                                                                                                                                                            MD5:B1E8660F650C5C8D95DF80E87851321B
                                                                                                                                                                            SHA1:C18411FD7C8B8A903EA90F82B72F87DA6B5E3F3F
                                                                                                                                                                            SHA-256:D031D75D075E0A90E618AB591A19A7315D8CF731C75DF1646964C05509490390
                                                                                                                                                                            SHA-512:E5A7313EEDD1EA96D6F395225ACEF16B730685FBB613417F08FA3FF6CF386A0A6969DC876538551B9695DD84DFB0DE248E939C52F40988E8C0B503D0740485AB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Dokon.ite nastavenie online ochrany ZADARMO.",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Chr..te sa.",.. OEM_TOAST_VARIANT_INFO: "Aj online m..ete by. v.bezpe... Pridajte ochranu vyh.ad.vania do produktu McAfee Web Protection a.zv..te svoju bezpe.nos. online.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Zapnut.m ochrany vyh.ad.vania ste dokon.ili nastavenie McAfee Web Protection.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Sk..obn. verzia antiv.rusu od McAfee",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Ochrana online prehliada.a",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Ochrana prehliada.a tvor. prv. .rove. ochrany pred nebezpe.n.mi webov.mi lokalitami, odkazmi, stiahnut.mi s.bormi, malv.rom a .al..mi hrozbami.",.. OEM_TOA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4628
                                                                                                                                                                            Entropy (8bit):5.433533100276745
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:H7718TA7STZFOZGOA9wSdASMoNNPDgYK0hQOLYBB+T:b7glDu8ASMAtjK0mOEBAT
                                                                                                                                                                            MD5:60E06C7C2CC2E0EB1DD485432924B968
                                                                                                                                                                            SHA1:21F75F04176180A254C7412A114D12E7C3B9EBEE
                                                                                                                                                                            SHA-256:D98475CAC32A5E18EA43CC9D35D92119BD33C6DFF025DEB8F1834F92E0A1A593
                                                                                                                                                                            SHA-512:7CCA8C25852A4F907890C73E8B3A7DEB4CF2A46CCBD029B60CEEC0E06A799F455CAA3BE251C657BDBB7E1D5BAB4C5BB92B0E82E060F254DDA08DABEF5AC3F617
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Upotpunite za.titu na internetu . BESPLATNO!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Prava stvar!",.. OEM_TOAST_VARIANT_INFO: "Mo.ete biti mnogo bezbedniji na internetu. Dodajte za.titu pregledanja kako biste upotpunili McAfee Web Protection i pobolj.ali bezbednost na internetu.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Upotpunili ste postavku McAfee Web Protection omogu.uju.i za.titu pregledanja.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Probna verzija McAfee antivirusnog programa",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Za.tita pregleda.a na internetu",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Za.tita pregleda.a je va.a prva linija odbrane od nebezbednih veb lokacija, veza, preuzimanja, malvera i jo. toga.",.. OEM_TOAST_VARIANT_FEATU
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4220
                                                                                                                                                                            Entropy (8bit):5.444091067154872
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HkTQd3F1N1KuBfzHv7afFmZMfSseE08bwzGt9S0NpQIrCF+AQmGIA:KWVBbz5vsec0zK9p1LL/IA
                                                                                                                                                                            MD5:06DDEDD0C278753F69E4FF4674E6614B
                                                                                                                                                                            SHA1:3470530D55FE8DDDCB363470D54B9177EFEB2937
                                                                                                                                                                            SHA-256:6076A19912D15B9DF572F3C268F825859B824F9193C9D64C57F95C7869974808
                                                                                                                                                                            SHA-512:BAA58DEC69C7B6257C8880A0EDC6FB04974C68DD20197232A30D38162DABE60289C2FB3CA57B7D59E95D08963F6EBFDEEC6D689E8DA415FF42ED584D474057CC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "Fullborda ditt skydd online - KOSTNADSFRITT!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "S.d.r ja!",.. OEM_TOAST_VARIANT_INFO: "Du kan surfa mycket s.krare. L.gg till s.kskydd f.r att komplettera McAfee Web Protection och f.rb.ttra din s.kerhet online.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Du har fullbordat inst.llningen av McAfee Web Protection genom att aktivera s.kskydd.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "Provversion av McAfees virusskydd",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: "Webbl.sarskydd online",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Webbl.sarskyddet .r ditt f.rsta f.rsvar mot os.kra webbsidor, l.nkar, h.mtningar, malware och mer.",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_NAME: "S.kskydd",.. OEM_TOAST_VARIANT_FEA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4525
                                                                                                                                                                            Entropy (8bit):5.530398100834962
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HsafCWrSckFzm3EzHFSCvXV4lsQtFT7tyJd:MaKWrSzm3EzHFSCP43PBy/
                                                                                                                                                                            MD5:A257776036EC055235476B933BB1A2F0
                                                                                                                                                                            SHA1:489E0CA8ED86E572A4940979AAC1399D38AF8370
                                                                                                                                                                            SHA-256:CC325C48332AD39AFF2C068020EFF1852A55B3AAE6CDF0617D587C0BC82078F5
                                                                                                                                                                            SHA-512:04FD6465239C9E196B33F1B769C77B103B52E67F87319CBEBC26D1EBBEC8E0EC8BCB836283981B715B06CD0D18D17C273BB0B76F1ED1B6335FC30FC571297AA8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: ".evrimi.i koruman.z. tamamlay.n - .CRETS.Z!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "Tebrikler!",.. OEM_TOAST_VARIANT_INFO: ".evrim i.i .ok daha g.vende olabilirsiniz. McAfee Web Protection'. tamamlamak ve .evrim i.i g.venli.inizi art.rmak i.in arama korumas.n. ekleyin.",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "Arama korumas.n. etkinle.tirerek McAfee Web Protection'. .evrim i.i kurmay. tamamlad.n.z.",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "McAfee Antivirus Denemesi",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: ".evrim i.i taray.c. korumas.",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: "Taray.c. korumas.; g.venli olmayan web siteleri, ba.lant.lar, indirmeler, zararl. yaz.l.m vb.'ine kar.. ilk savunma hatt.n.zd.r.",
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4033
                                                                                                                                                                            Entropy (8bit):6.107989660169052
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:HaLl2LYL7hjCL3PLYIL5LzLLL62KaLpLpLbYnL3LVeLuL/0LoqLlLVLvLkKLZRLp:H69N08pRNQ/OJJNZsjB90G3Qm/aCQVH6
                                                                                                                                                                            MD5:D2A4335DFB9EFCB73485D0C0807C2792
                                                                                                                                                                            SHA1:CF447A28A70F88168DEFE266798BDFEF3A044F1A
                                                                                                                                                                            SHA-256:EEEF0211C00E2E53D6DD6BE7B20D4379994D616691EC53B00FAB0CD180CE7041
                                                                                                                                                                            SHA-512:CCD66DE9416D7F8D31E7D2654BAE7533048FCA8B8DF4A0D877767615B5D50EE375D3CADD41EF8F27BE037958734065DA1688E6067A4750E96EB5F52F75EB7E7B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: "........ . ..!",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: ".....!",.. OEM_TOAST_VARIANT_INFO: ".......................................",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: ".......................",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "...........",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: ".......",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: ".................................",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_NAME: "....",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_DESC: "......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4288
                                                                                                                                                                            Entropy (8bit):6.168417961765325
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:HummxlGEjsinJjE8X7IujB0LbIF5fFrQTyKtyIs:OmmOvkEU7IuN0+5fF0vU
                                                                                                                                                                            MD5:E3BA53E61771C8BFD208DF6AE3412D95
                                                                                                                                                                            SHA1:64490728E322BCE3868B5D80109F923B4DC54155
                                                                                                                                                                            SHA-256:20CAA87E1DE50DFDA0B0019D1FD7E425CE050613DC1222B6F8CDC8B5FF0926BB
                                                                                                                                                                            SHA-512:0A5A25AA20A900D29CF5FC568D3C772F60ED91608D3C5C308E1377399902B54AEFBEAB4B708709C2BD2604F85F9A6BCDA5FBDEFD1845DBB02094D3A5ADB03335
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. // Specific for Cohort 1, 2.. OEM_TOAST_VARIANT_TITLE: ".......... . .....",.. OEM_TOAST_VARIANT_TITLE_SS_PROTECTED: "......",.. OEM_TOAST_VARIANT_INFO: "................ McAfee Web ...................",.. OEM_TOAST_VARIANT_INFO_SS_PROTECTED: "............. McAfee Web ......",.. OEM_TOAST_VARIANT_EXPIRED_LABEL: "EXPIRED",.. OEM_TOAST_VARIANT_EXPIRED_NAME: "McAfee Antivirus ..",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_LABEL: "ON",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_NAME: ".......",.. OEM_TOAST_VARIANT_FREE_LABEL: "FREE",.. OEM_TOAST_VARIANT_FEATURES_ENABLED_DESC: ".....................................",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_NAME: "....",.. OEM_TOAST_VARIANT_FEATURES_DISABLED_DESC:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3415
                                                                                                                                                                            Entropy (8bit):5.6725182562708305
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:calbcPcTkV6hxvM/L4PgzN/6hxO232sN4agGux:GUwdkec2sN4agGux
                                                                                                                                                                            MD5:1CE32A292F266E0D6E8079AE959D206C
                                                                                                                                                                            SHA1:F9ECB2DBE6C0BB745329B84F7C1DC74AA6288B7A
                                                                                                                                                                            SHA-256:7AE4303EDCBC48B3FAA5A7B0424845EAB9C756F2AEC392120D0EBE45348CEA19
                                                                                                                                                                            SHA-512:FA221BBE7B16CE232CA17CF38F23CA71B86FF73F25A363F2E693B940546C06043AACCFC78BA92F647286E0E44965E7BC558B6BC9FF5E08BBBE7C4C06B9EF07D0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "N.pov.da",.. HELP_FAQ_TITLE: "Nej.ast.j.. dotazy",.. HELP_SUPPORT_TITLE: "Podpora",.. HELP_EMAIL_US: "Za.lete n.m e-mail na adresu",.. ABOUT: "O aplikaci",.. ABOUT_DESCRIPTION: "D.ky aplikaci {0} se m..ete na internetu l.pe rozhodovat.",.. CREATE_SAFER_PASSWORDS: "Vytv..en. bezpe.n.j..ch hesel",.. DOWNLOAD_CONFIDENTLY: "Stahov.n. bez obav",.. SETTINGS_SS_OPTION_ALL: "Informovat o bezpe.nosti v.sledk. hled.n. ve v.ech vyhled.va..ch",.. SETTINGS_SS_OPTION_NONE: "Neinformovat o v.sledc.ch hled.n.",.. SETTINGS_SS_OPTION_SS: "Informovat o bezpe.nosti v.sledk. hled.n. pouze ve slu.b. Bezpe.n. hled.n.",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Vlo.te nebo zadejte adresu URL.",.. TRUST_SITE: "D.v..ovat str.nce",.. DONT_TRUST: "Ned.v..ovat",.. HELP_FAQ_SECTION_ONE_HEADER: "K .emu slou.. aplikace {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "D.ky aplikaci {0} se m..ete na in
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3222
                                                                                                                                                                            Entropy (8bit):5.3882022792999305
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cIWPf2VFTTGDGMZO4WVFwT/s9vyNnma/DvOvEiFk83qS8sDQTjmHBgpKSF:9FMZAOgFiizJMjmWB
                                                                                                                                                                            MD5:986CDDED8B1EE14C49744118BA341E1A
                                                                                                                                                                            SHA1:D02FB5756007D45A4B6F53807AF68C67152167D0
                                                                                                                                                                            SHA-256:EDD906A33E49B87978E8EB9BA897FB5D35996224686A2E4346E9CA84B747FD11
                                                                                                                                                                            SHA-512:0C8AA9C6D3C4260972D5A0C1DBA6B7198F195987C7709F2208463C522C133B05835799048BFD7A21E5E2D44F27D88CFD1956C88447CD608574632C7A285CFB77
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Hj.lp",.. HELP_FAQ_TITLE: "Ofte stillede sp.rgsm.l",.. HELP_SUPPORT_TITLE: "Support",.. HELP_EMAIL_US: "Send en mail til os p.",.. ABOUT: "Om",.. ABOUT_DESCRIPTION: "{0} hj.lper dig med at tr.ffe de rigtige beslutninger, n.r du er p. nettet.",.. CREATE_SAFER_PASSWORDS: "Opret sikrere adgangskoder",.. DOWNLOAD_CONFIDENTLY: "Sikre overf.rsler",.. SETTINGS_SS_OPTION_ALL: "Fort.l mig, om et s.geresultat er sikkert i alle s.gemaskiner",.. SETTINGS_SS_OPTION_NONE: "Fort.l mig ikke om s.geresultater",.. SETTINGS_SS_OPTION_SS: "Fort.l mig, om et s.geresultat kun er sikkert i Sikker s.gning",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Inds.t eller skriv URL-adressen",.. TRUST_SITE: "Har tillid til websted",.. DONT_TRUST: "Har ikke tillid",.. HELP_FAQ_SECTION_ONE_HEADER: "Hvad er {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} hj.lper dig med at tr.ffe de rigtige beslutninger, n.r du er p. nettet.",.. HELP_F
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3302
                                                                                                                                                                            Entropy (8bit):5.3882318909350255
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:c5vPqTKqMocuMD9nd/9j25ktHec9VYwpu4sD2oitoq:BNMVLac+uYwp9sD2ptr
                                                                                                                                                                            MD5:147D9271854988E85E6B7ABB0A19C8CC
                                                                                                                                                                            SHA1:198BAF847182F5717A63BFC28AB69C6638E3975B
                                                                                                                                                                            SHA-256:E60C824B97124AC58E92C4FC17DE0165E3ECE34D40FEE59B40D6FC225EDDF5BB
                                                                                                                                                                            SHA-512:4191A40093720B3067C3AB5CBD8B5DF09223885690FB7499DA1439FFD0B7C77B748AA00E109723B1353D7A88F6FB5F9AE761A92216B50BAFABB383B8854A81B2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Hilfe",.. HELP_FAQ_TITLE: "H.ufig gestellte Fragen (FAQs)",.. HELP_SUPPORT_TITLE: "Support",.. HELP_EMAIL_US: "Senden Sie uns eine E-Mail:",.. ABOUT: "Info",.. ABOUT_DESCRIPTION: "Dank {0} k.nnen Sie besser entscheiden, welche Websites Sie unbesorgt besuchen k.nnen.",.. CREATE_SAFER_PASSWORDS: "Sicherere Kennw.rter erstellen",.. DOWNLOAD_CONFIDENTLY: "Sichere Dateien herunterladen",.. SETTINGS_SS_OPTION_ALL: "In jeder Suchmaschine Bewertung von Suchergebnissen anzeigen",.. SETTINGS_SS_OPTION_NONE: "Keine Bewertung von Suchergebnissen anzeigen",.. SETTINGS_SS_OPTION_SS: "Nur bei der sicheren Suche Bewertung von Suchergebnissen anzeigen",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "URL einf.gen oder eingeben",.. TRUST_SITE: "Site als vertrauensw.rdig einstufen",.. DONT_TRUST: "Nicht als vertrauensw.rdig einstufen",.. HELP_FAQ_SECTION_ONE_HEADER: "Was ist {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "Dank {0} k.nnen Sie
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5323
                                                                                                                                                                            Entropy (8bit):5.039884397341082
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:czSqYMiAFSTIbO48c2aO490VuVMGzqRcAF+gx/ijYz2HC8Tt7iVJnIjz1NCPcWFa:DMO8w3BVGt22jz1QPltZIH9
                                                                                                                                                                            MD5:5EEB7AEFCA08B09AE14A82AF082D0319
                                                                                                                                                                            SHA1:25D9DBAED0B56792DA46B93EADE09A8292611688
                                                                                                                                                                            SHA-256:87AE0C4040364164D26A77121A7B011553C6FCF36D57BC954FB46261AE16BB94
                                                                                                                                                                            SHA-512:BD3FDF238F8CB5D42C584752F327D49CE7357D12B9E6F8FD8CC7787CCE674F188A4CB0D26695401137418C7F8EB7792776B20E2BFB4398EFA22538B60F9D3DC9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: ".......",.. HELP_FAQ_TITLE: "...... .........",.. HELP_SUPPORT_TITLE: "..........",.. HELP_EMAIL_US: "....... ... ...... ............ ............ ... .........",.. ABOUT: "...........",.. ABOUT_DESCRIPTION: ".. {0} ... ..... .. ......... .......... ......... ....... .. ... ......... ... ... Internet.",.. CREATE_SAFER_PASSWORDS: "............ ............. ........ .........",.. DOWNLOAD_CONFIDENTLY: "......... ...... .. ........",.. SETTINGS_SS_OPTION_ALL: ".. ............ .. ... .......... .......... ..... ....... .. ........... ......... ..........",.. SETTINGS_SS_OPTION_NONE: ".. ... ............ ..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2970
                                                                                                                                                                            Entropy (8bit):5.340531156221564
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:cwr9pTTyT7Few0MxjU99E/E0v7StLuJHTuiGextXq/JXTGpUx86NQ4QeQr4+8LkF:cwr9pPyTEMxI99E/fTStLOz7xtulGOx2
                                                                                                                                                                            MD5:E416F05EF2C13255FB856E2540354401
                                                                                                                                                                            SHA1:4A201A5C87AE5CC5FC1F0587B208B6797ED608CF
                                                                                                                                                                            SHA-256:E53F29691725551E77455FE08AE06D49E6D76C700A314EB5B9C728A77F6664ED
                                                                                                                                                                            SHA-512:71F8FE59EC173ED13EF7D3002B7AEB3B80710CF62D998386E4D8EB66B85CDFBAAC9E85C8B344B18751BCE9344AFFFA3E6726344B7B8DAC2A09A3884F68D35304
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Help",.. HELP_FAQ_TITLE: "Frequently Asked Questions (FAQs)",.. HELP_SUPPORT_TITLE: "Support",.. HELP_EMAIL_US: "Email us at",.. ABOUT: "About",.. ABOUT_DESCRIPTION: "{0} helps you make better decisions about what you do online.",.. CREATE_SAFER_PASSWORDS: "Create safer passwords",.. DOWNLOAD_CONFIDENTLY: "Download confidently",.. SETTINGS_SS_OPTION_ALL: "Tell me if a search result is safe in any search engine",.. SETTINGS_SS_OPTION_NONE: "Don't tell me about search results",.. SETTINGS_SS_OPTION_SS: "Tell me if a search result is safe only in Secure Search",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Paste or type your URL",.. TRUST_SITE: "Trust site",.. DONT_TRUST: "Don't trust",.. HELP_FAQ_SECTION_ONE_HEADER: "What is {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} helps you make better decisions about what you do online.",.. HELP_FAQ_SECTION_TWO_HEADER: "How do I share {0} with others?",.. HELP_FAQ_SECTION_TWO_CO
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3318
                                                                                                                                                                            Entropy (8bit):5.384176124857811
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cDEMyiTKKM+hOeBgn/qfBJq3/GQjD7mQujWoIcsAluB:vieH+g1D7mfIcsCuB
                                                                                                                                                                            MD5:287426C61EF34FE81F04FF539428702A
                                                                                                                                                                            SHA1:5722B989E9151788335E457F6D04DAA7E38C8605
                                                                                                                                                                            SHA-256:2C6435C4521F498D03742FC5221E5C3F9FE364632D1F498B40FC062B3214D3F2
                                                                                                                                                                            SHA-512:0695FEB3D1E32C9778F4BDC263882643B90579FA7C3A5893FF4787EED1B78CA4C4AC7C6C1D855D980D80D6AE7976FCE1815B3418FE802569E6A6BC5C5796F368
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Ayuda",.. HELP_FAQ_TITLE: "Preguntas frecuentes",.. HELP_SUPPORT_TITLE: "Soporte",.. HELP_EMAIL_US: "Env.enos un correo electr.nico a",.. ABOUT: "Acerca de",.. ABOUT_DESCRIPTION: "{0} le ayuda a tomar decisiones m.s fundamentadas acerca del uso que hace de Internet.",.. CREATE_SAFER_PASSWORDS: "Cree contrase.as m.s seguras",.. DOWNLOAD_CONFIDENTLY: "Descargue con seguridad",.. SETTINGS_SS_OPTION_ALL: "Informarme si un resultado de b.squeda es seguro en otro motor de b.squeda",.. SETTINGS_SS_OPTION_NONE: "No informarme de resultados de b.squeda",.. SETTINGS_SS_OPTION_SS: "Informarme si un resultado de b.squeda es seguro solo en B.squeda segura",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Pegue o escriba la direcci.n URL",.. TRUST_SITE: "Confiar en el sitio web",.. DONT_TRUST: "No confiar",.. HELP_FAQ_SECTION_ONE_HEADER: ".Qu. es {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} le ayuda a tomar decisiones m.s fu
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3269
                                                                                                                                                                            Entropy (8bit):5.39923044166933
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cDEMRrT9tM+hOeBJDfE/ZABFWeLT91e5kkmpouToIc2eoxkrHX:SRO+gEDUkkmAIc6eHX
                                                                                                                                                                            MD5:9BE106DBA0A89616F11CF5439894919C
                                                                                                                                                                            SHA1:39353BB978FF16BB7C377CE04E367F0D3FA57C93
                                                                                                                                                                            SHA-256:185D769876360325900E05E3318664A02F5EABE5F4FACB348FB9979032C71D92
                                                                                                                                                                            SHA-512:AAA3D7CD6E69109A1A646C6152F6F9F9CF3E3ABC42590CB25276E38097B6383947609CAF47DE9CD27185CE70CAC375518818D5DBB126252AA1CA3D8EF0A84C15
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Ayuda",.. HELP_FAQ_TITLE: "Preguntas frecuentes",.. HELP_SUPPORT_TITLE: "Soporte",.. HELP_EMAIL_US: "Env.enos un correo electr.nico",.. ABOUT: "Acerca de",.. ABOUT_DESCRIPTION: "{0} lo ayuda a tomar mejores decisiones acerca de lo que hace en l.nea.",.. CREATE_SAFER_PASSWORDS: "Cree contrase.as m.s seguras",.. DOWNLOAD_CONFIDENTLY: "Descargue con confianza",.. SETTINGS_SS_OPTION_ALL: "Comunicarme si un resultado de b.squeda es seguro en cualquier motor de b.squeda",.. SETTINGS_SS_OPTION_NONE: "No comunicarme sobre los resultados de b.squedas",.. SETTINGS_SS_OPTION_SS: "Comunicarme si un resultado de b.squeda es seguro solo en b.squeda segura",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Pegue o escriba la direcci.n URL",.. TRUST_SITE: "Sitio de confianza",.. DONT_TRUST: "No confiar",.. HELP_FAQ_SECTION_ONE_HEADER: ".Qu. es {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} lo ayuda a tomar mejores decisiones acerc
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3156
                                                                                                                                                                            Entropy (8bit):5.3436619335033475
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cFjnmzGSTEMQHo+X/lFYpHNVbA5yZq0Ui4ce:dzGSxDlNFR8i4F
                                                                                                                                                                            MD5:78DC242841C8955CA096D7109F84940E
                                                                                                                                                                            SHA1:1595F8915EF01CC7BE9D792216F96350A5096682
                                                                                                                                                                            SHA-256:16FD60BA1EA186B157DCCFD608540B10BB066332450D3D99636DE206006D1A1D
                                                                                                                                                                            SHA-512:521B6CEABCC8CD9914B5743C30F037199F37C7E37AF779BA599361F356E9D4E352E0BDD113A68DF8A131484DE7C057CE75D05A871852D3360939947358090101
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Ohje",.. HELP_FAQ_TITLE: "Usein kysytyt kysymykset (UKK)",.. HELP_SUPPORT_TITLE: "Tuki",.. HELP_EMAIL_US: "L.het. meille s.hk.postia osoitteeseen",.. ABOUT: "Tietoja",.. ABOUT_DESCRIPTION: "{0} auttaa sinua toimimaan verkossa turvallisesti.",.. CREATE_SAFER_PASSWORDS: "Entist. turvallisempien salasanojen luominen",.. DOWNLOAD_CONFIDENTLY: "Luotettava lataaminen",.. SETTINGS_SS_OPTION_ALL: "Ilmoita, onko hakutulos turvallinen, miss. tahansa hakukoneessa",.. SETTINGS_SS_OPTION_NONE: ".l. n.yt. ilmoituksia hakutulosten turvallisuudesta",.. SETTINGS_SS_OPTION_SS: "Ilmoita, onko hakutulos turvallinen, kun k.yt.n Suojattua hakua",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Liit. tai kirjoita URL-osoite",.. TRUST_SITE: "Luota sivustoon",.. DONT_TRUST: ".l. luota",.. HELP_FAQ_SECTION_ONE_HEADER: "Mik. on {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} auttaa sinua toimimaan verkossa turvallisesti.",.. HELP_FAQ_S
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3475
                                                                                                                                                                            Entropy (8bit):5.381791221753888
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cyXk9LMTrBXOkXco29M5t6QUxT//fM5NzyKt6yQjhEp2:zZR+ksoX4xgbyK1QjhEw
                                                                                                                                                                            MD5:487CD924C4ED60BD9F2EF8AB1E181DD5
                                                                                                                                                                            SHA1:9D2C4D25151FE2D6ACD20B97194721545AC67BFB
                                                                                                                                                                            SHA-256:68369D5DA42E5B5418FB2B35D0797C21AB502DF7D6416BB93EA137FDAC2BA53E
                                                                                                                                                                            SHA-512:9BDCAA1E97D41FC69A0EC5FD95DFF88EE1F61B890A7D0618CC9AE752018A7567028FFE0D06840460F8DBA4E7878D797155581762883C823C6770721E9546C2D8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Aide",.. HELP_FAQ_TITLE: "Foire aux questions (FAQ)",.. HELP_SUPPORT_TITLE: "Soutien",.. HELP_EMAIL_US: "Envoyez-nous un courriel au",.. ABOUT: ". propos",.. ABOUT_DESCRIPTION: "{0} vous aide . prendre de meilleures d.cisions sur vos activit.s en ligne.",.. CREATE_SAFER_PASSWORDS: "Cr.er des mots de passe plus s.rs",.. DOWNLOAD_CONFIDENTLY: "T.l.charger de fa.on confidentielle",.. SETTINGS_SS_OPTION_ALL: "Me dire si un r.sultat de recherche est s.r dans tous les moteurs de recherche",.. SETTINGS_SS_OPTION_NONE: "Ne pas me parler des r.sultats de recherche",.. SETTINGS_SS_OPTION_SS: "Me dire si un r.sultat de recherche est s.r seulement dans la recherche s.curis.e",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Coller ou saisir votre URL",.. TRUST_SITE: "Faire confiance au site",.. DONT_TRUST: "Ne pas faire confiance",.. HELP_FAQ_SECTION_ONE_HEADER: "Qu'est-ce que {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0}
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3557
                                                                                                                                                                            Entropy (8bit):5.407604941374556
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cyXkPWgMTpX56126MJk7OQTxN//i46XeNWtd0lDqKStVGC4jRgo5wRn:zrN1XU1G2xKnINCieo4
                                                                                                                                                                            MD5:EBFF2F699FA2915800E9E6EAF6DAD6C1
                                                                                                                                                                            SHA1:21E2827B4446D9AF0E9AC693E3A2405D989EFF39
                                                                                                                                                                            SHA-256:4C5470EEF6430967DB9346B9FF1B55C286F3AFBF71071A0CC184DD45EC63B214
                                                                                                                                                                            SHA-512:9773A3DD83DE8D775951250155C3BAAE277110AD14AEA6C7E7528BC671C38DC1539085FCB820E6EEB0932B87BBCBF248916989C73A124AB8BD6A3FF3ED4602A3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Aide",.. HELP_FAQ_TITLE: "Foire aux questions (FAQ)",.. HELP_SUPPORT_TITLE: "Support",.. HELP_EMAIL_US: "Contactez-nous par e-mail . cette adresse",.. ABOUT: "A propos",.. ABOUT_DESCRIPTION: "{0} vous aide . prendre les bonnes d.cisions en ce qui concerne vos activit.s en ligne.",.. CREATE_SAFER_PASSWORDS: "Cr.ez des mots de passe plus fiables",.. DOWNLOAD_CONFIDENTLY: "T.l.chargez en toute confiance",.. SETTINGS_SS_OPTION_ALL: "Me dire si le r.sultat de la recherche est prot.g. dans tous les moteurs de recherche",.. SETTINGS_SS_OPTION_NONE: "Ne rien me dire sur les r.sultats de la recherche",.. SETTINGS_SS_OPTION_SS: "Me dire si le r.sultat de la recherche est prot.g. dans la recherche s.curis.e uniquement",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Collez ou saisissez l'URL",.. TRUST_SITE: "Approuver",.. DONT_TRUST: "Ne pas approuver",.. HELP_FAQ_SECTION_ONE_HEADER: "Qu'est-ce que {0}.?",.. HELP_FAQ
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3286
                                                                                                                                                                            Entropy (8bit):5.450685577880872
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cv359TfWlMbZ5ur/cOKc+vOOES9Wxt9yzoIEZUDrBdjDeX:iLW2yYlVES9+96UuDrBdjDg
                                                                                                                                                                            MD5:6B0B147B984611AD62B274061C434872
                                                                                                                                                                            SHA1:5DAC514E617534A59C8561264196E52132E99D7D
                                                                                                                                                                            SHA-256:F06A5F59D0E9189B98B1E8F2ADD444B458079F66B498EF4EE008D544AE5585D8
                                                                                                                                                                            SHA-512:EAD2C79B8AE84D5BE8F3F9F835A1550AD601D0CB58639E410917E15CB51C76B7D5498F87BF67748D6761C7D37669E10ECD0C4E6563A17F89378E69E1AA879AD7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Pomo.",.. HELP_FAQ_TITLE: ".esto postavljana pitanja (.PP)",.. HELP_SUPPORT_TITLE: "Podr.ka",.. HELP_EMAIL_US: "Obratite nam se na adresi e-po.te",.. ABOUT: "O aplikaciji",.. ABOUT_DESCRIPTION: "{0} poma.e vam u dono.enju boljih odluka o tome .to .inite na mre.i.",.. CREATE_SAFER_PASSWORDS: "Stvorite sigurnije lozinke",.. DOWNLOAD_CONFIDENTLY: "Pouzdano preuzimajte",.. SETTINGS_SS_OPTION_ALL: "Obavijesti me ako je rezultat pretra.ivanja siguran u bilo kojoj tra.ilici",.. SETTINGS_SS_OPTION_NONE: "Nemoj me obavijestiti o rezultatima pretra.ivanja",.. SETTINGS_SS_OPTION_SS: "Obavijesti me ako je rezultat pretra.ivanja siguran samo u Sigurnom pretra.ivanju",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Zalijepite ili unesite svoj URL",.. TRUST_SITE: "Mjesto smatraj pouzdanim",.. DONT_TRUST: "Ne smatraj pouzdanim",.. HELP_FAQ_SECTION_ONE_HEADER: ".to je {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} poma.e vam
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3670
                                                                                                                                                                            Entropy (8bit):5.574443846574153
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:c491zbQ9T9aMhF7fQdq/SvRonzXfFNtvf1B1BER7yU8J:tbQ9hfQfRonzb/3iRGU8J
                                                                                                                                                                            MD5:211C56AD5F383EB02F69BA89FACAAAC6
                                                                                                                                                                            SHA1:45710CAC2EBBEC7BD5211C19819902703FF608AE
                                                                                                                                                                            SHA-256:0751370CECD364008724CEDD53187F0BA2D8CD53C317B30876F43951DDC766F2
                                                                                                                                                                            SHA-512:63BE908C6D7474E52D51F83F62E21F66449CF69A4583721D22E39789EAF4E845FA028B6F3E6765E5E44738D90FA6B9F9B574726AD5A644DE4F4E01DCAC42F452
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "S.g.",.. HELP_FAQ_TITLE: "Gyakran ism.telt k.rd.sek (GYIK)",.. HELP_SUPPORT_TITLE: "T.mogat.s",.. HELP_EMAIL_US: "K.ldj.n nek.nk e-mailt az al.bbi c.mre:",.. ABOUT: "N.vjegy",.. ABOUT_DESCRIPTION: "A(z) {0} seg.ts.get ny.jt ahhoz, hogy jobb d.nt.seket hozhasson az online vil.gban.",.. CREATE_SAFER_PASSWORDS: "Biztons.gosabb jelszavak l.trehoz.sa",.. DOWNLOAD_CONFIDENTLY: "Biztons.gos let.lt.s",.. SETTINGS_SS_OPTION_ALL: "T.j.koztasson a keres.s eredm.ny.nek biztons.goss.g.r.l b.rmely keres.motorra vonatkoz.an",.. SETTINGS_SS_OPTION_NONE: "Ne t.j.koztasson a keres.si eredm.nyekkel kapcsolatban",.. SETTINGS_SS_OPTION_SS: "A keres.s eredm.ny.nek biztons.goss.g.r.l csak a Biztons.gos keres.sben t.j.koztasson",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "URL beilleszt.se vagy be.r.sa",.. TRUST_SITE: "Megb.zhat. webhely",.. DONT_TRUST: "Nem megb.zhat.",.. HELP_FAQ_SECTIO
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3280
                                                                                                                                                                            Entropy (8bit):5.318299995140633
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cF+xiITUmLgSM+xy07Zg/ikrQs9N46fkjorok0jQxsTWa:QIIag/+fENbsErI0xsj
                                                                                                                                                                            MD5:1DAC66AF50FCE87B340469CD5F4EA749
                                                                                                                                                                            SHA1:3920F569D92358810BA439FD30949C424DACB7EE
                                                                                                                                                                            SHA-256:846156959A61C8949344F636FEBC9CAB9A41053F8422F9E389827A6D682432B2
                                                                                                                                                                            SHA-512:216898CE8DB4D99F3E71E40E60BCBE03DAC34B627497FA54486A41FDE7662F155E5E1BEECA449D7E2FB5D445F697B750B44B61C5371B7F6E129CF25D7E39D18B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Guida",.. HELP_FAQ_TITLE: "Domande frequenti",.. HELP_SUPPORT_TITLE: "Assistenza",.. HELP_EMAIL_US: "Contattaci via email all'indirizzo",.. ABOUT: "Informazioni su",.. ABOUT_DESCRIPTION: "{0} ti aiuta a prendere decisioni pi. consapevoli sulle attivit. online.",.. CREATE_SAFER_PASSWORDS: "Crea password pi. sicure",.. DOWNLOAD_CONFIDENTLY: "Scarica con la massima sicurezza",.. SETTINGS_SS_OPTION_ALL: "Comunicami se un risultato di ricerca . sicuro in un motore di ricerca",.. SETTINGS_SS_OPTION_NONE: "Non comunicare nulla riguardo ai risultati di ricerca",.. SETTINGS_SS_OPTION_SS: "Comunicami se un risultato di ricerca . sicuro solo in ricerca sicura",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Incolla o digita l'URL",.. TRUST_SITE: "Considera affidabile il sito",.. DONT_TRUST: "Non considerare affidabile",.. HELP_FAQ_SECTION_ONE_HEADER: "Che cos'. {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} ti aiuta a prendere dec
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3760
                                                                                                                                                                            Entropy (8bit):5.744044953556827
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cFuvhOT6tGCuqZu0KMV1V6Gq//0bNbJkKjixAwRm4wegixVU0s6:1YGtGCuyu0HfDFBPiKem4/gi/s6
                                                                                                                                                                            MD5:5705CB5E22FF4A7F3AF488D8D754E1E3
                                                                                                                                                                            SHA1:BB329D5C2A90344F4B420E6D223B66A0E9FE8E5E
                                                                                                                                                                            SHA-256:4A8A67866841B4B790B1A5317999059335CC2F24A7063584F2450BC01FF34285
                                                                                                                                                                            SHA-512:32A8AE21F4D5396A354615B9A0E0381369B3076BA3B11AFB42F40916CA6EAA229918D5402560DF6AB2639A736DD8CB2ED1E07484A7412D8967C2592FC30ACB42
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "...",.. HELP_FAQ_TITLE: "...... (FAQ)",.. HELP_SUPPORT_TITLE: "....",.. HELP_EMAIL_US: "........",.. ABOUT: ".......",.. ABOUT_DESCRIPTION: "{0} ...................",.. CREATE_SAFER_PASSWORDS: "...............",.. DOWNLOAD_CONFIDENTLY: "...........",.. SETTINGS_SS_OPTION_ALL: "..........................",.. SETTINGS_SS_OPTION_NONE: "..............",.. SETTINGS_SS_OPTION_SS: ".... .....................",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "URL ................",.. TRUST_SITE: "........",.. DONT_TRUST: ".....",.. HELP_FAQ_SECTION_ONE_HEADER: "{0} .......",.. HELP_FAQ_SECTI
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3451
                                                                                                                                                                            Entropy (8bit):5.825420860271677
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:c0hbqh5TgP81LM2z7i6B/+XP6HUdYXx/gAw8otAJ2y8BwG8:JWQ8S76X6Avot3hy
                                                                                                                                                                            MD5:681288B9279C9CBC25583FE9BEBD7010
                                                                                                                                                                            SHA1:43C5199831B5840915DB683237A646E93C819C1A
                                                                                                                                                                            SHA-256:A740211144E010392A722A92F26611FC89EC4A9492F04DD39C6CCE8660D0E469
                                                                                                                                                                            SHA-512:97BE222C733D9CD8FC0BD9624B61DC3872821435BCBE9702C2B85BA3A61E8999F8F27DAD8032EF66B4888D21ACE9BA14372166EF58226734126124895A62BC7D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "...",.. HELP_FAQ_TITLE: "... ..(FAQ)",.. HELP_SUPPORT_TITLE: "..",.. HELP_EMAIL_US: "... ..",.. ABOUT: "..",.. ABOUT_DESCRIPTION: "{0}. .... ... .. . ... ... .. . ... ......",.. CREATE_SAFER_PASSWORDS: ".. ... .. ...",.. DOWNLOAD_CONFIDENTLY: "... ....",.. SETTINGS_SS_OPTION_ALL: ".. .. .... .. ... .... ..",.. SETTINGS_SS_OPTION_NONE: ".. ... .. ... ..",.. SETTINGS_SS_OPTION_SS: ".. ..... .. ... .... ..",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "URL. .. ... ......",.. TRUST_SITE: "... ..",.. DONT_TRUST: ".... ..",.. HELP_FAQ_SECTION_ONE_HEADER: "{0}. .....?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0}. .... ... .. . ... .
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3107
                                                                                                                                                                            Entropy (8bit):5.357002813107769
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cA9ffAT6MuE50WT/CGoDAUtGZpn2g3BBIP:ejVoxtepD3B6P
                                                                                                                                                                            MD5:2F10B37F542A46D1752ADCEF7B5BB5D6
                                                                                                                                                                            SHA1:AA776B7E2B4035B2A94B309D4C6B8402A6171B9E
                                                                                                                                                                            SHA-256:D2DA58C39AB525B77F4D21A7028526BC8F0CCBBF5BB1483A77ADCC8710BE76CB
                                                                                                                                                                            SHA-512:6FB2DD20B5C71146F7DB145889749B826758F3DE36D66A6DB8638D42322398AE8E7D7136ECC4231CEA1C6DF66AF0426C628AF82BA42506C3AC1E5B56C9BC1E0A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Hjelp",.. HELP_FAQ_TITLE: "Vanlige sp.rsm.l",.. HELP_SUPPORT_TITLE: "St.tte",.. HELP_EMAIL_US: "Send oss en e-postmelding til",.. ABOUT: "Om",.. ABOUT_DESCRIPTION: "{0} gj.r det enklere . ta bedre avgj.relser om hva du gj.r p. Internett.",.. CREATE_SAFER_PASSWORDS: "Opprett sikrere passord",.. DOWNLOAD_CONFIDENTLY: "Last ned uten bekymringer",.. SETTINGS_SS_OPTION_ALL: "Fortell om et s.keresultat er trygt, i enhver s.kemotor",.. SETTINGS_SS_OPTION_NONE: "Ikke fortell meg om s.keresultatene",.. SETTINGS_SS_OPTION_SS: "Fortell om et s.keresultat er sikkert, men bare i Sikkert s.k",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Lim eller skriv inn URL-adressen din",.. TRUST_SITE: "Klarer omr.de",.. DONT_TRUST: "Ikke klarer",.. HELP_FAQ_SECTION_ONE_HEADER: "Hva er {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} gj.r det enklere . ta bedre avgj.relser om hva du gj.r p. Internett.",.. HELP_FAQ_SECTION_TWO_HEAD
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3196
                                                                                                                                                                            Entropy (8bit):5.33513380019923
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cwMUf5ztTk0aUPDMavouzNv/lzz0TldANPQ3tBvlv0Zg0:rhtaUQWiMctBvBIg0
                                                                                                                                                                            MD5:7635F959635490EFC057663B259EB2D0
                                                                                                                                                                            SHA1:F0DE31FFF76CBC8D97B295AC3D9EF48A8D35CC92
                                                                                                                                                                            SHA-256:2B862B5D5E0514761183AA6F1097131E87554AC00B83E72A911432E884EA1E57
                                                                                                                                                                            SHA-512:3953F5BDD3FB80961E7961212CBA06E59802F86CA17B7BD733C21085BA9C58521938CC89504317C9F73A00F2A71E2FE5E4121AF5058D1034B85F835CCAA6A7B5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Help",.. HELP_FAQ_TITLE: "Veelgestelde vragen",.. HELP_SUPPORT_TITLE: "Ondersteuning",.. HELP_EMAIL_US: "E-mail ons op",.. ABOUT: "Info",.. ABOUT_DESCRIPTION: "{0} helpt u betere beslissingen over uw online activiteiten te nemen.",.. CREATE_SAFER_PASSWORDS: "Maak veiligere wachtwoorden",.. DOWNLOAD_CONFIDENTLY: "Download probleemloos",.. SETTINGS_SS_OPTION_ALL: "Laat mij in elke zoekmachine weten of een zoekresultaat veilig is",.. SETTINGS_SS_OPTION_NONE: "Niets zeggen over zoekresultaten",.. SETTINGS_SS_OPTION_SS: "Laat mij alleen in Beveiligd zoeken weten of een zoekresultaat veilig is",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Plak of typ uw URL",.. TRUST_SITE: "Site vertrouwen",.. DONT_TRUST: "Niet vertrouwen",.. HELP_FAQ_SECTION_ONE_HEADER: "Wat is {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} helpt u betere beslissingen over uw online activiteiten te nemen.",.. HELP_FAQ_SECTION_TWO_HEADER: "Hoe kan ik {0} met
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3433
                                                                                                                                                                            Entropy (8bit):5.608809207063229
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cnWv3LDTIKXe8FDXdIzMn5VRe/8gAR+3jRsFAEEGs6L49l0v2dUPJJJZ:ZPUKpFDOIiRc7EA+lXUPJJ7
                                                                                                                                                                            MD5:1B0655B209680EC52E7AAF564F3F1147
                                                                                                                                                                            SHA1:A4BA7EBFBCE7724ED390272E229242059111C8A5
                                                                                                                                                                            SHA-256:E3761E59DDBCD74B8121027392D92DAEF066E575EC896D443165D265708A0162
                                                                                                                                                                            SHA-512:1EC9EB8C50B89F1AEAADF8157C7F02D588ACD8D665C2F6EC86B078484AF371C1807781D9903EB2489A8F3DB195D4923A188F3AD9F7CB8FE03714CA9AAF605CE8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Pomoc",.. HELP_FAQ_TITLE: "Cz.sto zadawane pytania",.. HELP_SUPPORT_TITLE: "Pomoc techniczna",.. HELP_EMAIL_US: "Wy.lij wiadomo.. e-mail na adres",.. ABOUT: "Informacje",.. ABOUT_DESCRIPTION: "Program {0} pomaga podejmowa. rozs.dne decyzje podczas przegl.dania Internetu.",.. CREATE_SAFER_PASSWORDS: "Tw.rz silniejsze has.a",.. DOWNLOAD_CONFIDENTLY: "Pobieraj bez obaw",.. SETTINGS_SS_OPTION_ALL: "Pokazuj oceny bezpiecze.stwa wynik.w wyszukiwania w ka.dej wyszukiwarce",.. SETTINGS_SS_OPTION_NONE: "Nie pokazuj ocen wynik.w wyszukiwania",.. SETTINGS_SS_OPTION_SS: "Pokazuj oceny bezpiecze.stwa wynik.w wyszukiwania tylko w wyszukiwarce Bezpieczne wyszukiwanie",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Wklej lub wpisz adres URL",.. TRUST_SITE: "Zaufaj witrynie",.. DONT_TRUST: "Nie ufaj",.. HELP_FAQ_SECTION_ONE_HEADER: "Co to jest {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "Program {0} pomaga podejmowa. rozs.dne
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3252
                                                                                                                                                                            Entropy (8bit):5.391105831619536
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cc0m2Tpgz2z24eMgUWy0/IULhYRukp+ATR8tXVfNTiWC4:wloYdMIuQ8FVfhic
                                                                                                                                                                            MD5:2E5EF44195F8C2DF73B2E860189724C4
                                                                                                                                                                            SHA1:320A61BA8B311BD3F621CE501BE0874BACAF95F1
                                                                                                                                                                            SHA-256:74AE28DAB2865D432D8AF840669AFB53A37FE367B511BFCF4FAC34C82BE28A46
                                                                                                                                                                            SHA-512:96EDE9CA7A46A4729CC3803A9A6213A83C72391007F6F619BC189231A490465FB1D923C2BF57DF9FCA19120876E769A7B627622252F718ED11787FAE750BA48A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Ajuda",.. HELP_FAQ_TITLE: "Perguntas frequentes",.. HELP_SUPPORT_TITLE: "Suporte",.. HELP_EMAIL_US: "Envie um e-mail para",.. ABOUT: "Sobre",.. ABOUT_DESCRIPTION: "{0} ajuda voc. a tomar melhores decis.es durante suas atividades online.",.. CREATE_SAFER_PASSWORDS: "Crie senhas mais seguras",.. DOWNLOAD_CONFIDENTLY: "Fa.a downloads com confian.a",.. SETTINGS_SS_OPTION_ALL: "Avise-me quando um resultado de pesquisa for seguro em qualquer mecanismo de pesquisa",.. SETTINGS_SS_OPTION_NONE: "N.o me avise a respeito dos resultados de pesquisa",.. SETTINGS_SS_OPTION_SS: "Avise-me quando um resultado de pesquisa for seguro apenas com a Pesquisa segura",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Copie ou cole seu URL",.. TRUST_SITE: "Confiar no site",.. DONT_TRUST: "N.o confiar",.. HELP_FAQ_SECTION_ONE_HEADER: "O que . {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} ajuda voc. a tomar melhores decis.es durante suas ativid
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3264
                                                                                                                                                                            Entropy (8bit):5.39131822590979
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:ccGmQ7XTlHUszMAqjI/O/rgZaFWCG3Ix5amxnZ:I7hHUlmwamxnZ
                                                                                                                                                                            MD5:2C919BCF8F2EED219B35CEAB18C6F251
                                                                                                                                                                            SHA1:7D80587256B5FC9B3DF150804CF3445601DEEBE2
                                                                                                                                                                            SHA-256:C76DB5DAB77301013A12E89D24D2975982B7F2B3A1F8FA16E5CFBEB9A0BE35B6
                                                                                                                                                                            SHA-512:A61BC3B00CD5F5228225F82A17EA0418E07C236B7F7439BD0D855CE7197D1F7DD71F746755F88BD1561FDA34E483FF59F9A661B0AF1314A9CF9136EE6BC9D577
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Ajuda",.. HELP_FAQ_TITLE: "Perguntas Mais Frequentes (FAQs)",.. HELP_SUPPORT_TITLE: "Suporte",.. HELP_EMAIL_US: "Envie-nos uma mensagem de correio eletr.nico para",.. ABOUT: "Acerca de",.. ABOUT_DESCRIPTION: "O {0} ajuda-o a tomar melhores decis.es acerca das suas atividades online.",.. CREATE_SAFER_PASSWORDS: "Crie palavras-passe mais seguras",.. DOWNLOAD_CONFIDENTLY: "Transfira com confian.a",.. SETTINGS_SS_OPTION_ALL: "Indicar se um resultado de pesquisa . seguro em todos os motores de pesquisa",.. SETTINGS_SS_OPTION_NONE: "N.o me informar sobre os resultados de pesquisa",.. SETTINGS_SS_OPTION_SS: "Indicar se um resultado . seguro apenas na Pesquisa Segura",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Cole ou escreva o URL",.. TRUST_SITE: "Considerar site fidedigno",.. DONT_TRUST: "N.o considerar fidedigno",.. HELP_FAQ_SECTION_ONE_HEADER: "O que . o {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "O {0} ajuda-o a toma
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4697
                                                                                                                                                                            Entropy (8bit):5.05412449617714
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cgyp6VTFkLeMF+TXVjM/2m9VzTUmw9+WTnoXTAqsS:LVRkHARMH4TnoDAqsS
                                                                                                                                                                            MD5:73032437E73E7447AE70F9A44FEBCDC0
                                                                                                                                                                            SHA1:1940D1CADF5E329593E97D26214646860ABE90BC
                                                                                                                                                                            SHA-256:1E821A5862C6DEF65373A430903135B76356437EAB854F8414A0FBDD4B15879C
                                                                                                                                                                            SHA-512:AB6F68D3E05307CC3E7FFCE6B017E1A873748875DBB712BC97E081B11659266458CA51015EB07193124E007BE3772F70F5D9ADAB670B88D4AE8036265D996D55
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: ".......",.. HELP_FAQ_TITLE: "..... .......... .......",.. HELP_SUPPORT_TITLE: ".........",.. HELP_EMAIL_US: "..... ........... .....:",.. ABOUT: ". .........",.. ABOUT_DESCRIPTION: "{0} . ... .........., ........... ..... ......... ........... . ..........",.. CREATE_SAFER_PASSWORDS: "........ ........ .......",.. DOWNLOAD_CONFIDENTLY: "........ ... ........",.. SETTINGS_SS_OPTION_ALL: "........ . ............ ........... ...... .. .... ......... ........",.. SETTINGS_SS_OPTION_NONE: ".. ........ . ............ ........... ......",.. SETTINGS_SS_OPTION_SS: "........ . ............ ........... ...... ...... . ..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3534
                                                                                                                                                                            Entropy (8bit):5.654635030313481
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:cwP+i9HTsGeKlMMUjY3n8BEM/f0vlJuOquLlXElBfoWagWpWrdimER7r+05+1s0T:cwPb9HTcKaMUy8aM/sX0ajnecmSr+HT
                                                                                                                                                                            MD5:5F9B7CA900708D3D00AC53624C5A0E81
                                                                                                                                                                            SHA1:B709D60FD41769D76BD06665D02DBE9296C83468
                                                                                                                                                                            SHA-256:11F51735F5C39AB369A4D82C1315F565C500E2AF566F0991BF83A7C93FD00FE5
                                                                                                                                                                            SHA-512:942E7EAA21F965F22786DC87DEC29DF4F47115C3971B80013CEFA447543C987F904C478EA47044E5362922EBE5E05AF2B243762BAB7197F847B4307A30F23ABF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Pomocn.k",.. HELP_FAQ_TITLE: "Naj.astej.ie ot.zky",.. HELP_SUPPORT_TITLE: "Podpora",.. HELP_EMAIL_US: "Po.lite n.m e-mail na adresu",.. ABOUT: "Inform.cie",.. ABOUT_DESCRIPTION: "Aplik.cia {0} v.m pom..e robi. lep.ie rozhodnutia o va.om .ivote online.",.. CREATE_SAFER_PASSWORDS: "Vytv.rajte bezpe.nej.ie hesl.",.. DOWNLOAD_CONFIDENTLY: "S.ahujte d.veryhodn. s.bory",.. SETTINGS_SS_OPTION_ALL: "Informova. o bezpe.nosti v.sledku vyh.ad.vania v ka.dom vyh.ad.vacom n.stroji",.. SETTINGS_SS_OPTION_NONE: "Neinformova. o v.sledkoch vyh.ad.vania",.. SETTINGS_SS_OPTION_SS: "O.bezpe.nosti v.sledku vyh.ad.vania ma informujte len v.zabezpe.enom vyh.ad.van.",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Prilepte alebo zadajte adresu URL",.. TRUST_SITE: "D.verova. lokalite",.. DONT_TRUST: "Ned.verova.",.. HELP_FAQ_SECTION_ONE_HEADER: ".o je {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "Aplik.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3203
                                                                                                                                                                            Entropy (8bit):5.449178183879912
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cvh5lgT19NMMgHg8/9WQqRZt8JZZmVau8KP8jvv/FUD8VSr:BhlmJXPdSD8VSr
                                                                                                                                                                            MD5:91776C4DCE4AE25054106EAAF0E5CF82
                                                                                                                                                                            SHA1:04FDBCF9D80AF17ECE34B4689B02A20A23DB5B98
                                                                                                                                                                            SHA-256:35414C84E97DC6217F49DA76C38973E7B78CB681E1DCE619F1DFA83EEC2E1A3C
                                                                                                                                                                            SHA-512:5943901383F207EAC4572A8FD10BDE0A52F7E7F0E04B291E594271DF46207B8C40E1F8173BF44CCE9AABBCD66E670ECE766DA40F20A749A86FB98ED9CB1FF128
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Pomo.",.. HELP_FAQ_TITLE: "Naj.e..a pitanja",.. HELP_SUPPORT_TITLE: "Podr.ka",.. HELP_EMAIL_US: "Po.aljite nam e-poruku na adresu",.. ABOUT: "Osnovni podaci",.. ABOUT_DESCRIPTION: "{0} vam poma.e da donosite bolje odluke o svojim aktivnostima na mre.i.",.. CREATE_SAFER_PASSWORDS: "Kreirajte bezbednije lozinke",.. DOWNLOAD_CONFIDENTLY: "Preuzimajte bezbri.no",.. SETTINGS_SS_OPTION_ALL: "Obavesti me u svakom pretra.iva.u da li je rezultat pretrage bezbedan",.. SETTINGS_SS_OPTION_NONE: "Ne obave.tavaj me o rezultatima pretrage",.. SETTINGS_SS_OPTION_SS: "Obavesti me samo u bezbednoj pretrazi da li je rezultat pretrage bezbedan",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Nalepite ili unesite URL adresu",.. TRUST_SITE: "Veruj lokaciji",.. DONT_TRUST: "Ne veruj",.. HELP_FAQ_SECTION_ONE_HEADER: ".ta je {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} vam poma.e da donosite bolje odluke o svojim aktivnostima na mre.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3145
                                                                                                                                                                            Entropy (8bit):5.469555751385765
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cayPkTXsNMjOlH/PROv5eFqNzXl9Rjz8BU535tP:3Dsu/TNl9Fz3bP
                                                                                                                                                                            MD5:8F155685D5E52273E8603231579DDEC0
                                                                                                                                                                            SHA1:AA44AA88B9EB1CD440C22166D7542384DBF1572F
                                                                                                                                                                            SHA-256:4D70A2F7E7F1E8083E750F82CF3832CA00B5086EE4986470B0749E7084090074
                                                                                                                                                                            SHA-512:224803062A4C68E5BC03178016F3F82149305D1DC4072424298B8CD21AF726CA44CB5196FC313FE9EF1283974589F9B187E1E45FD920BBD341507EBB0BAE2881
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Hj.lp",.. HELP_FAQ_TITLE: "Vanliga fr.gor (FAQ)",.. HELP_SUPPORT_TITLE: "Support",.. HELP_EMAIL_US: "Kontakta oss via e-post p.",.. ABOUT: "Om",.. ABOUT_DESCRIPTION: "{0} hj.lper dig att ta b.ttre beslut g.llande vad du g.r online.",.. CREATE_SAFER_PASSWORDS: "Skapa s.krare l.senord",.. DOWNLOAD_CONFIDENTLY: "S.kra h.mtningar",.. SETTINGS_SS_OPTION_ALL: "Informera mig om s.kra s.kresultat i samtliga s.kmotorer",.. SETTINGS_SS_OPTION_NONE: "Informera mig inte om s.kresultat",.. SETTINGS_SS_OPTION_SS: "Informera mig om s.kra s.kresultat, men endast vid s.ker s.kning",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "Klistra in eller ange webbadress (URL)",.. TRUST_SITE: "Ange som betrodd webbplats",.. DONT_TRUST: "Ange inte som betrodd webbplats",.. HELP_FAQ_SECTION_ONE_HEADER: "Vad .r {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} hj.lper dig att ta b.ttre beslut g.llande vad du g.r online.",.. HELP_FA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3451
                                                                                                                                                                            Entropy (8bit):5.517767275362882
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:cUCFiIkATzMz/k1/DJMWeTc3a/B6eCVt/zes6t3K8SLcwl39cNyOA:gngIDKQ/ei/Bik39cN+
                                                                                                                                                                            MD5:A679FE63A496141019718388B93F41BE
                                                                                                                                                                            SHA1:23C688A4555E5D9E74EC55C4E8C389D91B3A9500
                                                                                                                                                                            SHA-256:2BB125C0254413048BB41F43E5E1A2FC88934433AFEB43946DD976D71502F07A
                                                                                                                                                                            SHA-512:F973DA2B927F5ADFFEE427C9943CAFF0B3FDFC570EECCD6C67CF2F734423EB8EC7003AB80C03673572339D04574854965A51CBDF00A458178C2EA26F45E5EBA1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "Yard.m",.. HELP_FAQ_TITLE: "S.k Sorulan Sorular (SSS'ler)",.. HELP_SUPPORT_TITLE: "Destek",.. HELP_EMAIL_US: ".u adresten bize e-posta g.nderin:",.. ABOUT: "Hakk.nda",.. ABOUT_DESCRIPTION: "{0} .evrimi.iyken ne yapaca..n.z konusunda daha iyi kararlar alman.za yard.mc. olur.",.. CREATE_SAFER_PASSWORDS: "Daha g.venli parolalar olu.turun",.. DOWNLOAD_CONFIDENTLY: "G.venle indirin",.. SETTINGS_SS_OPTION_ALL: "Herhangi bir arama motorunda bir arama sonucunun g.venli olup olmad...n. benimle payla.",.. SETTINGS_SS_OPTION_NONE: "Arama sonu.lar.n. benimle payla.ma",.. SETTINGS_SS_OPTION_SS: "Yaln.zca G.venli Arama'da bir arama sonucunun g.venli olup olmad...n. benimle payla.",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "URL'nizi yap..t.r.n veya yaz.n",.. TRUST_SITE: "Bu siteye g.ven",.. DONT_TRUST: "G.venme",.. HELP_FAQ_SECTION_ONE_HEADER: "{0} nedir?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2969
                                                                                                                                                                            Entropy (8bit):6.138061744885662
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:cii4bo8iTBSeLHzMP0jnlOe/50vovlun8uTAlHWx3sMvZpSIOeN5SfKj0gPBFlpW:cii4boXTNHzMP07we/OQvl08GN8oZkII
                                                                                                                                                                            MD5:099FF0A2D163F4BD42BF7D0B81AA1280
                                                                                                                                                                            SHA1:A153027E4B93478EAA75ADC5ECFF468E7801CDCD
                                                                                                                                                                            SHA-256:91215BE8F51D46536B4284C43BDD48115246B3DCDC80ED537F9FF7FEA4F76815
                                                                                                                                                                            SHA-512:7A058E418229A21072B536195B83C4619C2474215D2D2589A5B13D4041825E0A88C532DBCD6F6C70209616AC13FABBFADB2F46343003DAD7ECFB46193D07452E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "..",.. HELP_FAQ_TITLE: "...... (FAQ)",.. HELP_SUPPORT_TITLE: "..",.. HELP_EMAIL_US: ".........",.. ABOUT: "..",.. ABOUT_DESCRIPTION: "{0}.................",.. CREATE_SAFER_PASSWORDS: "........",.. DOWNLOAD_CONFIDENTLY: "......",.. SETTINGS_SS_OPTION_ALL: ".....................",.. SETTINGS_SS_OPTION_NONE: ".........",.. SETTINGS_SS_OPTION_SS: "...................",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "..... URL",.. TRUST_SITE: "....",.. DONT_TRUST: "...",.. HELP_FAQ_SECTION_ONE_HEADER: "... {0}?",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0}.................",.. HELP_FAQ_SECTION_TWO_HEADER: ".......{0}?",.. HELP_FAQ_SECTION_TWO_CONTENT: ".
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3046
                                                                                                                                                                            Entropy (8bit):6.142381589154048
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:cjEUAb0CTgSztJYMreb0j9ruR/o0v5uJufDeQO1LDohNp+i6Zj5dCQU8+N/Sog5:cjpAbxT2Mru0p6R/TBmWDVMz7fU/N/Sn
                                                                                                                                                                            MD5:074DB446200882DC25777107B6384B08
                                                                                                                                                                            SHA1:FEF487B0C540A925C08098FA9331EFF94B4A69F9
                                                                                                                                                                            SHA-256:D959C314F52F516351B042A629153D4883B75A344DF6E3606D390DCF46A061BC
                                                                                                                                                                            SHA-512:C8F4DE094CECF6B1DF5568C6CE88917583F9FDEA1CE2203A90F7611C08012393C4FDF70DFA62DCE3E0D5E7249C5197D13F0B89358D2FA44FC19E2073BAC2AAF8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOptions_ = {.. HELP: "..",.. HELP_FAQ_TITLE: "..... (FAQ)",.. HELP_SUPPORT_TITLE: "..",.. HELP_EMAIL_US: "...........",.. ABOUT: "..",.. ABOUT_DESCRIPTION: "{0} ..................",.. CREATE_SAFER_PASSWORDS: "........",.. DOWNLOAD_CONFIDENTLY: ".....",.. SETTINGS_SS_OPTION_ALL: "....................",.. SETTINGS_SS_OPTION_NONE: "..............",.. SETTINGS_SS_OPTION_SS: "...................",.. SETTINGS_DEFAULT_TRUSTED_TEXT: "....... URL",.. TRUST_SITE: "....",.. DONT_TRUST: "....",.. HELP_FAQ_SECTION_ONE_HEADER: ".. {0}.",.. HELP_FAQ_SECTION_ONE_CONTENT: "{0} ..................",.. HELP_FAQ_SECTION_TWO_HEADER: "......... {0}.",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3708
                                                                                                                                                                            Entropy (8bit):5.703528964625756
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Kar2MPa6uw0VE2HYP9ouKQaMF2B8KVj5YVj8L7:K8zb0VE24FfKQXF2B8a3
                                                                                                                                                                            MD5:3494487177BC568440687E563727CD20
                                                                                                                                                                            SHA1:6BD9A3866BFB06BB24653DD0D172E6BF16F99137
                                                                                                                                                                            SHA-256:13B6F42AE50C82C7CFD663E611CD164C9648AFF45254A656A0864E0399925FD8
                                                                                                                                                                            SHA-512:917972BC21446EDCD94DA6A51E2E55339C044E6B0213EEEE0B0CD3404430C33B855DAD459E61A082904BAB1EFA202063B0DBDF24D3AC6461E152BBFB55C173F1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Kliknut.m na mo.nost {0} dokon..te nastaven. programu WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Povolit roz...en.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Nejste si jisti v..e uvedenou zpr.vou? Bu.te bez obav . va.e soukrom. je v.dy na.. hlavn. prioritou.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Pokra.ujte kliknut.m na mo.nost {0}. U. to skoro je!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Povolit roz...en.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "P.i p...t.m vyhled.v.n. budete po..d.ni o proveden. akce {0}, abyste dokon.ili nastaven. funkce Bezpe.n. hled.n..",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Ponechat zm.ny",.... SETTINGS_OVERLAY_CONTENT: "Klikn.te na zpr.vu {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "Bylo p.id.no roz...en. McAfee. WebAdvisor",.... INTRO_OVERLAY_CONTENT_1: "Otev.ete nab.dku prohl..e.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3577
                                                                                                                                                                            Entropy (8bit):5.4381316543356615
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:AqjTIrwTeQCMF0yt0nWmumEbX0B57Oye2wos/ctmwufpsdb4jHpsd9rijTl69:JIsdCMYnWmnEc7FxtmwipsGpnm
                                                                                                                                                                            MD5:28EA768E62D0CECAF2A798C26713AAE6
                                                                                                                                                                            SHA1:FBAE91590AD6C25E08CE6B32B8D3F5C2BE265955
                                                                                                                                                                            SHA-256:702DD8ED83AC00AB37A10D67EEE210304C8E4F668FA105EC10421AF1D0E2B04F
                                                                                                                                                                            SHA-512:8E5CD8B418FB47AB97BE7528C6DDF90A30ACB10A7532427D699B1E119E1CACE0D348F0C003DCCA8E42B5BB64622C80E3FD910CCA669A4F935F482E8C79558A28
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Klik p. {0} for at fuldf.re konfigurationen af WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Aktiv.r udvidelse",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Er du i tvivl om, hvordan du skal forholde dig til ovenst.ende meddelelse? Bare rolig . dit privatliv er altid vores h.jeste prioritet.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Klik p. {0} for at forts.tte. Du er n.sten f.rdig.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Aktiv.r udvidelse",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "N.ste gang du s.ger, bliver du bedt om f.lgende for at fuldf.re konfigurationen af sikker s.gning: {0}",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Behold .ndringer",.... SETTINGS_OVERLAY_CONTENT: "Klik p. meddelelsen {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. WebAdvisor-udvidelsen er blevet tilf.jet",.... INTRO_OVERLAY_CONTENT_1: ".bn menuen i Edge for at konfigurere Web
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3813
                                                                                                                                                                            Entropy (8bit):5.419432609242921
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:KClwI7loU8z+JpKGZVp978ACtA6YI2l46D6sITl2klcuu:KUToUfZVp978AmA6Rw46D6sIp2+I
                                                                                                                                                                            MD5:C214253921C6E52DCD0AC6FF79AADD47
                                                                                                                                                                            SHA1:A3471DD61C1D67DD2F02B26C4173EDA5DE64DDA6
                                                                                                                                                                            SHA-256:CD77F017C8445C5C7F6DD2C4052F5EA18FB0945E85754E2AAAE4B8A4D26C258D
                                                                                                                                                                            SHA-512:3C9E6E2A9D56A7363729A21BCC902A5D914884EBFC81FA53F886DF88A52DDF23CA3478CB267E3F4A093EB96F49541DF58F83320231AED0DA8D07F9A43254E088
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Klicken Sie auf {0}, um die Einrichtung von WebAdvisor abzuschlie.en.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Erweiterung aktivieren",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Sie sind sich unsicher wegen der oben angezeigten Meldung? Keine Sorge . der Schutz Ihrer Daten hat bei uns h.chste Priorit.t.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Klicken Sie auf \"{0}\", um fortzufahren. Fast fertig!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Erweiterung aktivieren",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Bei Ihrer n.chsten Suche werden Sie aufgefordert, auf \"{0}\" zu klicken, um die Einrichtung von \"Sichere Suche\" abzuschlie.en.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: ".nderungen beibehalten",.... SETTINGS_OVERLAY_CONTENT: "Klicken Sie auf die Meldung \"{0}\".",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. WebAdvisor-Erweiterung wurde hinzugef.gt",.... INTRO_OVERLAY_CON
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5373
                                                                                                                                                                            Entropy (8bit):5.070299580240164
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:E8VKRGASgEB4JcgBf05IdgKDy/ZZnEX89+92w5vzLz2Ww9xVH1pxvTSFPolGbBb+:PKUYel5agUIM392dF9xVV/vT2Kc9xKUa
                                                                                                                                                                            MD5:BACBC1D5E0914A3C6AF3F48AE3342A74
                                                                                                                                                                            SHA1:263AAF299F5EF7E6B07BEEAAB545CF879849920C
                                                                                                                                                                            SHA-256:1BA38788D09FE24CA410EA52478D47C68AF479DC07EC9D73EC0ACB0D7CCD062A
                                                                                                                                                                            SHA-512:A17DAEB1B3B9E379F09CBC5AE71199D1C8E1EB6BC79B974C70F3A22CA8CAB303A76EB025BCB96A91C77961E899C61C51BC1362151410B79DB0AAAEE2EC009AE3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "..... .... ... {0} ... .. ............ .. ....... ... WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "............ .........",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "... ..... ........ ... .. ........ ......; ... .......... . .. ........ ... ..... ..... . ...... ... ..............",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "..... .... ... {0} ... .. ........... ...... ..........!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "............ .........",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "... ....... .... ... .. ...... ........., .. ... ....... .. {0} ... .. ............ .. ....... ... .......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3473
                                                                                                                                                                            Entropy (8bit):5.459958570168688
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:hX+nTmLZpNvS6qfKmtBBiNgsbjBLNZoIJon512xyQy6ihdt7+Jb:FpfqfKwegw7jen2r
                                                                                                                                                                            MD5:F1541B7543D1B58F8450D90F26C8A1F9
                                                                                                                                                                            SHA1:C60F2CC25705314748F15DD0DB4370C0AA1BE60A
                                                                                                                                                                            SHA-256:15E645C99927E9BC5144F85748198A66F20E521EEFAA07680C22751C25A03B6D
                                                                                                                                                                            SHA-512:ADBFBBC5C52D41C11EB1E6AC1CDD86697DCCA60D867135002115F55F7E0A481B4C964F9B54E2FE69F99F106CD2782FCA200D1FFF5825BA67A4262A8B07D7E7BA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Click {0} to finish setting up WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Enable Extension",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Unsure of the message above? Don't worry &mdash; your privacy is always our top priority.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Click {0} to continue. You're almost done!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Enable Extension",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "The next time you search, you'll be asked to {0} to finish setting up Secure Search.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Keep changes",.... SETTINGS_OVERLAY_CONTENT: "Click the {0} message.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. WebAdvisor extension has been added",.... INTRO_OVERLAY_CONTENT_1: "Open the Edge menu to start setting up the WebAdvisor extension.",.. INTRO_OVERLAY_CONTENT_2: "Avoid risky sites while you browse, shop, and stream with free web
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3561
                                                                                                                                                                            Entropy (8bit):5.428699764656758
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:795vs3WVLAOOxYqGEsU9b5TaBl/t6/Pv5nQe:7LvKVk3U9tTa/E/PBQe
                                                                                                                                                                            MD5:3C79C69B2C22D26FF28399D34DE7244A
                                                                                                                                                                            SHA1:44269FDACFF10657BB535DEC8A58970363D0ED5D
                                                                                                                                                                            SHA-256:752AC43D21870A09E7758B3F8014BF8795823052480969722D33812A5A91015C
                                                                                                                                                                            SHA-512:D7FAA306590BE82964C9D6808749095685049E59DE66D5F09942B9E602CF9EA2867D2140BECA40AEB2AEF95ECCA9DEDC924C4D9B130B1CEAB398DC69C471A5CC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Haz clic en {0} para terminar de configurar WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Habilitar extensi.n",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: ".No est.s seguro del mensaje de arriba? No te preocupes; tu privacidad siempre es nuestra m.xima prioridad.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Haz clic en {0} para continuar. Ya casi has acabado.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Habilitar extensi.n",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "La pr.xima vez que realices una b.squeda, se te pedir. que {0} para terminar de configurar la b.squeda segura.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Conservar cambios",.... SETTINGS_OVERLAY_CONTENT: "Haz clic en el mensaje {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "Se ha a.adido la extensi.n McAfee. WebAdvisor",.... INTRO_OVERLAY_CONTENT_1: "Abre el men. de Edge para empezar a configurar la extensi.n WebA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3447
                                                                                                                                                                            Entropy (8bit):5.410709621150699
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:78BzdBs4G8LY3WBrDACAOuN0/4L9U1m4yxO2loA5nAQ1m4M0j+wbTcO1zPOE+sQQ:7qs4c3WBLAOuAd6j9bTNbOEQyNxe6x1v
                                                                                                                                                                            MD5:02E227C0A2260F7811015371C94BE888
                                                                                                                                                                            SHA1:3AC50CB97E7896022C8F0B2AC0F43C1560D9E54B
                                                                                                                                                                            SHA-256:EDFC8AC3A79DF1E6926F9C12B1DA2E84BAF4788F4F4FF4CA493B9275F5D1C066
                                                                                                                                                                            SHA-512:84E89B310B57E0D89B5E8664A07C65FABE4CFB14838A44014A6FC9DB929FDBC5D024C4D3796AF93A19F5B41F99CF537295E11A15F62E6139B7B316405BA3083A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Haz clic en {0} para completar la configuraci.n de WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Activar extensi.n",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: ".Tienes dudas sobre el mensaje anterior? No te preocupes. Tu privacidad es nuestra prioridad.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Haz clic en {0} para continuar. .Ya casi terminas!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Activar extensi.n",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "La pr.xima vez que realices una b.squeda, se te pedir. que {0} para que termines de configurar la b.squeda segura.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Conservar cambios",.... SETTINGS_OVERLAY_CONTENT: "Haz clic en el mensaje {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "Se agreg. la extensi.n de McAfee. WebAdvisor",.... INTRO_OVERLAY_CONTENT_1: "Abre el men. de Edge para comenzar a configurar la extensi.n WebAdvisor."
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3511
                                                                                                                                                                            Entropy (8bit):5.432546603738584
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:PNyeWArmSSL0jMwX/Bz7N208N2Kv7qw0qhah7ddaXETuMgPl+5UAeWS/:PMYGwvBz7Np8N7wj1ddaUi145UAm
                                                                                                                                                                            MD5:FAE7C899880D70456F2E2D99A31E7975
                                                                                                                                                                            SHA1:D5FD039F6DDF84D4C023B5866DEB3599340A6960
                                                                                                                                                                            SHA-256:F6EB64989E13613B9D26D008FC19BBD9B7F6B13DF67B1B65EE51F4D28C61A0FB
                                                                                                                                                                            SHA-512:21AF0BB16F1B3DF483D82AF7E18A93010C828CE89479A206B46772A121E0077903116A845821B3252C0B91B96A35A350DC130C28BBFE360CFB9A6DD378660124
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Napsauta {0}, jotta voit viimeistell. WebAdvisorin k.ytt..noton.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Ota laajennus k.ytt..n",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Etk. ole varma yll. n.ytetyst. viestist.? Ei h.t... Tietosuojasi on meille aina t.rkeint..",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Jatka napsauttamalla {0}. Melkein valmista!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Ota laajennus k.ytt..n",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Seuraavalla hakukerralla n.et pyynn.n {0} Suojatun haun k.ytt..noton viimeistelemiseksi.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "S.ilyt. muutokset",.... SETTINGS_OVERLAY_CONTENT: "Napsauta viesti. {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. WebAdvisor -laajennus on lis.tty",.... INTRO_OVERLAY_CONTENT_1: "Avaa Edge-valikko aloittaaksesi WebAdvisor-laajennuksen m..rityksen.",.. INTRO_OVERLAY_CO
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3808
                                                                                                                                                                            Entropy (8bit):5.389338411621855
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:RvCshWLo4LeWU3EWP8/41QYd2WwawjOk51nBXwQw81NimwIu4W8u4kVusr6p:hVt3EWPmWFwawSkpgQNYmwIHbHMry
                                                                                                                                                                            MD5:1F96946C13815EB6CD1E20E44B18A05D
                                                                                                                                                                            SHA1:FC5CAD8B9845E785A269F4D712915F551056B037
                                                                                                                                                                            SHA-256:1795FC59D9BD7AC80EFB6402409DCDD46631D89D74189F702233FFD4705045E3
                                                                                                                                                                            SHA-512:AE3EED80D12F9E03C8D8ABA3136D5022C520E2FE637DDF0714E2DD9A26145C805A93E917C4251C62E363F41052246E609437AA5B329A15694C71059DC30F502D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Cliquez sur {0} pour terminer la configuration de WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Activer l'extension",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Vous avez des doutes sur le message ci-dessus? Ne vous inqui.tez pas. votre confidentialit. est toujours notre priorit..",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Cliquez sur {0} pour continuer. Vous avez presque termin.!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Activer l'extension",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "La prochaine fois que vous effectuez une recherche, l'action suivante vous sera demand.e pour terminer la configuration de la recherche s.curis.e.: {0}.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Maintenir les changements",.... SETTINGS_OVERLAY_CONTENT: "Cliquez sur le message {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "L'extension McAfee. WebAdvisor a .t. ajout.e",.... INTRO_OVERLAY_CO
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3820
                                                                                                                                                                            Entropy (8bit):5.393348134441983
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:q4Hj53EWP1ww63K2z1gUYmwEF2HfuVHfuf40x:q4HywPUYZ0C2N2f4m
                                                                                                                                                                            MD5:33EE13908D070DBED590450A9815B52E
                                                                                                                                                                            SHA1:25003D88A2F5BC645D0DEFB542CCCAD747961E40
                                                                                                                                                                            SHA-256:1705E86C82B145515126D3FCB4B80A3D493582055DDE8E413487648D6F5107BE
                                                                                                                                                                            SHA-512:BD3FBF1D845F73772D707677C7139A46F4598B4C30D64562B1BE2BF99B9A07253D67F6623E5F329280F04D33187F02E8C53F418EF4F71214F2AC96673E381F10
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Cliquez sur {0} pour terminer la configuration de WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Activer l'extension",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Vous n'.tes pas s.r du message ci-dessus.? Ne vous inqui.tez pas, votre confidentialit. est toujours notre priorit..",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Cliquez sur {0} pour continuer. Vous avez presque termin..",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Activer l'extension",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "La prochaine fois que vous effectuerez une recherche, il vous sera demand. de {0} pour terminer la configuration de la recherche s.curis.e.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Conserver les modifications",.... SETTINGS_OVERLAY_CONTENT: "Cliquez sur le message {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "L'extension McAfee. WebAdvisor a .t. ajout.e",.... INTRO_OVERLAY_CONTENT_1: "Ouvre
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3559
                                                                                                                                                                            Entropy (8bit):5.502984682934437
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:iKtsjv9hNkY6z3qRQRMmCxgFXNNXxXlU201Ii8cb:iKev9I3oQRMmCxgFXNNXxXlv0ii8cb
                                                                                                                                                                            MD5:50D2065FA485C0DD1B43F24FE3C98210
                                                                                                                                                                            SHA1:D9C06221D3B5D7670B4B47247C8E2EB8E170B54A
                                                                                                                                                                            SHA-256:61CF75B4DDBDA34BB10A9F0D3F9EE471E859711F29231887D4FFD03FC5D0590B
                                                                                                                                                                            SHA-512:02839970F247AE48738AC898CEB6EA1C43837E2157846D7AFE289D01EED147DC213E48B2801C3467E858FC7888D1FA74E1D833CA62CAAACE29FF45062C067CDE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Kliknite {0} kako biste dovr.ili postavljanje WebAdvisora.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Omogu.i pro.irenje",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Niste sigurni p.to zna.i gornja poruka? Ne brinite . va.a privatnost je uvijek na. glavni prioritet.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Kliknite {0} za nastavak. Skoro ste gotovi!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Omogu.i pro.irenje",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Sljede.i put kada budete pretra.ivali, od vas .e se tra.iti da {0} da zavr.ite postavljanje sigurnog pretra.ivanja.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Spremi promjene",.... SETTINGS_OVERLAY_CONTENT: "Kliknite poruku {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "Dodano je pro.irenje McAfee. WebAdvisor",.... INTRO_OVERLAY_CONTENT_1: "Otvorite rubni izbornik za po.etak postavljanja pro.irenja WebAdvisor.",.. INTRO_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3871
                                                                                                                                                                            Entropy (8bit):5.605970565233804
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:BjeL2klA7qs9fOpTbYFBbyN6t6rksl9EJky2twp+2mTpT+2:x7qwmJLrksTE74lf
                                                                                                                                                                            MD5:67A92D709F88E2783C8F8AEF7B8B7D38
                                                                                                                                                                            SHA1:A296CB8CD6DFE346B46D17DC74A2580CE68B49B9
                                                                                                                                                                            SHA-256:BF358F095606236F58E0C367FF1DEB87976D9237BEE07DEE30EA83BBBE337167
                                                                                                                                                                            SHA-512:9BC38A71A719809F484B69CEE95BC63A1AAC370B45BFCF588ECBB21DFA56E1CB9DDC7C1ACF9363A9C55CDE622C202D02E1A1A757F29E12BAECD1EE7B6E5DD169
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Kattintson a(z) {0} lehet.s.gre a WebAdvisor konfigur.l.s.nak befejez.s.hez.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "B.v.tm.ny enged.lyez.se",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Nem biztos a fenti .zenetet illet.en? Ne agg.djon. Szem.lyes adatainak biztons.ga a legfontosabb sz.munkra.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Kattintson a(z) {0} elemre a folytat.shoz. Majdnem k.sz.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "B.v.tm.ny enged.lyez.se",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "A k.vetkez. keres.sn.l megk.rj.k, hogy fejezze be a Biztons.gos keres.s be.ll.t.s.t ({0}).",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: ".rizze meg a m.dos.t.sokat",.... SETTINGS_OVERLAY_CONTENT: "Kattintson a(z) {0} .zenetre.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "Hozz.adta a McAfee. WebAdvisor b.v.tm.nyt",.... INTRO_OVERLAY_CONTENT_1: "Nyissa meg
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3451
                                                                                                                                                                            Entropy (8bit):5.348340753731105
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:9wwjU923wJglntrSojRUym/tDu477DuKqougwwCZ7JBw/r11Aw+yFGxMfJ/QxM9i:9w0wJWteojRUyUw5Jaw5+/3Aw+ydJPw5
                                                                                                                                                                            MD5:A2CFF2E2DD1598F0A0CA46EFCCCB2443
                                                                                                                                                                            SHA1:76BB9CF06F0D18CC34A816EA354472252580576F
                                                                                                                                                                            SHA-256:BC3199D0C90E4C6D0A27C28D8423C1262D578A9BDDFDC739A18732222C4707E8
                                                                                                                                                                            SHA-512:34917EF5FB1C9A766240E2B26E4EBAE07A3512AA22FB8E07542CCD78E69A769A8AD75BEBBAF0518A5467725B564683C47B9E5CBEECFE6AA5926A7141498E1751
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Fai clic su {0} per completare la configurazione di WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Attiva l'estensione",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Hai dubbi sul messaggio mostrato sopra? Non ti preoccupare: la tua privacy . sempre la nostra priorit. assoluta.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Fai clic su {0} per continuare. Ci sei quasi.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Attiva l'estensione",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "La prossima volta che effettuerai una ricerca ti verr. chiesto di {0} per completare la configurazione di Ricerca sicura.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Mantieni i cambiamenti",.... SETTINGS_OVERLAY_CONTENT: "Fai clic sul messaggio {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "L'estensione McAfee. WebAdvisor . stata aggiunta",.... INTRO_OVERLAY_CONTENT_1: "Apri il menu di Edge per iniziare a configurare
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4710
                                                                                                                                                                            Entropy (8bit):5.646354476497411
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:5mF9hGIitPqUUJnILJn90N3l3QLzb3Nl3CprHEwPbbDiabGdtiDR9hG3sEl:5mF9hC91nQmLzTNoprH1b3JbctiDR9hk
                                                                                                                                                                            MD5:5E4CDB82DA217D1D4DD72B0872A3BCB0
                                                                                                                                                                            SHA1:F9D6C09464770771ABB54B7D61CF16CD673472A0
                                                                                                                                                                            SHA-256:847D5CFB31F71F7D215D97A12397EBB181B9B5802E0EE5859AD8E94B495BD006
                                                                                                                                                                            SHA-512:BEDD6E357D9BA53ECC7DBFF65444FC498358B96C34163F166C7CE266C1072E0A7ECCA6D4B22A2F569832591D1A8987E9F67D9C9B89C41D6399FF7732991D0A2B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "[{0}] ..............................",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "..........",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "..............................................................",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "[{0}] ..................",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "..........",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: ".........[{0}] ........... ........................",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: ".......",.... SETTINGS_OVERLAY_CONTENT: "......{0}.......
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3733
                                                                                                                                                                            Entropy (8bit):5.890401246526406
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:QYCvdMrjNB9ZGI4BGSS1FdMUB2dgSG36cBJsg57AB2vCC1vyqtYIvdalf:36ynuBGpFyUBkYBJsmcB2ZGQYlf
                                                                                                                                                                            MD5:98C15C14F762399F4FF9F8D9E048F2E6
                                                                                                                                                                            SHA1:2A9D0FD84501DC4093BEE69AA9BC428C9824342E
                                                                                                                                                                            SHA-256:8FD50E1A9DAD1A6EEC53060E74F049B1CE96CC982024647A0B0B6A8725C333EB
                                                                                                                                                                            SHA-512:1BC5742DF9A125D2DEF86D8005E87B9EA79378539215B58D36E93D519B01DC5532E9E3D1D3957A08E252C19AD68D048426EBD73BAA13896C6F144D278A88CBC3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "{0}.(.) .... ...... ... .......",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: ".. ..",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: ".. .... .... ......? .... ..... ... .. ... .. ... ... ......",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "..... {0}.(.) ....... .. ........",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: ".. ..",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "... ... . {0}.(.) .... .. .. ... ..... .... ......",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: ".. .. ..",.... SETTINGS_OVERLAY_CONTENT: "{0} .... .......",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. ...... ... .......",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3225
                                                                                                                                                                            Entropy (8bit):5.454970547992806
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:JQjwncYXavDKvukfwlPpu1pHSTpJMpGqZn:6jwW5p2pHYpJMpGOn
                                                                                                                                                                            MD5:E7D31466659BFE662A74A3EBFC1115F7
                                                                                                                                                                            SHA1:C8ADCD390083C649C941FA41AA921A9C9D08A08C
                                                                                                                                                                            SHA-256:25F12BC56B2EF7010C71651B02B81EE7B3905D2F4F33C78C8E2E40490CB1C81D
                                                                                                                                                                            SHA-512:888BF572B035F9E9994901C43418A189D9BE4035F3124A7C03E33E470CB2B2BD9A08BB9C749AC1F0A9F0CFD6AC150119D7F9A6B0153EB70C3BEE2110912483E0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Klikk {0} for . avslutte oppsettet av WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Aktiver utvidelse",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Usikker p. meldingen over? Ta det helt med ro; ditt personvern er alltid v.r topp prioritet.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Klikk {0} for . fortsette. Du er ferdig om et .yeblikk!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Aktiver utvidelse",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Neste gang du s.ker, vil du bli spurt om . {0} for . gj.re ferdig oppsettet av Sikkert s.k.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Behold endringer",.... SETTINGS_OVERLAY_CONTENT: "Klikk p. meldingen {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. WebAdvisor-utvidelsen er lagt til",.... INTRO_OVERLAY_CONTENT_1: ".pne Edge-menyen for . starte oppsettet av WebAdvisor-utvidelsen.",.. INTRO_OVERLAY_CONTENT_2: "Unng. risikofylt
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3315
                                                                                                                                                                            Entropy (8bit):5.3846972061624845
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:hYNSUmrH9+LhVyH81/nxxM3P7zLFSOXYNXwBxrcB5w7qTF951eUq5j6YUNGUFUO:qWoM81/3czLFLYNa4BO7qTB38/pO
                                                                                                                                                                            MD5:3CDC10A95FF36F2FF2EADEDF828B80F6
                                                                                                                                                                            SHA1:A77CCEBC0430740856E958119D42DC2A60B0C21B
                                                                                                                                                                            SHA-256:5B368A6EC4FD691B3EC759F9A8EF06573343BE0562616A6A9A43B64A42160C38
                                                                                                                                                                            SHA-512:B76FF410AFCB6C98975F300AC6F2FC05381B56E33A6A4A3119075A12B978FB3D4D7C0156290D29C838C7601F2A6030FB1FB67B2AE13CB5200E5C40947E7F7690
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Klik op {0} om het instellen van WebAdvisor af te ronden.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Extensie inschakelen",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Twijfelt u over bovenstaand bericht? Geen zorgen: uw privacy is altijd onze topprioriteit.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Klik op {0} om door te gaan. U bent bijna klaar!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Extensie inschakelen",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "De volgende keer dat u zoekt, wordt u gevraagd om {0} om het instellen van Beveiligd zoeken te voltooien.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Wijzigingen behouden",.... SETTINGS_OVERLAY_CONTENT: "Klik op het bericht {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. WebAdvisor-extensie is toegevoegd",.... INTRO_OVERLAY_CONTENT_1: "Open het Edge-menu om de WebAdvisor-extensie in te stellen.",.. INTRO_OVERLAY_CONTENT_2: "Vermijd risi
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3592
                                                                                                                                                                            Entropy (8bit):5.652266864021974
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:UMCvtaaOZWKfNNz9KqIbQUZW9TRNcWRlP+im+oS+oGIUwI0qUIX:UMC1aaOIxbQUI9TRpR95mhShnUB0qUIX
                                                                                                                                                                            MD5:62917B9DE7549FF092647AE612BE657A
                                                                                                                                                                            SHA1:3F37A32CA957BD472ED8A9579F68C95436B071E7
                                                                                                                                                                            SHA-256:113358A4B5D1A9AA51848B0B1DC07DB55CB875EDF03D3AEA4334505A8436716C
                                                                                                                                                                            SHA-512:AFB1445443A148A74873D3FF9164B9048564EABC112F996C2C1B30FC34F9FB755AB02EE245A8C6A76292F9F13437F3D785870ACA5F92BA11C003A295970CFCC4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Kliknij przycisk {0} aby zako.czy. konfiguracj. funkcji WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "W..cz rozszerzenie",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Nie masz pewno.ci co do powy.szego komunikatu? Nie martw si. . Twoja prywatno.. to dla nas zawsze priorytet.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Kliknij przycisk {0}, aby kontynuowa.. Ju. prawie gotowe!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "W..cz rozszerzenie",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Przy nast.pnym wyszukiwaniu pojawi si. monit o u.ycie opcji {0}, aby doko.czy. konfiguracj. Bezpiecznego wyszukiwania.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Zachowaj zmiany",.... SETTINGS_OVERLAY_CONTENT: "Kliknij komunikat {0}",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "Dodano rozszerzenie McAfee. WebAdvisor",.... INTRO_OVERLAY_CONTENT_1: "Otw.rz menu przegl.darki Edge, aby zacz..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3368
                                                                                                                                                                            Entropy (8bit):5.411669618684015
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:tBRKXbIv/U8cc0dGvgObgbIc1JS+RUkf8gy:tg8ccqsXcPSsUkfDy
                                                                                                                                                                            MD5:F3E28D951D1347B5A8E92C686628CB32
                                                                                                                                                                            SHA1:9F76F49E5E1BC175194C714953A69C89E2544814
                                                                                                                                                                            SHA-256:F14E02B7D183DE9DFBE613E62C1D95AEC35C79B85E6DD4A0D2BC5FC90A775C49
                                                                                                                                                                            SHA-512:4AE8B5A92287AC1A0AAE979D478C6CFD5AAC0765165CC26A80074C92A71D718521760778D581D9ACC6C4125ACB905F299EC9DE14CC19C88E0F73F42765BD25FE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Clique em {0} para terminar de configurar o WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Ativar extens.o",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "N.o entendeu a mensagem acima? N.o se preocupe . sua privacidade . sempre nossa prioridade.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Clique em {0} para continuar. Est. quase terminando!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Ativar extens.o",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Na pr.xima vez em que pesquisar, ser. pedido que voc. {0} para terminar de configurar a pesquisa segura.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Manter altera..es",.... SETTINGS_OVERLAY_CONTENT: "Clique na mensagem {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "A extens.o McAfee. WebAdvisor foi adicionada",.... INTRO_OVERLAY_CONTENT_1: "Abra o menu do Edge para come.ar a configurar a extens.o do WebAdvisor.",.. INTRO_OVERLAY_CONTE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3444
                                                                                                                                                                            Entropy (8bit):5.414333938149512
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:tcgHxIKIF/UyvFz7d+J0b5H3JgJSgnD2L+vl:tfHzC/V15gggnD2Kt
                                                                                                                                                                            MD5:25E2F44C6CD133B099B9F49FE1E60070
                                                                                                                                                                            SHA1:7DE934C907E2286A9CDF98E0F1EAAC95D301ACF9
                                                                                                                                                                            SHA-256:1A96F565DBEA0224CA713BA4869BAEE11AFC04BB9A796E7615FC31BB1ED2740D
                                                                                                                                                                            SHA-512:D69ED7B55A8E9179AECC3F9ACFF7C9E0C65E3E2F240FDF17C52E473E8AA52921B0B6B2F79730F45AB246470B95798C2B72D4780F8CE317AFA1B32F0FC0DBF003
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Clique em {0} para terminar de configurar o WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Ativar extens.o",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "N.o tem a certeza sobre a mensagem abaixo? N.o se preocupe: a sua privacidade . a nossa m.xima prioridade.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Clique em {0} para continuar. Est. quase!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Ativar extens.o",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Na pr.xima vez que pesquisar, ser. pedido {0} para terminar a configura..o da pesquisa segura.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Manter altera..es",.... SETTINGS_OVERLAY_CONTENT: "Clique na mensagem de {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "A extens.o do McAfee. WebAdvisor foi adicionada",.... INTRO_OVERLAY_CONTENT_1: "Abra o menu do Edge para come.ar a configurar a extens.o do WebAdvisor.",.. INTRO_OVERLAY_CONTE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4888
                                                                                                                                                                            Entropy (8bit):5.13322206660522
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:km1cmOcoujLEUXirQfZVaSy/lcv8xv0pv6eyH5Z6LX6L0YA5ANvPuYV1kwgkebON:bSP52Z7Iqv8IvzSt/vPuYV9gkbEYZfB
                                                                                                                                                                            MD5:8464FBF4B026D2ED80F0C4C406E7DB03
                                                                                                                                                                            SHA1:B1F71D1678AD41C5213AD0789382C1918BCF33BC
                                                                                                                                                                            SHA-256:498A6AFEC80C15A24AADEDB4DFA19F2ED0E406E2340E629FCCC0B7543779FE79
                                                                                                                                                                            SHA-512:06490FD967349776FC20B1D2F885DBA5D8C5294A0C46E670D391734AE6A37506A692E471B72840CFC644658AB2E921C0F523F82AE374E72E2B866C1526EBE1DD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "....... {0}, ..... ......... ......... WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "........ ..........",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "............ . ......... ....? .. ............, .... .................. ... ... ....... ......",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "....... {0}, ..... ........... ..... ......!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "........ ..........",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: ".. ..... .......... ...... ... ..... .......... {0}, ..... ......... ......... ........... .......",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "......... .........",.... SETTINGS_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3645
                                                                                                                                                                            Entropy (8bit):5.654582138744028
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Za1q+c5nLPgGcp7rGEaqHNGXaGWSnEBCh:Za1CcGcpPGEaoNGXaGWSnEBCh
                                                                                                                                                                            MD5:D10BEE9E2F24452E61B7A38AC9602318
                                                                                                                                                                            SHA1:36FD48D7854941D6FEA720879521870C443BD773
                                                                                                                                                                            SHA-256:5A8F4621170505932A81F6542DB54ADE13C822689D4A3C488CE306B2EAE2CB62
                                                                                                                                                                            SHA-512:F2CE9C24A0719F3FD919B5A63DA614310034D6810A605123D24A81A0017EB3EDBF3A675A7DE8689DBD715F9D23104396FBFC13062133BF91A9162A2DE7A7270F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Kliknite na mo.nos. {0} a.dokon.ite nastavenie slu.by WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Zapn.. roz..renie",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Neviete, .o znamen. uveden. spr.va? Nemus.te sa b.., va.e s.kromie je na.ou prioritou.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Kliknite na mo.nos. {0} a pokra.ujte. U. to skoro m.te.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Zapn.. roz..renie",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Pri .al.om vyh.ad.van. sa zobraz. v.zva {0}, aby ste dokon.ili nastavenie funkcie Zabezpe.en. vyh.ad.vanie.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Ponecha. zmeny",.... SETTINGS_OVERLAY_CONTENT: "Kliknite na spr.vu {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "Roz..renie McAfee. WebAdvisor bolo pridan.",.... INTRO_OVERLAY_CONTENT_1: "Otvorte ponuku Edge a spustite nastavenie roz..renia We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3448
                                                                                                                                                                            Entropy (8bit):5.5258323663503175
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:bOKu5rhXVaOiD7jvSrPKPq/BhedVJDBDKOTV08Eyj8GmS4kSOhi7ICcX7E0o7X7D:CKwa7ruIwBho7Pjxm+FhiJcrERrEzt92
                                                                                                                                                                            MD5:DB2429854408F47C39CFF58EA2234126
                                                                                                                                                                            SHA1:660AD2F6EE59019DAB2A4AFA3024BC13E88ACA4F
                                                                                                                                                                            SHA-256:195CDCA022E9B3FEDEF21654E14E2248FD03619D31E005D33F96A3EB0DA5EB16
                                                                                                                                                                            SHA-512:14647E139504DA336355937B1BF2290D7D0F3EEB69A8F6C7A6362C2D3056157A7CAE900AB7E75EA27950E7D0B8587C5C93295BA48605C0668790E3E9C7F0B620
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Kliknite na {0} da biste zavr.ili pode.avanje WebAdvisor-a.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Omogu.i ekstenziju",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Niste sigurni u gornju poruku? Ne brinite . va.a privatnost je uvek na. glavni prioritet.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Kliknite na {0} da biste nastavili. Skoro ste gotovi!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Omogu.i ekstenziju",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Slede.i put kada budete pretra.ivali, od vas c.e biti zatra.eno da {0} da zavr.ite pode.avanje bezbedne pretrage.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Zadr.i promene",.... SETTINGS_OVERLAY_CONTENT: "Kliknite na poruku {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "Dodata je ekstenzija McAfee. WebAdvisor",.... INTRO_OVERLAY_CONTENT_1: "Otvorite rubni meni da biste zapo.eli pode.avanje ekstenzije WebAdvisor.",.. INTRO_O
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3419
                                                                                                                                                                            Entropy (8bit):5.535488804632093
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:XLtr87bPTBKfvmX6L9AvAMbEFGt9M+WRRZJ1aq3CTCc2ZeGd6J:btkPdKfvLLGS3NDZje
                                                                                                                                                                            MD5:F5C16637BF72EDD5743D0C5F3D6117CE
                                                                                                                                                                            SHA1:2748DB9C7C37737CAFD521B7CF2A67A719FB3E15
                                                                                                                                                                            SHA-256:9DBE42068BEFCE8987CCFF69EB582A0BCFF6F16C04CF471F4320F59AF5266780
                                                                                                                                                                            SHA-512:639FD3D8B7F588BB7796BA59BD90DFE7515FC5A5358EDB0051B47CD14C4EE69FD26E707AC74236C573245BFDD6FF4283FCED919EF4C38A740941650D9057CC43
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Klicka p. {0} f.r att slutf.ra konfigurationen av WebAdvisor.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Aktivera till.gg",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Os.ker p. ovanst.ende meddelande? Oroa dig inte . din integritet .r alltid v.r h.gsta prioritet.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Klicka p. {0} f.r att forts.tta. Det .r n.stan klart!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Aktivera till.gg",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Du blir tillfr.gad att {0} f.r att slutf.ra konfigurationen av s.ker s.kning n.sta g.ng du s.ker.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "Beh.ll .ndringar",.... SETTINGS_OVERLAY_CONTENT: "Klicka p. meddelandet {0}.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. WebAdvisor-till.gget har lagts till",.... INTRO_OVERLAY_CONTENT_1: ".ppna Edge-menyn f.r att b.rja konfigurera WebAdvisor-till.gget.",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3505
                                                                                                                                                                            Entropy (8bit):5.560477366213013
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:8gTrSRlazqTSoc8T4mq+pxP3yfK2XsCzjW3A/O20q3kJ:LMTSzUtCBwDJ
                                                                                                                                                                            MD5:DE09C051CBC5D0A16DE9646EB1DD573F
                                                                                                                                                                            SHA1:60676A3E60A7B84C021BFA46D897C294E4948CF1
                                                                                                                                                                            SHA-256:F6245E1A4A8B807F1782B5F38A7E9B21D9FD8076AECC2180663CC1594402E9AE
                                                                                                                                                                            SHA-512:62774122610B9237794AC5A1FEF3B228FA1211CCAA73A095B903EAB3DAC2643A01ED1EDA63B5045DA74208E57D002917C7756C1D47D8A3BAFD9EA14F313DB7A7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "Web Advisor kurulumunu tamamlamak i.in {0} ..esine t.klay.n.",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "Eklentiyi etkinle.tir",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "Yukar.daki mesajdan emin de.il misiniz? Merak etmeyin . gizlili.iniz her zaman birinci .nceli.imizdir.",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "Devam etmek i.in {0} ..esine t.klay.n. Neredeyse bitti!",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "Eklentiyi etkinle.tir",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "Bir daha arama yapt...n.zda, G.venli Arama kurulumunu tamamlamak i.in {0} i.lemi istenecek.",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "De.i.iklikleri koru",.... SETTINGS_OVERLAY_CONTENT: "{0} mesaj.na t.klay.n.",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "McAfee. WebAdvisor eklentisi eklendi",.... INTRO_OVERLAY_CONTENT_1: "WebAdvisor eklentisinin kurulumuna ba.lamak i.in Edge men.s.n. a.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3122
                                                                                                                                                                            Entropy (8bit):6.212538664409796
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:6UrfcU6lnW9tyEQeLJrcwfrZaq0KSVnUUJfQpr1Z8y:6UrkF0t2excYzSVnUU9Kr1ZZ
                                                                                                                                                                            MD5:945847BBCB1913BC9C9D5A165DB0F995
                                                                                                                                                                            SHA1:F2BF3225E8B318BC8A1FBF68BE20CBBED4864167
                                                                                                                                                                            SHA-256:38674F155AC95729FC671ED29B48AE19D69FBB0D6EB6A2BCAE49E19F39D4D3C4
                                                                                                                                                                            SHA-512:A72415C4BA1530063EF7CCBDB3934DD746944664ECC29A40BA1CCE4CE584A0EC65D3995E9FEC1195A3069CB39EAF81D95F8E000D509E0BDC501EB2C220735877
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: ".. {0} ..........",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "......",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "...............................",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: ".. {0} .........",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "......",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "............. {0} ..........",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "....",.... SETTINGS_OVERLAY_CONTENT: ".. {0} ...",.. SETTINGS_OVERLAY_CONTENT_BOLDED: ".... ...........",.... INTRO_OVERLAY_CONTENT_1: ".. Edge ................",.. INTRO_OVERLAY_CONTENT_2: "..........................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3232
                                                                                                                                                                            Entropy (8bit):6.28804097658073
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Fnm6KjBr0E5eC+WKA4DKoYwWAV85brkeUwmxm3VBpRBpG2m6xCG:JbM5dtKPDVfeZrkRwGm1pDbB
                                                                                                                                                                            MD5:04F2F159FD84A76DAAA10031A812ABA8
                                                                                                                                                                            SHA1:15B3F23697F56F0F0A1C4079E24BA050145D19C3
                                                                                                                                                                            SHA-256:D511D934188402B3919DE4C77617E3C5FA5C52F5B542789BFA0A811840BFDA07
                                                                                                                                                                            SHA-512:7E8EEA213CD528F52A6F4A143E2C06CA200E02370577004C11024452E72C48AD782578FE8FC5FCC5EB0D17F07E0B164C032FA286001C8A58F0D2BA17A27927AC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrOverlay_ = {.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1: "... [{0}] ... WebAdvisor ...",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_1_BOLDED: "......",.. ENABLE_EXTENSION_OVERLAY_WA_CONTENT_2: "...............................",.... ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1: "... [{0}] .........",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_1_BOLDED: "......",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2: "............... [{0}] ..........",.. ENABLE_EXTENSION_OVERLAY_SS_CONTENT_2_BOLDED: "....",.... SETTINGS_OVERLAY_CONTENT: "... [{0}] ...",.. SETTINGS_OVERLAY_CONTENT_BOLDED: "... McAfee. WebAdvisor ....",.... INTRO_OVERLAY_CONTENT_1: ".. Edge ........ WebAdvisor .....",.. INTRO_OVERLAY_CONTENT_2: "...............McAfee .
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.483185986771839
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHP2cnmsWmQjdp:CRsyeBmWfV8ZSXSH7msWnxp
                                                                                                                                                                            MD5:8A55E0A184A07C8A6847AEF2A3480C2A
                                                                                                                                                                            SHA1:A0AC4E07A3DC7D69A6DE0CE5C18CE13FD57DD84F
                                                                                                                                                                            SHA-256:856B51574ADF626B7190520C9C03441B4CFBEC34E66AE3270B6BA3A89A270764
                                                                                                                                                                            SHA-512:A71AA6EF132A4C87B241CD268C3861DAD729A112EB60FBD2D0DCB9F8FFD3AF223DA13BC443F5317C77AA2D85A90F9226CB281032737F9999549507F79A15FE9D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//779B7FF97A347B2B60B9C695E9510C17D732EBB76D59FB261483CFA334C621BE432AAB53CC8D1E9E3D32EE1F9DE1586783006FB0F10AC2E82CFD3DCE40D484F1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.470363467852289
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHjaLch8jQo3R/Jis:CRsyeBmWfV8ZSXSHj+Jjnt8s
                                                                                                                                                                            MD5:68CE7E2CA2C47EFB97C447E9B1555BD6
                                                                                                                                                                            SHA1:B0F3ED0ACA62EF41D101BCEB756565E70B541F5D
                                                                                                                                                                            SHA-256:F6BEF1984BED66D908CD004B9B9D07CF00BA3DB3C169B17D672226633875CBE6
                                                                                                                                                                            SHA-512:5E990CA464B56A08F0023FDDC197184283B847DEA21DDA98A2473098B643BDB5B88DEAB352FCB647AB0AA6FACF080469A0D3A7361168C74D44D18E68BC53CF45
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//C58CD5D0DDDA0BDC3DDF95C3EA647DCF210034D40B8A2B3C776FEF41796B0E506655473CC23984412910551A66AA79BB51A1AA5DC1EF9BDEF91A3545A14F32EE++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.464304293445782
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSH9gycgUUFoNaG5:CRsyeBmWfV8ZSXSH9gycMoP5
                                                                                                                                                                            MD5:C7B219EC86DC401B23495DF92086686C
                                                                                                                                                                            SHA1:64AC08BCC0E0F74D003EB965854B68F0CF7C396E
                                                                                                                                                                            SHA-256:209FD86CEE00B85E500254C88FF405C5BFE10D324B0ED5E8D65ACA037ACD371B
                                                                                                                                                                            SHA-512:86BEA1580AB20D690A99D6AF5D9FF6B9AAA5BDFED5E0FB42961E6ED23D44E4A7F89919031F614242C2B95A600B57A9B6EC60555D9927263B6F37727A3BA30112
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//11871E1444B5EFB64FDE040E276FDD5B610839D185910EB29BBAB0ED1DEE4C24CAFBB75A5B372E4ABFAEAA47CC45C0D31EF9508B835F6CB656F85E78CF829BFF++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.476492001999947
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:qwBMgWkWKs5RR+2cKQzGJC8WKskeGedmLpEfSvc8GNKpoXb2JpeRNuSwTu0GYOjW:pCPR+2cyeBmNEfSU8ZpoXSHquSXxyx99
                                                                                                                                                                            MD5:56ACFC1DD811AD98D55879ED590E39A4
                                                                                                                                                                            SHA1:5E5AE245F1600D0AA8F3C00C3DD1CEC41FF12981
                                                                                                                                                                            SHA-256:2577A8EC6214327D469C6947FBEE3F627B5F1A1C7AAE6DAF79B61790DA402724
                                                                                                                                                                            SHA-512:FCE2EAD90CBFBC2CFBA7842FD273EA9BB286E35B9C755A058A72E4ADC77FCD3CA1F4DC2932AD327BD1706FA02062A78D72BE3EBB2BB270E17EDF7DA66DCB9594
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//10A2AB7B43469BA25D1F69F13AB4C89B1A6A923B76FA2735C6BBFD3E1A30A4900FB12D4B2255D5ED08309C091724C51DBC83AC985FFC5D3B909DBD20E9BC0D53++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.483670313619899
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSH280rSTVY3hd3:CRsyeBmWfV8ZSXSH+rSTVMh1
                                                                                                                                                                            MD5:100F55A1A3DC968EFC26DDE73747FD87
                                                                                                                                                                            SHA1:9DC3BBE79C82004FA1415B216D636E8C352779E1
                                                                                                                                                                            SHA-256:7FD3C0E53C3CA5902FCE6D3C55E511EB29B9E1E4AA7CCF9610D692B194673EE5
                                                                                                                                                                            SHA-512:9011528745B64B61DCA221AD55409B7F6D00195F47FCAB9384B467DAA6D10C398AADCFFB91B10C3C028C6E704A3EE1FD3ABA87F9579679CDB1C7519ADBEC4147
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//538533566FD1B9F5834362C7400758216C8737D085235B9E67B16E51DBE93F49D97847BE5BEFFEF8FA52BCD4E329FB7F8924585922B952AFB50DC98B8D5B6A8F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.4774614387651965
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHd8XIrv9tOYgEoj:CRsyeBmWfV8ZSXSHFrVwnj
                                                                                                                                                                            MD5:5A402B5245FB541EA65C3C2ED575CF07
                                                                                                                                                                            SHA1:30DA35F4D0ED12EB4CE927ED38D3F864EA2436B9
                                                                                                                                                                            SHA-256:37D1E6393D86A7C8CC3888DD52FA30144F1A25831CA70716353CFEB005289BB4
                                                                                                                                                                            SHA-512:6027308D33D201A298C5F40ED2ED375D99DB86ECE763B02AE460F78FE4A53A6724FF172E9A19C7FAFB5F1C5D3386ABD2496B0827AFFA9CF3F2F7493198380ADB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//49EF530EB3DA9A6889B72D369EDA9388CB601DD1B256148A7BCA5F055B02F4FAF8794A168DEDFF4E313D64C58C08D434E98B5DB85FA187BAE38D567DD473747C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.46410718057219
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHnNgHIUhZyMB7:CRsyeBmWfV8ZSXSHnyoUhZj7
                                                                                                                                                                            MD5:F11DD951A4A0FEEE66F504B6F4A9E050
                                                                                                                                                                            SHA1:5479885497E55472DF16689E2A72431F3EC65A90
                                                                                                                                                                            SHA-256:CAC7FCC119F603D3209E606A13D4A8CCE1C1E7A4AF7986BC9762D01BA32D8D16
                                                                                                                                                                            SHA-512:766B7F15C6B81B35612E24354D852E0A2FD1E6BDE9B848501BE5EF3B168A425F7CE9E716C622B1FC2DDCF1D8FA677145DDF3BD582A6E09EA2559FB25EA8B19AD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//6DBF9FBB37BB8547C23A00B408DFD5CBB8C9AD32D4D729539ACA64F0791E5891CFFBF35FDDB73A87B691112CA5BEB7DCBE008B8FA383F9DDD360293CA3E873C9++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.492592530316645
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHQSDBMtCIQB3:CRsyeBmWfV8ZSXSHQSlxB3
                                                                                                                                                                            MD5:D27E51178B6CB12F7E2F723D058A9A1C
                                                                                                                                                                            SHA1:5F9389CC1B9D99C23FDFFD79E50EEDB3FC324671
                                                                                                                                                                            SHA-256:7E441138B08DB093B139815FB3E21D3809188BCF79CB4A1AE713A252BDEFF4DF
                                                                                                                                                                            SHA-512:8F9EBB48F37519AD08590B8BFDA8B499B176B7F9AAAFBCD3CF26CAAE03E17EBAAD3D8A55C9AB1B60BC8004FD7B7A319B98E5452AEA2FDF62630FF30B06A9536A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//96448B1DF0CDFDEFA2055FD03D1354E1DF3B828E0A83026E0FA0FA0A300FC1F397F87814BF7782828DD4CA6AD45F73769B2A1461592B39597D2F9ADF7BAF8A3D++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.4578323481596085
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHXNMt3vgmdO:CRsyeBmWfV8ZSXSH9tn
                                                                                                                                                                            MD5:69D6F26C5B12666C309F63AC3B2CDC80
                                                                                                                                                                            SHA1:961FD14E2295D0D607D94DDF49C6B45CCAFC52D6
                                                                                                                                                                            SHA-256:BB3EB893857EC7C6660E5C0DF53E9D08EAE83E65DD1CFB0F6C862C5B278DBE5D
                                                                                                                                                                            SHA-512:DCDD6E6120E897CDE77A049415F2509CE6FDB6AC02FB1B54366A16FCCEBE51DAA3CBF5A4FBF67582C8CA077A7226DD2AB07C0DA7DA98B70261C7BE8E95AF8778
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//B825D07F236C9CBEAE089DFBF837BE2C3EFB400BC36D743EA83BD789EBF2609F9B75C5460DC4C2BB358D2EB01E04AA63BFE05A937DFAE33DCC2104C717AFD4E6++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.46207116731783
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:qwBMgWkWKs5RR+2cKQzGJC8WKskeGedmLpEfSvc8GNKpoXb2JpeRndCFqWf5h+rk:pCPR+2cyeBmNEfSU8ZpoXSHtFqg+rv5G
                                                                                                                                                                            MD5:2E6FCD5DDB734322FBA066499382B954
                                                                                                                                                                            SHA1:8736E82A7E77E09A9DDA64302FF55312D439C6B6
                                                                                                                                                                            SHA-256:5765AB76060D562767F40D35822052B85F3D171D32478821B15E585E54C095DD
                                                                                                                                                                            SHA-512:5A653BB7CC863387FF6D2B150E5F04CC5B452E4B37B75FF0EDF8C8EC76327C56F67C14C36AA067470942D80EE3F267F0A088484091C445A826E378206E85E50E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//48FC58BE02F6C12E9428DA51AE23662687C2F8DE207F3C277B89099A62861089EB66F2E94EA5DBC3DCC826FB5CFB7D6A02E9E532B35D13BDAD1D0DCC952D2399++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.456480118474768
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHORfkjyhh5MGigjqX4Sh:CRsyeBmWfV8ZSXSHORfn4GiZp
                                                                                                                                                                            MD5:5EABA7C98C02265CDE1FB5EBF6CF9A40
                                                                                                                                                                            SHA1:A4ED9BDCD9490BC4CC60E2743ACFC87B9E3EE693
                                                                                                                                                                            SHA-256:1DB2AC3D031C03426CECF0C8A2B92578888DE604E62A5F2D642CA9EA9C3D3366
                                                                                                                                                                            SHA-512:B456E348FB0AAE0CEC76D09DE428444649A2D5D8FD3F05E59DFDC6D1F7582000965893E2727FE149DD5A1A0FBA184B34CCC7FE62C30A1977A17A5EE1D720DC8B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//EEEDE7711DCA6590F99E7AF95AD32C88D88FBF57A6199760608887CCD2D9241AA15A8BA3CF78716E2DC1450FFF5FAB81AFD2799AD25FF38FC95DFEC736A28277++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.485651449071428
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHerozhKnCvwgF:CRsyeBmWfV8ZSXSHerC8Y
                                                                                                                                                                            MD5:4CFBA2943AEC00CF3AC0F668DEEFAE1C
                                                                                                                                                                            SHA1:B5D9BF4A8CE44999FBAF7A98758D587EC1016879
                                                                                                                                                                            SHA-256:890E743E14006E8489157356D99D29D4F01E27CA283858AB0D84098BB522964D
                                                                                                                                                                            SHA-512:E6CF38772EFBA67A5CD6ADDDBAB3DEE8E9D9F2393EFBCAFB6F14C4B10A1A6D3C6C1ED633C9EAE3361EB6E1DEBB11912F6F225A88A3186C4DB08016E2311648C5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//90EB780E16E8F65109458C1F86600208E13B07963E86071D5A9E1A29BFA4207CDA49DB66B367C3E4988699E55FB4094BC3F99498D5A8DE1CF9EDF62B86324A02++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.4743818470449295
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHoUlTvHcx1CTd/gQyO:CRsyeBmWfV8ZSXSHtycWQd
                                                                                                                                                                            MD5:BDFF501C8E0FD793C9BB763D9C80CEDD
                                                                                                                                                                            SHA1:F1FB7F3E9C7856094869D1AF2A73AF8457DD47BA
                                                                                                                                                                            SHA-256:57E0D1E58AEDBA759D4C2FCFB60B62E6EEFB8C4D7D23D83366BA016006354935
                                                                                                                                                                            SHA-512:43BEDB6029375DDCA9A5BB0CAB61B3110B80A8BB76F907332F53B152CF7BF8224C9708E938D34A6F53DBB5C7097170FF7F762BB008E0A30BFABB1E06F9FCCCCA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//198FC54EDE5D4DDFC0D1FB64FA7C3506E942E8826476BB919A06CE23D48B976D4D8D895EEB23735FFB1CA10B42D3612B78F90EEF39EEB6E7CC14393C73339859++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.475935258072216
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHrXqrjfgiWb74k:CRsyeBmWfV8ZSXSHMfgj
                                                                                                                                                                            MD5:A0FA25412DD8F6B1642AEAB0C2B43A5C
                                                                                                                                                                            SHA1:5D848F134B0FA49A6A9D79F51268DD46FCE984B8
                                                                                                                                                                            SHA-256:6CB94F12C952A2919864F82F7655A4620FD6E546AE1E3CCA7B58D734210F5C70
                                                                                                                                                                            SHA-512:0D9506C51A7A17D1AE9E0EE16CA71C955DB47B51224C54E7A83E2C9009A90C8A4A6DB057F82ED20167EA5C267FBB9A30DA50D8FE371C2708DA02A78F0D621BE9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//882A8F5DB2A0DBAF151EEB31B0D0AE06ED48BF60C78560F1A2EA8CA497AC4CD1DE1D0A4B6F934F54222F868298EA1B13594073882DE67FD43AFC30AD85C2AF35++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.495942385043319
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHPCRUxRCjmaS:CRsyeBmWfV8ZSXSHPCyxRC6J
                                                                                                                                                                            MD5:50AB36BB209778F1C55CB5654D46334C
                                                                                                                                                                            SHA1:A41546FF370A12AA41A279A321FCEC4E068328A9
                                                                                                                                                                            SHA-256:D80CAEE10B16DEC90606E13724EDDD1B2944D219B2D553D388C4A815FB57C4A3
                                                                                                                                                                            SHA-512:1A294716DF9FFD71532330395AFDCA704B93E7282DE1ADE6373D7D1E23972D46C34840C041E343B768A89B7C44D7613A1383AB19A547EBEB3D364C366E2F347C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//6F72F5C6915409203EC6C8F9EA50428B23E0C0273A6ADA6171053584A0B457F90ACB9904EB312411D3E573F53F22B5972DFA94254D4696E096C4535A02336385++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.469004306713551
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:qwBMgWkWKs5RR+2cKQzGJC8WKskeGedmLpEfSvc8GNKpoXb2JpeRHGC+zfeVDo8o:pCPR+2cyeBmNEfSU8ZpoXSHnzCo19B19
                                                                                                                                                                            MD5:FBC234726DAC88382EF2C15DC96D0848
                                                                                                                                                                            SHA1:6B70C0C9F92F3DB4A6FD03049A453D6481BB3CBC
                                                                                                                                                                            SHA-256:C0FFAF02B0A499EE09496AE58C04C73DBF387CEB611890E2B3C154A3D788BE5E
                                                                                                                                                                            SHA-512:12B092B5926DAAB4E8FBEEE24AED2B1FC830996A4D2CD10BBF100433C1F5EB36E1521515F7E1F3B031F5961A143FD0033A382AF66F0BC1B4C14805928C559B11
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//86A984FD038693739ECF3A9F7D76445D3D6A0ADD7B8EC77DD64A59D78DF249BFF53785D7720226AA6E34704D4346A56C6DB98D3223D16D022C62E3BD0B9F17A6++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.4738843132819595
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:qwBMgWkWKs5RR+2cKQzGJC8WKskeGedmLpEfSvc8GNKpoXb2JpeRkmdU6d67eeyp:pCPR+2cyeBmNEfSU8ZpoXSHIdma84T
                                                                                                                                                                            MD5:0B4BD9B6B2F45C327AAC05A8C6A8082C
                                                                                                                                                                            SHA1:41720B1C989F5AB1726C275A7E1ABEB83717F539
                                                                                                                                                                            SHA-256:1CF758BEA8F6D3149A73E81BCA1418286D37F5FB02FFE136F125848FCB5B02F2
                                                                                                                                                                            SHA-512:70837F65DEBB8FF916980C49D64F62468691DC4E166695B81A61F76E17A56E93A426C111961DDD4D9A1AB59331F29B009C2B2F05F32099BA58377E1E88CD814E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//A15C599ADD02FC398C10860BC0ECD1178EEE2186F59EB012C3C741A00204898956A0F59FEAF41E1661BBCA71D782D8FAF0E41FF7814809BD51CA6294B3F9A79D++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.470036256437061
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHH1dtKmwShBc:CRsyeBmWfV8ZSXSHH1dtKmwShi
                                                                                                                                                                            MD5:044338D6F9E8275912F89814B2F30059
                                                                                                                                                                            SHA1:DEA5721CC6F951B83CB0F662BA23E1B85E16C727
                                                                                                                                                                            SHA-256:25801D244DD567C93558EB917FF5E18D1FD8E76D73983995DE07E0125E1A084A
                                                                                                                                                                            SHA-512:EFCDDE83DE6083F7CF4B380B34A34DD50E95593CE5F64DE479C7ED649B961BC6CFF90E08E47E5D5024E92FFE29B2D9F352521A4FEA669208A980FB2199BEC509
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//8BD368FDFFB4EA20079B3E2C1276507EFFE5C7EFF4B8E3C7210CA0B9BF42A8B3203034E29CFD180F2481BF316EBEAED76C7CAEB96095901CFB69D82D3F9A61FD++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.422792541724916
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHjZRjgWRpk2CDD:CRsyeBmWfV8ZSXSHjjgWjJAD
                                                                                                                                                                            MD5:682B9901E2904079F13F266C64B08E0C
                                                                                                                                                                            SHA1:6C01EE55020FD9BC1B76B3B4B01D0E84A713D211
                                                                                                                                                                            SHA-256:71258219C7357066CAED9F9111C17C338FB599814EC267E48042950A81AF8045
                                                                                                                                                                            SHA-512:BFA51E4A88AF77B695EA9837C02B812BAFFA88F5E5526947454E11DF59C763F7427D16C7D696EC0CFA7689470740964AE74A68A16206525467418DB761F964CE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//F1F9AD5C3DC2AF99BAB05513A2D5FD66E11BE4A11B157E25D3ABEA79B14AE1F93BA7C7FC97F46A773BC883EDECB3E9EAA95EA0A1A977A201E0CDBABBD9219339++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.457875816162936
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:qwBMgWkWKs5RR+2cKQzGJC8WKskeGedmLpEfSvc8GNKpoXb2JpeR6M1TnN2OWYj3:pCPR+2cyeBmNEfSU8ZpoXSHNIrNZIY
                                                                                                                                                                            MD5:BA9175971DF351154157D53355F8D440
                                                                                                                                                                            SHA1:DAA6CAECA319BD54C283C0E4AE6FDC318BC058AE
                                                                                                                                                                            SHA-256:EFF588E1AED4F734C17E9CEABE1175C9DF43B6BAF11EA530A779D5EF43E8D274
                                                                                                                                                                            SHA-512:FF66ED42900F13912AE5762DEB9AC64316179EA7773F5A7191F8AE77DD17DC20C78BD9DF1F0671191D7B6120FADA39E183E414250A5FDBD6D8A5DF4E0F1E98BB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//9A982904F084236422BE18EB0F6CE060BE8E15A2068C32D1CEB00F2E1733578B343AFCD3638193FDC6FB1C10B9EB1AF162FB1FD09E8313DB8C78F0EEFB0348DF++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.459356963784258
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHjIs/DCezHEJsS:CRsyeBmWfV8ZSXSHjIs/2ezSsS
                                                                                                                                                                            MD5:83130A13CC410DE99D8F067412667E5D
                                                                                                                                                                            SHA1:0A9C99FEDC871BD967B76381F16D1326D735629A
                                                                                                                                                                            SHA-256:A9F0B9178322333DBDCC7AB5244CC0323A5BA02C00EC8C7E24BB2A7D4BBA8A66
                                                                                                                                                                            SHA-512:47ECB482C8B515EC862B8A2AA863CDFF39C7A3A44C42B0BECD62356CD1711CE2F1DBCF691C31BEE437ECC37547553D4E355CFAD7AD7715AA090DA0D132355865
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//C331E0FFE037C234BE06DE25A983DF01EAE7A2726907BDE577A72E75C66BC0E1D75C05D1777E33A16EC428177A6646DD85B0FFBF10D2C6114249BA2CA1967A5E++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.475353258660528
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSH6gsYswIlMen:CRsyeBmWfV8ZSXSH6gsYswIV
                                                                                                                                                                            MD5:3BE119FE3E6330E0730A80796B3CA9FF
                                                                                                                                                                            SHA1:2954293A16B2CBE1EF2FAD5CD611E97C3B9C3861
                                                                                                                                                                            SHA-256:E503EB8BDF4E4CE922257ACFCE1F15E65BDB4419EC6AA124FB27DA33AA826BE1
                                                                                                                                                                            SHA-512:83CE7F139C87550641EB5570A84E0809AFCC13916A9432D5DB418D9F0A098359EC1C678348846E0F9A244B43686B0B7F74E87F3A3B1F998FE08C30B43644BD49
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//F43809A83B5C6EA08A744E2130B9FEC4A9A8A8F61A85AEE97C4BD2FD31F4B2EB2AD3D2A77C5B147CB6AAC69BDE3762DD5F37D4A604CF7BF5978A17ED2229F911++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.493050363802037
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHIqGzzrVB1G:CRsyeBmWfV8ZSXSHwzzpG
                                                                                                                                                                            MD5:8E3B30D31FDF8FC9FE9B7ACF335BCB5A
                                                                                                                                                                            SHA1:755275E4FF374B07BA8DE6FB1EF971A829B006ED
                                                                                                                                                                            SHA-256:B281FB28BB41C86CBB1FABDF93D044D8E2A772B543C5DDB610710260F34F8DED
                                                                                                                                                                            SHA-512:222CFBEB1C6AEAB7308FA43093A045A2BBE2023F52C70C7BC8CD99962F3F1830728B498D88711A07CFA9631E28C2C50EEC58FDEFE996B80688ADAC89415B0C50
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//82FF624D72A6FAA2B1905C65C4A98BC593FB309A2D9E577663CCCE5B0AA6B8CAC826E0748828C5629818770FEF4353B0BF07D680757117E75913F9D65BBEA409++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.451309364031569
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:qwBMgWkWKs5RR+2cKQzGJC8WKskeGedmLpEfSvc8GNKpoXb2JpeR2SBuQn/I4DDk:pCPR+2cyeBmNEfSU8ZpoXSH2V3UF
                                                                                                                                                                            MD5:9C6061A4B4E67F431AAE63D76177DF30
                                                                                                                                                                            SHA1:24985E30FF76B0EB81D86958AB50B21D8B983977
                                                                                                                                                                            SHA-256:287CAC7868287E4D312F69ABD48B8BA302D58CE890C2C0ED4D124DC4A6969C3B
                                                                                                                                                                            SHA-512:BEE3636943930ECD7CCA15EAE1DCF3CCF1012ED8C1E13CCD0B4FE46135EC9D821BA7CC1228A4341F86818F85FF69E6625886FD1F6AE5F79B333766FC783CD448
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//FCB8F4F8FB73E2B27C7FD72AD5AC853E39BB1264CBE60C947817E8E265C55B9CE77C76F5D3BEA0693D3C283727FA0B23847B9A7CD174F3B7533D4ED9878C8CAB++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.449750602929413
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:qwBMgWkWKs5RR+2cKQzGJC8WKskeGedmLpEfSvc8GNKpoXb2JpeRE7Z/eAtypsRW:pCPR+2cyeBmNEfSU8ZpoXSHV5xw1O2D
                                                                                                                                                                            MD5:3091D3A063743E6FEBEAAB42B85A0DB7
                                                                                                                                                                            SHA1:2A89C2D454D23D0E2CB15CA3E8524C29DFB59304
                                                                                                                                                                            SHA-256:872017EF35CD1A11F77882E025F50B91F5E80ADE678C464C3A88DB285744D090
                                                                                                                                                                            SHA-512:5AA8FF07251A479ADDC0F538CE9FBF5B4A75214072BF008EDA3353CC59AD569A8469933FE6D79273313A216D4CA34A8C78F2F37AF57328B74035E76A4658B582
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//D7DDD596097C38BCEB0D428FF821F99EC672C17DA78CA82818190A332A4A34CC0D8DA11F3ABDCCC4B388E13444AB6E4F3F7EB8B7371E2C135D00DC35DE21CC9E++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.492530568430693
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSH/8pmXflwTfbann:CRsyeBmWfV8ZSXSH/pBnn
                                                                                                                                                                            MD5:BF7900147A827F07120DAF5B5B98734B
                                                                                                                                                                            SHA1:AF92B2F400CDFA17BF6CFA00A84B2B30DC1085C1
                                                                                                                                                                            SHA-256:E0995DE32214F75522586622DDF7F7555EE0733266D7B59603C82EBEE04B07CA
                                                                                                                                                                            SHA-512:B72188F30E381332F5248E03161C411A29D36155586D3F74D3738936A9A5424F832B6697F62D4CCCA1009A2C24341ED99089E975AECE982C2063559F34D34105
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//74EB87A572168350886A4402BAF30706D52251A02D350BB88DFCE57137F9F41ACABBE056EB94FAE308606C845930EADF1B68B396070E96BB86A52C669E11A4D1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):411
                                                                                                                                                                            Entropy (8bit):5.487688196631357
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:pCPR+2cyeBmNEfSU8ZpoXSHrpT+S32YwKO:CRsyeBmWfV8ZSXSHh+S32Ye
                                                                                                                                                                            MD5:9BAAC7F78864EF3593D6102291016028
                                                                                                                                                                            SHA1:347A5AFBF7B14A46ECADE34515F18A8D04BEC100
                                                                                                                                                                            SHA-256:B0D898CA87EDDCC009CF0F28B70E5264236536E7ABDBE2B16EF97A12DD6F66DC
                                                                                                                                                                            SHA-512:FA9FB05A7B188B04656D387486366F5382313FD2DBEE66287FC28D790F0EC3AF13B3D304A6431053BFD02364B8107D455B46F63C6F24570C206CD1D5759DFB2E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _pscoreToast_ = {.. PSCORE_TOAST_DESC_HEADER: "Get to know your Protection Score",.. PSCORE_TOAST_DESC_BODY: "Your protection score helps you monitor your overall digital health and safety.",.. PSCORE_BUTTON_ACCEPT: "Get started",.. PSCORE_BUTTON_DECLINE: "Not now",..}..//83ADBEB9D45332DF7BF514453B957B6917B346DBAA0DAD3454E02359A289C1E9A797B83FFEE21184837400E309739B56228E4EBFB428610B63A367BD37E76904++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):716
                                                                                                                                                                            Entropy (8bit):5.6123995105579825
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfx6v9LuO4biqra6fMocbkLwT5zxjAHo8+9wuRToEwCWHmlva:7e9SlNLiaf4v9KO4zG6fMocWIOHo8+9G
                                                                                                                                                                            MD5:00F4E38B48072F3869B60E0D95C2A9B6
                                                                                                                                                                            SHA1:C8CE5CA8F175008CCBEC78275E757F62FE9C635A
                                                                                                                                                                            SHA-256:C2D22278512E32727CB434EA10F23C86AE9C08CAF0AE4DAB02F02FCB1041BB99
                                                                                                                                                                            SHA-512:64429F44AD0594E529C1C4CE9FFB87981790E67BAAF4CA3E704FE13C2BAE720E602E9ED2D74F3E9664A91EC6B3C1524070137732798EB8B4E830996379C3C16D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verze",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Prohl..en. o ochran. osobn.ch .daj.",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Hotovo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//7915940C39986F4880E6A2FBC9737543635F5A1D110ED6E3AFFDAFAB149C5AFF1703FFC9466951316626F1FBB58178AEBD100D0078DABFC21D0714D0CEEA119F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):728
                                                                                                                                                                            Entropy (8bit):5.552900854514872
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4biUvzbkLwT5zxjAHo8wN9wuRTo6NHMxracRckCdXt:7e9SlNLiafLYFv9KO4Z7WIOHo8wN9ZR/
                                                                                                                                                                            MD5:B2C903C076A41A1737DB816018633A98
                                                                                                                                                                            SHA1:FAD0008D1C2D4713239C3D9058685919F656B7AD
                                                                                                                                                                            SHA-256:F525F6EAF3880731B179D85B090C0632DA0D913FC84E5E3F98071AF276259F55
                                                                                                                                                                            SHA-512:95283B3B641A234A122386A6E7D1D8358FD5AC67F1F72262E53B028A5927B12EAF501A2D4E4B45A14014D96CAE69C0E514540CEA80686F1696901E609E14E805
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "meddelelse om beskyttelse af personlige oplysninger",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "F.rdig",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//514C43E98B794D2AC98CC2A39D1794688A93B8FE872BF50CB063364579F1BEA8C13AEB945A186AC919AC0B33B114C4CDF8877E143AD3B5EDF237023A807AE010++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):695
                                                                                                                                                                            Entropy (8bit):5.549081746702864
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4bi+p3ibkLwT5zxjAHo8+N9wuRToEKQw/Fht:7e9SlNLiafLYFv9KO4pSWIOHo8+N9ZRQ
                                                                                                                                                                            MD5:D758E0A6DA482AE0EEB46E0B8A65C9CD
                                                                                                                                                                            SHA1:7945EA60F5AFC84819283037B2FF493CB8224C5E
                                                                                                                                                                            SHA-256:14F8DB188A0130B264D3A34D0ADD757FD1BE3C5A5E02E581BC0A9D578F736B87
                                                                                                                                                                            SHA-512:E93EB661D24C40DD2375B521B256EE9F3CAE01868E261B2F4ECA39CF8BE37C7C0120097DAA365B8F5503D0388FA70E8E26E1F795E27E0BA903BC5444FEF2E55E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Datenschutzhinweise",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Fertig",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//9F9083EA4FDED455F3A23B016952128F280E9BB91D2498BDFC250400DD82FD928136390AEA869B7A1C014FE3C0760121E9800361A5837B39456C1EDC9746BEF2++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):750
                                                                                                                                                                            Entropy (8bit):5.77117399690753
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kft6v9LuO4bi7XKfRWkGmbkLwT5zxjAHo8JP9wuRTol6VFB:7e9SlNLiafEv9KO4mXCWkHWIOHo8JP9t
                                                                                                                                                                            MD5:1C8FFEDEC34AB60D998C996AC7D55462
                                                                                                                                                                            SHA1:58B78A462590B78A421024E70D4CF89434AA7BC1
                                                                                                                                                                            SHA-256:CBCB9411E7947D6483DF5E05D967C9531AAAA0CA3F233E86994247818540CA5E
                                                                                                                                                                            SHA-512:83A500DDD5064EC74808E28A1544862D47FA42188E0AD57B22E0241529147261DA4AF60017EFF000ADBF88E307A6FA56C78963D73AC9A6B2536E2FD2B9D81D56
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "......",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "...... ............ .... .........",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: ".....",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//D7F2DA34F1B7920CDF501DA892A6EF4E0F0482D5B374A1842AA59B4D81D84459C21E6F05926E192B86431EBB5037EB33BDA11B0E22308710E9627D7E7BBDD102++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):688
                                                                                                                                                                            Entropy (8bit):5.487912643529434
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4biqkCbkLwT5zxjmT9wuRTo/upmkI2uDiSRgC:7e9SlNLiafLYFv9KO4zkCWIoT9ZRRIk8
                                                                                                                                                                            MD5:CC46B4069EB88FCA4183A1802345E488
                                                                                                                                                                            SHA1:06D6CABDCD0E67EBE402C81E12963AA00E04E799
                                                                                                                                                                            SHA-256:ADF2EC9276CD96BAA46E217DCE9586664C7DFFA22986B26596AC985D3E0C3903
                                                                                                                                                                            SHA-512:1DD44483C0ACF7442FE1DAADF0FD3256C1099EBF63265984CEC610F8811CEAE867A1081D8BB8B9B801E08BDE0E8D7E265BA4A36536B0E47FC000E262F23B8848
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Privacy Notice",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Done",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//93ECAFC6B6FA905461032E6E8DB4729D2263C0306E689F6F2ED8EBDE9DEEB34B003A93CD10F9DA8B1526F7017FC0F77DFDA6CAA0F0FEE67BE1F16FE012A4EE93++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):700
                                                                                                                                                                            Entropy (8bit):5.5223212774827966
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfri6v9LuO4bicmuXnbkLwT5zxjcglP9wuRTo2XZwfIuN1gC:7e9SlNLiafrFv9KO40AnWIqgV9ZRFQf
                                                                                                                                                                            MD5:54A4EB2032797DD5698E222029700740
                                                                                                                                                                            SHA1:2F7E07CEB0295F3239CE8F12E8A9D40277CDD301
                                                                                                                                                                            SHA-256:30055D95C0B902C93AA58EDB2743B19D928212C2F7549148E79EFAA99E263BF9
                                                                                                                                                                            SHA-512:C05E874A388172D7CD8921F4C1F9D61AC8F03D0EB53EC4CDB0ECB530461264A948560B949FE6416BEA2077440AA44F0B60F0BB0C19A986F042433E2C141CE8C6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versi.n",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Aviso de Privacidad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Aceptar",.. DONE: "Listo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//D637B12E35A4ABAF510C98358FC89098EE8C5F537636E86A2E74A59998CBCCEADD062E0D121A282C7F190C2006C9FEF1A0F154606AF95776592B825C8C802D02++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):700
                                                                                                                                                                            Entropy (8bit):5.537604554770778
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfri6v9LuO4bicmuXnbkLwT5zxjcglP9wuRTo6mVa4V9ncmIv:7e9SlNLiafrFv9KO40AnWIqgV9ZR1QfA
                                                                                                                                                                            MD5:AB2324AA7C6A311DC97B36ADA22046CF
                                                                                                                                                                            SHA1:5932FD81A2126A13F7C03910E68744C7F41DE394
                                                                                                                                                                            SHA-256:A7D4654BAE3D149D345A887A7892962793D061C9E755F251A7D19C2F564B939B
                                                                                                                                                                            SHA-512:E538DACA1AED4E6B3273DD1388B7A0FA576CD3ABDF156DCF6C3D816F14B7516711724C77E1C98E2B672981E32558CB7DFE4E4850A634F6C021BFE84BEF1EC267
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versi.n",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Aviso de Privacidad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Aceptar",.. DONE: "Listo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//1496EF941B55F4BF4FF8C580A2561563C6BC322E226844D8B8F8BACF0FBFDA7F6BA401BFB844DE187768CB4BE50BA3807F79D92D3D499CA70EB86A09479E101D++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):694
                                                                                                                                                                            Entropy (8bit):5.5173328903737
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfft6v9LuO4biO6EGbkLwT5zxjAHo88WN9wuRTo8M9DEXW+A29dC:7e9SlNLiafsv9KO43GWIOHo8Z9ZRnS+Q
                                                                                                                                                                            MD5:2EFAA2FE73F61AAA9575F06A7EE25AAA
                                                                                                                                                                            SHA1:28DB2864BC91CFEC0F615800C7C48D0954F8DE61
                                                                                                                                                                            SHA-256:3D65ACAD9615F07267279B3C6EF547C033D37B1F55E9F393BA5F07149BF158ED
                                                                                                                                                                            SHA-512:57D8821F7C5EFA9B630E3CB0A9CFB51E0A1BC81D8FBCECB0595FA2373B3B8AC488717516EDBE4DF07E83D372E73341BD04A3907745D7AB5C08100FE9141B5E67
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versio",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "tietosuojaselosteen",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Valmis",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//592438C477D7D5A0FCDE0A4ABEEC1E61160F3ADB96ED593D2336CB7F85A5D7ED20530ED0297802AE44966CA63AEC0B0D86E87CCF49CB09DA32283990C5157737++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):710
                                                                                                                                                                            Entropy (8bit):5.571075904252609
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4bieQdbkLwT5zxjAHo8g9wuRToHcONXKvL+u9vFJ:7e9SlNLiafLYFv9KO4wdWIOHo8g9ZR2Y
                                                                                                                                                                            MD5:B1FEF06E6DB7C7840355CFDC9E66DFA9
                                                                                                                                                                            SHA1:1A72F5525215F467F2687052C1C107143BFBC497
                                                                                                                                                                            SHA-256:CA51CECD55303BF09C0F9E0E8285419EED57BB2E457E906FDC06763F1AABE64A
                                                                                                                                                                            SHA-512:0D3A8FC6D51795EBD7116CF30FE7371A01ABAC64D898045EA8BF1E22C975E2E805B9ABF2B51BCD9B12A10CC56941320869E63A818DBAEAA72764010251757171
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "d.claration de confidentialit.",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Termin.",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//E31462AD7B349988780C04B0BC7C8C4421A8A65C2B0267E5BA72FC3F8BB7278C1889AB97283D655440681525FC18608C9BF44C79B9E6B01A384AB197AD90FD4C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):710
                                                                                                                                                                            Entropy (8bit):5.544187033409281
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4bieQdbkLwT5zxjAHo8g9wuRTompOE6pzxcgRg:7e9SlNLiafLYFv9KO4wdWIOHo8g9ZRHN
                                                                                                                                                                            MD5:81FF80E529C769AECE9D98592D14A500
                                                                                                                                                                            SHA1:88D9EC34A3852BB8577FDC4ED89AD71A79862F5C
                                                                                                                                                                            SHA-256:98DDF02B185AC2036F8EBBB6ADF9C7B4FA14FC8CA9FBD19B7FFBFEA3770977F4
                                                                                                                                                                            SHA-512:24C932AD5D51E1B014E8BBB5371104884EC3A20530F8D6653F28D6F52F2571A2ACDF70D803EF12FA7D974DD3907632676F0BEBA0CB679D46E46D3AB7B9B3CCE7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "d.claration de confidentialit.",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Termin.",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//6272E90B87E22993E4A9C7AFBD1EA5F6E826D3D603124F3F6DA42CB6FD6A7CA04857CE3220935E918503D17C26ED9CE2AD48B2A2C83030EBCF9BE923DD91B71E++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):703
                                                                                                                                                                            Entropy (8bit):5.5270598050887205
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfv66v9LuO4biaBzcbkLwT5zxjHT9wuRTo4jRF4zOAkE4XG0:7e9SlNLiaflv9KO43BoWIVT9ZR774zhK
                                                                                                                                                                            MD5:7AAE3B6206C930CD459C11C26F120447
                                                                                                                                                                            SHA1:9B5AE66FBDE3B0E7AD58C1D69A7DAF40AACEDC67
                                                                                                                                                                            SHA-256:8DCD9C2FB5873BB4F522C9E8209A0CD93242C1B1B47EC53166E2E03355668E1D
                                                                                                                                                                            SHA-512:47977AC2A48626E4500E7E8A84E9843FF2C7CF5CC403AC58629B13D0DFA288BE320A48436332D0AC2FEF97D7959F14BE2DDFBB50FA35516C03070E56A694DDA3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verzija",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Obavijest o privatnosti",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "U redu",.. DONE: "Gotovo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//C5921FB8FE54F0C9BADA85486599B32A165D30DEEA2DDBC8609E4045DAA88AD032F6AB1D073C3AEC92DB86343CB0733C39A62CA3F84D756E6E086481CE8F7AAF++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):699
                                                                                                                                                                            Entropy (8bit):5.578115457562142
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfQdU6v9LuO4bihIHmdcbkLwT5zxjAHo8Kwv9wuRToXaaMM:7e9SlNLiafQd7v9KO4k6ocWIOHo8Kwvw
                                                                                                                                                                            MD5:BEB5960C719B090AA684968F630B674F
                                                                                                                                                                            SHA1:30F3214BFE12A27A84BDC14446F4F57AF96E46B9
                                                                                                                                                                            SHA-256:3851B97C8DBCFE1A9E85AB1B712E3F4B8388BFD7EC665211C83D66A59C5A8772
                                                                                                                                                                            SHA-512:33E3874AF7AD6186532F1B5EC90156287C3D73837183EE4934D7919AA8A43145DFC6413840782E759E8B65211673AE3A8794DA424EC9B565875CEA709D6AD17F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verzi.",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Adatv.delmi k.zlem.ny",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "K.sz",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//0D63EE19641986D9D825A8C5134A9CE24F11402D1E1B0E33B2454ACB50E4A62EF5E0C8E59D2ABEA7BF41C597CE801D9CE9A00D9E4A4FFA823C7789863F9BE63C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):697
                                                                                                                                                                            Entropy (8bit):5.505876168763784
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfy6v9LuO4biNp7mbkLwT5zxjm79wuRToSj0hWSWzpp+8:7e9SlNLiafVv9KO4apKWIo79ZRXPzpg8
                                                                                                                                                                            MD5:A14208DB73B39365C4D6C838776981D9
                                                                                                                                                                            SHA1:FEB20B19EF9C58C6CC10914A9E139ECC617D91A1
                                                                                                                                                                            SHA-256:E13248A02CC9BF468A097DBAFF0BEED57176284BD10E431E4005C525B91C8618
                                                                                                                                                                            SHA-512:53A3E81DB1AD91A64D281AE089C8AB4526873D7A1EBBA27C93146320CB132160EF7441DDECFC715C2F28F5901E74E9B1EC02116C247C287458AE4F7DD5899373
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versione",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Notifica sulla Privacy",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Fine",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//9D53CF31538C018BAE126DDA881FFD6C157AD09EBFB4BDBA389AED758E33FCE052A61F8F331AEC363DAE8E19DA957FBD41B0D08A44EBDA2D4CDEC8D669091087++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):808
                                                                                                                                                                            Entropy (8bit):5.7409373263357235
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7e9fLdo5ijdfA6Dlv9o4A2AWIOHo8UHv9ZR6Ued3:K9fLdICdfA49XLAWIOfUHFKdd3
                                                                                                                                                                            MD5:28B7739A421835EB9CD88B6013D4E689
                                                                                                                                                                            SHA1:DCF2CCD130415AC7F2C45E4495AAFC5EC976B058
                                                                                                                                                                            SHA-256:0C69D07D25EADA8203C4207A619F31992E1EC223D9550E645E2780C4BF3C29FA
                                                                                                                                                                            SHA-512:501684FDD4B4569C5BFB7A4F7E4C32B7FD8272E2B4961958F64B03E6B74D5767E19E17133F43A3CE5ED4DD932DE509C96C2D57F53B8C60318F03AE764A86EE0E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "..... .........",.. PRODUCT_NAME_LIVE: "..... ......... ...",.. PRODUCT_NAME_TRADEMARKED: "...... .........",.. VERSION: ".....",.. WEBADVISOR: ".........",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "........",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "..",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//26438DF7DDD1B7091ED260C5751D4A077CA382594D057744E7A18123A105135A5502DE2EC8D32B83E5301B99F1BF5EEC74B00DEF5B1B21DBF4CDBD9CC6109029++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):742
                                                                                                                                                                            Entropy (8bit):5.82878368970307
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSd6ds63i7R6ikfV/i6v9kc4biyGbkLwT5zxjsGiFW9wuRToa+g/N0u+Ho:7e9Ed13isnfVtv9kc4sWIViQ9ZR2gl4I
                                                                                                                                                                            MD5:53F240755A3E1938272249CCF8BD05D7
                                                                                                                                                                            SHA1:770F628BB772CC9461CF3D234E061EA4D810B119
                                                                                                                                                                            SHA-256:51DCD424DE086E10A9591AB85F830A8F466108F9DBBAA4B47A6DBAFB04BF2986
                                                                                                                                                                            SHA-512:54E1024EFC0B118C78C2406FB7D92E9794A241CBDE0D122957CC2C0C9628B443EE3EB7BEB916C83AD6BA7E8A706BFC8B7A78513119902A867A3728938EDE2A50
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee ......",.. PRODUCT_NAME_LIVE: "McAfee ...... ...",.. PRODUCT_NAME_TRADEMARKED: "McAfee. ......",.. VERSION: "..",.. WEBADVISOR: "......",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: ".. .. ....",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "..",.. DONE: "..",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//277BE604E32720DCF4BFF19AAA4CE10DDD8BABD440063659C78111528AE8B9281D266930182575EBEEBD256C8A040C4507A85B56B99FD882D9F3380D6FDEEA77++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):696
                                                                                                                                                                            Entropy (8bit):5.566757432761514
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kf3Hi6v9LuO4biqyNLMBHbkLwT5zxjmf9wuRToQMLVXQQgAe:7e9SlNLiaf3Fv9KO4zyNsHWIof9ZRtMA
                                                                                                                                                                            MD5:13FAE2BC4589EEB043806433697F4963
                                                                                                                                                                            SHA1:3D8CFA01762AEE740AA79236BADF9377275C8056
                                                                                                                                                                            SHA-256:F566A0C874B6497D4062F50ED554E5B997E4802E3B38AE70F59ED5787E39ACE9
                                                                                                                                                                            SHA-512:0A9DA7FA70D04D7AB53E4B7965EE8B6985BA1B2F6B2BACDFBEA92958ADAED25DC469BF6CA81B17BB75F53D3F5E39EFC3828984CC2346D1AFA6E6DAD14F364025
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versjon",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Personvernmerknad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Fullf.rt",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//E6C0634EF860473E5E1AC5DB56979665B177B654AF315AE120E64100E5693F76AC7D9890274062266625FE1B3B2BE60A8D8495F7A38F8C8C5EC99648483D6C21++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):746
                                                                                                                                                                            Entropy (8bit):5.619956078029764
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfP6v9LuO4biKGCEnbkLAWB2CT5zxjAHo8CW9AWB2CuRToJI5rcn4:7e9SlNLiafyv9KO4TGCEnWtB26OHo8Cb
                                                                                                                                                                            MD5:92F19DA62297C36C9E535BC5BF8B2F61
                                                                                                                                                                            SHA1:4BACE2C47E227ED1FEA94EF2712745FCC7F17E2D
                                                                                                                                                                            SHA-256:55CA92573C4E375DD2036798B34060BB822CB3B30396806A414539B5BF247474
                                                                                                                                                                            SHA-512:7B8F12E39550B6ED65D50606D4CA8D8D52252D0527FE62538F1653339E3FCD36E16F096391D63A1A0A2FCCA1C210F16D0E79EDC0F66008D3BB0F8F12E20A69A1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Versie",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "privacyverklaring",.. PRIVACY_URL: "https://www.mcafee.com/consumer/nl-nl/policy/legal.html",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Gereed",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/consumer/nl-nl/policy/legal.html",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//85B81632B31DF611B6DB04A1F9D62E994290E36CF52C98D4DBD8811EE052DF144CC11541848F2D1C2C3DB510126DF77205BF71332EE9E5CB31D881E9C857B245++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):709
                                                                                                                                                                            Entropy (8bit):5.575958834672549
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kf6v66v9LuO4bipidGGnbkLwT5zxjmO9wuRTo/xumdtLwnVC7dTN3:7e9SlNLiaf6vtv9KO4oMGGnWIoO9ZRi/
                                                                                                                                                                            MD5:0303083C987D0942CFF17CE9D0027E93
                                                                                                                                                                            SHA1:FF1E0146514A442652002DD534A41046937B5914
                                                                                                                                                                            SHA-256:56188A2ED3326B0860D9CF76D6961CB643FC1A2F93E2FFB4DA2ABC0FF8640116
                                                                                                                                                                            SHA-512:ECC7AB3D3F27CB2383AA8C49F86F6C6BFA1027148997D4F92825D9B730641D214C95C0BE924B71575B1395A61267F34CBA6CF27D13E2F8D9EFDF753E6749C76C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Wersja",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Informacje o ochronie prywatno.ci",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Gotowe",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//2B110267F6341264500B29DC41AFD0C0D54141C5440DF4870008641509E32199642C5F03BF1696B79BA1C750119560BDEC726C2E3E852CCC3A6285FD7890EE61++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):700
                                                                                                                                                                            Entropy (8bit):5.549994684984163
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfqX6v9LuO4bicmHbkLwT5zxjAHo8kf9wuRTo12WFze9jTXEPvOun:7e9SlNLiafBv9KO40HWIOHo8K9ZR2Mt6
                                                                                                                                                                            MD5:801B89861183733EA35C952F78618985
                                                                                                                                                                            SHA1:E32C18AC6CA2B460C09759604CFC012AA030C03C
                                                                                                                                                                            SHA-256:95115CF18EE1E1A4896B08DBA7F24D012FB1B019215F86EC0FCE99141DEA9EFB
                                                                                                                                                                            SHA-512:3E0654E78080E2B6C5FF461F9DC4F85AD29D19754DD46880E80A4208E134CE2D5B6E449F9AC65592DC2BBDC2B7E44234998F0F7700CFA1E0218851FD5EEF5531
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Vers.o",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Aviso de privacidade",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Conclu.do",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//38319A37158F74349C56AE780D2FE1EA74369BCF9BF2139B6E7E1F6356EE6BF27E0781B2EC874623B3ACBC61CBD4F20A336E5563F143AC8483FE50230576700A++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):700
                                                                                                                                                                            Entropy (8bit):5.5619311609747175
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfqX6v9LuO4biHfHbkLwT5zxjmkf9wuRToePiIUngpgph8kWhuGCs:7e9SlNLiafBv9KO4ofHWIoK9ZR1BUkvt
                                                                                                                                                                            MD5:0826E1B34CD2718A14E67DB7471FEFF8
                                                                                                                                                                            SHA1:466CF995CD7E7673DF269E4DA917833DECFDEAEF
                                                                                                                                                                            SHA-256:E84BDF8D70A4D9032B2ECD3B2920DFA245E4420A1A05D2681A661D358D6804BB
                                                                                                                                                                            SHA-512:041E3F2164BA3C67A4F306855B59AF7BC516AFCEADD315FFE8E28A573CF2FE2DFD1B8F62A2C509ED85D9D24D95D56EEEB7D22D10A5CA007BF13A24F069089031
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Vers.o",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "aviso de privacidade",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Conclu.do",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//62715013ADB65289BD1425F49A9D44B5CF85BB826081DA7BECE9C3AE4217243A475EC1084D7F31910504181A52A7F7B35DA37012AB7F3002AE77CF8DF6F40CC2++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):751
                                                                                                                                                                            Entropy (8bit):5.755930371819692
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kf96v9LuO4bi4epiXbkLwT5zxjhKgE9wuRTowy3NvVknWaZpFkWc:7e9SlNLiafUv9KO4sWWISt9ZRmvVknP6
                                                                                                                                                                            MD5:CB17FD8DACE0C83B800F99F280D52A63
                                                                                                                                                                            SHA1:337B214690529E33BA2294A73E957F6D608788B0
                                                                                                                                                                            SHA-256:04271C792B07D7C0AA35385B55D51D3CD95398588C2F45D934775E669BB183AA
                                                                                                                                                                            SHA-512:6C47919977A192326E14B13C58CBF056901B12CC03B4C22B15D299E0D7538F49C21873E0A744E77924492468EA4F7F42FC42DBA610B24872DDEA397AE4539CD8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "......",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "........... . ..................",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "..",.. DONE: "......",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//88620717E9EE799EB8AA7F2E1760C2014F35B651171979FE060EC65AA5F267F05ADEDAC3569FF2A423984079CA92354D45A0F0554C8443802E3B39E48FEC628D++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):719
                                                                                                                                                                            Entropy (8bit):5.6102161711105865
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfa6v9LuO4biIAbkLwT5zxjAHo8+9wuRToS+Y4nU:7e9SlNLiafNv9KO4uWIOHo8+9ZR8Y4nU
                                                                                                                                                                            MD5:54082BF3A6B20F715D94808EF1951E71
                                                                                                                                                                            SHA1:B338216AA1F573D6F3EE14D26A514C5B9741C3EF
                                                                                                                                                                            SHA-256:C291BC36DF5BED83B96AC1A20B18B1B26A50035BF78B392A87A8205AC3EF169E
                                                                                                                                                                            SHA-512:126630161BD3266CAF11661A20AF0662EAE3263CA0D489CDF1B03796F2C732BABD865A37AE7B143ABD8EFA6AE1CFDD928710F33008058D22E8C153EFD8AF39E6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verzia",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Vyhl.senie o pou..van. osobn.ch .dajov",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "OK",.. DONE: "Hotovo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//5624C53BCE8EA93E7C318B6470C5FD2BEA3CDF9448B5D8D70C5A88356E4684C1840F2A24BACB9BB5EC460482E3A6AD71B85856879DC16C66C82BC35A4E3EF13B++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):706
                                                                                                                                                                            Entropy (8bit):5.554327092493012
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfv66v9LuO4biagkcbkLwT5zxjHT9wuRToojRkm5e4eRgiX20qdSh:7e9SlNLiaflv9KO4cjWIVT9ZRnfeBg0X
                                                                                                                                                                            MD5:0C9AFEA80408DB59A843AAFA6C0BC23C
                                                                                                                                                                            SHA1:D9BECCE27AC0CC8ABD9DABB30EE7B23618CA7E7F
                                                                                                                                                                            SHA-256:F3ED198C41D3CDA9E9C973CE8C69650A2D66F8A496822AAC76FBBD4B23B779F9
                                                                                                                                                                            SHA-512:34C1977CEABEDA559AAD30E9162D3C4DEBCDD852EB3B79EF137739430479CDD0B6054D56973EECAA13B184596C42CB987DA26ED37D34DF34B7E7C8AF4F35D7CB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Verzija",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Obave.tenje o privatnosti",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "U redu",.. DONE: "Gotovo",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//1A84BCFAB89E78FD65597DBB6DEDC6ECA87B05E1F9B47ABDC62D1AD910BA86893B1F3895942A45176464D7D9FEC7BACF6A8B07D4191E028305DAD41F83806930++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):690
                                                                                                                                                                            Entropy (8bit):5.513710902007872
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfLYi6v9LuO4bieGbkLwT5zxjmf9wuRTofn0mzpNlBFjhoepkhn:7e9SlNLiafLYFv9KO4JGWIof9ZRcn0c+
                                                                                                                                                                            MD5:F70671A24786782017CD814AC6AC72C1
                                                                                                                                                                            SHA1:26F9AC77B1764AD13371B720A92F3A15158BEE40
                                                                                                                                                                            SHA-256:CD852B915D12B12640D3E5197CEB2D464A1B495CB78A3B6680C3F09EAD0ED91E
                                                                                                                                                                            SHA-512:AB57130DC2E669B486BE710A98AC90F37D0C27970EF2CE12D6F1ED2A544103AAD0FD166373A8D76F2E62B8A506233A4FCB5DBFBCCFFE3B4B85D7259E470C4E9F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "Version",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Sekretesspolicy",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Ok",.. DONE: "Klart",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//F9E40AAC3AB58D47F27C4E63326E01B8315CDD4E1995A9F361D05DD7B20E79F8EBE2F210A12CF91EBE35A4C492EF923C7A37BEBD67F790E5AA02D49BB75EF0EA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):696
                                                                                                                                                                            Entropy (8bit):5.545555209314935
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfT6v9LuO4bij2VbkLwT5zxjAWoN9wuRToq8TMJ81S1oQtZvrgn:7e9SlNLiafGv9KO48QWIuv9ZR3qr
                                                                                                                                                                            MD5:6968161BAA9545B01DDA30AF5FB7A36F
                                                                                                                                                                            SHA1:7E78CE16FE43653B060C217ED37A1CD65C38CD04
                                                                                                                                                                            SHA-256:148E55B8F85C7837B17520E2100AA5C2A8F956FBEACB18E84876F7C12A98C654
                                                                                                                                                                            SHA-512:2B47FD43A6BE7701B6EB24174EEB78251E194EE8764B04F0CF53CB33C063EE08DE6D535C1CD2033FCEBF36309E3797C76139014D4A2EE5773EF076DB6DFF77BD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "S.r.m",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: "Gizlilik Bildirimi",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "Tamam",.. DONE: "Bitti",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//8776C33924D3DE44C8ADF4713EB85340482CAC0087E39DAE7CD3D05592F58E39FD4C4D7E36F383819137D5CFB5EEA1E8CE9717243D9763F93875A3834861584A++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):719
                                                                                                                                                                            Entropy (8bit):5.935688545805366
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSuKxi7s6kfF6v9bgbi5ywbkLwT5zxjtDYv9wuRTopfLfT7XbP7:7e9uui7s/fsv9bg4ywWIv49ZRufLXbz
                                                                                                                                                                            MD5:80C3F7CF329979756A2483C61FDC94E0
                                                                                                                                                                            SHA1:4D789234D75ACF3E6876C742D7E4B2DB660E15A4
                                                                                                                                                                            SHA-256:77888F083FA21B5CFD2EB5CBE5C6407A7421BB04D76F127F49DD5BD426D1C572
                                                                                                                                                                            SHA-512:4C2C012A7D27C2C0DE54B1650D24AB7C909A871CEFF1410D1E2EB3BC9F8783F8928F812813D970AEA92D7989CF669771B7FFA18431A3132510D4CC459204D81A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: ".......",.. PRODUCT_NAME_LIVE: "..........",.. PRODUCT_NAME_TRADEMARKED: ".... ....",.. VERSION: "..",.. WEBADVISOR: "....",.. COMPANY_NAME: "...",.. PRIVACY_NOTICE: "......",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "..",.. DONE: "..",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//F6E98D5300FA7FAC3CDBD26ECC83D725DB0761530427BCE04CAF85A01F83E6368A59F8EE59AAF5009800F25844EFB5700CEED010C18D0F0F99E2C31715A94B21++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):694
                                                                                                                                                                            Entropy (8bit):5.6689804706681635
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7ekSSlN95i5kfF6v9LuO4biP3emebkLwT5zxjgDYv9wuRToar0jJ5H91/f:7e9SlNLiafsv9KO4d1WIG49ZRhr0jP/f
                                                                                                                                                                            MD5:5BC62AD32578785B4E38CC765AD01B86
                                                                                                                                                                            SHA1:388C382BEDA295EDAA6ED522EFABF3F4F917976C
                                                                                                                                                                            SHA-256:888CB78E02C9F494C4C43B93D35379125379F52DD5EFCB9EF93B985142A2A710
                                                                                                                                                                            SHA-512:4DD4107512C06F65816C0926FA7E35BE8DEF88923C5EC14F3FEF175D579163BF1B8DFD73B3921E684F038B82B6D45D1BF43705F0BAAC266F3FF0EFAF33CAE0C5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrShared_ = {.. PRODUCT_NAME: "McAfee WebAdvisor",.. PRODUCT_NAME_LIVE: "McAfee WebAdvisor Live",.. PRODUCT_NAME_TRADEMARKED: "McAfee. WebAdvisor",.. VERSION: "..",.. WEBADVISOR: "WebAdvisor",.. COMPANY_NAME: "McAfee",.. PRIVACY_NOTICE: ".....",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. CHROME: "Chrome",.. FIREFOX: "Firefox",.. IE: "Internet Explorer",.. OK: "..",.. DONE: "..",.. LICENSE_AGREEMENT_URL: "https://www.mcafee.com/legal",.. COMPANY_NAME_TRADEMARKED: "McAfee."..}..//3BFEE6F1AAA6203888EACD212AA6EA71B5BEE9F5E25B2EBFBF7067F80AE1F91149DA1C89745A5D6C58244D823622DBDAD484EB12F3CCDC2A6A8C7775DA7229D1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3828
                                                                                                                                                                            Entropy (8bit):5.649207863349993
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:ElmtVPut9muF9guJVDWtfDUEWP4gU4zTA46AOifPY:ELt9mG9gMVDMfD7VgUeb6Z9
                                                                                                                                                                            MD5:1B10868D37908BD86B7016A29B5F25EE
                                                                                                                                                                            SHA1:C2E4775797236C4D6ADA09ACCA7DF1396A253C6B
                                                                                                                                                                            SHA-256:243269C9EE1A0B2214FBCC4D8B8CC60B19C49DE2391657D61566D94B633DBC8E
                                                                                                                                                                            SHA-512:17790A9419F8C60D7827E7EA0F6F6C2342262A5A0E329FB7646BF7F194C29122A2BF6851F8F3EFDD8B4D592F02AE7A9417C837D0CBDD9AAD490C3016D4B19D99
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "M.te z.jem o je.t. lep.. zabezpe.en. vyhled.v.n.?",.. TOAST_VARIANT_CHECKLIST: "Ano, chci po restartov.n. zapnout slu.bu Bezpe.n. hled.n..",.. TOAST_VARIANT_BUTTON: "Hotovo",.. TOAST_VARIANT_BUTTON_FREE: "Hledat se zabezpe.en.m . ZDARMA",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Hledat bez ochrany",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Nechci bezplatnou ochranu",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Va.e webov. ochrana nen. zcela nastavena . aktivujte ji zdarma",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Dokon.ete nastaven. bezplatn.ho proch.zen. internetu McAfee",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Chra.te sv. osobn. .daje",.. TOAST_VARIANT_1_INFO: "Proch.zejte web a vyhled.vejte s v.dom.m, .e va.e osobn. .daje jsou chr.n.ny. .ekneme v.m, kter. str.nky jsou bezpe.n. . a kter. mohou b.t nebezpe.n..",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3597
                                                                                                                                                                            Entropy (8bit):5.38823145550783
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:w/A9Lqnt+lLcLvjcU7s1KWfENcDh22BqOQiixQ:etCLovj5AIWfENkBqBy
                                                                                                                                                                            MD5:DFC68793AEBF3814FFC8951F1C9788C6
                                                                                                                                                                            SHA1:E34F45A30A65D8C82389F8BB9E5CE0F9D255DBFD
                                                                                                                                                                            SHA-256:1278F116A2F0E427DFCE371703EDC0E43D866FA6FD05524E6C1FD621B5D13475
                                                                                                                                                                            SHA-512:0A97336896050C8A613F4BBB5623E59D9D39734E4AEF008B6A5A01661D317DA57C6F87012E46225A1581D31F833B181EC7D6840DD3B4038AABC566096843C242
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Vil du tilf.je ekstra s.gebeskyttelse?",.. TOAST_VARIANT_CHECKLIST: "Ja, aktiv.r sikker s.gning, n.r jeg har genstartet browseren.",.. TOAST_VARIANT_BUTTON: "F.rdig",.. TOAST_VARIANT_BUTTON_FREE: "S.g p. sikker vis . GRATIS",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "S.g uden sikkerhed",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Jeg vil ikke have gratis beskyttelse",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Din webbeskyttelse er ikke fuldt konfigureret . aktiver den gratis",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "G.r konfigurationen af din gratis McAfee-webbeskyttelse f.rdig",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Beskyt dine personlige oplysninger",.. TOAST_VARIANT_1_INFO: "Gennemse og s.g, vel vidende at dine personlige oplysninger er beskyttet. Vi fort.ller dig, hvilke websteder der er sikre og hvilke der kan v.re farlige.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Fjern bekymringen fra
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3722
                                                                                                                                                                            Entropy (8bit):5.3472044793355
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:MO3e8qGlKtiKL/7vdAmPegpo1fkJFfVQz4bLECx8OoEHHyg:xdqGYtj/7vdAjgpSfkJBVQ8bI6Bo6Hyg
                                                                                                                                                                            MD5:0A2ED30C3EECB4CF37765E646CACC6CB
                                                                                                                                                                            SHA1:A12B346BCB761123CD56F7E5C2CCB89EFDEF06CE
                                                                                                                                                                            SHA-256:CC221A68C93F13C53558D2055BDA3FAB80D10F40C90EE51336540032CDB4A260
                                                                                                                                                                            SHA-512:AD7900FEDC2769C1FC137042F5857DA305C8AC5BB13B0C7B2D067B82FA45B2C5B7FE013A26DB4BFE668F947AE2D17309CB94113C955C1DA64C3D16538F5AD1A4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "M.chten Sie zus.tzlichen Schutz bei Online-Suchen?",.. TOAST_VARIANT_CHECKLIST: "Ja, die sichere Suche nach dem Neustart meines Browsers aktivieren.",.. TOAST_VARIANT_BUTTON: "Fertig",.. TOAST_VARIANT_BUTTON_FREE: "Sicher suchen . KOSTENLOS",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Ungesch.tzt suchen",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Ich m.chte keinen kostenlosen Schutz",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Ihr Web-Schutz ist nicht vollst.ndig eingerichtet . jetzt kostenlos aktivieren",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Schlie.en Sie die Einrichtung des kostenlosen McAfee-Web-Schutzes ab",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Sch.tzen Sie Ihre pers.nlichen Daten",.. TOAST_VARIANT_1_INFO: "Surfen und suchen Sie mit der beruhigenden Gewissheit, dass Ihre Daten sicher sind. Wir zeigen Ihnen, welche Websites sicher sind . und welche nicht.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_T
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6107
                                                                                                                                                                            Entropy (8bit):5.0275663208917445
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:3/3ftrYEERsgXRx/+P5BLE27ww5X4e0TSS8bW0u2Ml4:33trhEfXT+P5lrMSS8bEbq
                                                                                                                                                                            MD5:E371C4E4181BB6C48BA1059BAF7F825E
                                                                                                                                                                            SHA1:B65EBD4853A55203D7B2CB4427D0B0E060B0A0EF
                                                                                                                                                                            SHA-256:4E0049A9B211F6E189F266BBB0AA2A535EF1B524A5077BE437C8ECEC67AA2A1D
                                                                                                                                                                            SHA-512:9EB8139A47A6C2D3662ECEE5875E9B0321D08C565D9D607E90BF5DEB2D890ABAE9C87E3141288D6697E1D69FAAA0D786A8347BA11129444473DC6C6CAFD5A873
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "...... .. .......... ........ ......... ..........;",.. TOAST_VARIANT_CHECKLIST: "..., .. ............. . ....... ......... .... ... ............ ... ............ ...........",.. TOAST_VARIANT_BUTTON: ".....",.. TOAST_VARIANT_BUTTON_FREE: "....... ......... . ......",.. TOAST_VARIANT_BUTTON_UNPROTECTED: ".. ....... .........",.. TOAST_VARIANT_BUTTON_NOT_WANT: "... .... ...... .........",.. TOAST_VARIANT_TITLE_NOT_SETUP: ". ........... ... ......... ... ..... ...... ........................ ... .......",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "........... .. ....... ... ...... .......... Web ... .. McAfee",.. // Toast varia
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3367
                                                                                                                                                                            Entropy (8bit):5.339447864418538
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:KDGTsDGspn5vrfL5mwfPUpGRtBRTyCM0RL+K8KfEKxKxUT4TyALYrkyL0LEtTC6m:XIisJlwrmtBJZM4d9AY4GbJpMlD+R6
                                                                                                                                                                            MD5:D65E21982BE527D20993CD94770C365E
                                                                                                                                                                            SHA1:DCAE25BB116F7E57C2D417D3E6D7D023FEA5C609
                                                                                                                                                                            SHA-256:F8A20862376EB665A3552163ACE561D8FFF208FE3873EA1BE074F8A8416CD9FE
                                                                                                                                                                            SHA-512:F2A00E42497F571643695246417A0A6E115112FD9E04743E9DE7F66F5C73EF17816AC788F6B4580E7F702F234236E499F36E8BAF1DFBCBA00FB75E399D1FFE57
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Would you like to add extra search protection?",.. TOAST_VARIANT_CHECKLIST: "Yes, turn on Secure Search after I restart my browser.",.. TOAST_VARIANT_BUTTON: "Done",.. TOAST_VARIANT_BUTTON_FREE: "Search securely . FREE",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Search unprotected",.. TOAST_VARIANT_BUTTON_NOT_WANT: "I don.t want free protection",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Your web protection isn.t fully setup.enable it for free",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Finish setting up your free McAfee web protection",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Safeguard your personal info",.. TOAST_VARIANT_1_INFO: "Browse and search with confidence knowing your personal info is protected. We.ll tell you which sites are safe &mdash; and which could be dangerous.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Take the worry out of the web",.. TOAST_VARIANT_2_INFO: "Browse worry-free k
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3632
                                                                                                                                                                            Entropy (8bit):5.3655626722955745
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Ks358rLYfTJnrXJm8Up0RtjRoZgeCYSL+VKDKNuKA5K7oUlYZxBOGsdUXc+Kno3U:vRg0tjy4BONb9GEjiGWPc+BIT
                                                                                                                                                                            MD5:7086DB58BEF90E2485362A687B1193E2
                                                                                                                                                                            SHA1:40F7EF9DF1B038E21C2407B2700EECCC770EC715
                                                                                                                                                                            SHA-256:73E3F3A389CB6D68CB8364E22C7ADC14D4B799E935764C0C704D27F3ADB76899
                                                                                                                                                                            SHA-512:A3EF7BC7CC94B67999A85C7127F4E08F53AE3A07D90762DD050E6A2B39670E0EBA32578C3B08068E15E341F630E5E802E63B03AE6AD270B08F79D7003CCE6E0E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: ".Quieres a.adir protecci.n extra en tus b.squedas?",.. TOAST_VARIANT_CHECKLIST: "S., activar la b.squeda segura despu.s de reiniciar mi navegador.",.. TOAST_VARIANT_BUTTON: "Listo",.. TOAST_VARIANT_BUTTON_FREE: "Buscar de forma segura GRATIS",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Buscar sin protecci.n",.. TOAST_VARIANT_BUTTON_NOT_WANT: "No quiero protecci.n gratis",.. TOAST_VARIANT_TITLE_NOT_SETUP: "A.n no has terminado de configurar tu protecci.n web: es gratis",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Termina de configurar tu protecci.n web de McAfee gratis",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Protege tu informaci.n personal",.. TOAST_VARIANT_1_INFO: "Navega y busca con confianza sabiendo que tu informaci.n personal est. protegida. Te indicaremos qu. sitios web son seguros y cu.les podr.an ser peligrosos.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Olv.date de los pe
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3652
                                                                                                                                                                            Entropy (8bit):5.368536208302948
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:KHJS5wrLYl0ImbIrXJmfUp0RtjvZgPChBxZSLWKJKDuKlZKIUldZxecemv+G0pPN:QskmV0tjvHhHs4Db+XVpIWYcXBMEuaM
                                                                                                                                                                            MD5:C6C6C0D571E7CB6CC5F59B4FCAE365BF
                                                                                                                                                                            SHA1:F31FB42D5B7A12FE26D2DAECEF38474682A2AC45
                                                                                                                                                                            SHA-256:31DBA508B21F883090D05786870C58B4D9699EA1504A08DD91E7C7DE4C17DAE1
                                                                                                                                                                            SHA-512:185777C5FB3B47873306144B669DC68DBD5DF829E7E1EFF7B26153EFA50C3EAD4216D7241A62F730F7E6D056C9A76F8AB37050A916F5F42937C2235C89EC3E0F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: ".Te gustar.a agregar protecci.n de b.squeda adicional?",.. TOAST_VARIANT_CHECKLIST: "S., activar B.squeda segura despu.s de reiniciar mi navegador.",.. TOAST_VARIANT_BUTTON: "Listo",.. TOAST_VARIANT_BUTTON_FREE: "Busca de forma segura, GRATIS",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Buscar sin protecci.n",.. TOAST_VARIANT_BUTTON_NOT_WANT: "No quiero protecci.n gratuita",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Tu protecci.n web no est. completamente configurada: habil.tala gratis",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Termina de configurar tu protecci.n web gratuita de McAfee",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Protege tu informaci.n personal",.. TOAST_VARIANT_1_INFO: "Navega y busca con confianza sabiendo que tu informaci.n personal est. protegida. Te diremos qu. sitios son seguros y cu.les podr.an ser peligrosos.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Navega por la
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3556
                                                                                                                                                                            Entropy (8bit):5.351456330736935
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:dWem9nFXHGetHHST0of6hMJHL5Y+jMp1t3NQh8G6:shXmetHyYof6hMJHLm+jEt3NSU
                                                                                                                                                                            MD5:3E35952F91E14F643ABF2158AC781B8E
                                                                                                                                                                            SHA1:07BE2380AEA1C0C75FEFF727F0EA433B90D57D75
                                                                                                                                                                            SHA-256:2DEA9DBD87C484B89384B3F3C46020E376674C0CB780B04699682E354A647294
                                                                                                                                                                            SHA-512:82C14CE249BF7ED53A7B052A3D4582AA3823D4C3D605FAB4A588E6929615A92B82E6A3BF3AA27EFBCFFA73B2F94C587CDF47099F22840D6662435A453397937B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Haluatko lis.suojausta hauille?",.. TOAST_VARIANT_CHECKLIST: "Kyll.. Ota suojattu haku k.ytt..n, kun k.ynnist.n selaimen uudelleen.",.. TOAST_VARIANT_BUTTON: "Valmis",.. TOAST_VARIANT_BUTTON_FREE: "Hae suojatusti . MAKSUTTA",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Hae ilman suojausta",.. TOAST_VARIANT_BUTTON_NOT_WANT: "En halua ilmaista suojausta",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Verkkosuojausta ei ole otettu t.ysin k.ytt..n . ota se k.ytt..n maksutta",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Viimeistele McAfeen maksuttoman verkkosuojauksen k.ytt..notto",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Turvaa henkil.kohtaiset tiedot",.. TOAST_VARIANT_1_INFO: "Selaa ja hae huoletta . henkil.kohtaiset tietosi suojataan. Kerromme, mitk. sivustot ovat turvallisia ja miss. voi piill. vaaroja.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Ei huolen h.iv.. verkossa",.. TOAST_VA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3937
                                                                                                                                                                            Entropy (8bit):5.32281826348224
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:a/ScFsBmXt/CuFCNSCAQ9BYYmWJmn9AvwuHAnp/SsQWgXReX:aKOEAt/tFqSpQ9BhrmKYEApKsQA
                                                                                                                                                                            MD5:5E5D7AFF28354B21C5A1E9FF5E5F445F
                                                                                                                                                                            SHA1:1320DE789DBAB278A23B9A220EC6E3021C9DE0E9
                                                                                                                                                                            SHA-256:05F9D8EE834A095D78AEBA4B337DF6E1D2E30930149F6EDC5A4CBCA44DD9CB8F
                                                                                                                                                                            SHA-512:AD3A6168A54ACAD4793A51A0A4B21131994DCC51B3D862E5CFDEB1E38210516A306858BCDB12D55681CB276A68ED3652498E998B1EEF0254C06A4DDB52140A9B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Aimeriez-vous ajouter une protection suppl.mentaire . vos recherches?",.. TOAST_VARIANT_CHECKLIST: "Oui, activez la recherche s.curis.e au red.marrage de mon navigateur.",.. TOAST_VARIANT_BUTTON: "Termin.",.. TOAST_VARIANT_BUTTON_FREE: "Recherche s.curis.e - GRATUIT",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Recherche non prot.g.e",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Je ne veux pas de protection gratuite",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Votre protection Web n'est pas enti.rement configur.e. Activez-la gratuitement.",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Compl.tez la configuration de votre protection Web McAfee gratuite",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Prot.gez vos donn.es personnelles",.. TOAST_VARIANT_1_INFO: "Naviguez et recherchez avec confiance en sachant que vos donn.es personnelles sont . l'abri. Nous vous indiquerons quels sites sont s.rs et ceux qui pr.sentent un danger."
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4024
                                                                                                                                                                            Entropy (8bit):5.3193359368658095
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:b34FUJtSNXfN0SPAuWXhC00ZmnfQR9SujAnV3Jym4b:bQMtkWS4umSmoCgAVab
                                                                                                                                                                            MD5:A1892E90594E3605834BEC1E7931CF1D
                                                                                                                                                                            SHA1:F6098342968B92E3F300BDFA8A723BA6908671FE
                                                                                                                                                                            SHA-256:57D605C9A444A6EE90DC8BEE5D0B33E010E0F259576BFAD4546B09DD8C0AD4F1
                                                                                                                                                                            SHA-512:3E7E10ECC980BC07613B9C4A9B35D4D3C61BD16E00F71D25D8ED996F583EF03EDDB1524CF9A3AC5D88A2BC228197DA70F5293DF7F4780BD494B9C1C0A5E4F580
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Souhaitez-vous ajouter une protection de recherche suppl.mentaire.?",.. TOAST_VARIANT_CHECKLIST: "Oui, activer la recherche s.curis.e apr.s le red.marrage du navigateur",.. TOAST_VARIANT_BUTTON: "Termin.",.. TOAST_VARIANT_BUTTON_FREE: "Rechercher de fa.on s.curis.e . GRATUITEMENT",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Rechercher sans protection",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Je ne souhaite pas de protection gratuite",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Votre protection Web n'est pas totalement configur.e. Activez-la gratuitement",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Terminez la configuration de votre protection Web gratuite McAfee",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Prot.gez vos informations personnelles",.. TOAST_VARIANT_1_INFO: "Naviguez et recherchez en toute confiance en sachant que vos informations personnelles sont prot.g.es. Nous vous indiquerons quels sont les sites s.c
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3635
                                                                                                                                                                            Entropy (8bit):5.451457989016017
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:ajcHGot9qU8FSKd49nVVtx5B9Psk+20fm0F:zBt9z8Fjd493txz/L0fmU
                                                                                                                                                                            MD5:635A8B7F820BB0D938227C1D4EAB0281
                                                                                                                                                                            SHA1:E7C3AEB1FEE9E598DE081EDD47BF0C81C5C9DF82
                                                                                                                                                                            SHA-256:C148F624285950E8B4B1984735624DE878F8BFE122A01954B21F45CBD0804679
                                                                                                                                                                            SHA-512:A7699FA0FBDCD0B17E1F88999E45E01AFCECFE9EAAD973D8F1341A37445B2439D856BF7C1E801AA69DC82D66D36448C3D3BD0DE23E41208D91E175EE711B95D4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: ".elite li dodati dodatnu za.titu pri pretra.ivanju?",.. TOAST_VARIANT_CHECKLIST: "Da, uklju.ite Safe Search nakon .to ponovno pokrenem preglednik.",.. TOAST_VARIANT_BUTTON: "Gotovo",.. TOAST_VARIANT_BUTTON_FREE: "Tra.ite sigurno - BESPLATNO",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Pretra.ivanje neza.ti.eno",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Ne .elim besplatnu za.titu",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Va.a web za.tita nije u potpunosti postavljena - omogu.ite je besplatno",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Zavr.ite postavljanje besplatne McAfee web za.tite",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Za.titite osobne podatke",.. TOAST_VARIANT_1_INFO: "Pregledajte i pretra.ujte s povjerenjem znaju.i da su va.i osobni podaci za.ti.eni. Re.i .emo vam koje su web lokacije sigurne & mdash; a koje bi mogle biti opasne.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Uklonite
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3828
                                                                                                                                                                            Entropy (8bit):5.519316831709829
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:KQpmKkwbL+sDfLlUpxKRtIC0vCGNAgc+LP+K5LK3TRKwJKV54QUQQ99P1s+l2cSl:6QtdTBPqw3Tg/UgbCx+lN4Dg
                                                                                                                                                                            MD5:96E295A9F114204E890862271C63D880
                                                                                                                                                                            SHA1:6878B3AE55F0949F06AC8DF45831CDC551826B24
                                                                                                                                                                            SHA-256:AFCFA1C8DD34E600C3258226C78FADDC260DE7187BECE3F04AA3110615E5459A
                                                                                                                                                                            SHA-512:19F84EE8BBD7D996684496B0B0333987280C0172FDD20A1A7523595DB734A73551A8BFBABBD508B0BA209D0A2AD0081480BCE410FE6C11D15DD23CC618062E3C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Extra keres.si v.delemre is sz.ks.ge van?",.. TOAST_VARIANT_CHECKLIST: "Igen, legyen bekapcsolva a biztons.gos keres.s funkci., miut.n .jraind.tom a b.ng.sz.t.",.. TOAST_VARIANT_BUTTON: "K.sz",.. TOAST_VARIANT_BUTTON_FREE: "Keressen biztons.gosan . INGYEN",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Nem v.dett keres.s",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Nem szeretn.k ingyenes v.delmet",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Webes v.delme nincs teljesen be.ll.tva . kapcsolja be ingyenesen",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Befejezte az ingyenes McAfee webes v.delem be.ll.t.s.t",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Szem.lyes adatok v.delme",.. TOAST_VARIANT_1_INFO: "Magabiztosan b.ng.szhet, hiszen szem.lyes adatai biztons.gban vannak. Megmondjuk, hogy mely oldalak biztons.gosak, .s melyek lehetnek vesz.lyesek.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3548
                                                                                                                                                                            Entropy (8bit):5.225354583301116
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:9xj3zLp7tpe0ddA4Pxt9Qmcnq1qYENfDI/0DEufz3:T17tpe0sQxt9QZ+qHY0xfz3
                                                                                                                                                                            MD5:C699BE946595D5570117C65EFC33D351
                                                                                                                                                                            SHA1:2AD5115FBC1C3B6D21575004BD044F4D3FECBAA3
                                                                                                                                                                            SHA-256:4D56FD1B919C62545A20051E60B3B7CBBD6714948DCAFEFB3A91FF4823B5ADEA
                                                                                                                                                                            SHA-512:EBE4B83924023ADFDB56AD456FD77B119FB1DFBC9FE2171CB4B338AE72425DFD73EBC034F8BE9A9CF95145307BF80170877350EF4C766FA7EEF41BC896642E5D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Vuoi aumentare la protezione delle ricerche?",.. TOAST_VARIANT_CHECKLIST: "S., attiva la ricerca sicura dopo il riavvio del browser.",.. TOAST_VARIANT_BUTTON: "Fine",.. TOAST_VARIANT_BUTTON_FREE: "Ricerca sicura . GRATIS",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Ricerca senza protezione",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Non desidero la protezione gratuita",.. TOAST_VARIANT_TITLE_NOT_SETUP: "La protezione Web non . configurata completamente. Attivala gratis.",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Completa la configurazione di McAfee Web Protection",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Tutela le tue informazioni personali",.. TOAST_VARIANT_1_INFO: "Naviga e cerca senza timore sapendo che le tue informazioni personali sono protette. Ti segnaleremo i siti sicuri e quelli che potrebbero essere pericolosi.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Naviga sul Web in tutta tranquillit.",
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3960
                                                                                                                                                                            Entropy (8bit):6.013797513205256
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:6hHMKEaeQVt4/aWso3rOx4mc2JYtwhnoIZH7ShZ0:YB5ztO57Ox4mJ8Eogmv0
                                                                                                                                                                            MD5:40C99A285789A907E8BEF19FB7B52C28
                                                                                                                                                                            SHA1:91FCBE513966FE10F78BE3D6DD8AA870788D7ECC
                                                                                                                                                                            SHA-256:EC8238149FBDA3CA54C7C2220E992D19347387AFDE2B798062D218754ABFB87A
                                                                                                                                                                            SHA-512:25B20C459978D9F30DA84564038F5FB2497196CA3C50DEC649B71CFAFDD878B95DAACF7934A79A216D7BBA248AD95B6D8F532DC805A3132BEDE8F5C0913ED7C3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "..............",.. TOAST_VARIANT_CHECKLIST: ".................. ...........",.. TOAST_VARIANT_BUTTON: "..",.. TOAST_VARIANT_BUTTON_FREE: "..... - ..",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "..........",.. TOAST_VARIANT_BUTTON_NOT_WANT: ".........",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Web ...................................",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "........ Web ...................",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "............",.. TOAST_VARIANT_1_INFO: "..................................................",.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3783
                                                                                                                                                                            Entropy (8bit):5.9318006777716
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:KwNX9/6gkTR6wtUp7RtlvCI/Lg7KoR/+KNM2KHK4Uq0RxIZr1ZNpiL8s/cCM7R+W:P26Ft8+W/rNIqxmQlbe6qX7
                                                                                                                                                                            MD5:D1F82AA54D8927A5408E7F40A522959A
                                                                                                                                                                            SHA1:C515FF839390EB21E564ECA95F28B0638F1D22AF
                                                                                                                                                                            SHA-256:323724ADD81E31420FFEF259F0D55830A48EDE568829254AB4AC076102A689C4
                                                                                                                                                                            SHA-512:252CF1BDF3890420BA59B56C8FFA9D7CCA6D75304F8E8B8FBDCA82638CFB76AEB6527A9C9D38A526248604D74AD28F84E6DC0952AC97BF34085155F005C2BAE7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: ".. .. ... ........?",.. TOAST_VARIANT_CHECKLIST: "., . ..... .. ... . .. ... .......",.. TOAST_VARIANT_BUTTON: "..",.. TOAST_VARIANT_BUTTON_FREE: "... .. - ..",.. TOAST_VARIANT_BUTTON_UNPROTECTED: ".. .. ..",.. TOAST_VARIANT_BUTTON_NOT_WANT: ".. ... .... ....",.. TOAST_VARIANT_TITLE_NOT_SETUP: ". .. ... .... ...... ... ........",.. TOAST_VARIANT_TITLE_FINISH_SETUP: ".. McAfee . .. ... ......",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: ".. ... ......",.. TOAST_VARIANT_1_INFO: ".. ... .... .... .... ....... ... .... ... . .. .... .......",.. // Toast variant 2 specific.. TOAST_VARIANT_2_T
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3599
                                                                                                                                                                            Entropy (8bit):5.366390217230944
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:wMQx7teYFyZ8K3XdIcJK10kNeso2bMUaMZiBdiPQ:8teYFyZ8K3N9E10kNtoYMUaMZo
                                                                                                                                                                            MD5:B6779C95B817DDA4E330B888D069BF45
                                                                                                                                                                            SHA1:98C7C2F7F92447FB366EFA9AE083204F37466AA8
                                                                                                                                                                            SHA-256:9C1F0ED884D7047FFA694C48DB200939B3692EE1D2BF635DEEE6AFD44CE7AF0D
                                                                                                                                                                            SHA-512:6ADFE8FCB5CF891EC81D88E9087BB88A38F5BD23950B446F48B06766F24AA29A6ACEC9529E37966ECE99C19FA839600A920662B6F4B91FFF935B1A65CCF925F3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Vil du ha ekstra s.kebeskyttelse?",.. TOAST_VARIANT_CHECKLIST: "Ja, sl. p. Sikkert s.k n.r jeg starter nettleseren p. nytt.",.. TOAST_VARIANT_BUTTON: "Ferdig",.. TOAST_VARIANT_BUTTON_FREE: "S.k sikkert . KOSTNADSFRITT",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "S.k uten beskyttelse",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Jeg vil ikke ha kostnadsfri beskyttelse",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Nettbeskyttelsen din er ikke ferdig konfigurert . aktiver den kostnadsfritt",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Konfigurer resten av nettbeskyttelsen din fra McAfee",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Beskytt personopplysningene dine",.. TOAST_VARIANT_1_INFO: "Du kan surfe og s.ke uten bekymringer i visshet om at personopplysningene dine er beskyttet. Vi forteller deg hvilke omr.der som er sikre og hvilke som kan v.re farlige.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Slipp . beky
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3539
                                                                                                                                                                            Entropy (8bit):5.3233739834300255
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:WupCvikhC0tR356VrLrVHgKFteK5/AhK/pxFoD4QkH2:WupCvikbt9AVrLrVHhuk/AhK/pxOD4Qr
                                                                                                                                                                            MD5:3265D24F7B970691AE283AA43AA82D38
                                                                                                                                                                            SHA1:44A6DCD5CDC1850B588854B867EDB3B7A6A9F2DB
                                                                                                                                                                            SHA-256:390661E5979CC2481DDA85BBBBCC35D90C9E4FA5A3DD0F6AB18A7F824237A244
                                                                                                                                                                            SHA-512:18D4C45393F35C584F8C07E7FB023CC55C44C4B65B206DF3872704230D96EFF59B610472692E664A075D77ADDD86EE46CE431300513C1AA0A72ACD04E59E677B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Wilt u aanvullende zoekbescherming toevoegen?",.. TOAST_VARIANT_CHECKLIST: "Ja, schakel Beveiligd zoeken in nadat ik mijn browser opnieuw heb gestart.",.. TOAST_VARIANT_BUTTON: "Gereed",.. TOAST_VARIANT_BUTTON_FREE: "Veilig zoeken . GRATIS",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Onbeschermd zoeken",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Ik wil geen gratis bescherming",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Uw webbescherming is nog niet volledig geconfigureerd. Schakel uw bescherming gratis in.",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Uw gratis McAfee-webbescherming instellen",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Bescherm uw persoonlijke gegevens",.. TOAST_VARIANT_1_INFO: "Browse en zoek vol vertrouwen in de wetenschap dat uw persoonlijke gegevens worden beschermd. We laten u weten welke websites veilig zijn, en welke mogelijk niet.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Zorgeloos browsen",
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3618
                                                                                                                                                                            Entropy (8bit):5.593202969337174
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:QrIqKLAst649Gs63IcBPevJwh8i8iiQlacMrIMXkIxL:QcHtn9/pcBPevJwh8i8iiQlacMcMVF
                                                                                                                                                                            MD5:B2EF550A2B6B891FC4885EDC053196ED
                                                                                                                                                                            SHA1:DCF3E630E1FEEF0F3EBD207FCAA54954C32D3271
                                                                                                                                                                            SHA-256:58BD78EE577D8A7C3DB8B7E4D3FDB88A362F192C1F9230CAA14DECEE5C981663
                                                                                                                                                                            SHA-512:77AD4D35C0D99F0901123E8B8B4E03ED7C35452FC127073ABBCCA625DA6C3017C0513A2C1F11F7F0132C018D423548C6A20212F434B90B346103D9E60532150F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Chcesz zwi.kszy. bezpiecze.stwo wyszukiwania?",.. TOAST_VARIANT_CHECKLIST: "Tak, w..cz Bezpieczne wyszukiwanie po ponownym uruchomieniu przegl.darki.",.. TOAST_VARIANT_BUTTON: "Gotowe",.. TOAST_VARIANT_BUTTON_FREE: "Wyszukuj bezpiecznie . BEZP.ATNIE",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Wyszukuj bez ochrony",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Nie chc. bezp.atnej ochrony",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Twoja ochrona w sieci Web nie jest do ko.ca skonfigurowana . w..cz j. bezp.atnie",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Uko.cz konfiguracj. bezp.atnej ochrony sieciowej McAfee",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Chro. swoje dane osobowe",.. TOAST_VARIANT_1_INFO: "Spokojnie wyszukuj i przegl.daj, wiedz.c, .e Twoje dane osobowe s. chronione. Powiemy Ci, kt.re witryny s. bezpieczne, a kt.re nie.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Spokojnie korzyst
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3738
                                                                                                                                                                            Entropy (8bit):5.341816172018693
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:KpaRlEpnKqfJuUuRwyUptRtbVaKjJOhCf+L7UKkKwKfK6TU0kPVdq54420uUFLtO:w3HtvJxfqFZC/tdHLwjL7+
                                                                                                                                                                            MD5:76F46CD2B966706F21093AA71A1A8EF5
                                                                                                                                                                            SHA1:BCE9512FDC8257AE0AB1D367A453DA4B5D8B9193
                                                                                                                                                                            SHA-256:A7488A665B0498C299063FA3BC97E99523E91FEEC72E6598072210FEEE03998F
                                                                                                                                                                            SHA-512:AED61176AF728CFEA03C90FD795114C2402ED8C6818DD3CC9128370C1EA1AE9FC45D8E34D2127E9806ABF41AC5F2BF65E8DB66F6384063E0D8C3FAA03F06EDFF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Voc. gostaria de adicionar prote..o de pesquisa extra?",.. TOAST_VARIANT_CHECKLIST: "Sim, ative a pesquisa segura depois que o navegador for reiniciado.",.. TOAST_VARIANT_BUTTON: "Conclu.do",.. TOAST_VARIANT_BUTTON_FREE: "Pesquise com seguran.a GRATUITAMENTE",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Pesquisa n.o protegida",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Eu n.o quero prote..o gr.tis",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Sua prote..o na Web n.o est. totalmente configurada. Ative-a gratuitamente",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Conclua a configura..o da prote..o gratuita da Web da McAfee",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Proteja suas informa..es pessoais",.. TOAST_VARIANT_1_INFO: "Navegue e pesquise com confian.a, sabendo que suas informa..es pessoais est.o protegidas. Informaremos quais sites s.o seguros . e quais podem ser perigosos.",.. // Toast variant 2 specific.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3683
                                                                                                                                                                            Entropy (8bit):5.333373479671786
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:KVFTplRl0d61FB0yUpDRtbVaK6HOd0TZeC5p30BL7UKkKHKMKFTUBk30aB5qyQOc:GE3ttmud03zEPFqtvEezHWNd62
                                                                                                                                                                            MD5:507B9571E311F50013920017D26891B7
                                                                                                                                                                            SHA1:8F66344D4870A95D6558EB91EE894CCE2C560633
                                                                                                                                                                            SHA-256:5E7798ADC4AB204D50ECF6984AFA3285E3E795066A5A95BB3369171199059C86
                                                                                                                                                                            SHA-512:8B0760E09F14391DF1E4B32782CA8FED55108729FD04FB9256FA16F1383C05C5C669B3E69E18EC6DA2CA7AFE2E661CEC9D9E5F643605022842E35C2D77CC925E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Pretende adicionar prote..o de pesquisa suplementar?",.. TOAST_VARIANT_CHECKLIST: "Sim, ativar a pesquisa segura ap.s reiniciar o meu browser.",.. TOAST_VARIANT_BUTTON: "Conclu.do",.. TOAST_VARIANT_BUTTON_FREE: "Pesquisar em seguran.a . GR.TIS",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Pesquisar sem prote..o",.. TOAST_VARIANT_BUTTON_NOT_WANT: "N.o quero prote..o gratuita",.. TOAST_VARIANT_TITLE_NOT_SETUP: "A sua prote..o Web n.o est. conclu.da: ative-a gratuitamente",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Termine a configura..o da sua prote..o Web da McAfee",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Proteja as suas informa..es pessoais",.. TOAST_VARIANT_1_INFO: "Navegue e pesquise com a confian.a de que as suas informa..es pessoais est.o protegidas. Vamos indicar-lhe que sites s.o seguros e os que podem ser perigosos.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Deixe
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5374
                                                                                                                                                                            Entropy (8bit):5.134747831277087
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:/Li+T0t5WKRmY8vzQedwpNv473IdQ/NtRk3:f0t5Dl8vzQex7DNPU
                                                                                                                                                                            MD5:6AC6EA6256C064FAE13981FA508E046D
                                                                                                                                                                            SHA1:97AB6B196AB4DEBA93EA779BE7E0F0C9CC19D4BB
                                                                                                                                                                            SHA-256:82AE1DA37D5BBA6BE06FE96F45B521E2140BE6D714AF1188C2E393BCA664E063
                                                                                                                                                                            SHA-512:6A4067E422B3F11317DFFE8F224AB3FB4399F0A3CE53E0822CF433DDBA260F4CE90BD90F65669A44B536DC02B9FFE8BD68BCDEA127743AFA348B4246DBBDC214
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "...... ........ .............. ...... ......?",.. TOAST_VARIANT_CHECKLIST: ".., ........ .......... ..... ..... ........... .........",.. TOAST_VARIANT_BUTTON: "......",.. TOAST_VARIANT_BUTTON_FREE: ".......... ..... . .........",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "..... .. .......",.. TOAST_VARIANT_BUTTON_NOT_WANT: "... .. ..... .......... ......",.. TOAST_VARIANT_TITLE_NOT_SETUP: ".... ...-...... ......... .. ......... . ........ .. .........",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "......... ......... .......... ...-...... McAfee",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "........ .... ...... ..........",.. TOAST_VARIANT_1_INFO:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3752
                                                                                                                                                                            Entropy (8bit):5.646352630188663
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:G/v3lJ6qJt9g29MgiL+tBjYE7+R8LB0HDDx+UHnFn:G3l4At9g29MnL+tpYE7o8LB0Xx+GFn
                                                                                                                                                                            MD5:391A2E6DD3E758834DF894E83A12EBF8
                                                                                                                                                                            SHA1:0CF94794984AA8C1B21014D812719EB5D677FAB2
                                                                                                                                                                            SHA-256:535322F326167CB53DB5E7F9DD0FF3E2A92AFD140105A210B0F3BEAC0E49BCA9
                                                                                                                                                                            SHA-512:6492C0523193497F1284A9084C2DF32E60C54985E1B86F9BBEEA8872525E85CAE16868E85CA461A5D792AE3CECA269A214B191A9D461E5B0D5019EA094681FC8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Chcete zv..i. zabezpe.enie vyh.ad.vania na internete?",.. TOAST_VARIANT_CHECKLIST: ".no, zapn.. zabezpe.en. vyh.ad.vanie po re.tarte prehliada.a.",.. TOAST_VARIANT_BUTTON: "Hotovo",.. TOAST_VARIANT_BUTTON_FREE: "Vyh.ad.va. so zabezpe.en.m . ZADARMO",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Vyh.ad.vanie nie je chr.nen.",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Nechcem ochranu zadarmo",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Webov. ochrana nie je .plne nastaven. . aktivujte ju zadarmo",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Dokon.ite nastavenie webovej ochrany od McAfee zadarmo",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Chr..te svoje osobn. .daje",.. TOAST_VARIANT_1_INFO: "Preh.ad.vajte web a.vyh.ad.vajte inform.cie bez ob.v v.aka ochrane osobn.ch .dajov. Uk..eme v.m, ktor. lokality s. bezpe.n. a.na ktor.ch hroz. nebezpe.enstvo.",.. // Toast variant 2 specific.. TO
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.445792953663574
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:5541sqXt9UFE+s49f8cQq5gAWFLrf9UQbb:5Yt9UFq49LQqyfFvOQbb
                                                                                                                                                                            MD5:4BF1A45DD0062D14B5E73AA77D5E4264
                                                                                                                                                                            SHA1:3DAEB57E91EE1520654627AEEC3656F7346D2886
                                                                                                                                                                            SHA-256:624ACB70E6C4387F96BD5A39B74A146AC9400795398168817362D3E15792B556
                                                                                                                                                                            SHA-512:AF5AD3754806776B378EE00F14360E4339B475CC90952541765C35517399F1DCE43E2E42D15AEDBE8306E08ED74E7135F3ECAD9895C6890E82464FB7774EF9DF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: ".elite li dodatnu za.titu pretrage?",.. TOAST_VARIANT_CHECKLIST: "Da, uklju.i Secure Search nakon .to ponovo pokrenem pregleda..",.. TOAST_VARIANT_BUTTON: "Gotovo",.. TOAST_VARIANT_BUTTON_FREE: "Pretra.ujte bezbedno . BESPLATNO",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Pretraga nije za.ti.ena",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Ne .elim besplatnu za.titu",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Va.a za.tita na internetu nije u potpunosti postavljena.omogu.ite je besplatno",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Zavr.ite postavku va.e McAfee za.tite na internetu",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: ".titite li.ne informacije",.. TOAST_VARIANT_1_INFO: "Pregledajte i pretra.ujte bez brige znaju.i da su vam li.ne informacije za.ti.ene. Re.i .emo vam koje lokacije su bezbedne . a koje mogu biti opasne.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Uklonite brigu sa veba"
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3492
                                                                                                                                                                            Entropy (8bit):5.431086625606851
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:KaGqWQzrHqWU7B10Up8LRtXbY8ACXGiLuKcUCLK6LKVKo9U31Ta920FLlpx/TV56:B6CtsQ2klVdM5+9npxU2oBZvOGj
                                                                                                                                                                            MD5:70B8C274779F7889BD6A8AFF5E18D565
                                                                                                                                                                            SHA1:820BD74BFBD9D238B22FB259C265827F872CFB87
                                                                                                                                                                            SHA-256:C7C2FF04AC3C5904F54FB52B50CABC1C8F35E37C2B66427CCAE2E8F56D8614BE
                                                                                                                                                                            SHA-512:C0FD21AD75E602E725A334227760475DC02294770758861A1445A8CE9294C0A76A01D5C6B9122FF37C3A6C8AB260150D9495850996DDC849D93A2E5B399BAECD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Vill du l.gga till extra s.kskydd?",.. TOAST_VARIANT_CHECKLIST: "Ja, aktivera s.ker s.kning n.r jag har startat om webbl.saren.",.. TOAST_VARIANT_BUTTON: "Klart",.. TOAST_VARIANT_BUTTON_FREE: "S.k s.kert - KOSTNADSFRITT",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Oskyddad s.kning",.. TOAST_VARIANT_BUTTON_NOT_WANT: "Jag vill inte ha kostnadsfritt skydd",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Inst.llningen av ditt webbskydd .r inte fullbordat - aktivera det kostnadsfritt",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "Fullborda inst.llningen av ditt McAfee-webbskydd",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Skydda din personliga information",.. TOAST_VARIANT_1_INFO: "Surfa och s.k tryggt i vetskap om att din personliga information .r skyddad. Vi ber.ttar vilka webbplatser som .r s.kra . och vilka som kan vara farliga.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Surfa p. n.tet utan oro",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3702
                                                                                                                                                                            Entropy (8bit):5.50838372099097
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:K2rafAlFLhKpoLQHdPUpI5LRtHyderOYC3LCyrsgLLsnLKIlIKfLKb3LKyjqMURs:CCIbtSgyGyouKx+bG/dDeFfQ3t16h8E
                                                                                                                                                                            MD5:7271EB48AC8670DCFB2660DFE70AFFB7
                                                                                                                                                                            SHA1:E43A98848A809F9378A2B2ADCB40886A5ECA27D5
                                                                                                                                                                            SHA-256:1E28229CF8C4EBF3BB6D878EDCE4C0E20BF80308F8153F1BF324C0AFDB98A4FE
                                                                                                                                                                            SHA-512:A7DCB170713CBCD66FD31D1E8E6D5C571A11CB246DCB3603CE234DF1A9F3FF07DEF5A1339AC2C96639F6024D69B02313BFD07E6343B6BA0D90C5E1438E2E8E77
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "Ekstra arama korumas. eklemek ister misiniz?",.. TOAST_VARIANT_CHECKLIST: "Evet, taray.c.m. yeniden ba.latt.ktan sonra G.venli Arama'y. a..",.. TOAST_VARIANT_BUTTON: "Bitti",.. TOAST_VARIANT_BUTTON_FREE: "G.venli arama yap.n - .CRETS.Z",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "Korunmadan arama yap.n",.. TOAST_VARIANT_BUTTON_NOT_WANT: ".cretsiz koruma istemiyorum",.. TOAST_VARIANT_TITLE_NOT_SETUP: "Web koruman.z tam kurulmam.., .cretsiz etkinle.tirin",.. TOAST_VARIANT_TITLE_FINISH_SETUP: ".cretsiz McAfee web koruma kurulumunuzu tamamlay.n",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "Ki.isel bilgilerinizi koruyun",.. TOAST_VARIANT_1_INFO: "Ki.isel bilgilerinizin korundu.unu bilerek g.venle gezinin ve arama yap.n. Hangi sitelerin g.venli, hangilerinin tehlikeli olabilece.ini size s.yleyece.iz.",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "Endi.eleri webten uzak tutun",
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3220
                                                                                                                                                                            Entropy (8bit):6.3278451090740155
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:KpV0YrIr3BkaxUpYNRtt5K2dCaLQzKeKGBKHlKCQUDlFJ5g68a1MzflHS/+xKAYq:aS9KotKvaLJ8CJFPl8aSwXNtl43ec
                                                                                                                                                                            MD5:D3F97BFDCE355DDE0CF1F3553D16BE65
                                                                                                                                                                            SHA1:29042AABB6ECA8DD6ACC3813FA43731490F5D5E6
                                                                                                                                                                            SHA-256:B309E8FEE0E568DE9999166FA80166C043EA11275CF9E668969653A50F072838
                                                                                                                                                                            SHA-512:2DA5402CE577B7F3CDB3CC15FA39977C204BB1C4D6B3CAB66F4FE225B760F630CC589665C056C0FDD6F7A83371C88A63B19FE25AAD43AE68B1A6D44EAE6FC9AE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "...........",.. TOAST_VARIANT_CHECKLIST: "................",.. TOAST_VARIANT_BUTTON: "..",.. TOAST_VARIANT_BUTTON_FREE: ".... . ..",.. TOAST_VARIANT_BUTTON_UNPROTECTED: "......",.. TOAST_VARIANT_BUTTON_NOT_WANT: "........",.. TOAST_VARIANT_TITLE_NOT_SETUP: "...................",.. TOAST_VARIANT_TITLE_FINISH_SETUP: ".............",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "........",.. TOAST_VARIANT_1_INFO: ".................................................",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: "......",.. TOAST_VARIANT_2_INFO: ".........................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3309
                                                                                                                                                                            Entropy (8bit):6.333278042576984
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:LjGwO6t6wKA44s2xr92kwcK8jtUuhSSmSK:tt6wc4s2xrskwc3U6SS/K
                                                                                                                                                                            MD5:35EBE25CC3A2E5DB8F8BCDC7F40F5AF7
                                                                                                                                                                            SHA1:0750AFD4587645E7A27EA892101D88EF4AC82329
                                                                                                                                                                            SHA-256:A46AF7AF0A79C5262FF095245702E882129D76E97C2BCF64C922F4DDD460EB55
                                                                                                                                                                            SHA-512:7B98F0549487364DC8D354C035B5B52C63C207DE915A8F26EA8887DAFD612F16DC8496F066E368DB332FD32A984437DF85860C0431A0645C9727B7E5AE3221AC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSSToastVariants_ = {.. TOAST_VARIANT_QUESTION: "..............",.. TOAST_VARIANT_CHECKLIST: "...................",.. TOAST_VARIANT_BUTTON: "..",.. TOAST_VARIANT_BUTTON_FREE: ".... . ....",.. TOAST_VARIANT_BUTTON_UNPROTECTED: ".............",.. TOAST_VARIANT_BUTTON_NOT_WANT: "........",.. TOAST_VARIANT_TITLE_NOT_SETUP: "..... Web ...........",.. TOAST_VARIANT_TITLE_FINISH_SETUP: "..... McAfee Web .....",.. // Toast variant 1 specific.. TOAST_VARIANT_1_TITLE: "........",.. TOAST_VARIANT_1_INFO: "................................................",.. // Toast variant 2 specific.. TOAST_VARIANT_2_TITLE: ".......",.. TOAST_VARIANT_2_INFO: "..........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2317
                                                                                                                                                                            Entropy (8bit):5.724232664480202
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvSUqYRSK+R28Y2zgJsQqpq/83qkj6B9nw4RJtlzJMO90:C6UnSKOY2zegB6Dn3Me0
                                                                                                                                                                            MD5:8FBFC0B500D0BC4EFE3EC1A966E1085C
                                                                                                                                                                            SHA1:8BD7E8CB64DF6CA9FA4136177617BE7F0BEFEE70
                                                                                                                                                                            SHA-256:563443189E2D314696BA333452D09EBA24AF779A3B54CC59B2051EE1E7AA5D3F
                                                                                                                                                                            SHA-512:8E690D9BD250E2BDD6BEF345A60547EA1A7BBC90FA667F6865B5C6F3CCED50AE4E9B74EBF5F68F242529203AB7655C58F7D003097705597A20556307F184ED71
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "M.te k dispozici dal.. mo.nosti ochrany",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Vy... ochrana je p.ipravena",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Vy... ochrana je vypnuta",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Tyto funkce vy... ochrany v.m zajist. v.t.. bezpe.. online. Zapn.te je.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "V.e je nastaveno! Kdy. p...t. znovu spust.te prohl..e., budete moci s jistotou vyhled.vat pomoc. funkce Bezpe.n. hled.n. McAfee, kter. v.m uk..e, kter. str.nky lze bezpe.n. nav.t.vit.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Je vypnut., proto.e bylo zak.z.no nebo odebr.no roz...en. pro hled.n., kter. je sou..st. vy... ochrany. Z.skejte tyto funkce zp.t.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "Funkce Bezpe.n. hled.n. McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2319
                                                                                                                                                                            Entropy (8bit):5.421754373500763
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvJjkjVsFprf0Ksd4Ajfm0p4TS4Zudo0xTn:Ctk5Ux3Ajfme4TSjxTn
                                                                                                                                                                            MD5:034A852A7AFFC3EF7DBDCED3254C3778
                                                                                                                                                                            SHA1:870E0006CF102E9DDAF9042AE551346C5DD8CAF1
                                                                                                                                                                            SHA-256:030D2160B2884238A9F1043DC7DBBD15D603F62E2F49C10A258F76B915FB64C4
                                                                                                                                                                            SHA-512:5F4A8D4CFFE613CC64FE45A606AF50D09F36F14B9864923A24183070CC354C0E7AD803F19AF3B6AAF724CD0326C044D9792B71BD1FF3AAE7E4A0A486AEC81705
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Du har flere beskyttelsesmuligheder",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Ekstra beskyttelse er aktiveret",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Ekstra beskyttelse er deaktiveret",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Disse ekstra beskyttelsesfunktioner forbedrer din onlinesikkerhed. Sl. dem til.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Alt er parat. N.ste gang, du starter browseren, kan du surfe p. internettet i sikkerhed, fordi McAfee sikker s.gning viser dig, hvilke websteder det er sikkert at bes.ge.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Funktionen er deaktiveret, fordi s.geudvidelsen, der er en del af den ekstra sikkerhedspakke, er sl.et fra eller er blevet fjernet. F. disse funktioner tilbage nu.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee sikker s.gning", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} viser dig, hvilke websteder d
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2382
                                                                                                                                                                            Entropy (8bit):5.446769832572551
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvzhxfTyDKyA7h3CFycAOFsxEclSgHcFhXo09:C1xfeDS3CT2IrTXoi
                                                                                                                                                                            MD5:F3F4A62E48EB00A428DCE99AAB56426E
                                                                                                                                                                            SHA1:C5075EF807FB5F4C9B7D106DDBE13068074ABA3F
                                                                                                                                                                            SHA-256:1C4A14BCFA12486607EC885B49C66B88180295A20F613F7F2F3715B0FB9F2E79
                                                                                                                                                                            SHA-512:F84088D8F7DA40D4F41F5559FBB8111D1945AACC8A26B2E07F2302E51BB4CB375E394BEAB100FECA5229B01B3B1C94D063A23BCE5CB69E197F840E6F66C5C68D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Es sind weitere Schutzfunktionen verf.gbar",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Zus.tzlicher Schutz wartet auf Sie",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Zus.tzlicher Schutz ist deaktiviert",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Mit diesen Funktionen des zus.tzlichen Schutzes sind Sie online besser gesch.tzt. Aktivieren Sie sie.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Alle eingerichtet! Wenn Sie das n.chste Mal Ihren Browser .ffnen, sollten Sie die sichere Suche von McAfee nutzen, um in Ihren Suchergebnissen zu sehen, welche Websites sicher sind.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Sie ist derzeit nicht verf.gbar, da die Sucherweiterung, die eine Komponente des zus.tzlichen Schutzes ist, deaktiviert oder entfernt wurde. Aktivieren Sie diese Funktionen jetzt wieder.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee Sichere Suche", .. SEARC
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3630
                                                                                                                                                                            Entropy (8bit):5.084257425787037
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CNwyIyaSMAwsC38BDAeuDFKed0uHpUjF0:CNuzDAAmtuJlDpUS
                                                                                                                                                                            MD5:0D24410CF5B30B902325CC2FC0D81A35
                                                                                                                                                                            SHA1:F2277D2512CD12B8AAB40A37D945B16E3029B4F7
                                                                                                                                                                            SHA-256:2CA59554DC742F0AAA6D7DA6790D63963751D5177F32634D7B207D2CB507290C
                                                                                                                                                                            SHA-512:E70CF3F294F1B459DDD6526F354E6884A19D6B019451A6DBE34FFD5CB31DACE9695C90E664AFE5B562ED1AF4359AFF6884744780D5B646CD96C15C9CB965456B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "..... ........... ......... .........",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: ". ........ ......... ..... ......",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: ". ........ ......... ..... ................",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "..... .. ........... ......... .......... ... ....... ... ........ online. ............. ... ............",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "..... .......! ... ....... .... ... .. .............. .. ......... .......... ..., ......... ........... .. ..... .. ... ...... ......... McAfee ... ... ....... ..... .....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2039
                                                                                                                                                                            Entropy (8bit):5.454774830011741
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Cv45dlzloc0Zvdr05DJMtWXS7bJ3sLEISktCRHJ:CKHzloLZ25DJMtiUW4NkML
                                                                                                                                                                            MD5:15A864FD05C99B179425837A13C4CBE0
                                                                                                                                                                            SHA1:EE95A3F34014E21B93BE7E6E3862EE99611D5B39
                                                                                                                                                                            SHA-256:A0D9E7F74A3C0FFFCC2DAB33E2D65D634D5BEE10BB5C324E36C40475FBF8C9CA
                                                                                                                                                                            SHA-512:68FC08552E65B82F877589CCB772EC86B0277081F4A21C9CE55DEABCC8D188DCCB2B4AF59E5DB5AC6053EA7D9DD408B5E4D6030A315585CF697C5013D7C92CC6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "You have more protection available",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Added Protection is ready",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Added Protection is off",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "These Added Protection features keep you safer online. Turn them on.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "All set! The next time you restart your browser, search confidently with McAfee Secure Search showing you which sites are safe to visit.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "It's off because the search extension that's part of Added Protection was disabled or removed. Get these features back now.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee Secure Search", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} shows you which sites are safe before you visit them.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_2: "Ad Blocker", .. SEARCH_TOAST_ADBLOCK_BULLE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2325
                                                                                                                                                                            Entropy (8bit):5.427575417384713
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOvdgk9mBAPBQdBFXyUzwXFoI1mfCzZA8hmUA1ov8KJMfePnEW4dpaPVFk4/3PD:Cv7MkYFXTzGFoIEWPyovzQArVZGLIAgh
                                                                                                                                                                            MD5:B519B450222241C6A0601353CC10AABA
                                                                                                                                                                            SHA1:836433CE93A836B5DCA03BA58AF0B105D6FED78E
                                                                                                                                                                            SHA-256:3D1D0075BFEE0F425D78329DD03C12DB39E4D9EEDD19415D255BBD656E7BC60B
                                                                                                                                                                            SHA-512:C3E68EF44D59BB81951EB037B178FCA15A6301D324396CAFDBDB56B68A83E45314DC3C8318D5FC900892A79298FD01E485BF4412984542F3AA722E96660AD402
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Puede disfrutar de m.s protecci.n",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "La Protecci.n a.adida est. activada",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "La Protecci.n a.adida est. desactivada",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Estas funciones de Protecci.n a.adida le mantienen a salvo en Internet. Act.velas.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Ya est. todo configurado. La pr.xima vez que reinicie su navegador, tendr. la tranquilidad de saber qu. sitios web son seguros gracias a la B.squeda segura de McAfee.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Est. desactivado porque la extensi.n de b.squeda incluida en la Protecci.n activa est. desactivada o se ha eliminado. Vuelva a activar estas funciones ahora.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "B.squeda segura de McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} le muestra q
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2241
                                                                                                                                                                            Entropy (8bit):5.4587498644754175
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOvdgWQIvN6tKQtqWmwUV5mOZzZCB4vhmUwRKJhZfeT5gAdFqdVtBcwKHvcJi94:CvlQIjWZKTZ8Kp6c0jqrtqvEIU3
                                                                                                                                                                            MD5:5F2DD39BAE6409010449EBA3F028DA7C
                                                                                                                                                                            SHA1:442432AD15E77776A44CF557C4C3B397141ABEB9
                                                                                                                                                                            SHA-256:19873840D8D3FAC6D4CBC3624378C5850704A85FA0475883E1A50ECB131E6650
                                                                                                                                                                            SHA-512:AB73D271CDA2CD94667CBD7B37A26303CB59EB9EEBFFCEE30C232F59434A75454F154AD273E2047CD05C99EC66E0DCB0338546C31BF357AE609DCF1592796B2C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Tiene m.s protecci.n disponible",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Protecci.n adicional est. listo",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Protecci.n adicional est. desactivado",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Estas caracter.sticas de Protecci.n adicional lo mantienen seguro en l.nea Act.velas",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: ".Todo listo! La pr.xima vez que reinicie su navegador busque con confianza ya que B.squeda segura de McAfee le mostrar. cu.les sitios son seguros para visitar.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Est. desactivado porque la extensi.n de b.squeda que es parte de Protecci.n adicional fue inhabilitada o eliminada. Recupere esas funciones ya mismo",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "B.squeda segura de McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} muestra qu. sitios son seguros ant
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2246
                                                                                                                                                                            Entropy (8bit):5.418192884712719
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOvdgGvLPUQPmMdzpP5x4bICHA4fEOGVGd1Pwsx7LmNhI+a6soNxawi9dySBx74:CvXlmMd9m6mdFwWrZ6kxuFrCQeNQ
                                                                                                                                                                            MD5:7579677AE9F8F2336BAF326735569F81
                                                                                                                                                                            SHA1:FF6B16BE83B94E74410FC80C63D0843383BFF6D0
                                                                                                                                                                            SHA-256:AA0DC11B2EFEAE5A32399F52E5DB42B4B8A07D332C29F132C42E33CFDB6C93E5
                                                                                                                                                                            SHA-512:86EDB2E70DB3245399AADF449CF79015D381CB22B57F267FCBB33CB8EFEAFF03033DC49071F34D828B54F55399509CF87788A25B052B53E277158C246E23B6EA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Lis.. suojausta saatavana",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Lis.suojaus on valmis",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Lis.suojaus on poissa k.yt.st.",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "N.ill. lis.suojausominaisuuksilla pysyt paremmin turvassa verkossa. Ota ne k.ytt..n.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Kaikki on valmista. Kun ensi kerralla k.ynnist.t selaimen uudelleen, voit tehd. hakuja turvallisin mielin McAfeen suojatulla haulla, joka n.ytt.. vaarattomat sivustot.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Se on poissa k.yt.st. siksi, ett. lis.suojaukseen kuuluva hakulaajennus oli poissa k.yt.st. tai se poistettiin. Hanki ominaisuudet heti takaisin.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfeen suojattu haku", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} n.ytt.., mitk. sivustot ovat vaarattomia ennen
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2413
                                                                                                                                                                            Entropy (8bit):5.4551318322529045
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvmQM4M92AhLMdlzu5ZHl0l1nD2qqhhUq:C+W42AhLmlzu5BkJyqCV
                                                                                                                                                                            MD5:3273690404BBDBBF2689E7BAF956D827
                                                                                                                                                                            SHA1:3A8C6C6D74B75F860CCADE4B19A53A7475B2DBC8
                                                                                                                                                                            SHA-256:68FE7B0E79443C8D982B2DC52E9B9C25292CEA579E2EB3B407D9171CEC2EC46D
                                                                                                                                                                            SHA-512:0E20B1324F39FAE3EBA994BEEF3C5FB30E80B1D19406C17FA0B9C556E7740D9AC36EAA4B8A2EA99507C836E9003BF79587672A587ED8DA3DCBFCF06F70C845FD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Plus de protection disponible pour vous",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "La protection accrue est pr.te",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "La protection accrue est d.sactiv.e",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Ces fonctions de protection accrue vous apportent plus de s.curit. en ligne. Les activer.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Pr.t! La prochaine fois que vous lancez votre navigateur, parcourez le Web en toute qui.tude pendant que la fonction de recherche s.curis.e McAfee vous indique les sites dignes de confiance.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Cette fonction n'est pas activ.e car l'extension de recherche qui fait partie de la protection accrue a .t. d.sactiv.e ou supprim.e. R.tablir ces fonctions maintenant.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "Recherche s.curis.e McAfee", .. SEARCH_TOAST_ADBLOC
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2494
                                                                                                                                                                            Entropy (8bit):5.43753803112721
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvqwGuHF9o9/EuB8u5J5AxHaaydCPjPXnbch:CSwGeY/EuB8u5olydCPrbK
                                                                                                                                                                            MD5:13CBA9B83E6EFA161D75727DF200180E
                                                                                                                                                                            SHA1:B2811B7661A2340AAB559FA0E478C360AA499977
                                                                                                                                                                            SHA-256:92A78F8512A48A9C48BBFC851101CAB367180892F0B98724463FBB98122BCCE4
                                                                                                                                                                            SHA-512:84C2FB055BA88C6B0331A37DE8B8661CE7EBE04B1448E7AE2A0C8FD8BCC7E5EB92DF5EDD050E2FA9076DD507FD1BF52535CF008E2E0A5B02602A61942098D4CB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Vous avez d'autres protections disponibles",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "La Protection renforc.e est pr.te",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "La Protection renforc.e est d.sactiv.e",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Ces fonctionnalit.s de Protection avanc.e assurent votre s.curit. en ligne. Activez-les.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Vous .tes pr.t.! La prochaine fois que vous red.marrez votre navigateur, vous pourrez effectuer des recherches en toute confiance . l'aide de la Recherche s.curis.e McAfee, qui indique les sites que vous pouvez consulter en toute s.curit..",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Elle est d.sactiv.e car l'extension de recherche qui fait partie de la Protection renforc.e a .t. d.sactiv.e ou supprim.e. R.cup.rez ces fonctionnalit.s maintenant.",.. SEARCH_TOAST_ADBLOCK_BULLE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2273
                                                                                                                                                                            Entropy (8bit):5.530360206154129
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvIoaSjp60i4X476LRiouHFshwFZcBqeOzT:CAejbVA8RcHFsh0yqeA
                                                                                                                                                                            MD5:1B410752E8CDEB1343ED2406A08B9D0E
                                                                                                                                                                            SHA1:E7DFF0CE68B129DE2DE50DCE20F05450B1D5B6C0
                                                                                                                                                                            SHA-256:69000E655ED5329D01F0F2C299EC51A0FC2DAAC5B9E3CE2EE9830185F9659769
                                                                                                                                                                            SHA-512:49F704BD64D9990723D50F6C25245D1175FCB36C624F5492C97E1B0CE530C483C694A63F08846276CA2C54AA45A5D6D4DD33D431BE6F1253D06806CFAE3EDCBD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Dostupna vam je ve.a za.tita",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Dodatna za.tita je spremna",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Dodatna za.tita je isklju.ena",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Ove funkcionalnosti dodatne za.tite .ine vas sigurnijim online. Uklju.ite ih.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Sve je spremno! Sljede.i put kada ponovo pokrenete svoj preglednik, samouvjereno pretra.ujte uz McAfee Secure Search koji .e vam pokazati koje je stranice sigurno posjetiti.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Isklju.eno je jer je pro.irenje pretra.ivanja koje je dio Dodane za.tite onemogu.eno ili uklonjeno. Vratite ove zna.ajke sada.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee sigurno pretra.ivanje", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} vam pokazuje koje stranice su sigurne prije nego ih posjetite.",.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2388
                                                                                                                                                                            Entropy (8bit):5.626397646753971
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvtCmH9aqAIDT5WSSWp7IpKwYnZmT+FLepwiV3l+MW:CFCmHMVIqtYY+BWGMW
                                                                                                                                                                            MD5:E30CC8500AD87568C691A364F78EECBA
                                                                                                                                                                            SHA1:F136DD6557D69578C6120D6379239B283824B61A
                                                                                                                                                                            SHA-256:DDB352B8333DE60947356150E70E45EC17064AA2A906183345FE2393AE39AFBF
                                                                                                                                                                            SHA-512:EC5C92CD8BEB4F7FFFC690074E09C46EC85F51C8F607B2A203678F626E910F2F8C9F5B3A3123610E8E0430FE438AFE3DA0A8A765CEC293C81DF4A4E877A0DAB5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "M.g hat.konyabb v.delem .rhet. el",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "A tov.bbi v.delem k.szen .ll",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "A tov.bbi v.delem ki van kapcsolva",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "A tov.bbi v.delmi funkci.k m.g nagyobb biztons.got ny.jtanak online. Kapcsolja be .ket.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Minden k.szen .ll. A b.ng.sz. k.vetkez. elind.t.sakor magabiztosan kereshet a biztons.gos keres.s funkci. r.v.n, amely megmutatja, hogy mely webhelyeket keresheti fel biztons.gosan.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Ki van kapcsolva, mert a tov.bbi v.delem r.sz.t k.pez. keres.s b.v.tm.ny le lett tiltva vagy el lett t.vol.tva. Vegye ig.nybe .jb.l ezeket a funkci.kat.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee biztons.gos keres.s", .. SEARCH_TOAST_ADBLOCK_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2180
                                                                                                                                                                            Entropy (8bit):5.430870827158706
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvlUzrFEVioJofWr5HsJcxnyhXpwfJwTRraIiLG/J:CpVioJoerVsJWylSm4Ig0
                                                                                                                                                                            MD5:5D8598F2201E45B9968CE8A89748048A
                                                                                                                                                                            SHA1:B250DF2841FF5539739BB8AA7ED2E3D0DD173652
                                                                                                                                                                            SHA-256:646BCC9EA896F1839F2D2FF0CDDDC84E13CF386AEB4D8CBF7A55825D024153B4
                                                                                                                                                                            SHA-512:258CE89EB60E5F8622ABD2EA6B3FB4F66148EA1CE0846725EECFA0B3DB8F239B5052F43C27AB04B9433104E074BEA59153C282C0EC9A73B12D6FDC862E4F76F3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Puoi aumentare la protezione",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "La protezione aggiuntiva . pronta",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "La protezione aggiuntiva . disattivata",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Queste funzionalit. di protezione aggiuntiva aumentano la tua sicurezza online. Attivale.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Tutto pronto. La prossima volta che avvierai il browser, la ricerca sicura McAfee ti mostrer. i siti sicuri da visitare.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: ". disattivata perch. l'estensione per la ricerca che fa parte della sicurezza aggiuntiva . disattivata o . stata rimossa. Riattiva subito queste funzionalit..",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "Ricerca sicura McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} ti mostra i siti sicuri prima di visitarli.",.. SEARCH_TOAST_ADBLOCK_BULL
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2689
                                                                                                                                                                            Entropy (8bit):5.783492922423992
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CDihdOhGELq02HhMyCYaYPuMLmeStoN5PcvhvD8vsOgah:CDihdsjz2BMRNkmTgg5wRgah
                                                                                                                                                                            MD5:4BED5D33E177BDA09929FBDD72EA51DD
                                                                                                                                                                            SHA1:2AF0721F2D2792C6C556313AF9D05B53F976560A
                                                                                                                                                                            SHA-256:3D400ACB69A7B7ECA3EAD276C21EFE3F6F696C89895AEE57379823C7C332C87D
                                                                                                                                                                            SHA-512:6263770A13E14F21021C918B9CD0BA27D72269FC9AB8E4CEF40D7D714EAD5C8FBE0175F5208E1A7B932831642F8F0608CFD96583E3BCE3997762610A6DA45065
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: ".........",.. SEARCH_TOAST_ADBLOCK_HEADING: "..............",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "............",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "...............",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "............................... .............",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: ".......... ....................... .... ....................................",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: ".............................................. ...........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2396
                                                                                                                                                                            Entropy (8bit):5.90958145143297
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOVLgXlf/klv04CjUXktjHaQLKOudpQVg/xFSQXmYQgpyyqK4wQNqDhOnwIju2O:C8FJUXy6XlbSvYi3wiQ2O
                                                                                                                                                                            MD5:C96049216F6CF6DD9C07B87211553581
                                                                                                                                                                            SHA1:870E75BD0CAB8F15ACCB40CF2F53D6A28975BB6A
                                                                                                                                                                            SHA-256:51E2F7E5A5FCFA12C0B536ED4B8F5382C13661992D2F6844E771BCDA4FC993FC
                                                                                                                                                                            SHA-512:943095D8F02D7567B75D5B243D993B295FBCDE8AF6C1B233AA15CA08110FB7E6C5483149EBDF750FAFAC29E8A2A54142E77E12496FB0B297F05CF1B572C2EDA2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "......",.. SEARCH_TOAST_ADBLOCK_HEADING: "... ... . ....",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: ".. ... ... . ....",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: ".. ... .. ....",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "... .. .. .... ... ... ... ..... ... ....",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: ".. ........ ... ..... .. .... McAfee .. ... .... ... .... ..... .... ... . .....",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: ".. ... ... .. ... .... .. .... .. ... ... . ..... ... ... .. ......",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee .. ..", .. SEARCH_TOAST
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2170
                                                                                                                                                                            Entropy (8bit):5.4514491250427435
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvJIksPYZC/uu6YZJN5QsKYmOArOhR/QExYkR2S:ChI1Y0/u3YYsGKrYS7
                                                                                                                                                                            MD5:BB18F9BC97B5745E3C01D856D596071A
                                                                                                                                                                            SHA1:01FA3741217B0A9180EC9C18DB48FB44F705791A
                                                                                                                                                                            SHA-256:1DE722273E719DA415E21D398F0C4720A2B0EE1CE7E08C0BC5328CBAE6C5C694
                                                                                                                                                                            SHA-512:525305A69E08AF263330D8CDE5594C91B849D9A4884BE1A31A1FC82E1D0456F6B44CF1911EB93409ACEAB6AE1330322C88FDFF30F7C65BE2D5B641B6BF7B52A7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Flere beskyttelsesfunksjoner tilgjengelig",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Ekstra beskyttelse er klart",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Ekstra beskyttelse er av",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Disse funksjonene i Ekstra beskyttelse holder deg sikrere p. nettet. Sl. dem p..",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Alt klart! Neste gang du starter nettleseren, kan du trygt s.ke med McAfee Sikkert s.k. Funksjonen viser deg hvilke omr.der som er sikre.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Den er av fordi s.keutvidelsen som er en del av Ekstra beskyttelse, er deaktivert eller fjernet. F. tilbake disse funksjonene n..",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee Sikkert s.k", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} viser deg hvilke omr.der som er sikre, f.r du bes.ker dem.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_2:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2216
                                                                                                                                                                            Entropy (8bit):5.445156491013825
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvKJpceq6RTcyrCBuH1ibZ/Pp93MK64kFUq5EpvnSWA8i:CQSN6Roy8uHwZHpi34TqmpqW1i
                                                                                                                                                                            MD5:FC49ED40CB38256B5A7CBE1F0C4B2202
                                                                                                                                                                            SHA1:498A72B88F985C16F27F8F364133B095BE714D43
                                                                                                                                                                            SHA-256:46FCA5BFF9AFC70ADD46917F5E2912D7788BF06231B80C7D8A0A756032520A4D
                                                                                                                                                                            SHA-512:F6131A864EEE2F067F23960DD756E1BA1CFC63245C8BF50835E0994A389D1EA82EFA614EE69040C32D586CF3D0F7EC1E7BCB020F23472F7FB5E237A4BE1D9AB4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "U kunt over meer bescherming beschikken",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Extra bescherming is gereed",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Extra bescherming is uitgeschakeld",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "De functies voor Extra bescherming verbeteren uw online veiligheid. Schakel ze in.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Klaar! Wanneer u uw browser opnieuw start, kunt u zorgeloos zoeken met Beveiligd zoeken van McAfee dat u precies laat zien welke sites u veilig kunt openen.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Het is uitgeschakeld omdat de zoekextensie die deel uitmaakt van Extra bescherming, is uitgeschakeld of verwijderd. Schakel deze functies nu opnieuw in.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "Beveiligd zoeken van McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} laat u zien welke sites veilig zijn voordat u ze bezo
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2289
                                                                                                                                                                            Entropy (8bit):5.686524926637267
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Cv4058MjlxcXI9qWiXgwsIvE8QK0tKWhEZ0JILHVI16sSIIRXCVmO:CQ01jCI9qXXLsIvE8Q5K+EOgVIEsSFX2
                                                                                                                                                                            MD5:4E9C8EBB617AEFA754BB752550446493
                                                                                                                                                                            SHA1:2576650CD564A5B1B1FB07F878B67B265A21312E
                                                                                                                                                                            SHA-256:7774036B9B221F424A7504AD1098A1B448CF4469CC295BAA5133EE511AC078A2
                                                                                                                                                                            SHA-512:BE70D312829A074BB81D2D1289C8C87482D18FDD553948922998AAD412CF14974865552005483C4538DD172BB8D235BA44A4E9423C22F0230ED74361691012F7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Dost.pne jest wi.cej ochrony",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Dodatkowa ochrona jest gotowa",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Dodatkowa ochrona jest wy..czona",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Funkcje Dodatkowej ochrony pomagaj. chroni. Ci. w Internecie. W..cz je.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Konfiguracja zako.czona! Po nast.pnym ponownym uruchomieniu przegl.darki, Bezpieczne wyszukiwanie McAfee pomo.e spokojnie wyszukiwa., informuj.c o bezpiecznych witrynach.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Jest wy..czone, poniewa. rozszerzenie wyszukiwania b.d.ce cz..ci. Dodatkowej ochrony zosta.o wy..czone lub usuni.te. Odzyskaj teraz te funkcje.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "Bezpieczne wyszukiwanie McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} pokazuje, kt.re witryny s. bezpieczne,
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2225
                                                                                                                                                                            Entropy (8bit):5.478804103947096
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvVVlKrZ/ez2L3dpZszSJEufUo7G+Dz0I:CNq62LizsUoCaD
                                                                                                                                                                            MD5:BE1565B167CA665AF9DA89F2C99C6050
                                                                                                                                                                            SHA1:91D77D275A806BD2CD948C6B7F946C970CAC6556
                                                                                                                                                                            SHA-256:C3D3598C8B7A700D33665D64B15B01BDD44A1CD2AD6579861B67223021CF8571
                                                                                                                                                                            SHA-512:AF92ABE944E3DB088F4BFCE3E8959F3A20A5061E13E0E8BE68AD3023369766145AA7F1C675A20BF82975C4DEE24EAD14F4683FFF67A0771B66B7C41F4BD303B3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Voc. tem mais prote..o dispon.vel",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Prote..o adicional est. pronta",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Prote..o adicional est. desativada",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Esses recursos de Prote..o adicional o mant.m em seguran.a online. Ative-os.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Tudo pronto! Na pr.xima vez que reiniciar seu navegador, pesquise com a Pesquisa segura da McAfee que exibe os sites seguros de visitar.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Desativado porque a extens.o de pesquisa que . parte da Prote..o adicional foi desativada ou removida. Traga esses recursos de volta imediatamente.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "Pesquisa segura da McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} mostra quais sites s.o seguros antes de voc. visit.-los.",.. SEARC
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2324
                                                                                                                                                                            Entropy (8bit):5.473262216183594
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvOb9fKjnZdVrzzHUUFZeEi351TgV4/QbG9Ddzw:CWJmZTLUUFZgLQiTzw
                                                                                                                                                                            MD5:3AFD031732AA78F7BAB6E1214D420900
                                                                                                                                                                            SHA1:9E1EB0CE1D9A8833FCE6869724EC356E53C16369
                                                                                                                                                                            SHA-256:B7BBB3ECF66EF27C200D02057A369802E0AC2A149F791C783B32EBFF0B246861
                                                                                                                                                                            SHA-512:ED8BE2C8DF3C6BD33EB1931FAA9F43C6866E1F707FC90BA44C3DC6C0B1E598FB52B8F899A02C5E2D7466E973586E6FA750F280D87C40BED406F9D4DCD7494EE7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Tem mais prote..o dispon.vel",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "A prote..o adicional est. pronta",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "A prote..o adicional est. desativada",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Estas funcionalidades de prote..o adicionais mant.m-no seguro online. Ative-as.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Est. pronto! A pr.xima vez que reiniciar o seu browser, pesquise com confian.a com a Pesquisa segura da McAfee a mostrar-lhe que sites pode visitar em seguran.a.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Est. desativada porque a extens.o de pesquisa que faz parte da prote..o adicional foi desativada ou removida. Obter estas funcionalidades novamente agora.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "Pesquisa segura da McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} mostra-lhe os sites que s.o seguro
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3288
                                                                                                                                                                            Entropy (8bit):5.143824214783734
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:COrsBqgVZBkBuYVCdpLVREi4c1rTZPNiNbdD1P:CCsBqgVZiuYV8pLV16hV
                                                                                                                                                                            MD5:DDD046C06FEC8646E05300BDB004A799
                                                                                                                                                                            SHA1:58F0669910C890ECE44C3B739939675E48DACD7E
                                                                                                                                                                            SHA-256:F486043DC3C4CAE1C518FA434E0A89E4CF0E18FC73B7DC432DD61AC5BB92F629
                                                                                                                                                                            SHA-512:39A11A7C19273CA753418240C0D1C73CBE8DFC808C96E0F4546066C33455D65D551136B4D0FBFC4C78A8B442FEF9BCBBDB312F16753E947B9EF68CB7930F099C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: ". ... .... ...... ............ ... ......",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: ".............. ...... ......",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: ".............. ...... .........",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "... .............. ....... ...... ............ ............ . .......... ........ ...",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "... ......! . ......... ... ..... ............ ........ ......... ..... . ....... ....... ........... ...... McAfee, ....... ........., ..... ...-..... ......... ... ..........",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADIN
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2276
                                                                                                                                                                            Entropy (8bit):5.7622122869733
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOvdg0FQ8YIcT3JOzrgffdIxL8EHbgnDHKXldVV/aVcFUC7wQi0o0ekfSanwINx:CvW8zM6pE2VDVGc377SI/xzF1
                                                                                                                                                                            MD5:E16F194FFDA6AB76D2D868046FB2F2B8
                                                                                                                                                                            SHA1:E0E1B13814F8FB44B310B334F5572AC756DBB2BC
                                                                                                                                                                            SHA-256:5E15279D70F7C588A90FAA6389BAAD0D34C1F8604C9CCAB074A6DF5E9D4B8156
                                                                                                                                                                            SHA-512:34DF75A842BA4BDA5B2E89FD5B9B307E89661502CB7956E15FCBD395DC6EC6DA069D73151D19824202B221708F9C13FB4839384E6D399698F1952103D03C9267
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Pon.kame v.m viac funkci. na ochranu",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Zv..en. ochrana je k.dispoz.cii",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Zv..en. ochrana je vypnut.",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Uveden. funkcie zv..enej ochrany v.s ochra.uj. online. Zapnite ich.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "V.etko je nastaven.. Po re.tartovan. prehliada.a v.s zabezpe.en. vyh.ad.vanie McAfee ochr.ni pri prehliadan. a.zobraz. str.nky, ktor. je bezpe.n. nav.t.vi..",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Funkcia je vypnut., lebo roz..renie vyh.ad.vania, ktor. je s..as.ou zv..enej ochrany, bolo vypnut. alebo odstr.nen.. Z.skajte tieto funkcie sp...",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "Zabezpe.en. vyh.ad.vanie McAfee", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} v.m porad., ktor
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2217
                                                                                                                                                                            Entropy (8bit):5.532907790773258
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvzaSNcoHl5A0Pt0opbUbFpGbQg55EfVLssM:C5NH5AatiFpNMc4sM
                                                                                                                                                                            MD5:B225B3E84906A0A5B8454B9CC16403E5
                                                                                                                                                                            SHA1:F2FE84A206A0B63DF3C53EC5440CB9A51C532DB4
                                                                                                                                                                            SHA-256:3E1B25C92A7094643954D22E7C7299B76A5D636BC4EFDC6AE16C0C852EC620ED
                                                                                                                                                                            SHA-512:CFFF68546E00A7EBEC7B737CCB6091E2CCC1F0A1EBB03F1E2407E75AF90D8A396FB296F32F6FEC6959755F021ED2C8E5C6BCF12F7C5D116CF450988B0850660A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Imate na raspolaganju vi.e za.tite",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Dodatna za.tita je spremna",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Dodatna za.tita je isklju.ena",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Ove funkcije Dodatne za.tite .ine vas bezbednijim na mre.i. Uklju.ite ih.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Sve je spremno! Slede.i put kad budete ponovo pokrenuli svoj pregleda., pretra.ujte sa samopouzdanjem uz McAfee Bezbednom pretragom koja vam pokazuje koje lokacije su bezbedne za pose.ivanje.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Isklju.ena je jer je ekstenzija pretrage koja je deo Dodatne za.tite onemogu.ena ili uklonjena. Vratite odmah ove funkcije.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee Bezbedna pretraga", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} pokazuje vam koje lokacije su bezbedne pre nego .to i
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2111
                                                                                                                                                                            Entropy (8bit):5.531940800460125
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOvdggWQRZC50gO/GNxNteo7XH8QU/OC8Q5zuVJAlbGF5ON1y8mJbc3NU7nfv1Q:Cvg5Lf7jC1iVJkbJ1YJbYChTR+N
                                                                                                                                                                            MD5:3403610FDAC61B972ED43C219F22F672
                                                                                                                                                                            SHA1:DEE8ECDAABE38D9C88714F3082E0C32307834863
                                                                                                                                                                            SHA-256:55BC9A5B80F0D0608F5596A37FDA04F1C75AFCD7B92A3C05FFE73BDB55409BF0
                                                                                                                                                                            SHA-512:7BD79D1ACA466FB3040B9EDB563B279CD48C1667C920B0324DDF86F2DDFD1374BA8071A5F537DF0133D14E6B59E258F5E4492B4066D6B4945DE536290E928EDC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Du har mer skydd tillg.ngligt",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Ut.kat skydd .r redo",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Ut.kat skydd .r av",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Ut.kat skydd-funktionerna h.ller dig s.krare online. Aktivera dem.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Klart! N.sta g.ng du startar om webbl.saren kan du s.ka tryggt d. McAfee s.ker s.kning visar dig vilka webbsidor som .r s.kra att bes.ka.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Det .r av eftersom s.ktill.gget som .r del av Ut.kat skydd inaktiverades eller togs bort. F. tillbaka funktionerna nu.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee s.ker s.kning", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} visar dig vilka webbsidor som .r s.kra innan du bes.ker dem.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_2: "Annonsblockering", .. SEARC
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2206
                                                                                                                                                                            Entropy (8bit):5.572151998283136
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOvdg/UOH95vCfoXiRvLa/sGcdDSqi+2O1ebxZQ25BMblR/B2sK3SZ/Z9vKlmCO:CvSG/GoSqi+Z7bQspvKG68dd30nUv
                                                                                                                                                                            MD5:A2BF5A99464327D8C6CB893F6C439EEB
                                                                                                                                                                            SHA1:07B8E11224358434B69A9517C87AAB4560CDBF7D
                                                                                                                                                                            SHA-256:1FC51E901832EE6C1570A9D9167FF7C14C016996BA019C100434F87A2BAC474C
                                                                                                                                                                            SHA-512:ACACA98D1F2CD472822C9478AF83DDEFED8D49B16AC88EAF9ACE7D543354AEC45725B2926BAEE0EA4687A74107D27B12855E6A3574E6E3E5E4608EB42643E9A9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: "Daha fazla koruma se.ene.ine sahipsiniz",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "Ek Koruma haz.r",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: "Ek Koruma kapal.",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "Ek Koruma .zellikleri sizi .evrimi.i korur. Hepsini a..n.",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "Her .ey haz.r! Taray.c.n.z. bir sonraki ba.lat...n.zda, hangi sitelerin ziyaret edilebilece.ini g.steren McAfee Secure Search ile g.venle arama yap.n.",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "Ek Koruma'n.n bir par.as. olan arama uzant.s. devre d... b.rak.ld... veya kald.r.ld... i.in kapal.. Bu .zellikleri hemen geri al.n.",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee Secure Search", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0} ziyaret etmeden .nce hangi sitelerin g.venli oldu.unu g.sterir.",.. SEARCH_TOAST_ADBLOCK_BU
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2043
                                                                                                                                                                            Entropy (8bit):6.252788266367725
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOZgVstn8dWjt8EWNjtM7LLyllJtjEcjt/dcz58qNAMdstxjl7BnwIj86+HXJJH:CjBt/wppKWMGzRl9d+3CjTQb
                                                                                                                                                                            MD5:136E335FFFF5C09C8D45F3AC2DCCCCA2
                                                                                                                                                                            SHA1:E678FDB546E8DEF80C4669A03359185766707BFA
                                                                                                                                                                            SHA-256:57D566D0D6C5322BD4B3AE3E32E43A81048142D127FBF638A0668807EF211CFD
                                                                                                                                                                            SHA-512:55EF7E5F7103D08F055163C4EC7462D025393D473F69A2171FC03979F474C0280CA28945FBB5582E5E48748F1529214380ADACF89C2861BBBFF095919A445145
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "....",.. SEARCH_TOAST_ADBLOCK_HEADING: "..........",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: "..........",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: ".........",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "...................... .....",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "..... .................................",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: "........................ ...........",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: ".......", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: ".......{0} ..........",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_2: "......", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_2
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2123
                                                                                                                                                                            Entropy (8bit):6.278958296554494
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:CvaX+Mm6t8MZoD+KKtSr5FlITWiyViRXixEfUMu:CCX+Mm6WcCKWQi4SxEMMu
                                                                                                                                                                            MD5:6086CC3903036253F01AF24FDEE7C53A
                                                                                                                                                                            SHA1:CA0CA223E2C748EF97FC55CB0CC0C470CE068522
                                                                                                                                                                            SHA-256:06869E709D71E852F90DB62AC5D72DEF614B6B7862ADCB5A80C4E61A351DA04B
                                                                                                                                                                            SHA-512:03C892A4839C3B09F7A790FA889AA73938C4C52B95B500D43024C6818CBC81DE0B4A5EA840265D8445722CAE04FD89A0E2C0DA133D71DE2A730B5BE07E1106A5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_ADBLOCK_HEADING: ".........",.. SEARCH_TOAST_ADBLOCK_READY_HEADING: ".........",.. SEARCH_TOAST_ADBLOCK_REENABLE_HEADING: ".......",.. SEARCH_TOAST_ADBLOCK_SUB_HEADING: "............................",.. SEARCH_TOAST_ADBLOCK_READY_SUB_HEADING: "................McAfee ..............................",.. SEARCH_TOAST_ADBLOCK_REENABLE_SUB_HEADING: ".............................................",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_1: "McAfee ....", .. SEARCH_TOAST_ADBLOCK_BULLET_NORMAL_1: "{0}.......................",.. SEARCH_TOAST_ADBLOCK_BULLET_STRONG_2:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):908
                                                                                                                                                                            Entropy (8bit):5.688820613029769
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HUDAS6FXOqZG1g4zBFU+K6IPHf7q4qtoxnuBaY2MUKmbt:7HbzFOKGy16IPTq47uqbt
                                                                                                                                                                            MD5:25600BAE80F5CB75634E66D438A3ED87
                                                                                                                                                                            SHA1:A6BD998A6F8BC4228AB739D30118E587FCEF229A
                                                                                                                                                                            SHA-256:4D9275A965EA4DB4423AFD61F15BBCF892A16B841039C49CDBC4C2C2E7137992
                                                                                                                                                                            SHA-512:52741F63385F776C8393DC7ABE4B931D48E95FB4882020A343D4FD68F363F7C71FE3CBBE22A4459E25F3A9A8923CE175A0FC86550CAF97E7160BC23208B9B4C0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Nem.te slu.bu Bezpe.n. hled.n. . bu.te opatrn.",.. SEARCH_TOAST_SUB_HEADING: "Slu.ba Bezpe.n. hled.n. v.s ve v.sledc.ch hled.n. prov.d.n.ho pomoc. vyhled.va.e Bing upozorn. na rizikov. str.nky.",.. SEARCH_TOAST_BODY_TEXT: "Chcete vyhled.va. Bing doplnit o slu.bu Bezpe.n. hled.n. a b.t v.dy o krok nap.ed p.ed podvodn.ky?",.. SEARCH_TOAST_SUB_FOOTER: "Po restartov.n. prohl..e.e zapneme slu.bu Bezpe.n. hled.n. a nastav.me vyhled.va. Bing jako v.choz..",.. SEARCH_TOAST_YES: "Ano",.. SEARCH_TOAST_NO: "Ne, d.kuji",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Zapneme slu.bu Bezpe.n. hled.n. a nastav.me vyhled.va. Bing jako v.choz.."..}..//FF98ACC354B545567CA5D01D513C6EB584299B4AB03A5FA783F85AE184C0527F66C6AD287475F6E30D2FBFC1C93534ABA862DEE5CB9259BD5D78343BDF2D9C64++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):807
                                                                                                                                                                            Entropy (8bit):5.48546336024787
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HaufsEtijFTUd42Vd+PQhF2FAZePvosQ:++s9TUd42Vd+Y3VeXtQ
                                                                                                                                                                            MD5:B703435844FC64ACB0E8B66023BBBF72
                                                                                                                                                                            SHA1:2A30A8373B69E603EBEE037C9619A77BE41AB40D
                                                                                                                                                                            SHA-256:9679209EA147A58E6208244A1FE1096F27F7E7562C7A9336CC97611354277D2E
                                                                                                                                                                            SHA-512:689AB439FF9A18D7A3C1B62B2CC7098A924FDFB77CD046641C8D9BDC2FE4D15E0132F7AF030F392EC6ACF0E95B5C9A1A3FF9E45F896A15777C53E78CEB52F36A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Du har ikke sl.et Sikker s.gning til . s. v.r forsigtig!",.. SEARCH_TOAST_SUB_HEADING: "Sikker s.gning leder dig v.k fra risikofyldte websteder i Bing-s.geresultaterne.",.. SEARCH_TOAST_BODY_TEXT: "Vil du f.je Sikker s.gning til Bing, s. du undg.r at komme ind p. grimme steder?",.. SEARCH_TOAST_SUB_FOOTER: "Vi sl.r Sikker s.gning til og .ndrer standards.gemaskinen til Bing, n.r du genstarter browseren.",.. SEARCH_TOAST_YES: "Ja",.. SEARCH_TOAST_NO: "Nej tak",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Vi sl.r sikker s.gning til og .ndrer standards.gemaskinen til Bing."..}..//AC3E60B396EE5D724C7E17F84B4F779296FF62D757427CF7185926D7D8A2258157CF441CB9D0379D0B13CBD65B35520D68E4CF032ED0860B1F15198A523ADE01++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):863
                                                                                                                                                                            Entropy (8bit):5.3420058632941165
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOaJltkh2FsMZCvXCQtROXJZMBTNJVrfIMX3K6DNJ4lIVFvF2wjpqtODNJ4lIgX:7HGgFJZ+X0qvX66Q+3F2wlPQ+gSZwj
                                                                                                                                                                            MD5:0E75E9D6285D37C533F5F4CC930AFA12
                                                                                                                                                                            SHA1:B82EEF55389EE9D554E98BAA6B9F54B7990BDBF6
                                                                                                                                                                            SHA-256:271299AEEEAE9E51AABA8E770E280E4F621CB08FFC2762DCF7358A68E314ADB6
                                                                                                                                                                            SHA-512:D45D245CC5678AE5EF00EB4C1DFE2F0AAF7C09C551A371CE00843975BEB5D1AAF640649D5C2846EFF9C6778B1CDFA4D559DB3C325D23973F21E101921EB285CC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Die sichere Suche ist nicht aktiviert . seien Sie vorsichtig",.. SEARCH_TOAST_SUB_HEADING: "Mit der sicheren Suche werden Sie vor risikoreichen Websites in Ihren Bing-Suchergebnissen bewahrt.",.. SEARCH_TOAST_BODY_TEXT: "M.chten Sie die sichere Suche zu Bing hinzuf.gen, um Kriminellen immer einen Schritt voraus zu sein?",.. SEARCH_TOAST_SUB_FOOTER: "Wir aktivieren die sichere Suche und .ndern Ihre Standardsuchmaschine zu Bing, wenn Sie den Browser neu starten.",.. SEARCH_TOAST_YES: "Ja",.. SEARCH_TOAST_NO: "Nein danke",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Wir aktivieren die sichere Suche und .ndern Ihre Standardsuchmaschine zu Bing."..}..//FFB880235CF4154BA0E03FB3C17C538DFF8032B766C32880B61AEB170C9CA4C6EBA5139B9C45716E3B219320D5395F3A0164CD3FA5C452EDF4C5DB1B7E5DE45A++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1522
                                                                                                                                                                            Entropy (8bit):4.955552194749003
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HB3IsMXLr2bnATla3ybWG2hbiLy+wgjxUbiPRjGXnMxv:W2UTlaLvbiVGbidCnMv
                                                                                                                                                                            MD5:39FB7B5125A164684B163EB346081AF1
                                                                                                                                                                            SHA1:651B92A732751624F9A9C4B1A4416B8F52175175
                                                                                                                                                                            SHA-256:B56D36EC8D9F9D4921D8391975A87A7FBECA1D0698E8FFA0F08C8963BF496C57
                                                                                                                                                                            SHA-512:30275A695980EB10A662AFFF7985F25BA79C5313800C413C5111BA0BE07F4E10A87E3EB3DF7ACA438622412AEB966616D0CE21FF267B02C5ED570F2155FEABE8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "... ......... ... ...... ........., .. ..... ...........",.. SEARCH_TOAST_SUB_HEADING: ". ....... ......... ... ........... ... ........... .......... ... ............ .......... ... ... ........... ... ......... .. .. ......... Bing.",.. SEARCH_TOAST_BODY_TEXT: "...... .. .......... ... ...... ......... ... ......... Bing ........... .. ..... ..... ... .... ....... ... .... ............. ...........;",.. SEARCH_TOAST_SUB_FOOTER: ".. ............... ... ...... ......... ... .. ........ .. Bing .. ............. ......... .......... .... ... .....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):780
                                                                                                                                                                            Entropy (8bit):5.341048253661898
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HdW9H3npSuVNTzLo4uiJH7IyOtS9eDqt1IyafdAYkuvNS:7H8XpSuVNTzxcCeD7FdAYBS
                                                                                                                                                                            MD5:A2FFDC45B6EE34B91AF0946585771BDE
                                                                                                                                                                            SHA1:94B05EDF970F53DC4BF9D12D3947A01A36BD719D
                                                                                                                                                                            SHA-256:8C14DAD3A286BAF2CFD48299C29CA207D001034C015EF506E36F1976B6671D2E
                                                                                                                                                                            SHA-512:CCBF2F98F761A8A7035248EB1FDEECC7AD1244495403E16179A61B2FF181BDF30396E8C5FB2A78B95B8EBE8EEE8669E0B00C54BE22DD5820FE9AF4EAFC74039B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "You don't have Secure Search . be careful",.. SEARCH_TOAST_SUB_HEADING: "Secure Search steers you away from risky sites in your Bing search results.",.. SEARCH_TOAST_BODY_TEXT: "Would you like to add Secure Search to Bing and stay ahead of the bad guys?",.. SEARCH_TOAST_SUB_FOOTER: "We'll turn Secure Search on and change your default search engine to Bing after you restart your browser.",.. SEARCH_TOAST_YES: "Yes",.. SEARCH_TOAST_NO: "No thanks",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "We'll turn Secure Search on and change your default search engine to Bing."..}..//B8F1A499F644094CDFB0462EDE3201EAD0A2F156E7AEA19B74C6F29FAD300BB976E31754B7E95BE5507A45F642230E99F2F92D930C510EEB53BF5CADF9F91399++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):834
                                                                                                                                                                            Entropy (8bit):5.3858921587981206
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HTOW06YIJHM8MEIoyLLQZSUJHHrSXXY0Vqt15ZSUJaN5HkgvpE3/0:7HqpQJHM8MnoyEpmHYGm5oN5HHes
                                                                                                                                                                            MD5:47049A10A4264E4DAACEC2A36EC9786B
                                                                                                                                                                            SHA1:F1B31EDC542651DB3E3088987B11FAC66B89B5CD
                                                                                                                                                                            SHA-256:1E4C4CDAB0233C51D0E14F21912C65CDF558C58626D1EBDC7F047BCDE34AFB52
                                                                                                                                                                            SHA-512:0F419C60637750154EB86B59E0173EB131E453438E0B9DFD915E82AA85A41AF53F3D3A7DD3B1786108D5999B035AAF649F792187D10217DAD0A9C4DBAF0B6A9E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "No dispone de B.squeda segura, tenga cuidado",.. SEARCH_TOAST_SUB_HEADING: "B.squeda segura elimina los sitios web peligrosos de los resultados de sus b.squedas en Bing.",.. SEARCH_TOAST_BODY_TEXT: ".Le gustar.a a.adir B.squeda segura a Bing y olvidarse de los malos?",.. SEARCH_TOAST_SUB_FOOTER: "Activaremos B.squeda segura y cambiaremos su motor de b.squeda predeterminado a Bing despu.s de que reinicie su navegador.",.. SEARCH_TOAST_YES: "S.",.. SEARCH_TOAST_NO: "No, gracias",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Activaremos B.squeda segura y cambiaremos su motor de b.squeda predeterminado a Bing."..}..//C3EFC3A6C064EAF1EBDA56B5E11061565E56D90CAC0D79DF9E495DCEDE018698A616475E7FBC1EFEF976CFC742F14760AC12BEED830F408576446472611C8BEF++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):848
                                                                                                                                                                            Entropy (8bit):5.377366640690806
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HT9+6YzsinKM8MEIe4LyO3KVoqZSUJHHrSXXY0Vqt1BbSUJKsQCIesw6hHZ:7HCsiKM8Mne4X3QpmHYGmboxCcb
                                                                                                                                                                            MD5:E94546A330D9A84041AF8C18130A13FA
                                                                                                                                                                            SHA1:8D14B572D01F1CA3189C7BF949B5A748CD3E53A4
                                                                                                                                                                            SHA-256:FD572014052A9D4D7DBD1984BCB2E4970C938BD062D5BD6593542B9BBF058AF5
                                                                                                                                                                            SHA-512:7A66F44908097BEEA94A6C4234A6F9FDDF56819AB0D5DB4894A92D8AD784B538FCF134CD873EDCC45D6F0A9FB557CC01D0D8909909432D863F1F5454649FAFC6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "No tiene b.squeda segura: tenga cuidado",.. SEARCH_TOAST_SUB_HEADING: "B.squeda segura lo aleja de los sitios peligrosos de los resultados de sus b.squedas en Bing.",.. SEARCH_TOAST_BODY_TEXT: ".Le gustar.a agregar B.squeda segura a Bing y mantenerse por delante de los malos?",.. SEARCH_TOAST_SUB_FOOTER: "Activaremos la B.squeda segura y cambiaremos su motor de b.squeda predeterminado a Bing despu.s de que reinicie su navegador.",.. SEARCH_TOAST_YES: "S.",.. SEARCH_TOAST_NO: "No, gracias",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Activaremos la B.squeda segura y cambiaremos tu motor de b.squeda predeterminado a Bing."..}..//774793A544BA2248B5833B0E776F4611EAA4EB7250A3A19C2D9E3F3EA4065586EF84326915E50F5B234F3B232B25C3570C991E0D4A36C9269E411010C66951FA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):837
                                                                                                                                                                            Entropy (8bit):5.4144506945268285
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HQ2htHsNn+dWfoRVfeEfoRilDiBOWKGk:5hFs1fgrfDcOWlk
                                                                                                                                                                            MD5:FFF760F6D0DD396B14B0914DD168BA6C
                                                                                                                                                                            SHA1:76F46B903184CCE7D107E00B96187EE777EB10B0
                                                                                                                                                                            SHA-256:A2D57FF4F6D92FEC608A19E5046DCFF235C729B54A7D937B5018DCF6A8E7F1F3
                                                                                                                                                                            SHA-512:900C7A228554B545DD5030B3107F2A7795CC22A5939FF0C5E470042127D2CDF45BE72A6F4D4B1799A413F6BC39FF2B0EB4D6108AA34F7735291F76846857EBC5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Sinulla ei ole suojattua hakua . ole varovainen",.. SEARCH_TOAST_SUB_HEADING: "Suojattu haku suojaa sinua vaarallisilta verkkosivustoilta, kun suoritat Bing-hakuja.",.. SEARCH_TOAST_BODY_TEXT: "Haluatko lis.t. suojatun haun Bing-hakukoneeseen, jotta pysyt jatkuvasti muutaman askeleen rikollisten edell.?",.. SEARCH_TOAST_SUB_FOOTER: "Suojattu haku otetaan k.ytt..n ja oletushakukoneeksi muutetaan Bing, kun k.ynnist.t selaimen uudelleen.",.. SEARCH_TOAST_YES: "Kyll.",.. SEARCH_TOAST_NO: "Ei kiitos",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Suojattu haku otetaan k.ytt..n ja oletushakukoneeksi muutetaan Bing."..}..//F36551F9A9786F5A72ED5D54B9955A66A49D8540ED039E8A9D7D0A6C8DED74F04BF183CE0823D30E21406B3B639C92401CD72EF71B41725F72E5E4919B98B23C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):927
                                                                                                                                                                            Entropy (8bit):5.353545614692768
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HW5WFTGeg5rqskm8wwbY6xQam8wwbY6NAQyBA:uWFTGeg5Wwv6Bwv6NncA
                                                                                                                                                                            MD5:7C90FFF94970FD205D36B3D5C6421F87
                                                                                                                                                                            SHA1:2BF3110C1DB900549DDD1D665FE854CBC0FDAD69
                                                                                                                                                                            SHA-256:2C89C632F1521FD9018ADCBCFBF2A230FDB566A7E753DB08C00AB5DA6216A741
                                                                                                                                                                            SHA-512:08A8C21DAE59127C95F3B3EBB510BD74522399803F97F04243029DB70931B1E78811E35738ECB9AFD88B0E89E7F0C6F02CE7E7C0AD18E028375D91D0D6F7E450
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Attention! Recherche s.curis.e n'est pas install.e dans votre navigateur.",.. SEARCH_TOAST_SUB_HEADING: "Recherche s.curis.e vous met . l'abri des sites Web dangereux figurant dans vos r.sultats de recherche.",.. SEARCH_TOAST_BODY_TEXT: "Souhaitez-vous ajouter Recherche s.curis.e au moteur de recherche Bing et d.jouer les escrocs?",.. SEARCH_TOAST_SUB_FOOTER: "Nous activerons Recherche s.curis.e et configurerons Bing comme moteur de recherche par d.faut apr.s le red.marrage de votre navigateur.",.. SEARCH_TOAST_YES: "Oui",.. SEARCH_TOAST_NO: "Non merci",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Nous activerons Recherche s.curis.e et configurerons Bing comme moteur de recherche par d.faut."..}..//57C8DAE1DF8839ACB4D9C48570AFCE42B073F5A306ACEBF8254FB5A7ED724684540E07C7BAD7328F7F4C6B8B88AA7D84D43C6F9B6FC18BA6902C2B144F45FF82++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):940
                                                                                                                                                                            Entropy (8bit):5.361699743281387
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HNL7EemtP5RTOpwemfw8uWY6xxAamfw8uWYSwwpd+g:R7EemtPaiwX6CwXAdh
                                                                                                                                                                            MD5:2808E40E4DEFAE387C8213265FF1C6BD
                                                                                                                                                                            SHA1:69F1AB49982FCA26E3C378F17D011F67DC104F6E
                                                                                                                                                                            SHA-256:131381B90DC8FCD58B612C1E740E80F3E18C564AE37C0744C526849128022A3B
                                                                                                                                                                            SHA-512:B9AA89A4F058A2D8045E160F32C7F821FB2632D4B3568F854AB5C8263B80466ED0B8BB7BABE30DF84B269532D9B78FF87D0C084CDABEBBADFE05E1A3DEEA410D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Soyez prudent, vous ne disposez pas de la recherche s.curis.e",.. SEARCH_TOAST_SUB_HEADING: "La recherche s.curis.e .carte les sites dangereux dans vos r.sultats de recherche Bing.",.. SEARCH_TOAST_BODY_TEXT: "Voulez-vous ajouter la recherche s.curis.e . Bing et garder une longueur d'avance sur les personnes mal intentionn.es.?",.. SEARCH_TOAST_SUB_FOOTER: "Nous activerons la recherche s.curis.e et d.finirons Bing comme votre moteur de recherche par d.faut apr.s le red.marrage de votre navigateur.",.. SEARCH_TOAST_YES: "Oui",.. SEARCH_TOAST_NO: "Non, merci",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Nous activerons la recherche s.curis.e et d.finirons Bing comme votre moteur de recherche par d.faut."..}..//EA11169CB4A238A8439DB55895CC03A02F88C6CFFE0A0BE6534AA158863B5454F409F9A1DE18BB8116832D1C71C0630A7A02E8E669F24D8C267131F8682DFA09++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):798
                                                                                                                                                                            Entropy (8bit):5.4203719090467235
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HM+9DuIg9sCZwzJl//L9hd9MuGvPJHCqtL9MuGkSUFSMf+z0VEj:7HMogol25vxHCD5kS2T+z0VK
                                                                                                                                                                            MD5:3DC9E0B9876B48A4B9AF1EEB885A8EEB
                                                                                                                                                                            SHA1:F49F1963BE7796E356DDE80CBD707A29D0D3BA72
                                                                                                                                                                            SHA-256:AABC136B40C5DC53335F87524A8A02F9A6BB21EA705A2DDDFFDFE1B12F4FC27D
                                                                                                                                                                            SHA-512:C776E51C6E602FECF0B52741A86F550C3FADAF61F0C5755F037815133CF6A01E94B0E32B28BE5B2E00C7B206E0A8BECB92EC36399861F5BA822D80CD778D7AC4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Nemate sigurno pretra.ivanje - budite oprezni",.. SEARCH_TOAST_SUB_HEADING: "Sigurno pretra.ivanje dr.at .e opasne stranice podalje od va.ih rezultata Bing pretra.ivanja.",.. SEARCH_TOAST_BODY_TEXT: ".elite li dodati sigurno pretra.ivanje na Bing i ostati ispred?",.. SEARCH_TOAST_SUB_FOOTER: "Okrenite sigurno pretra.ivanje i promijenite zadanu tra.ilicu za Bing nakon ponovnog pokretanja preglednika.",.. SEARCH_TOAST_YES: "Da",.. SEARCH_TOAST_NO: "Ne, hvala",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Okrenite sigurno pretra.ivanje i promijenite zadanu tra.ilicu za Bing."..}..//58564E968C6A1DD2A3B01E6CAA43C802D43886AA300213AB786B403029C4AFA1A15CFEA82F1E419D0F21A3BD40757F0000F2F410BEE9BCF0640F6E9AEAEEF483++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):922
                                                                                                                                                                            Entropy (8bit):5.595558799392145
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HL8d6oBd5US6Xdd7qQpuYeBdyEpFnY45EgpuYeBddpFtvF:q6ojijX/+QpuJjTYH+uJjj9
                                                                                                                                                                            MD5:B38B90C7D9DFD87A593F15953D541B8D
                                                                                                                                                                            SHA1:58DFE87DA7B330E62DF1B80F3F61B66304EB49D0
                                                                                                                                                                            SHA-256:FD5FB9E7E89817195524ADF8E387ADD1CA2D2EB6BE05F6BDB648ECF97618F1BE
                                                                                                                                                                            SHA-512:D68F00E1E0E9990D8C12829691C95814832D87A015435627FBD21F1895FDE6C85E91ACB36D805C69F7CA46E3FE607DA1469565E31C834F6F95EFC9B9165B94DD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Nincs biztons.gos keres.s funkci.ja . legyen .vatos",.. SEARCH_TOAST_SUB_HEADING: "A biztons.gos keres.s funkci.val elker.lheti a Bing keres.si eredm.nyei k.z.tt tal.lhat. vesz.lyes webhelyeket.",.. SEARCH_TOAST_BODY_TEXT: "Szeretn. hozz.adni a biztons.gos keres.st a Binghez, hogy n.h.ny l.p.ssel mindig megel.zze a rosszfi.kat?",.. SEARCH_TOAST_SUB_FOOTER: "Bekapcsoljuk a biztons.gos keres.st, .s a b.ng.sz. .jraind.t.sa ut.n az alap.rtelmezett keres.motor a Bing lesz.",.. SEARCH_TOAST_YES: "Igen",.. SEARCH_TOAST_NO: "K.sz.n.m, nem",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Bekapcsoljuk a biztons.gos keres.st, .s az alap.rtelmezett keres.motor a Bing lesz."..}..//ED836E20F822E064FC27F5397135316DE08C17C7B7CC8357DA7DC005E6CD3EE7CF05A51E030F4A904D09DABCBF494CBD1C7B366892AAF6A82D4948A06F82D824++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):819
                                                                                                                                                                            Entropy (8bit):5.274707792713194
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H1J1Z2psz/XEKapHoCv815HFl+pqtKHoCv8elQQEHn1X4O:7HB8OXEhpICvoFlIhICvtlyHOO
                                                                                                                                                                            MD5:2700305936DBB03114A934D5E9757167
                                                                                                                                                                            SHA1:A1AEDB794816FD8BA9B33455BFB848E68A659805
                                                                                                                                                                            SHA-256:93C9C109C10004B94C7D96E01C2759988FE6250C1F1B73247443FC6E45E40ACE
                                                                                                                                                                            SHA-512:47302DC536B6FE20680C89B55B77361FF70B2D35C1EF54B3FE58CEDBDA1BDE3CA577459804B8F5463B5261C52B884E0DF1036DCE96C82C1BEDCCD61CE7CD28FF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Attento, non stai usando la ricerca sicura",.. SEARCH_TOAST_SUB_HEADING: "La ricerca sicura consente di escludere i siti rischiosi dai risultati delle ricerche con Bing.",.. SEARCH_TOAST_BODY_TEXT: "Vuoi aggiungere la ricerca sicura a Bing e tenere alla larga i malintenzionati?",.. SEARCH_TOAST_SUB_FOOTER: "Attiveremo la ricerca sicura e imposteremo Bing come motore di ricerca predefinito dopo il riavvio del browser.",.. SEARCH_TOAST_YES: "S.",.. SEARCH_TOAST_NO: "No, grazie",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Attiveremo la ricerca sicura e imposteremo Bing come motore di ricerca predefinito."..}..//8BD8DCF847C401B1CCB745554373A6FFAA03B6BF5C11295B0B4E8F8D4493B225C738440B991532D6E3771E7B734A3CB86C14DAB121AD5678086207E4C8FE22CC++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):943
                                                                                                                                                                            Entropy (8bit):5.727860477750984
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7H8PQbHaQ4gy2XLCreYv6RlqkYvIsZc6FU:4PQzanP2XLInvKc1vIsZc6FU
                                                                                                                                                                            MD5:B9EA0C2C353F18C73103DCDE34582F81
                                                                                                                                                                            SHA1:2E1372FD055A0A653B74D1A59D93655D9325A232
                                                                                                                                                                            SHA-256:813D941EB5BA6E03DB6F03559A58C695155965CE4477262EA2FC16DADEFCB47E
                                                                                                                                                                            SHA-512:8B5F98EEA3F6ECD2E3DE81254FC74715DF3CCAB7388C82C0AAD8B885F156913EBF6FA687071159608D3C9BB51776A00ADED2FC6AEB48D98B2760048164777751
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: ".... ..........................",.. SEARCH_TOAST_SUB_HEADING: ".... .....Bing ....................",.. SEARCH_TOAST_BODY_TEXT: ".................. .... Bing ........",.. SEARCH_TOAST_SUB_FOOTER: "................ ...................... Bing .......",.. SEARCH_TOAST_YES: "..",.. SEARCH_TOAST_NO: "...",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: ".... ....................... Bing ......."..}..//DA01E07B3AED3210BAFE875F8D72CA79BF9454EEB7A2AF50A50C696C70F935F0F98C142936703D21CC5ADAA4AD572EB6A55E502717A8AED04C6E9520CFA33A06++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):823
                                                                                                                                                                            Entropy (8bit):5.904020544863617
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HN1I68EVZFj2F/40kOv8k16xQl07Cqtk16xQlXViKLPG:7Hx9E7ka8kg7CtJi0PG
                                                                                                                                                                            MD5:E4A9B3945989307F6F382464CD744E8B
                                                                                                                                                                            SHA1:D5E1E18DDE7569A5DD8FE13D515205DDC383BDFD
                                                                                                                                                                            SHA-256:C0E4EF29C1F6BE33016D640AA0C830FEF3A060BA54367279E3AF52FD10682994
                                                                                                                                                                            SHA-512:3133314D072BA67286DE48E0180C3C63003D5B9D4F2779B7FD2A460D7B4B9A767E2BA1295E038A59EE16E0D23E432780A8D311469B8D35ACE3B850D56D2403C3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: ".. .. ... .. - ......",.. SEARCH_TOAST_SUB_HEADING: ".. ... Bing .. .. . ... .... ......",.. SEARCH_TOAST_BODY_TEXT: "Bing. .. ... .... ... .. ........?",.. SEARCH_TOAST_SUB_FOOTER: "..... .. ... . .. ... ..... .. .. ... Bing.. ......",.. SEARCH_TOAST_YES: ".",.. SEARCH_TOAST_NO: "...",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: ".. ... ..... .. .. ... Bing.. ......"..}..//6A7DEE9087F9EC7BBA4AD778A150895A4B364827E29FDC6AE28234A1050818FF253B9B7A0FE703E9ECEBA311685E68285E7A05CF4E169D72B64BC0ED47120049++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):759
                                                                                                                                                                            Entropy (8bit):5.417701316840642
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H4jM/QjBU4dkyU/6FkbS7CWJCYfUfGKF2cFqtEFJCWJCYfUyx/YgQUsfopm8:7H0MojXdUCFHtrfyGKF2yZtrfF/FQUsY
                                                                                                                                                                            MD5:DCC0E4F0385CD17A2104343BA2911706
                                                                                                                                                                            SHA1:150AC510338E47891E9E2248349E1665897F2A02
                                                                                                                                                                            SHA-256:43429C208099375FA9FD521367429E21E24C46BFF9ACCE8185F16270CA23C0ED
                                                                                                                                                                            SHA-512:114F84A9F11FDFD9A22BD24084893025374E96B921D8A72EA81A52D1D75742FF8436658DA55C11554EE6872624483906ED77787CA4B5ABCAFCF314346B544197
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Du har ikke Sikkert s.k - v.r forsiktig",.. SEARCH_TOAST_SUB_HEADING: "Sikkert s.k holder deg unna skadelige omr.der i Bing-s.keresultatene.",.. SEARCH_TOAST_BODY_TEXT: "Vil du legge til Sikkert s.k i Bing for . ha et forsprang p. skurkene?",.. SEARCH_TOAST_SUB_FOOTER: "Vi sl.r p. Sikkert s.k og endrer standard s.kemotor til Bing n.r du starter nettleseren p. nytt.",.. SEARCH_TOAST_YES: "Ja",.. SEARCH_TOAST_NO: "Nei takk",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Vi sl.r p. Sikkert s.k og endrer standard s.kemotor til Bing."..}..//A72DA50EC9AC06D7482911C2F7459BA883D06416E8BC28EDE8D630AA5F1BC7517BFE51F448950ED756F6F8C9324714B9F09DA9ECD6CEBC538844F6B0E8AEEFC0++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):807
                                                                                                                                                                            Entropy (8bit):5.38083502499888
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HrtakxOEfqPZq7oYde5XPCF2sbde5XXiWLF5XTK:vkk8jPtYwRoDwsWJ5XTK
                                                                                                                                                                            MD5:5390F1358FB4E917C84EF5ABBC6C1658
                                                                                                                                                                            SHA1:EAC25B929A6FF110A89E16193763263CE887AD0C
                                                                                                                                                                            SHA-256:27A7D47438445F0BD5004A702E13BFD96B9914A073A023AAE7A4DE6023592C4F
                                                                                                                                                                            SHA-512:3B6E11C7F093EB57E9DB04DAC7B778E52B1BFB0E543DED0B1B46586130E242D830FFA6853918CC31D349D616F75C6A5BBAA4C76287A9418A3C67F6C8FDF1D446
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "U hebt Beveiligd zoeken niet: wees voorzichtig",.. SEARCH_TOAST_SUB_HEADING: "Met Beveiligd zoeken kunt u de riskante sites in uw zoekresultaten op Bing vermijden.",.. SEARCH_TOAST_BODY_TEXT: "Wilt u Beveiligd zoeken aan Bing toevoegen om criminelen een stap voor te blijven?",.. SEARCH_TOAST_SUB_FOOTER: "Wij schakelen Beveiligd zoeken in en maken Bing uw standaardzoekmachine nadat u uw browser opnieuw hebt gestart.",.. SEARCH_TOAST_YES: "Ja",.. SEARCH_TOAST_NO: "Nee, bedankt",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Wij schakelen Beveiligd zoeken in en maken Bing uw standaardzoekmachine."..}..//2AEDE587301434BD6F7D34E67A62ADC3A28EBCA3976817D65847907881E114CAC2C833806E77EEF466AA4C9CFB3C9511A83E097B4222AF2E53E2ED02B3200A94++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):840
                                                                                                                                                                            Entropy (8bit):5.562707190506282
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOnXZoB12oBsflpBcPMfaBpgXJveZsBpgXJZpucnp:qXZI12IAdcMGaX7aXztp
                                                                                                                                                                            MD5:8CD94C0E84D172021E443288F177B6BE
                                                                                                                                                                            SHA1:EB42776CCF5B8AF1C32DDD24B06F410B0613FE3A
                                                                                                                                                                            SHA-256:FBB644E96F686AE1851427470EA8E2445D108A5BC3E20E45B5071D416E5C548A
                                                                                                                                                                            SHA-512:9979911E8DD5B0D5B8F38EF614E3EEE6FBA3CAFE3F683C245B344902BBF4F11D80E04FC0BCC1D17F8220CB09D78AD1E8751321D0BDE4118EBFAB4481289D3FC4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Uwa.aj, nie masz wyszukiwarki Bezpieczne wyszukiwanie",.. SEARCH_TOAST_SUB_HEADING: "Bezpieczne wyszukiwanie eliminuje niebezpieczne witryny sieci Web z wynik.w wyszukiwania.",.. SEARCH_TOAST_BODY_TEXT: "Chcesz doda. bezpieczne wyszukiwanie do przegl.darki Bing i uprzedzi. zagro.enia?",.. SEARCH_TOAST_SUB_FOOTER: "Po ponownym uruchomieniu przegl.darki w..czymy bezpieczne wyszukiwanie i zmienimy domy.ln. wyszukiwark. na Bing.",.. SEARCH_TOAST_YES: "Tak",.. SEARCH_TOAST_NO: "Nie, dzi.kuj.",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "W..czymy bezpieczne wyszukiwanie i zmienimy domy.ln. wyszukiwark. na Bing."..}..//16D96677B35676937A9D41C8627A98A69B3B83E9FA31CCF16B911ED626E8BF510AB621E7B6F782168A4AC9C6A67137828AC2014635F879EFCF5A8793EED15A2C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):836
                                                                                                                                                                            Entropy (8bit):5.28267754410806
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HEJVEPlVLVGGWF/7Qy7XTLYG7MJgZ6GuISWM8jgqtNpG7MJgZ6GuzKh3/Eb+jXS:7HouiF/rDTLdtZy6MTZtZyziv5jC
                                                                                                                                                                            MD5:FFBFB67FFF4A57CB2BF6B0976961FD32
                                                                                                                                                                            SHA1:9DDD77AA9A47D86CFF915BAB18D68B38DFE62670
                                                                                                                                                                            SHA-256:FBEB7FDA6D73218AD42017694C6BCA596FBD0373CAF7B48D7EE7BF85008F9EF5
                                                                                                                                                                            SHA-512:A8769F0B93CC6FA3A5654ACCAE15A5EC5F3319D6795104C2382FEBB49DF4602448E34C536B42EFCC17809624D8EA4DCA5A98A84D097681A450FECC1C5A4A5383
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "A Pesquisa segura n.o est. ativada - tenha cuidado",.. SEARCH_TOAST_SUB_HEADING: "A Pesquisa segura evita os sites perigosos nos resultados da pesquisa do Bing.",.. SEARCH_TOAST_BODY_TEXT: "Gostaria de adicionar a Pesquisa segura ao Bing e se antecipar aos criminosos?",.. SEARCH_TOAST_SUB_FOOTER: "Ativaremos a Pesquisa segura e alteraremos seu mecanismo de pesquisa padr.o para o Bing depois de o navegador ser reiniciado.",.. SEARCH_TOAST_YES: "Sim",.. SEARCH_TOAST_NO: "N.o, obrigado",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Ativaremos a Pesquisa segura e alteraremos seu mecanismo de pesquisa padr.o para o Bing."..}..//C25ECF30C4BD302A13219B5A268DD6617F0CFAAB4048B1A0E5C75C3AD1A63ABBD4C845D23019F3FECEA14F1F0157E753907514F9C05FA81CF5A471409291697F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):823
                                                                                                                                                                            Entropy (8bit):5.329367395193231
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HR7EVLOEcQWFnQgj7366Jb7yg4HjSa8jgqtMJb7yg4HjmDdgAB82PhWgmU4:7HRrnFjjhJbOg4uaTRJbOg4qiAGMd4
                                                                                                                                                                            MD5:EFD9A142051629949381A15651137D9A
                                                                                                                                                                            SHA1:06CFE48E497E024F3BE5DB00A204618C5E8C67A8
                                                                                                                                                                            SHA-256:A580628E3F4A89BAF57948A960029934F9A5E81AF9EF973525D5E4E787F0D49D
                                                                                                                                                                            SHA-512:FBC96E939F5848DD13C89852CC086022074F0405FE9970CF1CFE686EF6B55F673E860D27C506D146B091D48532D8DF823FADC1E14C105DEC381AD9034DCDE71C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "N.o tem a Pesquisa Segura, tenha cuidado",.. SEARCH_TOAST_SUB_HEADING: "A Pesquisa Segura ajuda-o a evitar os sites perigosos nos resultados de pesquisa do Bing.",.. SEARCH_TOAST_BODY_TEXT: "Pretende adicionar a Pesquisa Segura ao Bing e antecipar-se aos malfeitores?",.. SEARCH_TOAST_SUB_FOOTER: "Vamos ativar a Pesquisa Segura e definir o Bing como o seu motor de pesquisa predefinido ap.s reiniciar o browser.",.. SEARCH_TOAST_YES: "Sim",.. SEARCH_TOAST_NO: "N.o, obrigado",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Vamos ativar a Pesquisa Segura e definir o Bing como o seu motor de pesquisa predefinido."..}..//E803ADAF0E5B8F915FF234994EC38446AD7ECB6139E7EC509291AA945F7F628F5BE421906DAB7B099AF0B8EFBB160A26E546B184E132EACAEFE47014D010CC3C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1189
                                                                                                                                                                            Entropy (8bit):5.126253876575131
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7H0i5Cke6gyt20qJNs2OSVptfnZMtXye4qfjFsX58cMtXye4qfHC6stx9O:IMCke6gyJqjbOSfNnS9yHiT9yHK9stO
                                                                                                                                                                            MD5:9843CA14E0D8184651EB3775C31B5128
                                                                                                                                                                            SHA1:3048CBB11C88908F0FECBA09BED67CD0AF78141F
                                                                                                                                                                            SHA-256:5E3E2F7B7221C2B348EB99FA98C8B897A0B944ED3D8CF9D712FC8626A276913E
                                                                                                                                                                            SHA-512:393CC1AF009661741EA405BC18C10CC85E7918138D50C5CE9B8E690F3AFD8402FC7D5CA5186692707E4293CED3557306E3BEDBC835D6F55EF97E1CFB0BC12A5D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "...... ........., .. ... .. ........... .......... .....",.. SEARCH_TOAST_SUB_HEADING: ".......... ..... .. ........ ... ........ .............. ....., .............. . ........... ...... Bing.",.. SEARCH_TOAST_BODY_TEXT: "........ .......... ..... . Bing ... ...... .. ...............?",.. SEARCH_TOAST_SUB_FOOTER: ".. ....... .......... ..... . ....... .... ......... ....... .. ......... .. Bing ..... ........... ...... .........",.. SEARCH_TOAST_YES: "..",.. SEARCH_TOAST_NO: "..., .......",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: ".. ....... .......... ..... . ....... .... .........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):959
                                                                                                                                                                            Entropy (8bit):5.700243558664091
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HUMukzWX/lJxvkgn45U1bORyg+yqto3bXsz7YWcm:7HmVXDxTbOsg+yuz7YFm
                                                                                                                                                                            MD5:BE2D6A1389AE9FB88C9647F21A2D5CE8
                                                                                                                                                                            SHA1:AED36EBFB36E6D75605B7ECAE45BA8046C6FA904
                                                                                                                                                                            SHA-256:86680FBD329AE08D4AA65432C290A35D9ACBE04B54AB4087DD9CBADA8750F38B
                                                                                                                                                                            SHA-512:8DFFEC80CA203AAF891ACBC47489D5834AAD4098B992F82D1E0A4D77C3FE13CD5AB46EAF490D2FF2B2E275213D6EF95880ED619F348AD6DA72661A004CFE333F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Nem.te zabezpe.en. vyh.ad.vanie . bu.te opatrn.",.. SEARCH_TOAST_SUB_HEADING: "Zabezpe.en. vyh.ad.vanie v.s vo vyh.ad.vacom n.stroji Bing chr.ni pred nebezpe.n.mi lokalitami vo v.sledkoch vyh.ad.vania.",.. SEARCH_TOAST_BODY_TEXT: "Chcete prida. zabezpe.en. vyh.ad.vanie do vyh.ad.vacieho n.stroja Bing a.zachova. si ochranu pred mo.n.mi .to.n.kmi?",.. SEARCH_TOAST_SUB_FOOTER: "Po re.tartovan. prehliada.a, povol.me zabezpe.en. vyh.ad.vanie a.zmen.me predvolen. vyh.ad.vac. n.stroj na Bing.",.. SEARCH_TOAST_YES: ".no",.. SEARCH_TOAST_NO: "Nie, .akujem",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Zapneme zabezpe.en. vyh.ad.vanie a.nastav.me vyh.ad.vac. n.stroj Bing ako predvolen.."..}..//4482827471F204E3CF5963D684DBF75B78AE5933F9404399755FD2B6A9A2E59F6D6248D3A145E8B79940C79A49BA15D222E30723290B39AB331AC24C4A199567++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):791
                                                                                                                                                                            Entropy (8bit):5.497616174223849
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HM3Rzi2T//nHkpIUaSB1kd1BgqDHCqtMB1kd1BgqRlgo6GBdihe7:7HM3B0T3kd/DDHC53kd/Dzue7
                                                                                                                                                                            MD5:B60F420D4E9C5CF72662E5D64B8CF1EC
                                                                                                                                                                            SHA1:CDFA09E1DBB11A6A960EA144DCBE7F1C3B17CAA7
                                                                                                                                                                            SHA-256:F7E5E8F5111BD5369979B92C1409B8F421CEA264884CE51858C82C965797BCE1
                                                                                                                                                                            SHA-512:FD6F20FDFBD61C0B5F9AF20418DD7EF74AC07322337480444D26ADF9C56DD74CEEE4B45F8663AFE7369AFB81E43C4B4BADA46D133F9050BB20355F496D96A603
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Nemate bezbedna pretraga - budite oprezni",.. SEARCH_TOAST_SUB_HEADING: "Bezbedna pretraga vas .titi od rizi.nih lokacija u Bing rezultatima pretrage.",.. SEARCH_TOAST_BODY_TEXT: ".elite li dodati bezbedna pretraga u Bing i ostanite napred?",.. SEARCH_TOAST_SUB_FOOTER: "Uklju.ic.emo bezbedna pretraga i promeniti podrazumevani pretra.iva. na Bing nakon ponovnog pokretanja pretra.iva.a.",.. SEARCH_TOAST_YES: "Da",.. SEARCH_TOAST_NO: "Ne, hvala",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Uklju.ic.emo bezbedna pretraga i promeniti podrazumevani pretra.iva. na Bing."..}..//0E4846AFB8160CCE421340A6DF95405F44E9D70A3FEB9306F787BFA142C7CBD10579A3E9F98362AA11DA6D935D1A133E38F29DE8F36814B26AD82A35E84D98E1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):847
                                                                                                                                                                            Entropy (8bit):5.475369864788056
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HBZa8gL2eN/Ttn2gW6DTXMoOF2FTnZ2gW6DTVi1EMeVljCCz:CuY/ZrT70GZrTkp6lmCz
                                                                                                                                                                            MD5:CF757C7351AED3455E772A926496AEFA
                                                                                                                                                                            SHA1:CB616A0D34E7FA86DF3BE171297507B01BC2E0D7
                                                                                                                                                                            SHA-256:417EB3E457AF7A78D01731B0E758345D123D8FCD2F652F29748432704D271526
                                                                                                                                                                            SHA-512:68680D92FD200A4631853FA0F56D7B3A67500E957A55E83B4D9078894C2D90888FCE68DDD0F10315D683F2DCD9FE7548D8FFF32C1A7FDE3D1AD5F4B09EAA4A3B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Du har inte s.ker s.kning . var f.rsiktig",.. SEARCH_TOAST_SUB_HEADING: "S.ker s.kning h.ller dig borta fr.n riskabla webbplatser i Bing-s.kresultaten.",.. SEARCH_TOAST_BODY_TEXT: "Vill du l.gga till s.ker s.kning till Bing f.r att h.lla dig steget f.re skurkarna?",.. SEARCH_TOAST_SUB_FOOTER: "Vi s.tter p. s.ker s.kning och .ndrar standardalternativet f.r din s.kmotor till Bing efter att du startar om webbl.saren.",.. SEARCH_TOAST_YES: "Ja",.. SEARCH_TOAST_NO: "Nej tack",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "Vi s.tter p. s.ker s.kning och .ndrar standardalternativet f.r din s.kmotor till Bing."..}..//747BE5AB5DD6F5DE8CB96EBD639FDF42EEF0AFD684EF611640FC1C8BFD9C221E06546E8FB0733498BE5FB42380DF1BDD409527B4C6D4FEBC18C53388AF8767C3++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):857
                                                                                                                                                                            Entropy (8bit):5.540532104557865
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HMhMT4PwAf00hBLUF8Tt7zYE3MKUR59HQmeonSqt9UxQme7osBUDdbdqJVZh:7H8O44Yh88x/YE8PJfTnStfSB6yVZh
                                                                                                                                                                            MD5:96B8EED5F1398DDD82F4EB5DA1BF6F93
                                                                                                                                                                            SHA1:A713EFDC1EF6F65E3DF1D2AC43534C5D79D9C1F8
                                                                                                                                                                            SHA-256:5C449AA1E4D7CA792C0E82382B4EBB84EACC6B283BD4F6F5ECB67A539A61F4C2
                                                                                                                                                                            SHA-512:742FF4869769691798A7B164E5E5E7942393BA9C2E8B08F6EC6CC7034F5636C55EA78931A999597CA2E2CEA180860B5111BCBE85DEE2B8A6061E76156C5EB163
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "G.venli Arama'ya sahip de.ilsiniz, dikkatli olun",.. SEARCH_TOAST_SUB_HEADING: "G.venli Arama, sizi Bing arama sonu.lar.n.zdaki riskli sitelerden uzak tutar.",.. SEARCH_TOAST_BODY_TEXT: "G.venli Arama'y. Bing'e eklemek ve k.t. ama.l. ki.ilerden uzak durmak ister misiniz?",.. SEARCH_TOAST_SUB_FOOTER: "G.venli Arama'y. a.ar ve taray.c.n.z. yeniden ba.latt.ktan sonra varsay.lan arama motorunuzu Bing olarak de.i.tiririz.",.. SEARCH_TOAST_YES: "Evet",.. SEARCH_TOAST_NO: "Hay.r, te.ekk.rler",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "G.venli Arama'y. a.ar ve varsay.lan arama motorunuzu Bing olarak de.i.tiririz."..}..//439ED26CBEA259FD87D7C2C49DB2EACDE1E8351C21F28AC028563BD0FAFC8B1E44FF77711F51DE465E0308229BD9E6EF010CA52775CEA9DAF0B1F6307B50FF24++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):777
                                                                                                                                                                            Entropy (8bit):6.220881869000409
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HZeVjrLdwETCJeYNVLkfD9nktuLMSleNyunyHS8K+9qtBuKeNyunyHc28ymyYmm:7HujCHVLkr96S4fnyHd99zfnyHFjPm
                                                                                                                                                                            MD5:7933D7D94B07C1C29DDEDE2C03A78A9F
                                                                                                                                                                            SHA1:1F57F17F623EB4E954A134BA64C0BB8296CC2A39
                                                                                                                                                                            SHA-256:8820E1EB2B0E28088EE152F8F086CE1F3EB2B09E8E2443CD68F86F79DA695304
                                                                                                                                                                            SHA-512:D4B5FED4291CE52EC642ACF5AB4BC2D30EA0235F1AA32B0CB2620DDC2A5D24E072FFC516B8371273D11C94991C7A0B40C08415E06A47EDAB571F43D9F0AAFD17
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "......... . .....",.. SEARCH_TOAST_SUB_HEADING: "......... Bing ............",.. SEARCH_TOAST_BODY_TEXT: "......................... Bing?",.. SEARCH_TOAST_SUB_FOOTER: ".............................. Bing.",.. SEARCH_TOAST_YES: ".",.. SEARCH_TOAST_NO: "....",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "..................... Bing."..}..//890317085F8CEFABEC755868532EC221C9D818F415040A7AE5A387E513810A375EC8079997465CCB14FA1F0C6DDE69A1F1F4BC7589D708A11FD4D91B93B8D3FB++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):747
                                                                                                                                                                            Entropy (8bit):6.176568616865499
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HdRjeD31S5BdlevclAZKdKX0S19HS8KFy9qtNSNv7l2Hch0lmjGGG+a:7H76D31Sy8AZKIz19Hd79qU7l2H2A/tV
                                                                                                                                                                            MD5:3B85E7578BA0B96B73EF59556E82E947
                                                                                                                                                                            SHA1:1CBDFF48CDFA06329E552F6A6044F39C1EDA2D1C
                                                                                                                                                                            SHA-256:E5E3B40926F66684B70BEAEFDD3329EBD160E50DF3CE593217A883BD34769218
                                                                                                                                                                            SHA-512:6DDE76E27BCCD6A68F0BC5A6F1EB71CDFCE2FF54C00BF413451E6B1CEDC6DDB2D8BF43C1BB77D2E375E994C1EA001F6916FBFD869D546D6AF18B4A811BE8D04A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "...........",.. SEARCH_TOAST_SUB_HEADING: "......... Bing ............",.. SEARCH_TOAST_BODY_TEXT: "......... Bing...........",.. SEARCH_TOAST_SUB_FOOTER: "............................. Bing.",.. SEARCH_TOAST_YES: ".",.. SEARCH_TOAST_NO: "....",.. SEARCH_TOAST_SUB_FOOTER_NO_RESTART: "...................... Bing."..}..//142BEDE18BA7AB5DDDECDB37BC8963E32AA4B73E08B695DF0CFC9C7ED8926518FC53AEB0D078295B055C4F3EB5790599CC4E8DCE078884BB5DF250DA74327391++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7420
                                                                                                                                                                            Entropy (8bit):5.691914931807602
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CXLFSeinF0GY2zegRdgmgV+2bt9kuB9Ouy9kuv9FoEGopoMgLmVvuu38:CXLF5WF0SHMt9kg9O39kIOEGQZVds
                                                                                                                                                                            MD5:0AF7B0D19B981DAC7835AFC59D0A895C
                                                                                                                                                                            SHA1:F73D39431035097600FB458CD055F592D89204EE
                                                                                                                                                                            SHA-256:F30A49A450B25B73172D9ADE7DE59BE0D445081AABB272441BEB689F43C9D1D2
                                                                                                                                                                            SHA-512:7DD8DAE8C6C1000E5CD548649D08381521B19AD44A5466A5F81CC1EA3A49B037C0A8DDC8E77671A165D7BAD477976F9B035A4F60DACB3EAD2B6244A478FE7F40
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Slu.ba Bezpe.n. hled.n. je vypnut. . bu.te opatrn.",.. SEARCH_TOAST_SUB_HEADING: "Slu.ba Bezpe.n. hled.n. v.s ve v.sledc.ch hled.n. upozorn. na rizikov. str.nky.",.. SEARCH_TOAST_BODY_TEXT: "Chcete zapnout roz...enou ochranu p.i hled.n., abyste byli v.dy o krok nap.ed p.ed podvodn.ky?",.. SEARCH_TOAST_OPTION: "Ano, chci po restartov.n. prohl..e.e zapnout slu.bu Bezpe.n. hled.n..",.. SEARCH_TOAST_DONE: "Hotovo",.. SEARCH_TOAST_HEADING_COMPLIANT: "Nem.te slu.bu Bezpe.n. hled.n. . bu.te opatrn.",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Slu.ba Bezpe.n. hled.n. v.s ve v.sledc.ch hled.n. upozorn. na rizikov. str.nky.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Chcete p.idat slu.bu Bezpe.n. hled.n. a b.t v.dy o krok nap.ed p.ed podvodn.ky?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Ano, p.idejte slu.bu Bezpe.n. hled.n.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6899
                                                                                                                                                                            Entropy (8bit):5.422872173360446
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CjNwgL2CS6ddGw2jKK3A/BZ6mQNeTNlspRmbM1BM0t+lWcoLa8XcZ+lWch9FF/3c:CWToK3A/Bj32ttCWy8XgCWSj/o03WwHS
                                                                                                                                                                            MD5:B88C65F680FBB8D21DB06A956B6E4857
                                                                                                                                                                            SHA1:A0A6BB3EAF5B7C94373BFAC4670B09394C936D2D
                                                                                                                                                                            SHA-256:96146C96D178F61671C796307668D7CD08FF9CF8D14F619A264F414E5601B53D
                                                                                                                                                                            SHA-512:D517F64A8514B945D5EDFEA7710E528B3186414CDF821DE96DCE9A6BD17EAE53440034AF4A9D23C8A173F6F800C28C8932E0029BAC8E486CC60C3684D180CA89
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Sikker s.gning er sl.et fra . v.r forsigtig",.. SEARCH_TOAST_SUB_HEADING: "Sikker s.gning leder dig v.k fra risikofyldte websteder i s.geresultaterne.",.. SEARCH_TOAST_BODY_TEXT: "Vil du v.re et skridt foran forbryderne og have ekstra sikkerhed, n.r du s.ger p. nettet?",.. SEARCH_TOAST_OPTION: "Ja, sl. Sikker s.gning til, n.r jeg genstarter browseren.",.. SEARCH_TOAST_DONE: "F.rdig",.. SEARCH_TOAST_HEADING_COMPLIANT: "Du har ikke sl.et Sikker s.gning til . s. v.r forsigtig!",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Sikker s.gning leder dig v.k fra risikofyldte websteder i s.geresultaterne.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Vil du tilf.je Sikker s.gning, s. du undg.r at komme ind p. grimme steder?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Ja, tilf.j Sikker s.gning til min browser, og s.g som standard ved hj.lp af {0}.", // {0} SEARCH_TOAST_*.. SEAR
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7159
                                                                                                                                                                            Entropy (8bit):5.352254521660053
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:C9EB5FeK92iZaU3vFJMGNMmXdtUGj/7vFyDGkHEXcFt98m:C+5/btltJ/7vFOEMpv
                                                                                                                                                                            MD5:72A9D075BE6CA7F50BC8502FC097FED4
                                                                                                                                                                            SHA1:49C7C3670E8A296E821D52F4BBCB5B81389A6AC0
                                                                                                                                                                            SHA-256:9B51B9AFFE147ACAC7CB4AC39293ED89CADA6522CD9D40B7647B311321C059B2
                                                                                                                                                                            SHA-512:E797E73D93D59E4657FD883087235641ECA8D5F018EB6BDA99D798CEEA3E4C13CB12998C6D195F35419E2F4E2BAA05F5DC747795997E7E181F1DFDEF83B9C1FE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Achtung: Sichere Suche ist deaktiviert",.. SEARCH_TOAST_SUB_HEADING: "Mit der sicheren Suche werden Sie vor risikoreichen Websites in Ihren Suchergebnissen bewahrt.",.. SEARCH_TOAST_BODY_TEXT: "Wollen Sie Internetkriminellen mit zus.tzlichem Suchschutz immer einen Schritt voraus sein?",.. SEARCH_TOAST_OPTION: "Ja, ich m.chte die sichere Suche nach dem Neustart meines Browsers aktivieren.",.. SEARCH_TOAST_DONE: "Fertig",.. SEARCH_TOAST_HEADING_COMPLIANT: "Die sichere Suche ist nicht aktiviert . seien Sie vorsichtig",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Mit der sicheren Suche werden Sie vor risikoreichen Websites in Ihren Suchergebnissen bewahrt.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "M.chten Sie die sichere Suche hinzuf.gen, um Kriminellen immer einen Schritt voraus zu sein?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Ja, die sichere Suche in meinem Browser hinzuf.gen und Suchen
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):991
                                                                                                                                                                            Entropy (8bit):5.765372087226622
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOM3oeWURG11jdHDUUOSj6TrY3jdHjdVtiSTj6cUnjdMA8Y9pcO48jeEy5v4:7HOvMrWh1WTMBgF5Rjnl
                                                                                                                                                                            MD5:AC1AB1A5C3522E1993EFA82AA6392230
                                                                                                                                                                            SHA1:BC08AE91A1D65EA1B0395B5F080F1B64B9B77CBC
                                                                                                                                                                            SHA-256:E30D87D35857D8007E8833A2951591585ADAB2D69614EC49584DCC468BAE9594
                                                                                                                                                                            SHA-512:399B70FCE8C0AAE1B1E4938A03A09E863A12E73CC6F5935BF5CA30EF1E0A94E90D7EA4A5D45B3E032C7552177D58B15DCD8647664BFD002BDEEF387F8587E2AA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "D.l.te si starosti s t.m, .e budete sledov.ni online?",.. SEARCH_TOAST_SUB_HEADING: "Pou.ijte prohl..e. DuckDuckGo s ochranou McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Soukrom. hled.n. s prohl..e.em DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} zaji..uje, .e historie hled.n. z.stane v soukrom..", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Funkce Bezpe.n. hled.n. McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blokuje .kodliv. odkazy ve v.sledc.ch hled.n..", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo bude pou.it jako v.. v.choz. vyhled.va..",.. SEARCH_TOAST_YES: "Vyzkou.et soukrom. a bezpe.n. hled.n.",.. SEARCH_TOAST_NO:"Ne, d.kuji"..}..//78E4C8A9ECD3F14644932DEEE8E0AFB4C675FE05800A7A6CF3878450A30239CC217CED8EA015DF6315C7BB6CF8657C8A459CAED3F2215AF27BE20BBF4357E2FD++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):900
                                                                                                                                                                            Entropy (8bit):5.583587789385049
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyODmFK9r7NWME1jdHvyjC8C9JYBjdHjda88SjNwojdbnEl48twdLORxG/kTAl:7HOvCQ9NWMEcCrYFnwinQ4KwdGkeLW
                                                                                                                                                                            MD5:A795497E5B860214E7B321E7E62C3DA6
                                                                                                                                                                            SHA1:DA11CF3323379526CC743F9034A66D00C258E91E
                                                                                                                                                                            SHA-256:80C415DC74EF8B294C40BF7D517DAE61B2004F870CB61DF1162C0B30843653C0
                                                                                                                                                                            SHA-512:A4FDA7FCDFA5A407E9CD28212029447A07194B6727BF8F4E018F82E0836E7CBA04CC67244ED583D42FE070E3A4890D98739643C073CCDC9F5D1392F476C93D8B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Er du bekymret for, at der bliver holdt .je med dig online?",.. SEARCH_TOAST_SUB_HEADING: "Brug DuckDuckGo sammen med McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Anonym s.gning med DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} s.rger for, at din s.gehistorik forbliver anonym.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee Sikker s.gning", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blokerer skadelige links i s.geresultater.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo bliver din standards.gemaskine.",.. SEARCH_TOAST_YES: "Pr.v anonym og sikker s.gning",.. SEARCH_TOAST_NO:"Nej tak"..}..//453BECE13AB4A6814C489EDA7109940ED88D91DD5238443CE3E44645B4844D55BC9A6BA7AD9C665FF1AAF719920BDB55A0159D69B86766BDFEC186B1220F7CA7++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):936
                                                                                                                                                                            Entropy (8bit):5.5537200344672035
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOIV8tfCIjdHkjPqqbjdHjdar9jICnqjkjdAhalRVnzQYjLzg0QjNNO+NOr:7HOvc8yqrLLBQJ7NO+Ur
                                                                                                                                                                            MD5:62C9351571E9B70C529B0BBE1650E186
                                                                                                                                                                            SHA1:6E685D1681C6F68969C89F31A774D496A3619D0C
                                                                                                                                                                            SHA-256:FFB02A8085057968BE4193592191A4092C6D1889061AE0B0945A438DAFE3D474
                                                                                                                                                                            SHA-512:D8A08A9E0E925E9163E1B96E009482839CC3478F69A90746B8F70558654B78331A708A385AB4FDFEA69200CBFBF1C835C60E987731AEFC27E1F619308FE6455E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Sie wollen keine Online-Tracker?",.. SEARCH_TOAST_SUB_HEADING: "Verwenden Sie die McAfee-Erweiterung in DuckDuckGo.",.. SEARCH_TOAST_BULLET_STRONG_1: "Privater Suchmodus in DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} . damit ist Ihr Suchverlauf f.r andere nicht sichtbar.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee Sichere Suche", .. SEARCH_TOAST_BULLET_NORMAL_2: "Die Erweiterung \"{0}\" blockiert b.sartige Links in Suchergebnissen.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo wird als Ihre Standardsuchmaschine festgelegt.",.. SEARCH_TOAST_YES: "Private und sichere Suche testen",.. SEARCH_TOAST_NO:"Nein danke"..}..//20B5260045C69615632672AC3CD0104B1E57CB0B1EDAB5EAA6C5CD79FBDB87FE48A21A362CA91007DFAD49E2D30322E897327AB0344F24F7D6005A19030E1CCA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1278
                                                                                                                                                                            Entropy (8bit):5.518147815258277
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOvdVOfNkrI8gvMi3QonM4diUPg4Z3TarwS3:CvdAVktgfQoMmiUDZ3TCn3
                                                                                                                                                                            MD5:9E2749A40AC2137D7873258524ACE18F
                                                                                                                                                                            SHA1:C945B26AC96CEC907F21529DCE13F5028DF9D53A
                                                                                                                                                                            SHA-256:4A5E4A85DA24C9485263FE4397727798F0A6B295CFF63AAF2A838FA6AD919DB4
                                                                                                                                                                            SHA-512:6ED7AB68286094A463F5A0C84D124409DCFF7BC65DE5AC57B3FE02DB8CDCFF2637D95B968DAB4906D7FA0CB0D8254B5BABD5D1C5243624663254C067F6DA1C93
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "... ........ .. ........... . ............. ... online;",.. SEARCH_TOAST_SUB_HEADING: ".............. .. DuckDuckGo .. .. McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "........ ......... DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: ".. {0} ..... .. ........ ... ........... ... .........", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "....... ......... McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: ".. {0} ......... .... ........... .......... ...... ... ............. ...........", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: ".. DuckDuckGo .. ..... .. ............. ......... .......... ....",.. SEARCH_TO
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):851
                                                                                                                                                                            Entropy (8bit):5.539248357264239
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyO8zqqNPR4t1jdHMLBjaPCuYh8jdHjdatBjPvkTzgjdA8xvsHqZOdszXpO9bF:7HOv8moyALKFYhl5kTzqsHqlzXKqc
                                                                                                                                                                            MD5:F9E842F3615AB3A48C6F73DCD7AB9F5B
                                                                                                                                                                            SHA1:14B77175DA047BBB62A0F2BA1897B9C87F1F975C
                                                                                                                                                                            SHA-256:2A8349A0FB11C957DCA4BBC666D08B171C3D5C18E984F9DD113B65DC6F08E675
                                                                                                                                                                            SHA-512:A4E16CC39D674755C6E570F7429E99F9D5DEA0337ED2DA5722CFB05A1C36FAAB40A3965A10E5CD86F66E0C86AF0B0B6DC917EE4D881E2DA51D228FA83DD508D5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Worried about being tracked online?",.. SEARCH_TOAST_SUB_HEADING: "Use DuckDuckGo with McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo Private Search", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} keeps your search history private.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee Secure Search", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blocks malicious links within search results.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo will become your default search engine.",.. SEARCH_TOAST_YES: "Try Private & Secure Search",.. SEARCH_TOAST_NO:"No thanks"..}..//1F6BBD78FF71A6E86A22F74CF8885B3CB12921D09A7B00C7F6D9E6C2E66154E368C4F2328CB80CAEB93836A62D76DD4EF6D47EF8D0F5C2884016C84145F40947++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):945
                                                                                                                                                                            Entropy (8bit):5.566317231814581
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyO9ocZRs11jdHCajW7SuTQQQjdHjd0Fmzjq0KdQjdEiSZSUjETASKse+krTq6:7HOvy71A7JPmS0gR54TYzmH8v
                                                                                                                                                                            MD5:EFA7F2BE0D78290500250354A70DF1A5
                                                                                                                                                                            SHA1:9B120B02B9956EAF2F453F0C7E4C3693D26080AA
                                                                                                                                                                            SHA-256:9F39A16F86B26E6A6D92816FD89AE93477BE0853CE3D4472A9E86811F6AE9F0B
                                                                                                                                                                            SHA-512:999846F8DC5C42BFC08826BE6BACCA591A0A3B7FA59013F11B523118E5DC8851162C02D9BD926FC5342A975E44CB62A12D2FCCFF8BE8F23EE416411AF23BA043
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: ".Le preocupa que rastreen sus actividades en Internet?",.. SEARCH_TOAST_SUB_HEADING: "Use DuckDuckGo con McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "B.squeda privada de DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} garantiza la privacidad de su historial de b.squedas.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "B.squeda segura de McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} bloquea los v.nculos maliciosos en los resultados de sus b.squedas.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo ser. su motor de b.squeda predeterminado.",.. SEARCH_TOAST_YES: "Pruebe las b.squedas seguras y privadas",.. SEARCH_TOAST_NO:"No, gracias"..}..//2CC7F7DE8FB2FB8F2D23DA93931DC7E74286D496627D3890C9B4F68A2E560E1C0D5F5C56A66878CF66A2D2B212647AE9774E5E623F37A5EE66A7CCEB1AE4153C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):925
                                                                                                                                                                            Entropy (8bit):5.5849308487806795
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyO9ZHhHmdks11jdHCajZyFK2jdHjd0Fmzjqrpo3FK2jdEDE/ZSUwIesOFsJzR:7HOvdHmdN1nnzmSiA74HcHy
                                                                                                                                                                            MD5:FC39A3F152024DBB756DB5AC6BDD5B62
                                                                                                                                                                            SHA1:72E644ADF19CF079367754BCFF0A82BA86549BC4
                                                                                                                                                                            SHA-256:A3DBC64103C0AC500B6B62EEAF56C5894E58A9FA4E27AD83AA8C6EA1F8E81FBA
                                                                                                                                                                            SHA-512:C0881795BD47A28E05D92E18DE50B627E1C1B3B5A78A892171E16894BCEB26EAAB0A31307E658DE0D08098E4791220283EFF18234671B7E0AD02CB2028B9F977
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: ".Le preocupa que lo rastreen en l.nea?",.. SEARCH_TOAST_SUB_HEADING: "Use DuckDuckGo con McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "B.squeda privada de DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} mantiene confidencial su historial de b.squeda", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "B.squeda segura de McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} bloquea v.nculos maliciosos dentro de los resultados de b.squeda", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo se convertir. en su motor de b.squeda predeterminado.",.. SEARCH_TOAST_YES: "Pruebe B.squeda segura y privada",.. SEARCH_TOAST_NO:"No, gracias"..}..//3D2C0AE6485024CF92B23EB01DD8179A977718DA7F854638666EF61B95C62C645B7527A63372E0E6A3D037D38D349760A50A939A7549BB1C97F6A87F75B473A0++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):870
                                                                                                                                                                            Entropy (8bit):5.535887266500711
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOmciWozjdHJmavj+rUEpjdHjdXpvjm0QCojd6U9hZ/kTIzRiFbSYE+s8:7HOv7iWoCUEBJOhuTI9GM+B
                                                                                                                                                                            MD5:21F24F0372570F17FE9AB75F1331F96E
                                                                                                                                                                            SHA1:4E9F36786F379DA7580D7A515F14F8E2C00DA32E
                                                                                                                                                                            SHA-256:462D9A1E2301118CA7C6797F8F35BA39A28D0B3F3CE823A1DF80966F7DC4AAD2
                                                                                                                                                                            SHA-512:E92E938F6D54A2FEAC2DF49D6BBE5F8DE7B965F971D939F619BEC49E75C64D654405C792CDFE874E61A50AED0717D12A05DCCD0383ACADDA00A71E7D91D01B6F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Huolestuttaako seuranta verkossa?",.. SEARCH_TOAST_SUB_HEADING: "K.yt. DuckDuckGota yhdess. McAfeen kanssa.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGon yksityinen haku", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} takaa hakuhistoriasi yksityisyyden.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfeen suojattu haku", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} est.. haitalliset linkit hakutuloksista.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo valitaan oletushakukoneeksesi.",.. SEARCH_TOAST_YES: "Kokeile yksityist. ja suojattua hakua",.. SEARCH_TOAST_NO:"Ei kiitos"..}..//1EDE6C7C81D1A8A01496AC68C635E667AD8A61F644BC3A913F15C4BFB8E84A26ECC168874847DBE2868D8C7D920A9F3D80963B1D37C3A13EF9244022711295A0++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):954
                                                                                                                                                                            Entropy (8bit):5.52620674882107
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOZKM/Jvf1jdH+9kRjBjdHjd55wjq39M5vjdShWvw/jFeOBjgVfx:7HOvBRMkbb7Wvw/jFeqjWx
                                                                                                                                                                            MD5:A2425A5D97FB524D51ED0098C4944361
                                                                                                                                                                            SHA1:A603A364A603F22E0F36FB45483E1915C53599E9
                                                                                                                                                                            SHA-256:961FC9B98AD67E001A3D1B7020E18BA9A1D75BA3980C8209319740A98ABA338D
                                                                                                                                                                            SHA-512:C473FBC791B9CF58290AE27C9F0676B28EFB3D9FB9647B8C7A449238F0F3B1A1D10C9BFBDA2F38D2A5D0F5B4F712269366743B1D4F7A6D7686B3CE8FFBE8D6D7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Inquiet d'.tre surveill. en ligne?",.. SEARCH_TOAST_SUB_HEADING: "Utiliser DuckDuckGo avec McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Recherche confidentielle DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} pr.serve la confidentialit. de votre historique de recherche.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Recherche s.curis.e McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} bloque les liens malveillants parmi les r.sultats de recherche.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo deviendra votre moteur de recherche . d.faut.",.. SEARCH_TOAST_YES: "Essayer la recherche s.curis.e et confidentielle",.. SEARCH_TOAST_NO:"Non merci"..}..//3A18BBCCF24ADEA3BBEE07D7440F6C54FA3FCFD2263540CBBA07D56F6DC1F1FCA55B6A4F607DFBC09F28DF7DAA3BC3355085EA12D1FF32DEE2094E82EE204E0D++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):949
                                                                                                                                                                            Entropy (8bit):5.553229361376515
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOR04/yohvf1jdHUzhCSjm+MjdHjd55wjDDJ3tp5vjdG4kWYXF9owhBbhvUY5:7HOvVyoRAzhNwKTkWYcwh5Bd9js+MS
                                                                                                                                                                            MD5:EC0E360434D61628F708F117FCFA8AAE
                                                                                                                                                                            SHA1:4C30BE0D7C68CD08276012BBBBBB339A69E825A0
                                                                                                                                                                            SHA-256:1BDB727046B0D9DAFD819E9CCEB9480C496867B7ECC05D69B615B877F5E1B932
                                                                                                                                                                            SHA-512:4AB8B304EA0C638EBCCA9B09ABF82E6272DBC34F3D6BD6028063A9F74E4B5671C838B1EDBC12200A34D3FB633ACDE354732A0D0655E24DE9116C4BA0AB87EB12
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Vous avez peur d'.tre suivi en ligne.?",.. SEARCH_TOAST_SUB_HEADING: "Utilisez DuckDuckGo avec McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Recherche priv.e DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "La {0} assure la confidentialit. de votre historique de recherche.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Recherche s.curis.e McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "La {0} bloque les liens malveillants dans les r.sultats de recherche.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo va devenir votre moteur de recherche par d.faut.",.. SEARCH_TOAST_YES: "Essayer la recherche s.curis.e et priv.e",.. SEARCH_TOAST_NO:"Non, merci"..}..//08CFD540ABCCBB01C658146D9633E0AC86CBDF8D9850D902A10E7760ADB2A346DCA0DFE3EC0AF5D44DF80A9063794BF3986286A3AED347F647F4B89F26A2979E++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):931
                                                                                                                                                                            Entropy (8bit):5.602724631555376
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOXmRUFqyW+1jdHOhjsgv2jdHjd6D39hjpfzJujdXoBcBw1S9Ieziy95v:7HOv2iYT+0vBZflUZVzz9J
                                                                                                                                                                            MD5:30626AA664B4C8817732C3C47E91372B
                                                                                                                                                                            SHA1:52EC037B682AFD550BF832136B546931C40303C5
                                                                                                                                                                            SHA-256:833908A51251BFEA658A1EC3F4B6EF75AA72FCC7CE3832F7AEF6015C99394547
                                                                                                                                                                            SHA-512:F9A80716758B9BD8A2821110A653A9F3BCF765F9F703AFFBA234C14CC2A68260A5190AAD03F1E44734208F08CB180174E6DD909B30F1B56A591C73A0D709D864
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Zabrinuti ste oko pra.enja na internetu",.. SEARCH_TOAST_SUB_HEADING: "Koristite DuckDuckGo s McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo privatno pretra.ivanje", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} dr.i va.u povijest pretra.ivanja privatnom.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee sigurno pretra.ivanje", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blokira zlonamjerne poveznice unutar rezultata pretra.ivanja.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo .e postati va. zadani alat za pretra.ivanje.",.. SEARCH_TOAST_YES: "Isprobajte privatno i sigurno pretra.ivanje",.. SEARCH_TOAST_NO:"Ne, hvala"..}..//7FCF789AE4D975F2BC9B78540C9A897CFDA71BE95818CF6FE1A9D223BED7B6058A8F29A238F0E08946805E22692736613AFF078418554484EBA70DEEA0B498FE++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):989
                                                                                                                                                                            Entropy (8bit):5.713237710998534
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOaC24TjrjdHGSHBjXllzFrYjdHjd8dHBjzEfCsbV0kjdUcjaSC65dGE76U87:7HOvaH6ESZzFddFE8dTadv6U8bZdyYn
                                                                                                                                                                            MD5:CCA7BB471FD815B5B22F69B9BECD669D
                                                                                                                                                                            SHA1:EB434E3936FE8479B15E2300BBDFB118812D181A
                                                                                                                                                                            SHA-256:70B3B929106A75E25C7E4212E5919DC9C099FC5C19BC8D025758B02E0F595CB6
                                                                                                                                                                            SHA-512:E332C5FB88FBAA4556FA658BBFBA5C21F6A1E427F624A7BDE74D5593D076B44B94343592C4EEE8C95C6063DC376F38F928EFD753A5597479E7AF093B3FED4274
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Agg.dik, hogy k.vetik online?",.. SEARCH_TOAST_SUB_HEADING: "Haszn.lja a DuckDuckGo szolg.ltat.st a McAfee-vel.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo priv.t keres.s", .. SEARCH_TOAST_BULLET_NORMAL_1: "A {0} gondoskodik arr.l, hogy keres.si el.zm.nyei szem.lyesek maradjanak.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee biztons.gos keres.s", .. SEARCH_TOAST_BULLET_NORMAL_2: "A {0} blokkolja a keres.si tal.latok k.zt a rosszindulat. hivatkoz.sokat.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "A DuckDuckGo lesz az .n alap.rtelmezett keres.motorja.",.. SEARCH_TOAST_YES: "A priv.t .s biztons.gos keres.s kipr.b.l.sa",.. SEARCH_TOAST_NO:"K.sz.n.m, nem"..}..//866BCE4F4124715994B9EFD585EB316B45D54DE9ABE229CF779B3D8C8D58073BF160A55F6082E6B912480BFCB46C93EB4C0E8391923A0149A3994CD4964DE267++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):886
                                                                                                                                                                            Entropy (8bit):5.455323924505363
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOfOMUUAR11jdHbFLjichFDojdHjd1TzjX+BbtAfpPjdEira8KF6wGysnnL/e:7HOvfa1fhFwTv+MfQiraewT6yt
                                                                                                                                                                            MD5:93C2A38A943F3FAC0C44C9809F113BD8
                                                                                                                                                                            SHA1:FB8254401C4155B7F4D535E0EB576C85B842334E
                                                                                                                                                                            SHA-256:BF0F6785F4FDDC680DDA874F9E1D4CFAB21ACBF8C301951266A2261B73CE7577
                                                                                                                                                                            SHA-512:A3AD58A7B5D4A8B404AAF85DA9FA9BB2012F196BF0E02564614F523380B2641D518F9FFF97029A2E882249FA8AA5D1897AAC157DEA37329C64FF74D5222B419F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Temi che le tue ricerche online vengano tracciate?",.. SEARCH_TOAST_SUB_HEADING: "Usa DuckDuckGo con McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Ricerca privata DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} mantiene private le tue ricerche.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Ricerca sicura McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blocca i link pericolosi nei risultati delle ricerche.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo sar. il tuo motore di ricerca predefinito.",.. SEARCH_TOAST_YES: "Prova la ricerca privata e sicura",.. SEARCH_TOAST_NO:"No, grazie"..}..//A7499B4C185993FBBD5EAB660B5FF8BDBD534CD3A3DF5CD855718A0CECBBD8BCF201CC03CB79D9CF5BE90100A515A299A20FD9DB258E3B507C970D75321A7E65++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1089
                                                                                                                                                                            Entropy (8bit):5.8955240087132745
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HO+ok2PLDnWzuynP6aG3/jD9vEU0nWzAAH9rEmlFIGx+:CZPQiaG3/v9v39EGs
                                                                                                                                                                            MD5:DEFA627147C91E3C12C6004FC297D12E
                                                                                                                                                                            SHA1:851AACD95AB4DA0CCD004E3A4691BA32FFD13279
                                                                                                                                                                            SHA-256:18BF713D55F8C89E1107BFFB23E2F00020476A7E9C0CD70F2E2C8790D596D36E
                                                                                                                                                                            SHA-512:5349D2D7118A2DDC86B074667003FA05FBEF398CF1E5744DF424762886BAFD938A470705C964F05D19D9D4980F0488BC733E22E58FF23ABEC8ECD47792032D86
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: ".........",.. SEARCH_TOAST_HEADING: ".......................",.. SEARCH_TOAST_SUB_HEADING: "......... DuckDuckGo .........",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo ...............", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0}...............", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "..... .... ...", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0}............................", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo ...................",.. SEARCH_TOAST_YES: "....................",.. SEARCH_TOAST_NO:"..."..}..//7EEFF685C98A6C86E3375E6A00FE427BFA3FDA64E
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):961
                                                                                                                                                                            Entropy (8bit):5.986397871278456
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOVlzFX8YwOhLRjdH2Zvj0qSwjzjdHjdipvjZF3jlESzjdQecDhLpjCn+OHeOdo:7HOVsYwO9mpSP3REz59pe+hO1YhD
                                                                                                                                                                            MD5:14F347718FAD5752880CEC5B08DD3BED
                                                                                                                                                                            SHA1:35484FE06D5FB4444356C36B1480BA0B99F64809
                                                                                                                                                                            SHA-256:9129C0820EF0C58CEB174F14200B0AF9198596EF052FB4C07F5B135B7A5097D5
                                                                                                                                                                            SHA-512:CC866DFD0EC93DA0D84274FF403F888992496D99B9DCFE58EAB4F5CAEC223809F058E5CE5987FE7B1C5E9E9E189A9888ACB4DE815C373C50B6647BCE1C8A32F1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "......",.. SEARCH_TOAST_HEADING: "... ... ......?",.. SEARCH_TOAST_SUB_HEADING: "McAfee. .. DuckDuckGo. ... ....",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo .. .. .. ..", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0}.(.) .. ... .... ......", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee .. ..", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0}.(.) .. .... .. ... ......", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo. .. .. .... ......",.. SEARCH_TOAST_YES: ".... .... ... ...",.. SEARCH_TOAST_NO:"..."..}..//34D180B77E21B01CE282AC79BC2E23DB886233349B8F2600E275E3B920BE926B8D8EB6ABACB4199B931D4BA30EE47710C848A099860A916973F861A4576E134A++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):845
                                                                                                                                                                            Entropy (8bit):5.5416390947886915
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyORW/G1jdHMLBj+WjdHjda+jns4jdHnfUMX4MFPYTDv86I:7HOvmGAL4mnfoMFwU6I
                                                                                                                                                                            MD5:015DD8385BAA2A703041AC3DB5E90989
                                                                                                                                                                            SHA1:78D5BE1D58951E70A8F97F347A4658FD929E76EA
                                                                                                                                                                            SHA-256:8D193A110819F6C2F759694AF67346E981884F32A332CE310422AD6056D518F5
                                                                                                                                                                            SHA-512:98405C01D5D3C6AFD07F821145BB7B4EBF1D14F7984CBB8AD83FCFAE39BA3FA23C263BE38A9D4951127FDBBF49461BDD16E4C8F5EDD55CC0E536E5B600D1F8D5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Er du redd for at du blir sporet p. nettet?",.. SEARCH_TOAST_SUB_HEADING: "Bruk DuckDuckGo med McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo Private Search", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} holder s.keloggen din privat.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee Sikkert s.k", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blokkerer skadelige koblinger i s.keresultatene.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo blir standard s.kemotor.",.. SEARCH_TOAST_YES: "Pr.v Privat og sikkert s.k",.. SEARCH_TOAST_NO:"Nei takk"..}..//A3C20748E79E79060337391538E8AFB06542F14EA9687EFA410B6672B2C5A44CD6EFA8086A3E3A887A23EA0208E6CC59DCECE178755F9EAC4498A6BD3B4C3A15++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):872
                                                                                                                                                                            Entropy (8bit):5.575280179937842
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOEKAQ1jdHcxRVjWw5KAjdHjdJMyVXjjvc6jdAYy0IYywQsHLFLdGvWsn:7HOvEPQCRsFCZ6dwQgnCWsn
                                                                                                                                                                            MD5:4AE3B6469961C258E33B47F2CB59106C
                                                                                                                                                                            SHA1:8F06FD4DF1F7C972F9DC239768CA24378EB2BD1A
                                                                                                                                                                            SHA-256:46BEB4D3A922BA7A94846607208F461EAD79C91DB1005D98E2AF117A7F360B56
                                                                                                                                                                            SHA-512:7C3366AB4220E3DFFDC13BC68F5CDCD91F39E28E44978827A584E63C6C8311918140276B01A5F237CDE18A8BDCCE89D05250224C8B1C928302C4A8673AE38FD2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Wilt u niet online worden gevolgd?",.. SEARCH_TOAST_SUB_HEADING: "Gebruik DuckDuckGo met McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Priv. zoeken met DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} houdt uw zoekgeschiedenis priv..", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Beveiligd zoeken van McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blokkeert schadelijke links in zoekresultaten.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo wordt uw standaard zoekmachine.",.. SEARCH_TOAST_YES: "Probeer Priv. zoeken en Beveiligd zoeken",.. SEARCH_TOAST_NO:"Nee, bedankt"..}..//10DDB4C652C040546E705001ED34439514CEA3E569EEB41B46DD67684BF4DC190BE125EE61087D8A8454C84109337C1D65B1F74668B7248BB6BA7CA344475A89++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):954
                                                                                                                                                                            Entropy (8bit):5.751602836444056
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyO7RR9AOx1jdHZ3LPjgnH8co3L/ujdHjdJ+ot3LwjNIg/Q3L/ujdEv3X2WJty:7HOv7riOxBHc8doB0k/fX2eB1W1oIr
                                                                                                                                                                            MD5:8E26BF7C12E07F410042FD9407770BF2
                                                                                                                                                                            SHA1:BEFAE78976B7F10569F41D2ECE33FD0447241BD4
                                                                                                                                                                            SHA-256:014C2194DA2357B03ADD7A350D38F8E9F72D0AC570349D05A0EBF201A64F5CC4
                                                                                                                                                                            SHA-512:5E185E487D4B3C11900E8B9D9536C9AD688C8ED27FA1A1DF7F86FED258972EF999E5EEA74154A53D7CFE0225EB58CF7CCF47ECDCC164392C1B609B791CDEDBC6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Obawiasz si. .ledzenia online?",.. SEARCH_TOAST_SUB_HEADING: "U.yj przegl.darki DuckDuckGo z produktem McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Prywatne wyszukiwanie DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "Przegl.darka {0} zachowuje prywatno.. historii wyszukiwania.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Bezpieczne wyszukiwanie McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "Przegl.darka {0} blokuje z.o.liwe ..cza w wynikach wyszukiwania.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo stanie si. domy.ln. wyszukiwark..",.. SEARCH_TOAST_YES: "Wypr.buj prywatne i bezpieczne wyszukiwanie",.. SEARCH_TOAST_NO:"Nie, dzi.kuj."..}..//E03606EF8215952BB9F638478B67D9C6747E55499DE3441D7704CA699722694ED368ABD0AC39472B680766D43E11B63B1436A4CC0A2B6C64E30D91657E383E0F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):905
                                                                                                                                                                            Entropy (8bit):5.557943167508346
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOamduRsK1jdHMLBjSHajdHjd2OtFcjq/C9yd+WFujdEiXGunNwDFPGtjSXXO:7HOvam9KALhB60FDYnNsPGWi
                                                                                                                                                                            MD5:C0E235A82F47A50A456ECF4725749CA1
                                                                                                                                                                            SHA1:110FD8EE366CD684E250BE399D2213BAB532BE2C
                                                                                                                                                                            SHA-256:BE0282812978AB1FBEE24080F9F342FF97772C41C4F130C5B9B03F8D9AF5ADD3
                                                                                                                                                                            SHA-512:EA732ED8345245923AD0C0CA79EEF6E6E198F3F82EC490751E8D4D8720A2AACFCD4C2F1349CAD51E749322CA57AA3DAE9BFDCA72170AC343386BC7994581DEFF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Preocupado com ser rastreado online?",.. SEARCH_TOAST_SUB_HEADING: "Use DuckDuckGo com McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo Private Search", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} mant.m seu hist.rico de pesquisa em privacidade.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Pesquisa segura da McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} bloqueia links maliciosos nos resultados de pesquisa.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo se tornar. seu mecanismo de pesquisa padr.o.",.. SEARCH_TOAST_YES: "Experimente pesquisas privadas e seguras",.. SEARCH_TOAST_NO:"N.o, obrigado"..}..//6B7AE701F838F08D676057D561B3DE5CA4B48101AEAD7466F557A1B351ED31F5644BD5068060D6B20238464CDB3CAD1DECA2902CBD400B27BE980F2BFB00C5DD++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):949
                                                                                                                                                                            Entropy (8bit):5.57686809243626
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOwON2GFfK1jdHcwOFoSjPH5jdHjd2OtFcjq/CGMoujdvIjmg57IIePGtjMRQ:7HOvwONFFfKEG+B6Ur5wPGSRvT5T3e
                                                                                                                                                                            MD5:E7C848CC8BEC0EC6FC7D81A2B790B7BC
                                                                                                                                                                            SHA1:DE0AD53FD818B388BA8656D4CDEC72B5489568BA
                                                                                                                                                                            SHA-256:A75ABDD5C74CA29B64E087B5FEEE9EA67DD7BA0A9F88609D225EE95B0E8AD8BC
                                                                                                                                                                            SHA-512:FC3AB831CE6375B778E83860B3D96F3CA11262B883DEEEFC66B55CB13FDD92272011CC378C7EEC01DEB1BE32B0A4E31F96DFC0FF833B808B1643C79AB993520C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Est. preocupado com a possibilidade de ser monitorizado online?",.. SEARCH_TOAST_SUB_HEADING: "Utilize o DuckDuckGo com McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Pesquisa privada do DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} mant.m o seu hist.rico de pesquisa privado.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Pesquisa segura da McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} bloqueia liga..es maliciosas nos resultados de pesquisa.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "O DuckDuckGo vai tornar-se o seu motor de pesquisa predefinido.",.. SEARCH_TOAST_YES: "Experimente a Pesquisa segura e privada",.. SEARCH_TOAST_NO:"N.o, obrigado"..}..//DB4E124205BE5E52D854D8513D6A5C19DC939BA164EF1B591E98E6EC6A2B74BBE48397D7F59069967AF6C8D8CA06312BA5AA04CF76FAA944A677AF782641D530++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1248
                                                                                                                                                                            Entropy (8bit):5.455304470642038
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HOvEzOMHAIonuRIovfPFt5rNlvytaiSAF+RQX/XJfzi+HtrXW:CvEK6AuLfPFPfvyciSAFffJ2+Htrm
                                                                                                                                                                            MD5:E285DD50E8492E68D9879BEFF16C24C3
                                                                                                                                                                            SHA1:573D97F2752D3B185D88BA1B22F01A838406D03E
                                                                                                                                                                            SHA-256:B8CFF6506B014BF2F33CEBD2213B6F187DC984D888C93A2632588729E795651B
                                                                                                                                                                            SHA-512:CE0947867FF21B9AE3D89CF05F3BD5373EDDF4D909410A54C5D186B3E54F1AF5BDE8C929B277AE9CC86A4663276390740E79A7487C52D6A5190000770B767988
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "............ .. ...... ............ ...... . .........?",.. SEARCH_TOAST_SUB_HEADING: "........... DuckDuckGo ... ......... McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "................ ..... DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} ......... .................. ...... ..... ....... .......", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: ".......... ..... McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} ......... ........... ...... . ........... .......", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo ...... ..... ......... ........ .. ..........",.. SEARCH_TOAST_YES: ".......... .
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):959
                                                                                                                                                                            Entropy (8bit):5.802499279139034
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOuKOG811jdHvXjy9RDujdHjdVlj6cKj/ujdDEmy9g72ckfDKeN3QV+D6O:7HOvuKp81rOOI7jRN9Y2ckfDV3Qcp
                                                                                                                                                                            MD5:74BD8CFC00F8CDF39E5C2372676467BA
                                                                                                                                                                            SHA1:2D9685E03CF4FC928B52B7215108213B8EB1E930
                                                                                                                                                                            SHA-256:5BBE2B57EA87C658089B32230959554EF02AB6E3C56C90215D52D208877A1EE1
                                                                                                                                                                            SHA-512:81E59973DCA8419D7CF03383B066068311DE19A15B6AE88AF9266236D2171F0F7D9120488DCF077061A7389255EBF7E318B6EBD21D248BA7585519D1E59F3F69
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Ob.vate sa, .e v.s niekto sleduje?",.. SEARCH_TOAST_SUB_HEADING: "Prehliadajte pomocou DuckDuckGo s.ochranou McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "Anonymn. prehliadanie DuckDuckGo", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} zabezpe.uje va.u hist.riu vyh.ad.vania.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "Zabezpe.en. vyh.ad.vanie McAfee", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blokuje .kodliv. odkazy vo v.sledkoch vyh.ad.vania.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo bude predvolen.m vyh.ad.vac.m n.strojom.",.. SEARCH_TOAST_YES: "Vysk..ajte s.kromn. a.zabezpe.en. vyh.ad.vanie",.. SEARCH_TOAST_NO:"Nie, .akujem"..}..//796B067838DC6674E8B3E2A13540570175B9C6A0A28D9AF3D02A2B321560852FA40D85B15B0F1B1C06E3278ED1E1694C75E1001DA6CC7D19FEDA5131127BE339++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):899
                                                                                                                                                                            Entropy (8bit):5.611279847020601
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyO5bp57xqyeE1jdHqj81jXjdHjdSjqQf7jdXoBSLgOYk/fhpNBmjcu4GTy:7HOv5rcsh1jlQfddLj//ij+
                                                                                                                                                                            MD5:553C67EE6AA012C0070A022A9789BAB4
                                                                                                                                                                            SHA1:E93AA806D9B73A6A08429D78590ABF2C334C33F0
                                                                                                                                                                            SHA-256:14DE1BB65D9A9DE1273C6D1AD14B686EAA2496A89D9B443062BEFCD6DB733BAB
                                                                                                                                                                            SHA-512:12E05FEBF3FD17C80379D39E5C4C6C741D07A7C519C44656E6E04DB45104C82CFE7C18FEF39C8B1C7BE5D3CA5B2152DFDBCD41732C150AB624A13950EBF21574
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Brinete da ste pra.eni na mre.i?",.. SEARCH_TOAST_SUB_HEADING: "Koristite DuckDuckGo uz McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo pretraga uz privatnost", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} .uva privatnost va.e istorije pretrage", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee Bezbedna pretraga", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blokira zlonamerne veze u rezultatima pretrage.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo .e postati va. podrazumevani pretra.iva..",.. SEARCH_TOAST_YES: "Isprobajte pretragu uz privatnost i bezbednost",.. SEARCH_TOAST_NO:"Ne, hvala"..}..//E5BA3232DFEA9DC34195A10163F9DE28B68C3F0434B326B3CF281367E6B6375E8759F2E92C156014B4CD72A9F1FD87632CA601E766A0DB6BC9A719453C64F4FA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):855
                                                                                                                                                                            Entropy (8bit):5.62439385080059
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOP10P/1jdHgjNejdHjd6HjSEqNjdc+yJLzwd3IBzgCXa333yd:7HOvt0XKYEV+yJ/wFIl5
                                                                                                                                                                            MD5:7B3E55118C8CC897C81C1490E1592E78
                                                                                                                                                                            SHA1:C4EBC15A02738B4656D212288BF4038716540325
                                                                                                                                                                            SHA-256:4B1F5D7EF73AE33F1ADD3A93A7854812CDA70AC4A54D0FB37C4563ACB6E2E97F
                                                                                                                                                                            SHA-512:B634317227FDE4B5888D6AFFF4A5D2172CA4080FF69E7ECFA176D3525F213A8DC1654EFA2920D9775BDE223AE72C9C525128427648F1841E834CAEF6783B262B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: ".r du orolig .ver att bli sp.rad online?",.. SEARCH_TOAST_SUB_HEADING: "Anv.nd DuckDuckGo med McAfee.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo Privat s.kning", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} h.ller s.khistoriken privat.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee s.ker s.kning", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} blockerar skadliga l.nkar i s.kresultaten.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo kommer bli standards.kmotorn.",.. SEARCH_TOAST_YES: "Testa privat och s.ker s.kning",.. SEARCH_TOAST_NO:"Nej tack"..}..//40420EE3C4957B88336546C5E19F3833F71175BE18E14ADD7D684C61E27AD71E5D19939A6054238013FC1D23DC2B419904C4E6F572CE6E7AB1C591750FEA0055++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):907
                                                                                                                                                                            Entropy (8bit):5.66545534231225
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOb0kPX0jdHCZjHvLWjdHjdatBjQ8JI3chAjdKlaUAcYQHcnT5O9a1J6:7HOvb023vLrubY/YQyTD6
                                                                                                                                                                            MD5:824195E8529D49CE8DBB45AF8A4526B7
                                                                                                                                                                            SHA1:21652581D0B81873FCCF951656526E34373879FD
                                                                                                                                                                            SHA-256:5CA38765F950A69CFFF388F8151FC642D492AE6105B208C5D8712F00DA38A62E
                                                                                                                                                                            SHA-512:6C54DB399DCD21B2C88E0A5D1A0AD8A8DA46CFCC2648A736D8F9DB67AE28C252872DDFD4AAE06E571804B936050478189DA7E0D434EB450D7D07B5BBD3FBC1CA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: ".evrimi.iyken izlendi.inizi mi d...n.yorsunuz?",.. SEARCH_TOAST_SUB_HEADING: "McAfee ile DuckDuckGo kullan.n.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo Gizli Arama", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} arama ge.mi.inizi gizli tutar.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee Secure Search", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} arama sonu.lar.ndaki k.t. niyetli ba.lant.lar. engeller.", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo varsay.lan arama motorunuz olacakt.r.",.. SEARCH_TOAST_YES: "Gizli ve G.venli Arama'y. Deneyin",.. SEARCH_TOAST_NO:"Hay.r, te.ekk.rler"..}..//ED3B53EA73DDCCBB6789F16FCD0D2DFFFD3FE2E4A30029C5B00A24CD64D5C574BB6EE5D9FED833AAD6C56E2D369EF0111C878F8C4CCF2C21975FBD6D5CDEBD46++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):848
                                                                                                                                                                            Entropy (8bit):6.110407142276801
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HO+9p0jdH4Ly0jJwCjdHjdOZLy0j2u1AjdKeNygHChN3LUic3iIg4AVGTjaWC:7HO2Lyyw5LyHf8gHyLlc3lg4Asal
                                                                                                                                                                            MD5:A39B6756E0010C6EBCD6EACA04DA6CC0
                                                                                                                                                                            SHA1:9F1127CF76AD978B9B0DB35B1D79B08C7C683796
                                                                                                                                                                            SHA-256:548868E3D9A6594B8D09D343283F72BDB362B051BE1D5EB8265C2DA8F75735EB
                                                                                                                                                                            SHA-512:F9EAE08DD1815EE5296A63C4CD83B664B2936EF710E167278F37A32F2FA50F4A528462721A657FD240832348E1A238762B7E7C633E6CF05899771157AFABB038
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "....",.. SEARCH_TOAST_HEADING: "........",.. SEARCH_TOAST_SUB_HEADING: "....... DuckDuckGo.",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo ....", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} .............", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: ".......", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0} .............", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo ............",.. SEARCH_TOAST_YES: ".........",.. SEARCH_TOAST_NO:"...."..}..//B768A285DE0438C37B1EDEB07896374615C31BDD662914F3488856A3C0221F560B0F98EFC76CD03E2BCB009F39008F80EA0D7BD238DF5599E042099BAA882550++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):863
                                                                                                                                                                            Entropy (8bit):6.095775654474349
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HOyOOcMZGjdHMLBj8SC5jdHjdtjkYjd/eBAM+bCvieD6ijM:7HOvupLyFeF0mjM
                                                                                                                                                                            MD5:FD8E7E8D75FF63AD21740C9FCAC51E2A
                                                                                                                                                                            SHA1:2C05818D69258F6F1A88355453BBC774E93F8A2D
                                                                                                                                                                            SHA-256:191F5B43BDE8AC16BC8EB9F1066AEDDB946842515B0B6B3092DCE99D6E11FE32
                                                                                                                                                                            SHA-512:AF17FBD26DD80973BE49E85F823C2ACB147869CADFDFA218DF9EAAC37F14412B2FB18697088EF84C8C172B0CDD43CB358A4DC658F83BE97EE3616F015159CB3B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: ".........",.. SEARCH_TOAST_SUB_HEADING: ".... DuckDuckGo . McAfee ..",.. SEARCH_TOAST_BULLET_STRONG_1: "DuckDuckGo Private Search", .. SEARCH_TOAST_BULLET_NORMAL_1: "{0} ...............", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_BULLET_STRONG_2: "McAfee ....", .. SEARCH_TOAST_BULLET_NORMAL_2: "{0}..............", //{0} SEARCH_TOAST_BULLET_STRONG_1.. SEARCH_TOAST_SUB_FOOTER: "DuckDuckGo ............",.. SEARCH_TOAST_YES: ".........",.. SEARCH_TOAST_NO:"...."..}..//ED64C1C9AA14D2D938E79D24EEE6EFAA66AE3FD8D9E81D3E15A8C48791F0A4E78C142F1A77FA1F73D70C1F9354DED851C63C6901DB50FE640DAFD1479CD16818++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with very long lines (307), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):11879
                                                                                                                                                                            Entropy (8bit):5.001882854112839
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:CBketuJEUrvtH9Ai5trhElBXXrhEN1QtfT6GQ:CBksuJEUrvNyi5tKBnkQVOGQ
                                                                                                                                                                            MD5:AA5032FE9B433362F30769BD096D16C7
                                                                                                                                                                            SHA1:B6359895A8A5914CC05F9F7B7B1E510C429F1661
                                                                                                                                                                            SHA-256:2A7ED01FF290E87AFB4675ACC8FF32280778C81AD25C179F64A43FD38E6839BA
                                                                                                                                                                            SHA-512:0A144DD1BCD81704CDCC86609A0DED08A1424BA46BBF7172A36BAECBA9737E03BFB8E71F61CC1F2F9772354579FFBAA80BDE22AC6707A3E8FDF215CF193BF2CE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: ". ....... ......... ..... ................, .. ..... ...........",.. SEARCH_TOAST_SUB_HEADING: ". ....... ......... ... ........... ... ........... .......... ... ............ ...........",.. SEARCH_TOAST_BODY_TEXT: "...... .. ......... ..... ... .... ....... ... .... ............. ........... .. ........ ......... ..........;",.. SEARCH_TOAST_OPTION: "..., .. ............. . ....... ......... .... ... ............ ... ............ ...........",.. SEARCH_TOAST_DONE: ".....",.. SEARCH_TOAST_HEADING_COMPLIANT: "... ......... ... ...... .........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6853
                                                                                                                                                                            Entropy (8bit):5.365114021792175
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:Ckl7LklkKuaz45DJMtR4fAgK0vQ8jwsClwJcv+ztBDABrBN9FC1WgjsRBva54Apw:CkWF+Uturjjj42tBABrFoUgOBixBC
                                                                                                                                                                            MD5:A9AE28A871D67DC424035B1B5480C270
                                                                                                                                                                            SHA1:AF7A82B156EB8A3B6E2BC9635DB280F50E3C5082
                                                                                                                                                                            SHA-256:746942A655E5D62BD2E029D11B258B3E96B7D1680ABEAE6A8F1A59468C2B580C
                                                                                                                                                                            SHA-512:548337D20CC57583532F8B8EABE28099BE823A96025E941B631E83CA4D3B73BD72F04918329F1623E056003DC589894BE693E5E7DF213130735358BA26C51F57
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Secure Search is off . be careful",.. SEARCH_TOAST_SUB_HEADING: "Secure Search steers you away from risky sites in your search results.",.. SEARCH_TOAST_BODY_TEXT: "Want to stay ahead of the bad guys with extra search protection?",.. SEARCH_TOAST_OPTION: "Yes, turn Secure Search on after I restart my browser.",.. SEARCH_TOAST_DONE: "Done",.. SEARCH_TOAST_HEADING_COMPLIANT: "You don't have Secure Search . be careful",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Secure Search steers you away from risky sites in your search results.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Would you like to add Secure Search and stay ahead of the bad guys?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Yes, add Secure Search to my browser and change my default search to {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",.. SEARCH_ENGINE_YAHOO: "Yahoo",.. SEARCH_ENGINE_YANDEX: "Yandex",.. SEARCH_ENGINE_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7166
                                                                                                                                                                            Entropy (8bit):5.357603886398829
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CikaW+DI24sA0etjy/gsjyw9FsBR52/MGSrZcUyxITK3mVa:CNL+DI23ktjy4sjyGeR5jKnOKWVa
                                                                                                                                                                            MD5:4397A9B4B554BAB39BBE68ED3BA2BD2B
                                                                                                                                                                            SHA1:03192E9FABA0C58FCC59713824E46B15D7908E24
                                                                                                                                                                            SHA-256:5D4F78273B484015A5DFED48702BA7A76E72FA8578F92B3054327C94A05FD0F6
                                                                                                                                                                            SHA-512:8269DCF69D7D80A02696EBFCA3A39DD81329A123DA89B8EC4050C8717A948DBF8A843DCFD584230D817D70D43247FE8271BFDD9B41742DADFB595FD542A970EC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "La b.squeda segura est. desactivada: ten cuidado",.. SEARCH_TOAST_SUB_HEADING: "La b.squeda segura elimina los sitios web peligrosos de los resultados de tus b.squedas.",.. SEARCH_TOAST_BODY_TEXT: ".Quieres ir un paso por delante de las amenazas con una protecci.n extra en tus b.squedas?",.. SEARCH_TOAST_OPTION: "S., activar la b.squeda segura despu.s de reiniciar mi navegador.",.. SEARCH_TOAST_DONE: "Listo",.. SEARCH_TOAST_HEADING_COMPLIANT: "No dispones de la b.squeda segura, ten cuidado",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "La b.squeda segura elimina los sitios web peligrosos de los resultados de tus b.squedas.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: ".Quieres a.adir la b.squeda segura e ir un paso por delante de las amenazas?",.. SEARCH_TOAST_OPTION_COMPLIANT: "S., a.adir la b.squeda segura a mi navegador y cambiar mi b.squeda predeterminada a {0}.", // {
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6972
                                                                                                                                                                            Entropy (8bit):5.376904672149746
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:C7nHt6A2Av8eK1mD8OOtjvQxj4jJ5QXGfTB9j:C7nN6dABK4wOOtjvQxj4lomTB9j
                                                                                                                                                                            MD5:D54C78C828AC7E907D0DE01D76278840
                                                                                                                                                                            SHA1:7DF62B8D99ADDF743C952403523195016BFFD835
                                                                                                                                                                            SHA-256:3C19F889D8EBFA80240761F56A5B0EB3B1FDD3346F7BB006A930E5DFC3A426D8
                                                                                                                                                                            SHA-512:52FE5711DE39C279E0B8354BFA63427342592C5C814D92962FFF17E660104113831177A4CCB229CBA04C3D25946971C93A2D4502867E67B579746E62176E43D2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "B.squeda segura desactivada: ten cuidado",.. SEARCH_TOAST_SUB_HEADING: "B.squeda segura elimina los sitios peligrosos de los resultados de tus b.squedas.",.. SEARCH_TOAST_BODY_TEXT: ".Quieres ir un paso por delante de las amenazas con una protecci.n extra en tus b.squedas?",.. SEARCH_TOAST_OPTION: "S., activar B.squeda segura despu.s de reiniciar mi navegador.",.. SEARCH_TOAST_DONE: "Listo",.. SEARCH_TOAST_HEADING_COMPLIANT: "No tienes B.squeda segura: ten cuidado",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "B.squeda segura elimina los sitios peligrosos de los resultados de tus b.squedas.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: ".Te gustar.a agregar B.squeda segura y adelantarte a los malos?",.. SEARCH_TOAST_OPTION_COMPLIANT: "S., agregar B.squeda segura a mi navegador y cambiar mi b.squeda predeterminada a {0}", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6713
                                                                                                                                                                            Entropy (8bit):5.4030553361914935
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:Cf5VcSzQubYOrlY0XRMYSJd1VtHyYZN66mHyY4Xub3:CfWJXecJtlf6vl8ub3
                                                                                                                                                                            MD5:567891348CD10BB69D73E248E2D12237
                                                                                                                                                                            SHA1:1DE368EECC996DBF74FACD6588FA50FACEF04E6C
                                                                                                                                                                            SHA-256:D89F8683685322D343FA32AFD4613F39B8735AD2CDE701CC0C80ADDB775080B4
                                                                                                                                                                            SHA-512:0447A7258E4770AD6E6F340F6D2849F641FA781A15FFB8C94104FA8AA400FC136A971ACDD939E820E9A0CB1AD241BE0CF8FD00AA01E8C0F7AB6A8A6ADA2BF573
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Varoitus: suojattu haku ei ole k.yt.ss.",.. SEARCH_TOAST_SUB_HEADING: "Suojattu haku suojaa sinua vaarallisilta verkkosivustoilta, kun suoritat hakuja.",.. SEARCH_TOAST_BODY_TEXT: "Haluatko lis.suojaa hakuihisi?",.. SEARCH_TOAST_OPTION: "Kyll.. Ota suojattu haku k.ytt..n, kun k.ynnist.n selaimen uudelleen.",.. SEARCH_TOAST_DONE: "Valmis",.. SEARCH_TOAST_HEADING_COMPLIANT: "Sinulla ei ole suojattua hakua . ole varovainen",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Suojattu haku suojaa sinua vaarallisilta verkkosivustoilta, kun suoritat hakuja.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Haluatko lis.t. suojatun haun, jotta pysyt jatkuvasti muutaman askeleen rikollisten edell.?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Kyll., haluan lis.t. suojatun haun selaimeeni ja muuttaa oletushakukoneeksi {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",.. SEARCH_ENGINE_YAHOO: "
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with very long lines (322), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7707
                                                                                                                                                                            Entropy (8bit):5.338885548324864
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:CNztZLR3dPCgbg0LUaJbQA1A/6yb2qz2KAnt/rF43U/HqBosOCA2FSUb:CB/CqQaKA1i64z27t/rF43U/KBosOCAW
                                                                                                                                                                            MD5:C91FA97BC47CA94BD6C68875C8A8B0A1
                                                                                                                                                                            SHA1:737F08638C981693587A61F3A218805241E82451
                                                                                                                                                                            SHA-256:D73FF4CE5A21E3E29EA0B01D1C459425F8ED0CB4F6CCCF8CAB62A85C38C3385A
                                                                                                                                                                            SHA-512:63C3579415079BB00FABC2C5C28A5CFFEF8E68D3CD15504B1773A99BD0ECB074DE3FF94A6F103590109644942D3B3158BAA3616C232722A3E0DE3AB3774B46C6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Attention! La recherche s.curis.e est d.sactiv.e",.. SEARCH_TOAST_SUB_HEADING: "La recherche s.curis.e vous met . l'abri des sites Web dangereux figurant dans vos r.sultats de recherche.",.. SEARCH_TOAST_BODY_TEXT: "Voulez-vous d.jouer les escrocs en vous dotant d'un moyen de protection suppl.mentaire?",.. SEARCH_TOAST_OPTION: "Oui, activer la Recherche s.curis.e une fois que j'aurai red.marr. mon navigateur.",.. SEARCH_TOAST_DONE: "Termin.",.. SEARCH_TOAST_HEADING_COMPLIANT: "Attention! La recherche s.curis.e n'est pas install.e.",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "La recherche s.curis.e .carte de votre recherche les sites internet risqu.s.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Souhaitez-vous installer la recherche s.curis.e afin de garder une longueur d'avance sur les escrocs du Web?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Oui, ajouter la recherche s.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7690
                                                                                                                                                                            Entropy (8bit):5.336020745326812
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:CsERzSimDtBPs31a2/DMEopt+3eOpPZA2XYGAq6:CXFABPq1x8t+3HZA2IGAq6
                                                                                                                                                                            MD5:2066D7546C542C117ABAF0C8A41DF5F4
                                                                                                                                                                            SHA1:088CD3253EDC709DEBEEA36E3C8AA5608E6D6303
                                                                                                                                                                            SHA-256:329307B9AD2302509FC80955696657398B1302DEFBD76BB60252A67640121C86
                                                                                                                                                                            SHA-512:996FDEE8E54D8E4556013EEBB2CA35BC6D3D6065BE497426188576C38A199E5D3B66FFF7C67937AE7D5DAF6EEAEC41E9F04AC69D778E31E470524BF584AA6399
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "La recherche s.curis.e est d.sactiv.e. Soyez prudent.",.. SEARCH_TOAST_SUB_HEADING: "La recherche s.curis.e .carte les sites dangereux dans vos r.sultats de recherche.",.. SEARCH_TOAST_BODY_TEXT: "Vous souhaitez une protection de recherche .volu.e qui vous mette . l'abri des utilisateurs malveillants.?",.. SEARCH_TOAST_OPTION: "Oui, activer la recherche s.curis.e apr.s le red.marrage du navigateur.",.. SEARCH_TOAST_DONE: "Termin.",.. SEARCH_TOAST_HEADING_COMPLIANT: "Soyez prudent, vous ne disposez pas de la recherche s.curis.e",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "La recherche s.curis.e .carte les sites dangereux dans vos r.sultats de recherche.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Voulez-vous ajouter la recherche s.curis.e et garder une longueur d'avance sur les personnes mal intentionn.es.?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Oui, ajouter la rech
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7046
                                                                                                                                                                            Entropy (8bit):5.489775216215936
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:C1/oREn0Rscvuy66DERG9MCt9qU8FCjN9JPh9qU8F/9FYeP5en2uRpPpQAK:CxnifBE6t9z8FAN9H9z8FFeQm5DPyAK
                                                                                                                                                                            MD5:1565A7A1978A975F26098FB81B07F1C1
                                                                                                                                                                            SHA1:A13E0B13C03D23351ED175B6FBC6A5448CC929E7
                                                                                                                                                                            SHA-256:E895451E303339D1A40FAFFA01C19C4764628EFB445A8708DF88E7FB7223BC95
                                                                                                                                                                            SHA-512:600ABED4BB9F8A769D02D452CF663D73A7EC1CB28809512FDCC49D566E2F37299ADEF6B8C724B4C4BF688A3C636B694834EB261AB6A3930214D33511A2EE09F7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Isklju.eno je Sigurno pretra.ivanje - budite pa.ljivi",.. SEARCH_TOAST_SUB_HEADING: "Sigurno pretra.ivanje dr.at .e opasne stranice podalje od va.ih rezultata pretra.ivanja.",.. SEARCH_TOAST_BODY_TEXT: ".elite ostati nekoliko koraka ispred negativaca s dodatnom za.titom pri pretra.ivanju?",.. SEARCH_TOAST_OPTION: "Da, uklju.i Sigurno pretra.ivanje nakon .to ponovno pokrenem preglednik.",.. SEARCH_TOAST_DONE: "Gotovo",.. SEARCH_TOAST_HEADING_COMPLIANT: "Nemate sigurno pretra.ivanje - budite oprezni",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Sigurno pretra.ivanje dr.at .e opasne stranice podalje od va.ih rezultata pretra.ivanja.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: ".elite li dodati sigurno pretra.ivanje i ostati ispred?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Da, dodaj sigurno pretra.ivanje mojem pregledniku i promijeniti svoju zadanu pretragu na {0}.", // {0} SE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7496
                                                                                                                                                                            Entropy (8bit):5.5550712038218695
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CyQ0mXVpV8YYxZXThD71WnkWYtezBPwe49Fnmsv31B94+CgbH:CxFXV8YabLtaB4jXH4g7
                                                                                                                                                                            MD5:2541A18DFA2FFB6F7A3BFFEA83D43E4E
                                                                                                                                                                            SHA1:F8D1E10B525C5C5E031D2115752D34F8DBD0B695
                                                                                                                                                                            SHA-256:3DE501821EF401E88582D773E23F6DFDF2AFBF7A37228E1933D39BBCD362F152
                                                                                                                                                                            SHA-512:74F9002BC25097E5338650FDC26A6D83CF982A9CD44E21DDEBFD44B2083D4632D8E497B020101254C176223399D0B0A7AA704ADE05201A01688B9A4AB4E08078
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "A biztons.gos keres.s ki van kapcsolva. Legyen .vatos!",.. SEARCH_TOAST_SUB_HEADING: "A biztons.gos keres.s funkci.val elker.lheti a keres.si eredm.nyek k.z.tt tal.lhat. vesz.lyes webhelyeket.",.. SEARCH_TOAST_BODY_TEXT: "Szeretne a rosszfi.k el.tt j.rni az extra keres.si v.delemnek k.sz.nhet.en?",.. SEARCH_TOAST_OPTION: "Igen, legyen bekapcsolva a biztons.gos keres.s funkci., miut.n .jraind.tottam a b.ng.sz.t.",.. SEARCH_TOAST_DONE: "K.sz",.. SEARCH_TOAST_HEADING_COMPLIANT: "Nincs biztons.gos keres.s funkci.ja . legyen .vatos",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "A biztons.gos keres.s funkci.val elker.lheti a keres.si eredm.nyek k.z.tt tal.lhat. vesz.lyes webhelyeket.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Szeretn. hozz.adni a biztons.gos keres.st, hogy n.h.ny l.p.ssel mindig megel.zze a rosszfi.kat?",.. SEARCH_TOAST_
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6908
                                                                                                                                                                            Entropy (8bit):5.237071715961501
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:CNcefx5VArSHAmTy+rr0l2BJ07tpelslpeWy++WVHJN:CL5OpmOU0lCJ07tpiWp4sj
                                                                                                                                                                            MD5:B5D0988C65F589401FA7DBF19ED0280C
                                                                                                                                                                            SHA1:A85E366C54C63DEAAC0C3B6ED3C03E524BE9EF07
                                                                                                                                                                            SHA-256:764E8C4D86D570A15A34E2AAAABDCA5A1DF23C8DE98235A1A6657C1732B94443
                                                                                                                                                                            SHA-512:3611562555D7AAE024F336210286F375639E05A0848ECD869150AF844266D5F8039BE60F085C58D73DD6CDFA2EC2CBE7F0145F88519D8E9E61396487A63A02F8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Attenzione: la funzionalit. di ricerca sicura non . attiva",.. SEARCH_TOAST_SUB_HEADING: "La ricerca sicura consente di escludere i siti rischiosi dai risultati delle ricerche.",.. SEARCH_TOAST_BODY_TEXT: "Vuoi essere sempre un passo avanti rispetto ai malintenzionati, grazie a una maggiore protezione delle ricerche?",.. SEARCH_TOAST_OPTION: "S., attiva la ricerca sicura al riavvio del browser.",.. SEARCH_TOAST_DONE: "Fine",.. SEARCH_TOAST_HEADING_COMPLIANT: "Attento, non stai usando la ricerca sicura",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "La ricerca sicura consente di escludere i siti rischiosi dai risultati delle ricerche.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Vuoi aggiungere la ricerca sicura e tenere alla larga i malintenzionati?",.. SEARCH_TOAST_OPTION_COMPLIANT: "S., aggiungi la ricerca sicura al browser e imposta il motore di ricerca predefinito su {0}.", // {0} SEA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):8147
                                                                                                                                                                            Entropy (8bit):5.846824348861508
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CPLfnSHyVfZ2H6EisoqNkij09yT4eKVX0fe66UqPJGNBcpIEdt4/L22XPJn4/799:CumbTi9Itk2s1EuSU8sJ7ny
                                                                                                                                                                            MD5:B1C564C9333C742497E5A9D3817CAC99
                                                                                                                                                                            SHA1:0020924D194D635F4A9AE0F6F669B51DC780128F
                                                                                                                                                                            SHA-256:3596EF93BF4488986B1A9B39F3C07523E72C40A85185600BE36A3054290E13BD
                                                                                                                                                                            SHA-512:3BB3A5088351D5E4919B4B86917FDCB43883E77F770322840A75103A99BD3C255A0E9CAD4BABF80975420F3156627BD4A3A9912D7D9E3662B3635AF5D46D6A35
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: ".........",.. SEARCH_TOAST_HEADING: ".... .................",.. SEARCH_TOAST_SUB_HEADING: ".... ........................",.. SEARCH_TOAST_BODY_TEXT: ".........................",.. SEARCH_TOAST_OPTION: ".................. ...........",.. SEARCH_TOAST_DONE: "..",.. SEARCH_TOAST_HEADING_COMPLIANT: ".... ..........................",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: ".... ........................",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: ".................. ...........",.. SEARCH_TOAST_OPTION_COMPLIANT: "........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7384
                                                                                                                                                                            Entropy (8bit):5.93260103930681
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CIfSwAbRpdRzltRSN79FIt4khpJAk/NzfH/:CIawKtRSNp1k+YDf
                                                                                                                                                                            MD5:A4007E048251B6D27DA1B76343BFF6E9
                                                                                                                                                                            SHA1:BC4042BEBAE991640DF7A832F6F48558151E1B53
                                                                                                                                                                            SHA-256:033188FBD5D83097F66C856F4DED8D9BE5B03439ACD072587BD21EF24206CF5A
                                                                                                                                                                            SHA-512:EF99DF808B68F4298EEAA306B36763324A18612CCBDC9D05DB76945EDFEFD652DFBBEC6B88D542B3B3966591712E3036E8D93E2A93350AC37BB4ECFB7BCB3EE2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "......",.. SEARCH_TOAST_HEADING: ".. .. ..... - ......",.. SEARCH_TOAST_SUB_HEADING: ".. ... .. .. . ... .... ......",.. SEARCH_TOAST_BODY_TEXT: ".. .. ... .. .... ... ........?",.. SEARCH_TOAST_OPTION: ".. . ..... .. ... . .. ... .......",.. SEARCH_TOAST_DONE: "..",.. SEARCH_TOAST_HEADING_COMPLIANT: ".. .. ... .. - ......",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: ".. ... .. .. . ... .... ......",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: ".. ... .... ... .. ........?",.. SEARCH_TOAST_OPTION_COMPLIANT: "., .. ... . ..... .... .. ... {0}(.). ......", // {0} SEARCH_TOAST_*.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6835
                                                                                                                                                                            Entropy (8bit):5.392606150649136
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:CKrYAXY8c4VteYFB8K3ueYFYRbyLXKFK4MwJ:CNGY8VVt7FB8K3u7F6yLXKFK7wJ
                                                                                                                                                                            MD5:079E49705B1F2786068AEAF22E68DD3B
                                                                                                                                                                            SHA1:BFFEBBB258DB9B0731CC72C494C93E8827ABC9C5
                                                                                                                                                                            SHA-256:CF8757AD22A8E4BE81F939351FCAC8DCB331A56EFD733EBF6DBE5935CF1CDB63
                                                                                                                                                                            SHA-512:276DF6AA234BF65FCC5809F1AD31BBFAA41C9F107CC13EEC659979EF76AC8E1BBDE43B63202B656FBB7FEDDFCBF8DD2EB154903CFBD1DF080BF6E56A8730A54B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Sikkert s.k er sl.tt av . v.r forsiktig",.. SEARCH_TOAST_SUB_HEADING: "Sikkert s.k holder deg unna skadelige omr.der i s.keresultatene.",.. SEARCH_TOAST_BODY_TEXT: "Vil du ha et forsprang p. skurkene med ekstra s.kebeskyttelse?",.. SEARCH_TOAST_OPTION: "Ja, sl. p. Sikkert s.k n.r jeg starter nettleseren p. nytt.",.. SEARCH_TOAST_DONE: "Fullf.rt",.. SEARCH_TOAST_HEADING_COMPLIANT: "Du har ikke Sikkert s.k . v.r forsiktig",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Sikkert s.k holder deg unna skadelige omr.der i s.keresultatene.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Vil du legge til Sikkert s.k for . ha et forsprang p. skurkene?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Ja, legg til Sikkert s.k i nettleseren min og endre standard s.kemotor til {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",.. SEARCH_ENGINE_YAHOO: "Yahoo",.. SEARCH_ENGINE_YANDEX: "Y
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6746
                                                                                                                                                                            Entropy (8bit):5.350952933198646
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:CHSyoqPxfaPVFJ1bshox+a3uz27w8iLt9ls3cLt3CPiMWbW3pDLrFvn:C2J4jtjbSLBh
                                                                                                                                                                            MD5:887A6B30FCDB774C89BB8A96CC48C50F
                                                                                                                                                                            SHA1:730511C363199AA4926106B8A7E184B7F0B7674C
                                                                                                                                                                            SHA-256:0C05174E2379824B0E43722D5018D5FF8A2F3317C8D4CBD13AA794BE096635E1
                                                                                                                                                                            SHA-512:0EF5FE0389BF621D262CBB12A4BF70EBCDE8F0441748FF325AAFEF3FB03224AAE0FC14629B5374803C2F7E479133AEA39E7E280BB20CFB835E7CADF88A00323F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Beveiligd zoeken is uitgeschakeld. Wees voorzichtig.",.. SEARCH_TOAST_SUB_HEADING: "Met Beveiligd zoeken kunt u de riskante sites in uw zoekresultaten vermijden.",.. SEARCH_TOAST_BODY_TEXT: "Wilt u de criminelen een stap voor blijven met extra zoekbeveiliging?",.. SEARCH_TOAST_OPTION: "Ja, schakel Beveiligd zoeken in nadat ik mijn browser opnieuw heb gestart.",.. SEARCH_TOAST_DONE: "Gereed",.. SEARCH_TOAST_HEADING_COMPLIANT: "U hebt Beveiligd zoeken niet: wees voorzichtig",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Met Beveiligd zoeken kunt u de riskante sites in uw zoekresultaten vermijden.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Wilt u Beveiligd zoeken toevoegen om criminelen een stap voor te blijven?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Ja, voeg Beveiligd zoeken toe aan mijn browser en verander mijn standaardzoekmachine in {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7048
                                                                                                                                                                            Entropy (8bit):5.61243549683091
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:Cp4EhuYbEvbH2jQWjlykLbLJLA1keuRgR1kv6z+tU9k8ir+IQB1y0g8CmYrvBjy/:Cp4EhuYbEvbH4QWjlykbpA1keuRk1kvI
                                                                                                                                                                            MD5:3B5FD528D7C629BE69E4801E505F90B4
                                                                                                                                                                            SHA1:9D14001C9EE9AC45BEB54FC9F931E0784141F4A5
                                                                                                                                                                            SHA-256:95D02F5D8184C9B68EBD5FB47CD14FC96D7A984955D0B222807476D0F3A1BDD9
                                                                                                                                                                            SHA-512:5423AC1449EBFFDC64189F7A98D32E0507FE8C9B96C7B047572B689D1D68FCDF00FC47611709E3F83A8DE1B1AF399015A271EC4406AE90415A4885F40869702C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Uwaga! Funkcja bezpiecznego wyszukiwania jest wy..czona.",.. SEARCH_TOAST_SUB_HEADING: "Funkcja bezpiecznego wyszukiwania eliminuje niebezpieczne witryny sieci Web z wynik.w wyszukiwania.",.. SEARCH_TOAST_BODY_TEXT: "Czy chcesz uprzedzi. zagro.enia dzi.ki dodatkowej ochronie wyszukiwania?",.. SEARCH_TOAST_OPTION: "Tak, w..cz funkcj. bezpiecznego wyszukiwania po ponownym uruchomieniu przegl.darki.",.. SEARCH_TOAST_DONE: "Gotowe",.. SEARCH_TOAST_HEADING_COMPLIANT: "Uwaga, nie masz funkcji Bezpieczne wyszukiwanie",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Funkcja bezpiecznego wyszukiwania eliminuje niebezpieczne witryny sieci Web z wynik.w wyszukiwania.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Chcesz doda. funkcj. bezpieczne wyszukiwanie do przegl.darki i uprzedzi. zagro.enia?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Tak, dodaj funkcj. bezpieczne wyszukiwanie do przegl.dark
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):662
                                                                                                                                                                            Entropy (8bit):5.7597397179634
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7Ha6F06FXOAdhcUbz4wpHyHK6IPHCTFad+d/LVqk8FCVkC:7HrLFOAdiIppSq6IPVsdiFCVkC
                                                                                                                                                                            MD5:9333738A73E36A2E269613A1D018210A
                                                                                                                                                                            SHA1:E0A71E913C575269C4BF44DFF74C817988EC2948
                                                                                                                                                                            SHA-256:A0581EFA5908137F14713CCE144FFD986A31FBD8C32AF3E5F6D34401175C9EDC
                                                                                                                                                                            SHA-512:6F032E00C9F0EDAC5148B31732A6B172A121BD9B5F33EA8C8A5BF2D16B0BE49932C613AFFD6B749B2EA57166395D78BADD4842CD99EEEFBFACD0E8F8D4BDF05F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Slu.ba Bezpe.n. hled.n. je vypnut. . bu.te opatrn.",.. SEARCH_TOAST_SUB_HEADING: "Slu.ba Bezpe.n. hled.n. v.s ve v.sledc.ch hled.n. upozorn. na rizikov. str.nky. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Chcete zapnout roz...enou ochranu p.i hled.n., abyste byli v.dy o krok nap.ed p.ed hrozbami?",.. SEARCH_TOAST_OPTION: "Ano, chci po restartov.n. prohl..e.e zapnout slu.bu Bezpe.n. hled.n.",.. SEARCH_TOAST_DONE: "Hotovo"..}..//E48885A4089C191F17100BFDF7E33E8198F4142B426AAC5DF923BCCF6590D0F6279F27D9A11B08236B5118D8F28E829298EA8155238D1AC065DDC6B95F2F396A++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):591
                                                                                                                                                                            Entropy (8bit):5.556587769890555
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H0Qs8HQMHQs8f2aw5VL0bdhPLjWR8exSYjnYBN:7Hfs49wsC2aw5t0bdhWR5xS8nGN
                                                                                                                                                                            MD5:5167EC440E9B60D834B74C163B466859
                                                                                                                                                                            SHA1:0315D48D553C4A01BBE37647C28359ADB1B96646
                                                                                                                                                                            SHA-256:53C7540204C5DBF54AF6590798A1CCCA6654E57669CD5B4DE19680C0615D3355
                                                                                                                                                                            SHA-512:CBA121F03DFC55DA30FE13CE5069C6540F77AAAF6141C57E554A765CDD73F8DE7E0A17AF2C71825F57E1A63F3C8A1E23667416A1AE6B7BFE05438AEDCE21940D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Sikker s.gning er sl.et fra . v.r forsigtig",.. SEARCH_TOAST_SUB_HEADING: "Sikker s.gning markerer de potentielt farlige websteder i s.geresultaterne. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Vil du have ekstra beskyttelse ved at g.re dine s.gninger mere sikre?",.. SEARCH_TOAST_OPTION: "Ja, aktiv.r sikker s.gning, n.r jeg har genstartet browseren",.. SEARCH_TOAST_DONE: "F.rdig"..}..//DDDC93AEB7D34452F7BFAF7B5E3231C2B201649F331175338D56FDD10D545BEAAA636B8EC78589BCC470F535CB4606852AECABE9B7FFCE3B3713D68C8B9E4C69++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):626
                                                                                                                                                                            Entropy (8bit):5.46994588054159
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HV5hKfCvXCQtROXlU1dhIQvQA3yDYBGNJXJWWqEOVhsNR1f/0e:7HfhKf+X08dbCYgOPsh/9
                                                                                                                                                                            MD5:DE979FA93BF682A07CFEB46648C9AF02
                                                                                                                                                                            SHA1:D1A39737B02B215D09791B0D6DD4B72876F7B271
                                                                                                                                                                            SHA-256:216AD61CD811B087D5F040D8F0F4942488720CD73B9BF2E99B19DEAD84272B99
                                                                                                                                                                            SHA-512:DB5F1E657B6DC238FB3E10157F04BFE6D4B13AD88B16E0764BA9E7400F95DFAD6E72DB2F5A9102F7B4F60924342678620ED9A5EF1C2D88199D749D0D0C7D6E46
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Achtung: Sichere Suche ist deaktiviert",.. SEARCH_TOAST_SUB_HEADING: "Mit der sicheren Suche werden Sie vor risikoreichen Websites in Ihren Suchergebnissen bewahrt. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Wollen Sie mit zus.tzlichem Suchschutz Bedrohungen immer einen Schritt voraus sein?",.. SEARCH_TOAST_OPTION: "Ja, ich m.chte die sichere Suche nach dem Neustart meines Browsers aktivieren.",.. SEARCH_TOAST_DONE: "Fertig"..}..//781BDE4AF95A67F6BF08097C19686398C7BA776D0B20431C0E4C6F45D4D53F251BF9EFBDFDD2D3EA8503B1454611F007F0DB96A6F43145B24D1298F03A4C6042++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):966
                                                                                                                                                                            Entropy (8bit):5.129622769173818
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HzMnpI0MXLr28dNWGmr3/TaMTyN/lPmv:SS268drb0le
                                                                                                                                                                            MD5:5289448506816447D15EB62E8D3A8EAC
                                                                                                                                                                            SHA1:C8E57B7F43E7E5C08CF284AF19BE25EBE9B75291
                                                                                                                                                                            SHA-256:BB50893CE6A58CE3C156E6D8D487A6BC33C42436A56B91D7161B1F4A15DAEF85
                                                                                                                                                                            SHA-512:CEE8BFEBC544BF151FC31DC0E4C4F2336BC316768E650A3BFAC748CBB08D3E8E65F4CB45D924385A980D569957FF6F772AC700DA559A794969C6D449491B7D61
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: ". ....... ......... ..... ................, .. ..... ...........",.. SEARCH_TOAST_SUB_HEADING: ". ....... ......... ... ........... ... ........... .......... ... ............ ........... {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "...... .. ......... ..... ... .... ....... ... ... ....... .. ........ ......... ..........;",.. SEARCH_TOAST_OPTION: "..., .. ............. . ....... ......... .... ... ............ ... ............ ..........",.. SEARCH_TOAST_DONE: "....."..}..//8ABC4EE494806AF244C67B673221383B313197DEC7804C5994E3EE2559C39528AA1CF76351E2690EF191B60E3D0229D70191E3D8DEB7AE8D58EFF26C225FA970++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):546
                                                                                                                                                                            Entropy (8bit):5.438478026475485
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H4HIWFH3npSuVJTsdhIEfRXK9m/NaU/KPEOHVagBjFDh7h:7H4NXpSuVJTsdjfRXKIVaYmrvDj
                                                                                                                                                                            MD5:50B27F1859C737418F3B8FAD6C60CCFA
                                                                                                                                                                            SHA1:6D9C0A1CF778F05725D8A0BA475CB76B13A05F28
                                                                                                                                                                            SHA-256:08F32499383319ABD3D2E60BFAAF9D633485F6DBE7FE922BD25A68AFBD148970
                                                                                                                                                                            SHA-512:0C3695585CEF7784CEA76E4BFB52B45FF37B5CC545A43A0C93B8836C2108CD94679E75A9DC8E2459FFFEDBC45BA014D99FB3EB01D349411BBE66A2ECD6D2381E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Secure Search is off . be careful",.. SEARCH_TOAST_SUB_HEADING: "Secure Search steers you away from risky sites in your search results. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Want to stay ahead of threats with extra search protection?",.. SEARCH_TOAST_OPTION: "Yes, turn on Secure Search after I restart my browser",.. SEARCH_TOAST_DONE: "Done"..}..//96EA14B58D06EA6D292E6EA56AC3DF0134F3F980FB5B5BC318F194D697843105615D3F4A1F7CD553206D0EE9E4F050AAF106A37E03FADE5B02133515F63052E6++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):621
                                                                                                                                                                            Entropy (8bit):5.538926666499625
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H1b6YjvHDkYdhDOnKjHZ/QC5MHYRczhbuUKsyD9:7HRHDkYdQneZ/7kYR+hbuUKbp
                                                                                                                                                                            MD5:ADCAADDD4131E780BFB6216607B155D1
                                                                                                                                                                            SHA1:2608554A423B6296461791A3ABC99B2DB6913AB7
                                                                                                                                                                            SHA-256:4D844C78842DE6FDC2C6BBA282041EE5EF0F18B20858012932AE20DDF3A64F28
                                                                                                                                                                            SHA-512:A09968BBBA5D66D9609E459D59851FFD15FA03E88D8797C7C1075DADE03B1C4F524001FC96511F9B6744A2277277D5D96A082BEE47AE9DBDB31A1ADF0C16776F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "B.squeda segura est. desactivada: tenga cuidado",.. SEARCH_TOAST_SUB_HEADING: "B.squeda segura filtra los sitios web peligrosos en los resultados de sus b.squedas. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: ".Quiere ir un paso por delante de las amenazas con una protecci.n extra en sus b.squedas?",.. SEARCH_TOAST_OPTION: "S., activar B.squeda segura despu.s de reiniciar mi navegador",.. SEARCH_TOAST_DONE: "Listo"..}..//F46FDE9F2473302E649EF27D6C28A0E0041CE6A60D7CCB2D2771B200C5968A158335280F63E8BC7DB3CE8576CE3F91251CE28338FA32F9A1DD7EB0CF8E9FF50F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):590
                                                                                                                                                                            Entropy (8bit):5.555932938953374
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7Heaf6Yrsi5KD/DdhDybH62P5MHrS2Rboo2SWQYJ:7HdLsiUDLd0rXPkm2RkZQYJ
                                                                                                                                                                            MD5:4D299AD9C33AE5F7221ACDFC6D8CB419
                                                                                                                                                                            SHA1:B5B1F34175D9C2882D809550255E3E9258D71E85
                                                                                                                                                                            SHA-256:06E8763D1A79C0B2F31C3A2D4CDE04A7264B96D497B1C8CFE652171B79832FA3
                                                                                                                                                                            SHA-512:C8A02922341E3C8ED158B8AE8944518F6C0C7625C50A166E15BF756ECD45D0387AD068DFED5F39750B2E22959CA3966B32577F3F7E47544D7F059E3E2B896DC6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "B.squeda segura desactivada: tenga cuidado",.. SEARCH_TOAST_SUB_HEADING: "B.squeda segura lo aleja de sitios peligrosos en los resultados de b.squeda. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: ".Quieres adelantarte a las amenazas con protecci.n de b.squeda extra?",.. SEARCH_TOAST_OPTION: "S., activar B.squeda segura despu.s de que reinicie mi navegador",.. SEARCH_TOAST_DONE: "Listo"..}..//F440553795D258CCD308C658E9E482E26720C16D38545458B05A2275CA943DCD179AFA03B7F44DC10B92C6B0CEB55D49F6771F151D4637EE37B731C4DAAF1626++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):594
                                                                                                                                                                            Entropy (8bit):5.551685954662295
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HpBjkIHMjpJNnddhFyXLcE6P8ljSy3FJHzWLSl3iWSf/m:7HpBBHsNnddeXInP8lmSFcLSlZ
                                                                                                                                                                            MD5:DC9F54AA3F300ECF790AA92628D3CF77
                                                                                                                                                                            SHA1:78077A363E5A448FA3230165D854804FEBE4572F
                                                                                                                                                                            SHA-256:8540FB93344738BBF71D19DF09AABF8E3B90D57D42C5AAF109DE94FA2134E718
                                                                                                                                                                            SHA-512:3CB6041A0E30126260F33D15D76B1EF0C87F1EEDD6C1AD698303649EC8AB40E2BF06FAF152DA51779372BF29B9B2E5EE9A609D296E754403B58B10A20F62A2D1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Varoitus: suojattu haku ei ole k.yt.ss.",.. SEARCH_TOAST_SUB_HEADING: "Suojattu haku suojaa sinua vaarallisilta verkkosivustoilta, kun suoritat hakuja. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Haluatko pysy. askeleen edell. ja hankkia lis.suojaa hakuihisi?",.. SEARCH_TOAST_OPTION: "Kyll.. Ota suojattu haku k.ytt..n, kun k.ynnist.n selaimen uudelleen.",.. SEARCH_TOAST_DONE: "Valmis"..}..//E0D86E5CD809B5C76CAF04F121AC8F615738D596AA4B00EB31DF24B6F439A32589C889436CC92F341F0D734F1A6B9F599E51EE29340A78CF96A14EAA1BCEB47C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):619
                                                                                                                                                                            Entropy (8bit):5.449837640437659
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7He5LuGrtBdhLjwQ8SlK3woEEn9CPOPuUiF9WJ/:7He5LustBd5wwlK3/Ea9yNcx
                                                                                                                                                                            MD5:8C2B50C751DEC6FE68104B2C3B785B7A
                                                                                                                                                                            SHA1:50630ED37996EACA21174B22A6D2D59A74C8B7F6
                                                                                                                                                                            SHA-256:3368ADDB6B95C9301EEE6497048A89A933483C1172E5A32B18638EE38B0520E9
                                                                                                                                                                            SHA-512:53C318367BF41D965C06B96FDB68E7E2D5F525FB24F7181F90420A38591F78596A2915E30924D34D17A06103120623473CEA6F6DF04286FF292A6A6E4D78C99D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Attention! Recherche s.curis.e est d.sactiv.e",.. SEARCH_TOAST_SUB_HEADING: "La recherche s.curis.e .carte de votre recherche les sites internet risqu.s. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Vous aimeriez garder les menaces . distance avec une s.curit. de recherche accrue?",.. SEARCH_TOAST_OPTION: "Oui, activer la recherche s.curis.e quand je relancerai mon navigateur",.. SEARCH_TOAST_DONE: "Termin."..}..//B009D31CB7307E982854F17EE84129B416280262293434696F0EC516C681FEFBAED83BBF71D228F4BBB9D3D0DA0906E77C9126C5469A71278BBC65225974E220++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):654
                                                                                                                                                                            Entropy (8bit):5.46466082595575
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HQ7vJmt/5Tdh0tTdQzFOQ8S4NKXzH6jctqVdD/9VXIHc3Z:7HQ7vJmtJdWtTOpKNKXb6BdTnXCk
                                                                                                                                                                            MD5:C4CEA16F909889D02A6D6FFD1B8C6991
                                                                                                                                                                            SHA1:3A8E59632230494C41B6B0117F29DDE010E2FE0D
                                                                                                                                                                            SHA-256:1CC748BF272A659EBDEECB25EC29667AEF5B25B2330CA8007FF78846CBD2E8F1
                                                                                                                                                                            SHA-512:FC231DD995A2B87B962CF2DE13993539773B19F02CCC7767830A4925026C5249CEC29962B1F6F9B1B16596CB11BE32C2ECB2863E1BC9096FBF20387EDD87E376
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "La recherche s.curis.e est d.sactiv.e. Soyez prudent.",.. SEARCH_TOAST_SUB_HEADING: "La recherche s.curis.e .carte les sites dangereux dans vos r.sultats de recherche. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Vous souhaitez garder une longueur d'avance sur les menaces avec une protection de recherche .volu.e.?",.. SEARCH_TOAST_OPTION: "Oui, activer la Recherche s.curis.e apr.s le red.marage du navigateur",.. SEARCH_TOAST_DONE: "Termin."..}..//EF49244BF3C7DDE9ACDF9BC3020BB15BE3BC2CD05AC5A92A4FEC7644E9C0DFBCD62E527E93FDCE507CB127EBAA8AE493F6BBC9D252A52B0509918367E2722E80++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):642
                                                                                                                                                                            Entropy (8bit):5.585450765906051
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HA+vZMuIg9s7sdhXNrY+Au1HQu8TPAu0TYa5MsLOETS+nh:7Hb2g2sdrkiQuI4uY5TLfXh
                                                                                                                                                                            MD5:96F9B117332775DC777AEA1F28DF2AC9
                                                                                                                                                                            SHA1:10459147C871654E4D02A70FA9403CFDA581CDAE
                                                                                                                                                                            SHA-256:89D45977D1D9E202C71A463E25F2F9B666EC2A27865FC90EDD5333BC89933AA4
                                                                                                                                                                            SHA-512:52863029F6B3CD736815B11CD2084204B3DD0EBA7E47E4D9F8A6871E4DB9060A29297723AC2CF83AAAC27442739F36678EF4C3A383F7CC733CA41508FF6470EF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Isklju.eno je Sigurno pretra.ivanje - budite pa.ljivi",.. SEARCH_TOAST_SUB_HEADING: "Sigurno pretra.ivanje dr.at .e opasne stranice podalje od va.ih rezultata pretra.ivanja. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: ".elite ostati nekoliko koraka ispred prijetnji s dodatnom za.titom pri pretra.ivanju?",.. SEARCH_TOAST_OPTION: "Da, uklju.i Sigurno pretra.ivanje nakon .to ponovno pokrenem preglednik",.. SEARCH_TOAST_DONE: "Gotovo"..}..//9C25629FF501E6CC7B94A4DDE5E531A78015E9F3D4FE722BFDD1853C7D3DD896EC96C5B6FDB517894D93D277C1C3B5030B4FE425AEE3D13D846011D32B2B8BEB++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):703
                                                                                                                                                                            Entropy (8bit):5.676694350972559
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HeBdauIvxgWeBdiituB7XcdhM2Frd0XR0WMruMYNSIt5d9XUL12k9GvZidIdhO:7HeBdauK0Bd5olXcdyiry1MSFNSEd6Lt
                                                                                                                                                                            MD5:69192E9A051F26059299D7C2C6976D27
                                                                                                                                                                            SHA1:6D671C3ABAEACA784FBBC1AFF1D3F1577A33B4D2
                                                                                                                                                                            SHA-256:24432A296BE079BD777340A34896779F48C551CA4F5B05DFBCB14D12023E94DA
                                                                                                                                                                            SHA-512:17B3FAE18DE06042AC2059C053B1DE7349CA3AA2312CC0FF6417470B59EC2EBBC56958A8C8D245CE1248E526C79089FCE149DE5B8D2ADEFC05235AC815DF7C9B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "A biztons.gos keres.s ki van kapcsolva. Legyen .vatos!",.. SEARCH_TOAST_SUB_HEADING: "A biztons.gos keres.s funkci.val elker.lheti a keres.si eredm.nyek k.z.tt tal.lhat. vesz.lyes webhelyeket. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Szeretne egy l.p.ssel a fenyeget.sek el.tt j.rni az extra keres.si v.delemnek k.sz.nhet.en?",.. SEARCH_TOAST_OPTION: "Igen, legyen bekapcsolva a biztons.gos keres.s funkci., miut.n .jraind.tottam a b.ng.sz.t",.. SEARCH_TOAST_DONE: "K.sz"..}..//497F932EB94DBD0E3CAC90E1F5C8555A33B05DBA1B94A36FEC6679A11A6D3B1F0C9315C4CD195A9AD4F2F030802034637ACAF46752401120D845EC07950C25E0++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):591
                                                                                                                                                                            Entropy (8bit):5.416000828200279
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:qsXHYKsW+x+2uvch4pilrtAfaJMdFEhKDP+ku1xvVyvCxNA+EfHOXOR9WJ5CM+Kf:7HtDdilrtAfzdhDK1+aYfHTCc0p
                                                                                                                                                                            MD5:21A957C0D15BB12B2805B1C4522C48AD
                                                                                                                                                                            SHA1:E83CCE41EE4BB664C9D74CFCE64EF92D62D54D86
                                                                                                                                                                            SHA-256:709269085CD0B11E61E31EC958B501B3FE3FAD4ED05F41B0C783B25D674FF2A2
                                                                                                                                                                            SHA-512:0B30C962FCC110786E1D1D3D8D14E227EBC07AE8F47095670EFF3DC6289CD949927D7A296A871507608261D5805A907DEFDE2052488CB3B96368413C85B60A87
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Attenzione: la funzionalit. di ricerca sicura non . attiva",.. SEARCH_TOAST_SUB_HEADING: "La ricerca sicura ti indica i siti rischiosi nei risultati della ricerca. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Vuoi tenere alla larga le minacce con una maggiore protezione delle ricerche?",.. SEARCH_TOAST_OPTION: "S., attiva la ricerca sicura al riavvio del browser",.. SEARCH_TOAST_DONE: "Fine"..}..//24CF2EE9582C3FC90BC13579DF4EE26C93E9AE00CA0DEB1681A4B680D060BEB0CD41AB07BC106FA3823793A1B6D12DE8114BD6A86CD84F6E19353D31C42E9621++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):640
                                                                                                                                                                            Entropy (8bit):5.963930964464233
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HUWisRqhWYcXYDkNWdhx8HWER9QilSh5RWmxISFvBYmuVz:7HUTOqvngUdcHbLZIrcl
                                                                                                                                                                            MD5:14DCA319A56B02209A671B6AB0756A36
                                                                                                                                                                            SHA1:3F2C2F8D426A3F76AF23E08CD29FD9362008E930
                                                                                                                                                                            SHA-256:8E86E62FEF7AB54030B887960B8EAFF54C5F313E9C0518E72658D08B34176F54
                                                                                                                                                                            SHA-512:2B877649D532476671B6B5FBCFD2B6366D827127E8862F30C7D6562457390F5FDCB8233BF0CF9AD7B4EB00FE63B7AFDB2355759B04D7097B8DBADFCDADF18F5D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: ".... .................",.. SEARCH_TOAST_SUB_HEADING: ".... ........................ {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: ".........................",.. SEARCH_TOAST_OPTION: ".................. ..........",.. SEARCH_TOAST_DONE: ".."..}..//0F1BD1D63E85EBF9FE85D4C40D0969D6A18DB1251B7A3F683DC8CE4F0CE1B41F84434B1EBDB1122FE31B6772B4F2903B620D557AB5D75BAA1F99117FC667E153++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):610
                                                                                                                                                                            Entropy (8bit):5.977686665492592
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HRgq8EDFj2FcdhkbQ2sIm8kATcVjPgU41Qco:7HvhEcd2BsIm8kgcVjPe6
                                                                                                                                                                            MD5:9F2BEA03FA9EF87DB13569F069B01DB9
                                                                                                                                                                            SHA1:C2831B7411DA27B00CEAA4CAED197FA419750B0D
                                                                                                                                                                            SHA-256:48BF5E2CEC6C8A31CDC47A1EF9840DE5B22392ED27F8990C1B840E95680A1209
                                                                                                                                                                            SHA-512:81E9B3B0EC9DFF52AA455BBF5C3C56BEC650EF0E46E4C41477C9267B669190A800DC73AE790605B2F0F6EAFFA5BC792F664FE043DC70CE5F1FC5C56296811905
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: ".. .. ... - ......",.. SEARCH_TOAST_SUB_HEADING: ".. ... .. .. . ... .... ...... {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: ".. .. .. ... .... ... ........?",.. SEARCH_TOAST_OPTION: ".. . ..... .. ... . .. ... .......",.. SEARCH_TOAST_DONE: ".."..}..//9209A02F6F8B503B7333FB2E90DD205B41E361BC5B69FC290CF3DB3956D1CF0FDF1CD91860A15C2A7E4380D018ECF7571851C36F971F65F7F7E8793BFDA006BC++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):571
                                                                                                                                                                            Entropy (8bit):5.585860981824038
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H0QhMHQjBUW4J9wdhPtkwxWsNW2/5U+kx:7HfhMwjIwdhywQsIekx
                                                                                                                                                                            MD5:B53A60627F2239B59F095A49D0A14730
                                                                                                                                                                            SHA1:16170A9EBC21DDE604D2A74A7C0AD73C5BE61A2C
                                                                                                                                                                            SHA-256:57758D0DFEF8D90CD7849AFA92436B365045EE9BC3C9FE6B97296D1FE6412DB9
                                                                                                                                                                            SHA-512:8C357A468C9E2BB30357AFBF1D087CA350CC3AACF8FEC1AE4557383C95CA956C7D5A5184E51256AFB9F6ED00DB609304DE6CD47ABF1F9CBC4D8C41700FD55BA9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Sikkert s.k er sl.tt av . v.r forsiktig",.. SEARCH_TOAST_SUB_HEADING: "Sikkert s.k holder deg unna risikable omr.der i s.keresultatene. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Vil du ha et forsprang p. trusler med ekstra s.kebeskyttelse?",.. SEARCH_TOAST_OPTION: "Ja, sl. p. Sikkert s.k n.r jeg starter nettleseren p. nytt",.. SEARCH_TOAST_DONE: "Fullf.rt"..}..//7F9E5EAF17E8F1227E38A25E7F41560CBDC6B83917451C99D91C302F756E574998F976B81D021A6C085BC16CFA7DE4402B3FF69F01E634FC5D624DFA1142ACEB++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):602
                                                                                                                                                                            Entropy (8bit):5.5121966627531975
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H7AySxXeOzOqodhIMLfcPkQkfM76FwUpWgnUAZ0n:7HzSxOBqodrLfccQkbFhpnU00
                                                                                                                                                                            MD5:CB36008F48B9A179465A060EFCF06732
                                                                                                                                                                            SHA1:8D19C2987F8D76C354EEF62B1DD82D2CD42C0554
                                                                                                                                                                            SHA-256:8697DDD7FABFDF87DD090ECAA453576156D3D1608FB2F6324F0458E468959EE9
                                                                                                                                                                            SHA-512:3B648C62108ACDE37B6530D3E6C3EABDCDFE61C7D9AE01EF7A2339DAC19091EDBAA34CC8F2D10D76A09A91F4A758946AE158E217E14BF3DB55B169F299E8D99B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Beveiligd zoeken is uitgeschakeld. Wees voorzichtig.",.. SEARCH_TOAST_SUB_HEADING: "Met Beveiligd zoeken kunt u de riskante sites in uw zoekresultaten vermijden. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Wilt u bedreigingen een stap voor blijven met extra zoekbeveiliging?",.. SEARCH_TOAST_OPTION: "Ja, schakel Beveiligd zoeken in nadat ik mijn browser opnieuw heb gestart.",.. SEARCH_TOAST_DONE: "Gereed"..}..//132213718FA4DF9769B65A174ABFF129686E878CCCD8731D3ABE1DFCDB37249461D3D4CC8CF53FB08FEB164B9BF36F11FD8A1DB41DA15A171B5C8FCA7DDC9A64++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):650
                                                                                                                                                                            Entropy (8bit):5.690654762493119
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HRmi53Lw8i53LE6PU3LOdhc1FKb3LCoPY3LcBt5tgR72RydAh:7HRZFuFIfSdi+jeoPMirt4hdAh
                                                                                                                                                                            MD5:A1299EC5C87CDA42A533F98B4709CEEC
                                                                                                                                                                            SHA1:0F5A70BC37D5A18FC0BE67146480526442F46754
                                                                                                                                                                            SHA-256:1CE435F5AC3E31BE513A8D5E477E29C565CFE517D39915BBABD16E174FACBC4E
                                                                                                                                                                            SHA-512:F27E15C8A8D14B422B5BAE18190E7CA7D43A31E36902FA6A2BC0CFFE115DA00A18F2E24B69C9C9202553BA56062EF30DD8A589F0C83E2F2D74489F3ABA81217C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Uwaga! Funkcja bezpiecznego wyszukiwania jest wy..czona.",.. SEARCH_TOAST_SUB_HEADING: "Funkcja bezpiecznego wyszukiwania eliminuje niebezpieczne witryny sieci Web z wynik.w wyszukiwania. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Czy chcesz uprzedzi. zagro.enia dzi.ki dodatkowej ochronie wyszukiwania?",.. SEARCH_TOAST_OPTION: "Tak, w..cz funkcj. bezpiecznego wyszukiwania po ponownym uruchomieniu przegl.darki",.. SEARCH_TOAST_DONE: "Gotowe"..}..//E67C9266445775342EF456DE0EE29BC20391A6164632CE51169FC7BE3DBBFC90CC444FECD255F706B3D40040C67C9CFC3EB1921EBF77C48C144B0B210683843B++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):572
                                                                                                                                                                            Entropy (8bit):5.490201533592935
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HcwalVTVGGWF/CdhEVMBoPcw7pVl9jy7/3tYJlXc5dJe:7Hu6F/CdGVMBoPcwXltSdJe
                                                                                                                                                                            MD5:BC5691977B799FA51CF593996451AB69
                                                                                                                                                                            SHA1:233C8407418012744DA1209EE67F8202C71C9461
                                                                                                                                                                            SHA-256:696A98D82BF176344F8A5C51F7FAB7768577DBA3B0044BD0CE17B366D1D89239
                                                                                                                                                                            SHA-512:F5E8F6A08F67725304A97B07C5B434A872CD2D3F6E97C8E05C17A35AE72E19CCBD4150EE1762FCB7C6D32A4ED74B37D25A3EF2BE2394D87AA364F6589FDB21CF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "A Pesquisa segura est. desativada - tenha cuidado",.. SEARCH_TOAST_SUB_HEADING: "A Pesquisa segura evita os sites perigosos nos resultados da pesquisa. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Quer ficar longe das amea.as com prote..o extra?",.. SEARCH_TOAST_OPTION: "Sim, ative a Pesquisa segura depois que o navegador for reiniciado",.. SEARCH_TOAST_DONE: "Conclu.do"..}..//79810015A4CBBC4EDC91809446417CF31E2EEBFAABE5C1ABD28FC532801BEA817FE81C6A6FC0B7DC4D45BDBD002BFA5982061C0BCECA2D95769BD008875ABED1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):597
                                                                                                                                                                            Entropy (8bit):5.514344817447737
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HcQyVTuEcc3WhZ2dhvGUO9N7tOsKaLkdUHrqmJxgci+lQ:7HNlhZ2dRGUcNgsHLkWHrq6gciV
                                                                                                                                                                            MD5:94C713C34215464B32CE0DE2440C9B93
                                                                                                                                                                            SHA1:D2C87D10C4F0440EF1F1F5BFD56FE0424A5EF90D
                                                                                                                                                                            SHA-256:CBB75E0276216001C7860194D08977DE494CF87BB097AB6A3F328F9F9DDC3805
                                                                                                                                                                            SHA-512:543B990DFFA367EF7348990D65A22EAE1E0C194E313EBBB0B9D711F096712B73FB63843C9206F1E0C0AAA4379295F3DC8B52582791D050AFD66F0B58D2BFFA55
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "A Pesquisa Segura est. desativada . tenha cuidado",.. SEARCH_TOAST_SUB_HEADING: "A Pesquisa segura ajuda-o a evitar sites perigosos nos seus resultados de pesquisa. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Pretende evitar as amea.as com a prote..o de pesquisa adicional?",.. SEARCH_TOAST_OPTION: "Sim, ativar a Pesquisa segura ap.s reiniciar o meu browser.",.. SEARCH_TOAST_DONE: "Conclu.do"..}..//47AF18EB50A5DA101FD7B34733F1DE8B29ED21DB70A1CD0B92FBD680CA348C221E681808F1125E9D689D7A8F51D09EBAE3E261D56B4227BC0FF82A2FC1478DF4++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):837
                                                                                                                                                                            Entropy (8bit):5.267015231290291
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7HYytHN6yt20qJNs2OSo7dL2IlIX2tCFe8SlJvA+wcnPx:8yNN6yJqjbOS6LiX2AKno+FnJ
                                                                                                                                                                            MD5:35A8D724FD8AF2C038A137DE5E6F19BA
                                                                                                                                                                            SHA1:36C5167BA9FF3B27D11C85486B2D37D94B76D9F0
                                                                                                                                                                            SHA-256:5A5CD1BA75B6732E814B548A74BA9FBE94D52E113EADF32B81E59C8BCA7AB55A
                                                                                                                                                                            SHA-512:BAF5CF10CD3D45AD0E041364BA126746263E9B246AE17F18FF4AC83BEA238A298AAB087FAB2DAEAD989BBD751B88EA997FD18D2DC11635802A490A57B25FEBE6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: ".......... ..... ......... ...... .........!",.. SEARCH_TOAST_SUB_HEADING: ".......... ..... .. ........ ... ........ .............. ....., .............. . ........... ....... {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "...... .......... .. ..... ... ...... .............. ...... ......?",.. SEARCH_TOAST_OPTION: ".., ........ .......... ..... ..... ........... .........",.. SEARCH_TOAST_DONE: "......"..}..//A1A09546187493B2E905A31D9318DA8444D0CDD309883B15265B059E3BFA1622A835F4488CC4271089169A5BB96C639C117AF548738DF2B3F4FBA1B4028CD908++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):649
                                                                                                                                                                            Entropy (8bit):5.787021399501204
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HLxCHLIOdhcUdOVzpG4kl9Uyc5DTS3Jn:7H9C0OdiSOVzpG4kXUyctTcJn
                                                                                                                                                                            MD5:C44D28237A6B757F95CE535CFEBFEDA7
                                                                                                                                                                            SHA1:B9EB40EB6B4F2EE30C9B96D65BFE4AA947FA408E
                                                                                                                                                                            SHA-256:1A83C1A9DC0ADBFE1E5DCCFD256F74436A7A62F083795083371A18C276B9442B
                                                                                                                                                                            SHA-512:B634252B6C6DEBC993A85F3B78D63CC1F13130623BC9349E22509141CDB5668E3B3BF0FD3830AFB292137BE5A6157FA26F85F86ADEF4BB7AB7D8460ACDF4767D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Zabezpe.en. vyh.ad.vanie je vypnut. . d.vajte si pozor",.. SEARCH_TOAST_SUB_HEADING: "Zabezpe.en. vyh.ad.vanie v.s chr.ni pred nebezpe.n.mi lokalitami vo v.sledkoch vyh.ad.vania. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Chcete ma. n.skok pred .to.n.kmi v.aka zv..enej ochrane pri vyh.ad.van.?",.. SEARCH_TOAST_OPTION: ".no, zabezpe.en. vyh.ad.vanie zapn.. po re.tarte prehliada.a.",.. SEARCH_TOAST_DONE: "Hotovo"..}..//149E6709C5CFD657DFEEA89947F6DBF418CBA8A0F7DF56594C44D023AF4F45537FBDBF6D2F9799727EBA1199EF93D26C0BC0415165BED05061F3E254AE76118C++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):605
                                                                                                                                                                            Entropy (8bit):5.6115676645450305
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H3ORkfi2TAdhX3UbQytlQuhUHFsWk64AFUAzgMBO:7H38kfwdqvQuhUHF3kLjmgMBO
                                                                                                                                                                            MD5:B7F48005676B897D23A2D77E1337EA82
                                                                                                                                                                            SHA1:91097E850AA2E65FA2D12F8D1168BFC9EF22ED49
                                                                                                                                                                            SHA-256:BF68150EF6A23C0E63D82E174FDB335C47B3496AE8B48EBA9BE35F6E7DD8523B
                                                                                                                                                                            SHA-512:F938ABB835D86C04CD3F95309F59011E3930D98409812DD55365625CC7A99F9E7911531DD6A8C3D6486E4A55EF551EDBAFA2BC035ECEE0CFB2B4094B26263FE9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "Bezbedna pretraga je isklju.ena . budite pa.ljivi",.. SEARCH_TOAST_SUB_HEADING: "Bezbedna pretraga vas .titi od rizi.nih lokacija u rezultatima pretrage. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: ".elite da budete u prednosti u odnosu na pretnje uz dodatnu za.titu pretrage?",.. SEARCH_TOAST_OPTION: "Da, uklju.i bezbednu pretragu nakon .to ponovo pokrenem pregleda.",.. SEARCH_TOAST_DONE: "Gotovo"..}..//2ACC2FEF55DE3B4194F8A6A236012B64A35645FB181AA1C5270D84E787D37FC441828776CAF3D5D67936CC200E30D250EAC3FEFD7A92DC70D1BDBAF394095E7F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):574
                                                                                                                                                                            Entropy (8bit):5.631845839445742
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7Hmg2AbjgZyDzL0HD4WkdhPN4McUQ4N94ije+ci38Gl1N:7H7DbEgLLdVWMHN94i6+hR1N
                                                                                                                                                                            MD5:39C2D771B371F6B034422856080ABACC
                                                                                                                                                                            SHA1:C1665F86C2964C1BF8AF7F1DA9C6CC64D808C822
                                                                                                                                                                            SHA-256:BEDF8B48BF6CBE896B2645E6638A80B38B5393516591C8069D99ADEDF48C6C07
                                                                                                                                                                            SHA-512:6789B62F9F7CD27573C6413DE9F227A54BA786986BA6A4CA0ED063B298C8BAC21688B007CDB77491AE93CFE2E1811FD77FC4BB2CB6FB43BA5755237B54015547
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "S.ker s.kning .r avst.ngd . var f.rsiktig",.. SEARCH_TOAST_SUB_HEADING: "S.ker s.kning h.ller dig borta fr.n riskabla webbplatser i s.kresultaten. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Vill du vara steget f.re hoten med extra s.kskydd?",.. SEARCH_TOAST_OPTION: "Ja, aktivera s.ker s.kning n.r jag har startat om webbl.saren.",.. SEARCH_TOAST_DONE: "Klart"..}..//F8E30110A1145C29647E579C7CDA99C3E5BC3A3B7CD17FEC113DCED5091E74BB8E14B659410AC439D4718E71E1EA8D8354AC28BA5FD3A66B40BAA183F0663096++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):589
                                                                                                                                                                            Entropy (8bit):5.622368928028239
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7H0i4Hb00hCdh29T1pGQMlwrX96UOO2deAa:7Hl4phCdA6VlwLb21a
                                                                                                                                                                            MD5:102E68C70E4D934A49B1A17CD3FA6F85
                                                                                                                                                                            SHA1:703B14279974DDA5270C734E6C885BDC876760F2
                                                                                                                                                                            SHA-256:C01582746CEA33E5564376604B4E572C1B6C9EFCFA4A7DD6589F5740FF03F7D1
                                                                                                                                                                            SHA-512:C8F5D1C81F513A8C2B33B0DDFD6EA25B107D61CAC31E145154A962599061C4845E7E5195AC405C4E66E2E15585FB163FF3027C7D9574AB9E48A65FB8473340BB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "G.venli Arama kapal., dikkatli olun",.. SEARCH_TOAST_SUB_HEADING: "G.venli Arama, sizi arama sonu.lar.n.zdaki riskli sitelerden uzak tutar. {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "Ek arama korumas. ile tehditlerin bir ad.m .n.nde olmak ister misiniz?",.. SEARCH_TOAST_OPTION: "Evet, taray.c.m. yeniden ba.latt.ktan sonra G.venli Arama'y. a..",.. SEARCH_TOAST_DONE: "Bitti"..}..//2E34B3229D4286580CD0781F64724D2FAEE038754346DA01CBF15F69B2E29FA428F93267F5D3F58443E53DC75E9A580D6C1937434564E5DAE1EEE9ADF0E7CD93++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):547
                                                                                                                                                                            Entropy (8bit):6.219020856626668
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HshRETCqdh2fDviKYE4aCeX7rBnP2dmegNREe:7HshVqd8rviKYEzPVP2dmeIREe
                                                                                                                                                                            MD5:690B33832BABAA078B978FDD4F6AD743
                                                                                                                                                                            SHA1:EB83BF314560B618CF7278609E9B5FC928B828D0
                                                                                                                                                                            SHA-256:BAF88339E23F2C026C07487B80A656E739F334DF820588650780441E73AC6B82
                                                                                                                                                                            SHA-512:9FB309D87AF322952AD2502099D288726D0D4A0050367A4C13661B08AAB35A5CE99C3F12B9E720AE9580D11125E9B52715D880F24A2063143249F3BF9BD0B3FD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "....... . .....",.. SEARCH_TOAST_SUB_HEADING: "...................... {0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: ".....................?",.. SEARCH_TOAST_OPTION: "...............",.. SEARCH_TOAST_DONE: ".."..}..//E87A6E9913C186CEE95654D6350532EA189E1D3D4C96E806A594110DE22C00328326A21D190D7A2D454D9DBF9D1D60826D8D06AD42BD12EF4B8E34CC40E25CF1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):555
                                                                                                                                                                            Entropy (8bit):6.203971338258118
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:7HamgrADLhZINcBjdhVfDaCBasqeDIYezud1A6ULKg:7Ha/cDtZINSdfrtarphzWK6gKg
                                                                                                                                                                            MD5:E221F413F3457CF7B8E6A2F19073F2AA
                                                                                                                                                                            SHA1:4571F544C1CF5C43776368514B6AAB27607CD990
                                                                                                                                                                            SHA-256:559860D0313C020894F71108E877BB95D5302632B5337002CE5FF9DAF7C5B76F
                                                                                                                                                                            SHA-512:0D0F52419D4ED4D5770BF418897F8AB34BF8B99B3C5C9719BDF8CBF724DCB2E9A35267BAD1E42F596E9716E7FD0CF0405D12B512EAB6ABAF253D9DE91C8C1EFE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_HEADING: "....... - ...",.. SEARCH_TOAST_SUB_HEADING: "........................{0}",.. SEARCH_TOAST_SUB_HEADING_STRONG: "......................",.. SEARCH_TOAST_OPTION: "..................",.. SEARCH_TOAST_DONE: ".."..}..//665E595423CA30C50F69453340F2E1F6F19A254BFF79E7F30BEDFF0FFE4F61055C51BFF0F883ED606A72C2DE49D5167A9B9ACE9DB77DADC2133D19C5230C7BD9++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6977
                                                                                                                                                                            Entropy (8bit):5.354677906533344
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CGsKDNR4J7qXQBLHEtvJd89CuvJd29Fx7sXYld4+X1p:CoDNR4x+tvJd89CuvJdMDwXcd4+X1p
                                                                                                                                                                            MD5:1EE03718AEDB679C9583C663F65D72B1
                                                                                                                                                                            SHA1:29A42FD946F5149CF768C6B7668601A2A5511981
                                                                                                                                                                            SHA-256:DE87F0DFC3E537C15B56509AE9D12B84F41059BCE8EE5F0C41D6D5B4CF686157
                                                                                                                                                                            SHA-512:56AAA511DC5DDFFDF15EC73B6D16268C1488C257C1F1AA5AD98EEC297DDF71ADBDF2BE1AA0219A03B7C658B21C27FE4B31BE7812DB8B254DCB262E19D32D2EBE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "A pesquisa segura est. desativada - tenha cuidado",.. SEARCH_TOAST_SUB_HEADING: "A pesquisa segura evita os sites perigosos nos resultados da pesquisa.",.. SEARCH_TOAST_BODY_TEXT: "Quer ficar longe de pessoas mal-intencionadas com prote..o de pesquisa extra?",.. SEARCH_TOAST_OPTION: "Sim, ative a pesquisa segura depois que o navegador for reiniciado.",.. SEARCH_TOAST_DONE: "Conclu.do",.. SEARCH_TOAST_HEADING_COMPLIANT: "A pesquisa segura n.o est. ativada - tenha cuidado",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "A pesquisa segura evita os sites perigosos nos resultados da pesquisa.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Gostaria de adicionar a pesquisa segura e se antecipar aos criminosos?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Sim, adicionar a pesquisa segura ao meu navegador e alterar minha pesquisa padr.o para {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",.. SE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7070
                                                                                                                                                                            Entropy (8bit):5.350688488062668
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:Chka9ILBeycgfmtmud0l9zEYmud0lkVHed0g574:ChknLBeycgmtm5PmqHyp4
                                                                                                                                                                            MD5:EEC4B6D886DE48F8CEDBE2134608DED6
                                                                                                                                                                            SHA1:B5FE71415CC592DDBC5677CE9ED5B46A05E51F10
                                                                                                                                                                            SHA-256:A395B4E3C670AC26E9F30E9C7049B1F95CC7FD7F2B39107F12A25905F49C9156
                                                                                                                                                                            SHA-512:0E83BEDCBF341E854E130738482E20E0F24FAE78FAF51572D7C1E3A65467C3ADB8957BB4048F83C5A397C2A4A1F25B461C6CCC0A7170076F7DE97D2986FDD185
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "A pesquisa segura est. desativada . tenha cuidado",.. SEARCH_TOAST_SUB_HEADING: "A pesquisa segura ajuda-o a evitar os sites perigosos nos seus resultados de pesquisa.",.. SEARCH_TOAST_BODY_TEXT: "Pretende evitar os utilizadores mal intencionados com a prote..o de pesquisa adicional?",.. SEARCH_TOAST_OPTION: "Sim, ativar a pesquisa segura ap.s reiniciar o meu browser.",.. SEARCH_TOAST_DONE: "Conclu.do",.. SEARCH_TOAST_HEADING_COMPLIANT: "N.o tem a pesquisa segura, tenha cuidado",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "A pesquisa segura ajuda-o a evitar os sites perigosos nos seus resultados de pesquisa.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Pretende adicionar a pesquisa segura e antecipar-se aos malfeitores?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Sim, adicionar a pesquisa segura ao meu browser e alterar a minha pesquisa predefinida para {0}.", // {0} SEARCH_TOAST_*.. SEARC
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with very long lines (309), with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):10279
                                                                                                                                                                            Entropy (8bit):5.11634369696361
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:CDxFR6OsBNVZPV/y/Vm1R1ut52Gu5U0DLTDGgr:CDxFR9I1yI1R1utQGuV5r
                                                                                                                                                                            MD5:2FE2D77FB1486F5A98D1281E4C28EF3C
                                                                                                                                                                            SHA1:DA6D04DB3CD1874A042ACFA757951E49ED59FBDC
                                                                                                                                                                            SHA-256:CB10D707EEC7340AAB7BE8C01E6AD67C0E6695EBB896337C840D66CF8D969866
                                                                                                                                                                            SHA-512:25F0984538E03F0A4B2270F868387F2DBDE7AABE83D775197A0C38B87CE3F6E103EC6F7D8F050EFB716812AB3414FE7E56B768E12F4FA43EB2F96CEFC12F4B44
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: ".......... ..... ......... ...... .........!",.. SEARCH_TOAST_SUB_HEADING: ".......... ..... .. ........ ... ........ .............. ....., .............. . ........... .......",.. SEARCH_TOAST_BODY_TEXT: "...... .......... .. ............... ... ...... .............. ...... ......?",.. SEARCH_TOAST_OPTION: ".., ........ .......... ..... ..... ........... .........",.. SEARCH_TOAST_DONE: "......",.. SEARCH_TOAST_HEADING_COMPLIANT: "...... ........., .. ... .. ........... .......... .....",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: ".......... ..... .. ........ ... ..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):7406
                                                                                                                                                                            Entropy (8bit):5.691254735980649
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:CgGE6x3pVIczmqoU5t9gga9BC9ge4rShIA:CgGE6vH6XU5t9gga9BC9grSOA
                                                                                                                                                                            MD5:6F7188EA8CE4375C51E7251A12201A47
                                                                                                                                                                            SHA1:0FDFFCD3489694047A46AD3A467E70E53B1CB397
                                                                                                                                                                            SHA-256:9786BCA0EEADC7F3D70CA76AB4DB2AB1F6B7C2FDAB60BAE612F8CBBC47C84E19
                                                                                                                                                                            SHA-512:E395C147BED5B33CC4350800072263B2836D36C6D63E319DCC708BE3FE706E5FC447F8FD8D5E7199DB5C37336E933A258F0B6ECBEA917F1EF5330C8E036360C7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Zabezpe.en. vyh.ad.vanie je vypnut. . d.vajte si pozor",.. SEARCH_TOAST_SUB_HEADING: "Zabezpe.en. vyh.ad.vanie v.s chr.ni pred nebezpe.n.mi lokalitami vo v.sledkoch vyh.ad.vania.",.. SEARCH_TOAST_BODY_TEXT: "Chcete ma. n.skok pred .to.n.kmi v.aka dodato.nej ochrane pri vyh.ad.van.?",.. SEARCH_TOAST_OPTION: ".no, po re.tartovan. prehliada.a zapn.. slu.bu Zabezpe.en. vyh.ad.vanie.",.. SEARCH_TOAST_DONE: "Hotovo",.. SEARCH_TOAST_HEADING_COMPLIANT: "Nem.te zabezpe.en. vyh.ad.vanie . d.vajte si pozor",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Zabezpe.en. vyh.ad.vanie v.s chr.ni pred nebezpe.n.mi lokalitami vo v.sledkoch vyh.ad.vania.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Chcete prida. zabezpe.en. vyh.ad.vanie a.zachova. si ochranu pred mo.n.mi .to.n.kmi?",.. SEARCH_TOAST_OPTION_COMPLIANT: ".no, prida. zabezpe.en.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6881
                                                                                                                                                                            Entropy (8bit):5.510612055221693
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CDvPQbt+oOuDdY9XXHci4ERt9UFE+fa9f+i9UFED9FV77GewuWZv9YT:Cj8at9UF89/9UF+TWZv9YT
                                                                                                                                                                            MD5:6459534816ED650A420B9254E5649E36
                                                                                                                                                                            SHA1:4BBFFC0B8AF32BEF18B5DCB96FD82B20188F1BCB
                                                                                                                                                                            SHA-256:20EB698CD0196E3D7E30C3AD414229493D37DD56789106325624FBF04D809593
                                                                                                                                                                            SHA-512:81828BF50F54DA2F064973C2C7EB1606B8F8016943B0DFE563266F4BBC8456C343DB5E3E281D87AD55F195CA94B0D052C91ABAF3DEC7A68977BA1C7528B84462
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "Bezbedna pretraga je isklju.ena . budite pa.ljivi",.. SEARCH_TOAST_SUB_HEADING: "Bezbedna pretraga vas .titi od rizi.nih lokacija u rezultatima pretrage.",.. SEARCH_TOAST_BODY_TEXT: ".elite da budete u prednosti u odnosu na .lo.e momke. uz dodatnu za.titu za pretragu?",.. SEARCH_TOAST_OPTION: "Da, uklju.i bezbednu pretragu nakon .to ponovo pokrenem pregleda..",.. SEARCH_TOAST_DONE: "Gotovo",.. SEARCH_TOAST_HEADING_COMPLIANT: "Nemate bezbedna pretraga - budite oprezni",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "Bezbedna pretraga vas .titi od rizi.nih lokacija u rezultatima pretrage.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: ".elite li dodati bezbedna pretraga i ostanite napred?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Da, dodajte bezbedna pretraga u moj pregleda. i promenite podrazumevanu pretragu na {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",.. SEARCH_ENG
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6625
                                                                                                                                                                            Entropy (8bit):5.4895771448474635
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CPWmMbkZdHSzoz9jp2rqntY25Sfs99FGlTuBLz704oH30wB9:CwbkOEtJ5SfsTzpEkwv
                                                                                                                                                                            MD5:9B3885CC66E9F52395E7D752E5CDF4F8
                                                                                                                                                                            SHA1:56A2B17274B399BD7F65DDF62931C50A70486612
                                                                                                                                                                            SHA-256:670DBF1CA1F3688472131452AB02A61AE9AFD1107042A8986EE95B96F4405F6E
                                                                                                                                                                            SHA-512:81FEBEFC5781869B3A4280D0A9BF823585FE06E7197868690E25F82EA36C9462E8B8DA153B0BDF89B0C16199634CFD7C4E7F44F3EB9193DA9E09701C614EBD85
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "S.ker s.kning .r avst.ngd . var f.rsiktig",.. SEARCH_TOAST_SUB_HEADING: "S.ker s.kning h.ller dig borta fr.n riskabla webbplatser i s.kresultaten.",.. SEARCH_TOAST_BODY_TEXT: "Vill du vara steget f.re skurkarna med extra s.kskydd?",.. SEARCH_TOAST_OPTION: "Ja, aktivera s.ker s.kning n.r jag har startat om webbl.saren.",.. SEARCH_TOAST_DONE: "Klart",.. SEARCH_TOAST_HEADING_COMPLIANT: "Du har inte s.ker s.kning . var f.rsiktig",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "S.ker s.kning h.ller dig borta fr.n riskabla webbplatser i s.kresultaten.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "Vill du l.gga till s.ker s.kning f.r att h.lla dig steget f.re skurkarna?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Ja, l.gg till s.ker s.kning till webbl.saren och .ndra standards.kningen till {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",.. SEARCH_ENGINE_YAHO
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6975
                                                                                                                                                                            Entropy (8bit):5.5449330549000395
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CcHgbQsEEkAWex0JFMRhtSgyLyowlSgB9FerI7ur22yp98j8:Ci6hMJF6t1yLyt13wrnr9yp9m8
                                                                                                                                                                            MD5:4A289029B90E0136FB8D25F9F1DC06CC
                                                                                                                                                                            SHA1:5CE0FD01CAB5768B3D7BF3EE4E7D626DAE875920
                                                                                                                                                                            SHA-256:BB990556BF0E9F031E5F9F7B9B9D8D43AC6CAEE35E469743F6523D624BD28D3B
                                                                                                                                                                            SHA-512:D40CB7BCAEBCEDDD966C01CBDF72E17726F4A3B75097FB5244E8CB0BE30F83ABCEA716E0F85105731EF11BCCCDFADB6122E9E276CE64FA41DDA91ED5F40B21E0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "G.venli Arama kapal., dikkatli olun",.. SEARCH_TOAST_SUB_HEADING: "G.venli Arama, sizi arama sonu.lar.n.zdaki riskli sitelerden uzak tutar.",.. SEARCH_TOAST_BODY_TEXT: "Ek arama korumas. ile k.t. adamlar.n bir ad.m .n.nde olmak ister misiniz?",.. SEARCH_TOAST_OPTION: "Evet, taray.c.m. yeniden ba.latt.ktan sonra G.venli Arama'y. a..",.. SEARCH_TOAST_DONE: "Bitti",.. SEARCH_TOAST_HEADING_COMPLIANT: "G.venli Arama'ya sahip de.ilsiniz, dikkatli olun",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "G.venli Arama, sizi arama sonu.lar.n.zdaki riskli sitelerden uzak tutar.",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: "G.venli Arama'y. ekleyerek k.t. niyetli ki.ilerden uzak durmak ister misiniz?",.. SEARCH_TOAST_OPTION_COMPLIANT: "Evet, G.venli Arama'y. taray.c.ma ekle ve varsay.lan aramam. {0} olarak de.i.tir.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing"
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6330
                                                                                                                                                                            Entropy (8bit):6.348346363907773
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CUk5RhhRDj8mxeX+lE8D9VkbXtK6XKS9FgXap7B0CCm:Ch/LxeXqEsGtBX/Dp9LCm
                                                                                                                                                                            MD5:AE61DE2CF0CAF5BEB18022515E8868E9
                                                                                                                                                                            SHA1:66DF21F7EEF504F4E2AA75AC466A1A41286A88B3
                                                                                                                                                                            SHA-256:D299B49CE26A7A26C20F42B7C4F7383B5B43AD840134C72A84AB88DB5010D341
                                                                                                                                                                            SHA-512:396DB989C5461F910C4F6E6AD82FB72C78648B124D3E3E3765DF5CBD8B8CED2129C56301AD6818660B3A140787E2A71C2671D5775657BFE1DDE4BC8EE1EEF4A6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "....",.. SEARCH_TOAST_HEADING: "....... . .....",.. SEARCH_TOAST_SUB_HEADING: ".....................",.. SEARCH_TOAST_BODY_TEXT: ".......................?",.. SEARCH_TOAST_OPTION: "................",.. SEARCH_TOAST_DONE: "..",.. SEARCH_TOAST_HEADING_COMPLIANT: "......... . .....",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: "......................",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: ".......................?",.. SEARCH_TOAST_OPTION_COMPLIANT: ".......................... {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",.. SEARCH_ENGINE_YAHOO: "Yahoo",.. SEARCH_ENGINE_YANDEX: "Yandex",
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):6347
                                                                                                                                                                            Entropy (8bit):6.335104550023616
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:CGhla0tPlgm6w6KdmnPZ1cSDGFtMDjNOWMDjB9FEKrYimnP:Ci7dgtOfSStMPNOWMP3wimnP
                                                                                                                                                                            MD5:EA17AFF0064CF31DE59D47A1F24A37A7
                                                                                                                                                                            SHA1:5B2A410C65B26F2181F37F01DC2337355765FF6C
                                                                                                                                                                            SHA-256:C8CA9C6C95C85ADA603FDBC487080097DBFBC7523E8A0B1953281068CE8B33C9
                                                                                                                                                                            SHA-512:5A95F4C078B4903E57A7D52EAEBA581450F2162BC36C0289A3BB022702147818FABA9AB59AC0008588428ED8929CD6D2E529FF23E54787ADEFDFAAB18F2F6BA0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. SEARCH_TOAST_PRODUCT_NAME: "WebAdvisor",.. SEARCH_TOAST_HEADING: "....... . ...",.. SEARCH_TOAST_SUB_HEADING: ".......................",.. SEARCH_TOAST_BODY_TEXT: "........................",.. SEARCH_TOAST_OPTION: "...................",.. SEARCH_TOAST_DONE: "..",.. SEARCH_TOAST_HEADING_COMPLIANT: "....... . ...",.. SEARCH_TOAST_SUB_HEADING_COMPLIANT: ".......................",.. SEARCH_TOAST_BODY_TEXT_COMPLIANT: ".......................",.. SEARCH_TOAST_OPTION_COMPLIANT: "........................... {0}.", // {0} SEARCH_TOAST_*.. SEARCH_ENGINE_BING: "Bing",.. SEARCH_ENGINE_YAHOO: "Yahoo",.. SEARCH_ENGINE_YANDEX: "Yandex
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2562
                                                                                                                                                                            Entropy (8bit):5.6867899274612075
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UjbcgNu0dSJUGlJ6qfveziXpAlJ2bRQmC3ptQfMmIm42wudadOlOfm92Nokzzj:UjbcgNurGGlJRemXalKRQmgpt4MmImi/
                                                                                                                                                                            MD5:B5C9547A3C4AE6189F5DD6D5B9C75131
                                                                                                                                                                            SHA1:C0BC16C9930BFD2E7CDCD821D45B903C385A1870
                                                                                                                                                                            SHA-256:1ACF7F0D31819CEDA9A4042F645EA99E69983DE1F482ABF101BA296DF68C1FB2
                                                                                                                                                                            SHA-512:6C12A308B2E7949F5CF67477B1C061223520CDDAA43C25FE78221786CAFB7AFB7A9F990B420BE6B4BF5D74C56CF37D592CE078B3C95623683628EE8E68CE021E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "V odinstalaci nelze pokra.ovat, dokud nebudou zav.ena v.echna okna prohl..e.e.<br/>Kliknut.m na tla..tko OK automaticky zav.ete v.echna okna prohl..e.e. Kliknut.m na tla..tko Zru.it tuto akci zru..te.",.. ADMIN_WARNING: "Aplikaci {0} nebylo mo.n. odinstalovat, proto.e jste k po..ta.i p.ihl..eni jako u.ivatel s omezen.mi opr.vn.n.mi. P.ihlaste se jako spr.vce syst.mu Windows a zkuste to znovu.",.. KEEP_FREE_PROTECTION: "Ponechat funkci Ochrana p.i proch.zen. internetu",.. NO_THANKS_UNINSTALL: "Ne, d.kuji. Chci ji odinstalovat",.. CANCEL: "Zru.it",.. NO_THANKS: "Ne, d.kuji",.. SURE: "Samoz.ejm.",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "Odinstalace aplikace {0} prob.hla .sp..n..",.. SURVEY_OFFER: "R.di bychom znali v.. n.zor. Pora.te n.m, jak m..eme tento produkt je.t. vylep.it.",.. SORRY_TO_GO: "Je n.m l.to, .e jste si aplikaci nenechali.",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2321
                                                                                                                                                                            Entropy (8bit):5.407870308134455
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:U9XpCmXa0Roqce7Coh4C3zOur+BYHexiAWFY502OUhMYI5Lp6+ZaKJq4U3rZ:U9XpbXaUz3x+BYWivW0uinhEaq4U3rZ
                                                                                                                                                                            MD5:C371F5545BC075A3AEAC14CAB178118C
                                                                                                                                                                            SHA1:57B39EAB60847B41A6910ADEC0F266EA0B611B7B
                                                                                                                                                                            SHA-256:D609D64279C59F8976638FBA48586929220FBD7A40DBF6B7BC489CE3C224887E
                                                                                                                                                                            SHA-512:3754B922D59C608A1430FA893825BCF52C25541306056134BD710C6703EA6B583D1B06D0F73493EEDF580A79F605E8B643E378E4E065E0D8C51D964512BF3345
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Lukke alle browservinduer for at forts.tte med at afinstallere softwaren.<br/>Tryk p. OK for at lukke alle browservinduer automatisk eller p. Annuller for at afbryde.",.. ADMIN_WARNING: "Du kan ikke afinstallere {0}, da du er logget p. computeren som begr.nset bruger. Log p. som Windows-administrator, og pr.v igen.",.. KEEP_FREE_PROTECTION: "Behold webbeskyttelsen",.. NO_THANKS_UNINSTALL: "Nej tak, afinstaller den bare",.. CANCEL: "Annuller",.. NO_THANKS: "Nej tak",.. SURE: "Selvf.lgelig",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "Afinstallationen af {0} er f.rdig.",.. SURVEY_OFFER: "Vi vil gerne h.re din mening. Hvordan kan vi efter din mening g.re dette produkt endnu bedre?",.. SORRY_TO_GO: "Vi er kede af, at du forlader os.",.. UNINSTALLING: "Softwaren afinstalleres ...",.. START_HEADER: "Vent! Vil vil savne dig, hvis du afinstallerer",.. START_SUB_HEADER: "Og du vil ogs. savne all
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2527
                                                                                                                                                                            Entropy (8bit):5.381960990709301
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UYDdXJ6UXJbcC87UQT9zw/eCJlgf0IyYuYL16OhrHAoKKmJvDkoxmTZ:UydXTXOs6fIYXLhgokkoxuZ
                                                                                                                                                                            MD5:33CAFE027F0B8C32E685AD92EB28BDF2
                                                                                                                                                                            SHA1:C60DDE3B88B174E76A4F4589C33EA7DF7072B8A9
                                                                                                                                                                            SHA-256:F3E0D5494866421A6F2B6D5C0BC7AC6073DB7281EEFE3A5DD61F4698E881CA9E
                                                                                                                                                                            SHA-512:93301A34B8F063B99EF5CD41562C7324A1DB5AFF75DE056E6589831B1AC5D80FCC6DDB117B218FC3B4695BB63FD986C1C9CE1FF8B974A5721AD21C35AC50874F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Die Deinstallation kann erst fortgesetzt werden, nachdem alle Browser-Fenster geschlossen wurden.<br/>Klicken Sie auf 'OK', um alle Browser-Fenster automatisch zu schlie.en, oder klicken Sie zum Beenden auf 'Abbrechen'.",.. ADMIN_WARNING: "Sie k.nnen {0} nicht deinstallieren, da Sie bei Ihrem Computer als Benutzer mit eingeschr.nkten Rechten angemeldet sind. Melden Sie sich als Windows-Administrator an, und versuchen Sie es erneut.",.. KEEP_FREE_PROTECTION: "Web-Schutz behalten",.. NO_THANKS_UNINSTALL: "Nein danke, bitte deinstallieren",.. CANCEL: "Abbrechen",.. NO_THANKS: "Nein danke",.. SURE: "Sicher",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "Die Deinstallation von {0} wurde erfolgreich beendet.",.. SURVEY_OFFER: "Wir freuen uns, von Ihnen zu h.ren. K.nnen Sie uns mitteilen, wie wir dieses Produkt noch verbessern k.nnen?",.. SORRY_TO_GO: "Schade, dass Sie unser Produkt nicht mehr verwenden m.cht
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4045
                                                                                                                                                                            Entropy (8bit):5.018197822286349
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:U4iYsFeBkg78VLgPHKM6V6WaLq/tit7lO7e5mS:U4iiam8hgPj6V6W0q/titcAmS
                                                                                                                                                                            MD5:F970CF47D49A33B1084B4379460D1768
                                                                                                                                                                            SHA1:072469DF0FA582F0ACF64D71D5E0F1FF56EC46A1
                                                                                                                                                                            SHA-256:A4805243E0A4DEB70F7C97EAAF6BCD974539727EECDDD8BBE16E010FDC3C63B6
                                                                                                                                                                            SHA-512:318B3C4EC8A21EBE396B49E6946F9A94D515186D928BF6F4319FEB6523E99881DC383D6C8A97C564117661EBB164C5B1B55BA708BE679BA9E5E75488B80DA867
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: ". ......... ............ ... ...... .. .......... .. ... ........ ... .. ........ ... ............ ...........<br/>....... OK ... .. ........ ........ ... .. ........ ... ............ .......... . ....... ....... ... .........",.. ADMIN_WARNING: "... ........ .. ........... ... ........... ... {0} ..... ..... ........ .... .......... ... .. ....... .. ............ ........... .......... .. ............ ... Windows ... ......... .....",.. KEEP_FREE_PROTECTION: "......... ... .......... Web",.. NO_THANKS_UNINSTALL: "... ........., ..... ..........
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2170
                                                                                                                                                                            Entropy (8bit):5.38971409651161
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UawX1F1LVSHccWK2aFe3ymc9oqTLvmLtwbvORLxeMZi:UxXfhQpe3ymco0uLtRLxeV
                                                                                                                                                                            MD5:46F2DBFC9B7B6AB39B2A9E699C70C32B
                                                                                                                                                                            SHA1:4EEF9802DF5A0D59062D469C1B384085406A264D
                                                                                                                                                                            SHA-256:7165D76B5BC7B5F1CD09D9F9A7A636591F80278E583F856D1925DB98D926BE97
                                                                                                                                                                            SHA-512:3AF47B81AF6C0A1F20D4EDE2CFCEF57AAAB81D6EA3CF5C92560E205831A3052121C8AEA7D7BB20CFAE471BF0B1DB8D53F8A3E7E42BDE2218EE38BF2A63CD445A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Uninstallation cannot continue unless all browser windows are closed.<br/>Press Ok to automatically close all browser windows, or Cancel to abort.",.. ADMIN_WARNING: "You can't uninstall {0} because you're logged in to your computer as a Limited User. Please log in as a Windows Administrator, and try again.",.. KEEP_FREE_PROTECTION: "Keep web protection",.. NO_THANKS_UNINSTALL: "No thanks, just uninstall it",.. CANCEL: "Cancel",.. NO_THANKS: "No thanks",.. SURE: "Sure",.. OK: "Ok",.. SUCCESSFULLY_UNINSTALLED: "You've successfully uninstalled {0}.",.. SURVEY_OFFER: "We want to hear from you. Can you share your thoughts on how to make this product even better?",.. SORRY_TO_GO: "We're sorry to see you go.",.. UNINSTALLING: "Uninstalling your software now...",.. START_HEADER: "Wait! If you uninstall, we'll miss you",.. START_SUB_HEADER: "And you'll miss all the good we do, like:",.. WE_SCANNED: "
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2342
                                                                                                                                                                            Entropy (8bit):5.374289352079449
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Uop2w+XfxK626IEkLmHVR9zgD/1jBv2a82Vj6Aux9M8KBkVSl9:UzwqfxnjVgjvv24KxS+S
                                                                                                                                                                            MD5:A66DBF3C4949571B37A77F05F100C0F7
                                                                                                                                                                            SHA1:43406EBCB86BC36C633724DC5DE5BBDC6918FDEF
                                                                                                                                                                            SHA-256:EF4C6A1511D42DD9867E1CE601253DDBB1FCB1D04722280463C081469F870551
                                                                                                                                                                            SHA-512:9679B864D11BA61B76811FEC59EAC20B54BD0B5D7432E1BD338EFE8A0E42CA1B6AD3D312930A92FA306CB6AF79E306EC8525FCE9C6A04FB1B54E9C593C94D3B2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "La desinstalaci.n no puede continuar a menos que cierre todas las ventanas del navegador.<br/>Pulse Aceptar para cerrar autom.ticamente todas las ventanas del navegador o Cancelar para anular el proceso.",.. ADMIN_WARNING: "No puede desinstalar {0} porque ha iniciado sesi.n en su equipo como usuario limitado. Inicie sesi.n como administrador de Windows y vuelva a intentarlo.",.. KEEP_FREE_PROTECTION: "Mantener protecci.n web",.. NO_THANKS_UNINSTALL: "No, desinstalar",.. CANCEL: "Cancelar",.. NO_THANKS: "No, gracias",.. SURE: "Claro",.. OK: "Aceptar",.. SUCCESSFULLY_UNINSTALLED: "Ha desinstalado {0} correctamente.",.. SURVEY_OFFER: "Queremos saber su opini.n. .Puede compartir sus ideas sobre c.mo mejorar este producto?",.. SORRY_TO_GO: "Sentimos que deje de utilizar el producto.",.. UNINSTALLING: "Desinstalando el software...",.. START_HEADER: "Espere. Si desinstala, le echaremos de menos",.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2389
                                                                                                                                                                            Entropy (8bit):5.387010405651874
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Uo72wwXfxjn6v6IEkLX/wrN9gZ0o/0BjBfjTz2VhSZ6c9VTC0CYFmz:U/wUfxnIwancfjTpVTC0nM
                                                                                                                                                                            MD5:3DA3C95538F7A23292CF788F7465E614
                                                                                                                                                                            SHA1:434A56E8BDFBD30163D145FA5FBF5F34EA22C20E
                                                                                                                                                                            SHA-256:EBF68D216085C88D331811DB6E08F90E9FB06B0AFA55FFE3D29C800DDFDE0239
                                                                                                                                                                            SHA-512:9217E2EADFC530E2FB87DE9854786CE02C287EE219B4AA55EF830C14EF9A18648230AFDC8031E60AC8D82BE92078921B54966D1830831132B3976C41989BC37D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "La desinstalaci.n no puede continuar a menos que cierre todas las ventanas del navegador.<br/>Presione Aceptar para cerrar autom.ticamente todas las ventanas del navegador o Cancelar para interrumpir el proceso.",.. ADMIN_WARNING: "No puede desinstalar {0} porque ha iniciado sesi.n en su equipo como usuario limitado. Inicie sesi.n como administrador de Windows y vuelva a intentarlo.",.. KEEP_FREE_PROTECTION: "Conservar protecci.n web",.. NO_THANKS_UNINSTALL: "No, gracias, desinstalarlo",.. CANCEL: "Cancelar",.. NO_THANKS: "No, gracias",.. SURE: "Claro",.. OK: "Aceptar",.. SUCCESSFULLY_UNINSTALLED: "Ha desinstalado {0} correctamente.",.. SURVEY_OFFER: "Queremos saber su opini.n. .Puede compartir sus ideas sobre c.mo mejorar este producto?",.. SORRY_TO_GO: "Sentimos que deje de usar el producto.",.. UNINSTALLING: "Desinstalando el software.",.. START_HEADER: ".Espere! Si desinstala, lo ext
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2389
                                                                                                                                                                            Entropy (8bit):5.3518634805529
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UrCot/9DbtMfbzwx1kF08hjltMEwTZVyY+vRVZY2f3gvai1Ov9:UrHmMx2BJt8TDmRVzIk
                                                                                                                                                                            MD5:F9554E08115C89B08EC634A0F4EB6E0D
                                                                                                                                                                            SHA1:33B111AC223505DC75E580E82CBF006C78E0244D
                                                                                                                                                                            SHA-256:1ED3D4E0D8FBC95F48C02FF389584ACEB8A3E37C48F7EF6356EC8CE671461422
                                                                                                                                                                            SHA-512:5A9F24D05F551750F4E757047CA196070027E970197887608EE7127AF2FC5C8F8CF9DE3C0E24482FD07BCF885C749E4A2C41CBAD5D5C8FE13D767B149C0397F7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Asennuksen poistamista ei voi jatkaa, jos kaikkia selainikkunoita ei suljeta.<br/>Sulje kaikki selainikkunat automaattisesti valitsemalla OK tai keskeyt. valitsemalla Peruuta.",.. ADMIN_WARNING: "Et pysty poistamaan sovelluksen {0} asennusta, sill. olet kirjautunut tietokoneeseen k.ytt.j.n., jolla on rajoitetut oikeudet. Kirjaudu Windowsin j.rjestelm.nvalvojana ja yrit. uudelleen.",.. KEEP_FREE_PROTECTION: "Jatka verkkosuojauksen k.ytt...",.. NO_THANKS_UNINSTALL: "Ei, kiitos. Poista asennus.",.. CANCEL: "Peruuta",.. NO_THANKS: "Ei kiitos",.. SURE: "OK",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "{0} on poistettu.",.. SURVEY_OFFER: "Kuulisimme mielell.mme sinulta palautetta. Haluatko kertoa meille, miten voisimme tehd. tuotteesta viel. paremman?",.. SORRY_TO_GO: "Ik.v.., ett. et halua jatkaa tuotteen k.ytt...",.. UNINSTALLING: "Poistetaan ohjelmiston asennusta.",.. START_HEADER
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2674
                                                                                                                                                                            Entropy (8bit):5.370515207845727
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UZbbplCgKbHGou9Uz0NHKVfNV7jUtmjV0fkJmTMOo8MXIHe5QXZhrgKHqeTsO:URbpEhDvVF5jUqckJXBIHe5scqqeTv
                                                                                                                                                                            MD5:1907F5229E4B8C09A7C3716EE531CDB4
                                                                                                                                                                            SHA1:933C89C28E04FF63969D6A3F137D2B43C84B2932
                                                                                                                                                                            SHA-256:22D276421691E4D7D2D27CA2697420902CF1DFF2E8B50D8D409C92B0821ABBB4
                                                                                                                                                                            SHA-512:4BB791A0671DC7663E7287B57558721C829618AC70F761D00B79BC992212B219649C1D1D5475F1113E74C3E28C661CB25B8E91E2E939D06336E3E9D1ED77A3C6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "La d.sinstallation ne peut pas se poursuivre sans avoir ferm. toutes les fen.tres du navigateur.<br/>Cliquez sur OK pour fermer automatiquement toutes les fen.tres du navigateur, ou sur Annuler pour abandonner.",.. ADMIN_WARNING: "Vous ne pouvez pas d.sinstaller {0}, car vous .tes connect. en tant qu'utilisateur disposant d'un acc.s restreint. Veuillez vous connecter en tant qu'administrateur Windows, puis essayez de nouveau.",.. KEEP_FREE_PROTECTION: "Garder la protection Web",.. NO_THANKS_UNINSTALL: "Non merci, d.sinstallez-la",.. CANCEL: "Annuler",.. NO_THANKS: "Non merci",.. SURE: "Bien s.r!",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "Vous avez correctement d.sinstall. {0}.",.. SURVEY_OFFER: "Nous souhaitons conna.tre votre opinion. Seriez-vous dispos. . nous dire comment nous pourrions am.liorer ce produit?",.. SORRY_TO_GO: "Nous sommes d.sol.s que vous nous quittiez.",.. UNINSTA
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2626
                                                                                                                                                                            Entropy (8bit):5.398923340868169
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UT3FlNKBwOdm79zoIuKntX3OPwnIeruBTCtnSo8sprasnmNz+f:UTVfsEtX+iIeq8XUsmNz+f
                                                                                                                                                                            MD5:DE01057169269BDE1CEDB411BE89DC66
                                                                                                                                                                            SHA1:4DCE5734177EC07EB100B875E54FA6508A590ABC
                                                                                                                                                                            SHA-256:78D07B024DDB4F7ED57F48A39FB0B933814F65E6842516F9851490EBD18242C2
                                                                                                                                                                            SHA-512:000B5F1B7C4988DC27610159B1FA245BF1D63DF245F2D4331EEC0B57226457C68D5182E7CEEF4823953DD1C2B85E1A6C76B8C21A2E1014162569D023E897DE59
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Impossible de poursuivre la d.sinstallation tant que toutes les fen.tres du navigateur ne sont pas ferm.es.<br/>Cliquez sur OK pour fermer automatiquement toutes les fen.tres du navigateur ou sur Annuler pour interrompre l'op.ration.",.. ADMIN_WARNING: "Vous ne pouvez pas d.sinstaller {0}, car vous .tes connect. en tant qu'utilisateur limit. sur votre ordinateur. Connectez-vous en tant qu'administrateur Windows et recommencez.",.. KEEP_FREE_PROTECTION: "Conserver la protection web",.. NO_THANKS_UNINSTALL: "Non merci, proc.der . la d.sinstallation",.. CANCEL: "Annuler",.. NO_THANKS: "Non, merci",.. SURE: "Bien s.r",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "Vous avez d.sinstall. {0}.",.. SURVEY_OFFER: "Nous serions ravis de conna.tre votre opinion. Si vous avez des id.es pour am.liorer ce produit, n'h.sitez pas . nous en faire part.",.. SORRY_TO_GO: "Nous sommes d.sol.s de vous voir p
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2390
                                                                                                                                                                            Entropy (8bit):5.44504076457636
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:U4qRJGbmxWQuD28CEnxSP+vuR4S0OaysKXXFrQ7zy5I:UxiRNC83kPEu30uRWPmI
                                                                                                                                                                            MD5:F50611583168626FCD098F95E000A6B7
                                                                                                                                                                            SHA1:9C4F81D6036D9309C7A126F3FAAF0460C75658AA
                                                                                                                                                                            SHA-256:E4B242AC00B9FD3BB9FAD9AFA140A03B87D3561D12F047C98736178BCB4174C2
                                                                                                                                                                            SHA-512:08CF92AE8D5FDCE90F296F15EC7F405275E8E1340652B515532B2F406AFBE0D2EF86C9B101FA49A55B70549571785FF4939775AA1E537097E6EA24C49725BF97
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Deinstalaciju nije mogu.e nastaviti ako svi prozori preglednika nisu zatvoreni.<br/>Kliknite na U redu da biste automatski zatvorili sve prozore preglednika ili Odustani da biste prekinuli proces.",.. ADMIN_WARNING: "Ne mo.ete deinstalirati {0} jer ste na ra.unalo prijavljeni kao korisnik s ograni.enim ovlastima. Prijavite se kao administrator sustava Windows i poku.ajte ponovno.",.. KEEP_FREE_PROTECTION: "Zadr.i za.titu na webu",.. NO_THANKS_UNINSTALL: "Ne, hvala, samo je deinstaliraj",.. CANCEL: "Odustani",.. NO_THANKS: "Ne, hvala",.. SURE: "Naravno",.. OK: "U redu",.. SUCCESSFULLY_UNINSTALLED: "Uspje.no ste deinstalirali {0}.",.. SURVEY_OFFER: ".elimo .uti va.e mi.ljenje. .elite li podijeliti s nama svoje ideje za pobolj.anje ovog proizvoda?",.. SORRY_TO_GO: ".ao nam je .to vi.e ne.ete biti na. korisnik.",.. UNINSTALLING: "Deinstaliramo va. softver sada...",.. START_HEADER: "
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2561
                                                                                                                                                                            Entropy (8bit):5.595928399408576
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Ud/4sBMK+ZvbkFzo5lQiw9Azz8eFRHJev0Dq4aVv/tYr8wlE:Ud/PBMKN6lu9aVFR4e2lFYr8wlE
                                                                                                                                                                            MD5:84F9AA20F6323ECEC5FA9B5EA8A9585A
                                                                                                                                                                            SHA1:3D6E310B88843329CEBDA20BDFECB7AA7973C95D
                                                                                                                                                                            SHA-256:966CEB24ABDD99AA360D683C84BED10CE523D9F71674E58D7EEB5C4EACB79CED
                                                                                                                                                                            SHA-512:A22FC3109FBF10A4D1A5E0B6667DE4A33764CFA70923BE68615532F8BBCAB1D4935D5B1D0234AC13191419DDF10764E85701FF87DDFF2E059A13E7D15DBB3F6D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Az elt.vol.t.s csak az .sszes b.ng.sz.ablak bez.r.sa ut.n folytathat..<br/>Az OK gombot megnyomva automatikusan bez.rhatja az ablakokat, a M.gse gombbal pedig megszak.thatja a m.veletet.",.. ADMIN_WARNING: "A(z) {0} szoftver elt.vol.t.sa nem lehets.ges, mivel a sz.m.t.g.pre korl.tozott hozz.f.r.s. felhaszn.l.k.nt jelentkezett be. L.pjen be Windows-rendszergazdak.nt, majd pr.b.lja .jra.",.. KEEP_FREE_PROTECTION: "Webes v.delem meg.rz.se",.. NO_THANKS_UNINSTALL: "Nem, egyszer.en t.vol.tsa el",.. CANCEL: "M.gse",.. NO_THANKS: "K.sz.n.m, nem",.. SURE: "Rendben",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "Megt.rt.nt a(z) {0} elt.vol.t.sa.",.. SURVEY_OFFER: "Sokra .rt.keln.nk a v.lem.ny.t. Megosztan. vel.nk, hogy v.lem.nye szerint hogyan tehetn.nk m.g jobb. ezt a term.ket?",.. SORRY_TO_GO: "Sajn.ljuk, hogy nem tart ig.nyt a szolg.ltat.sra.",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2426
                                                                                                                                                                            Entropy (8bit):5.330203387186763
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UUKu3r7X85X6/5Ouzl676xLqVDSdEfCXqYQ0d0ddfbOf5F:UDE/M5puk68VDcEK7vSdSxF
                                                                                                                                                                            MD5:E24D4C1F4903ECD3773373995AA3F80D
                                                                                                                                                                            SHA1:397F8056BB476BFE272F1CECB607E2518F132114
                                                                                                                                                                            SHA-256:4026AA1727001F5E178F82C61D038FD577458D973057833F3C461B5996D0FB6A
                                                                                                                                                                            SHA-512:EF4391809EC9651F927C906F93D4B8D01EFADFCC16CDBAAD512DAD578F797993887719C8EC20655E97C7163F60B9CCC43293997B34CE924B56647E545C1CE300
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Per procedere con la disinstallazione . necessario chiudere tutte le finestre del browser.<br/>Premi OK per chiudere automaticamente tutte le finestre del browser oppure Annulla per interrompere l'installazione.",.. ADMIN_WARNING: "Impossibile disinstallare {0} in quanto l'accesso al computer . stato effettuato come utente con restrizioni. Accedi come amministratore di Windows e riprova.",.. KEEP_FREE_PROTECTION: "Mantieni la protezione Web",.. NO_THANKS_UNINSTALL: "No grazie, disinstallala",.. CANCEL: "Annulla",.. NO_THANKS: "No, grazie",.. SURE: "Certo",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "Disinstallazione di {0} riuscita.",.. SURVEY_OFFER: "Vogliamo sapere la tua opinione. Vuoi condividere la tua opinione per migliorare ancora di pi. questo prodotto?",.. SORRY_TO_GO: "Ci dispiace che tu abbia deciso di lasciarci.",.. UNINSTALLING: "Stiamo disinstallando il software...",.. START_HEADER: "
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2813
                                                                                                                                                                            Entropy (8bit):5.7350879207820284
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UmgtjeIgCS7v06vDxzezcu5dbwaIVvOaaI9nCiGSGfKi4Z0YX+NrVd2J:UmgtjP6r3dzevdUnkbf4ANrVu
                                                                                                                                                                            MD5:D09966922D3E2BB7825A01483211000F
                                                                                                                                                                            SHA1:8C5C4D1A3DCA16BDCFF126299B7C3B787449E5D5
                                                                                                                                                                            SHA-256:04A2E68B9929FD7CB806BBA560D6B3959F484847A422A17C3C0C684FB9FC3AC2
                                                                                                                                                                            SHA-512:2A616AA8C9516A636386E7B53528FC7B65E5C0D467A380C8EA0704CF032694BF31129E40731C71983FB50318371C44BF06A87F3C211656462E46E3570DB2959C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: ".......................................<br/>[OK] .............. ...............................[.....] .........",.. ADMIN_WARNING: "{0} .........................................Windows ............................",.. KEEP_FREE_PROTECTION: "..........",.. NO_THANKS_UNINSTALL: "....",.. CANCEL: ".....",.. NO_THANKS: "...",.. SURE: "..",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "{0} ..................",.. SURVEY_OFFER: "...........................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2648
                                                                                                                                                                            Entropy (8bit):5.965466360269122
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UJfHnXcKfYWPiQrinx8fhU5aN0jFnSBra8ABYWajyqYOAl5us3aTLq9n:Upv2n0C5aejF4raNYdXAis+Lq9n
                                                                                                                                                                            MD5:51900FE8A49914FDA1FBE1F35775FF4C
                                                                                                                                                                            SHA1:3E5B62EE2F8252A8DA7159386015049176A84715
                                                                                                                                                                            SHA-256:349F8BB67FD381A88379E4D36C2A03497D69FBAF12E2636164149BCD536B9A98
                                                                                                                                                                            SHA-512:80CB766DE2522ED493CB0D9279F1B7D9C0C6E482A5BCDE8A27584042CA7BB49BE32BB8543FCF3367BE2647054DCCD7E6CAA0C1B378329B363465FD43BC34D69D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: ".. .... .. .. ... ... ... . .....<br/>... .. .... .. .... .. ... ... .. ... .......",.. ADMIN_WARNING: "... .... .... ..... .... {0}. ... . ..... Windows .... .... . .. .......",.. KEEP_FREE_PROTECTION: ". .. ..",.. NO_THANKS_UNINSTALL: "..., .....",.. CANCEL: "..",.. NO_THANKS: "...",.. SURE: ".",.. OK: "..",.. SUCCESSFULLY_UNINSTALLED: "{0}. ..... ........",.. SURVEY_OFFER: "... .... .. ..... . ... .. ... .. ... .........?",.. SORRY_TO_GO: "... ..... .... . .. .... ......",.. UNINSTALLING: "...... .
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2338
                                                                                                                                                                            Entropy (8bit):5.396206405077309
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:U2AUYbOdeMb72i5iur+vrJBFJZG5biH7kFJqSCLUhS0TGpCaiSV5TNnH:ULkX2G+vNBFSbiHIFCAc6SPNH
                                                                                                                                                                            MD5:D4879747D956E1916B263E98200D8135
                                                                                                                                                                            SHA1:302BC33C8CEC22BEF418C04B4E67C45304AF3722
                                                                                                                                                                            SHA-256:A20D5B7650772D59B347703844F9EF56191394681355B17346BEE90B99A6D9E9
                                                                                                                                                                            SHA-512:95BB36B92D4A8FC9B04A6EDDF45255B6F9A662036A62F68BE33CD379459E695042FC884ECED1BDE92C72121400B57A5E9F9453E3589C65907827CB3026E56645
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Avinstallasjonen kan ikke fortsette f.r du har lukket alle nettleservinduer.<br/>Trykk p. OK for . lukke alle vinduene automatisk eller p. Avbryt for . avbryte.",.. ADMIN_WARNING: "Du kan ikke avinstallere {0} fordi du er logget p. datamaskinen som en Begrenset bruker. Logg p. som Windows-administrator og pr.v p. nytt.",.. KEEP_FREE_PROTECTION: "Behold webbeskyttelse",.. NO_THANKS_UNINSTALL: "Nei takk, bare avinstaller det",.. CANCEL: "Avbryt",.. NO_THANKS: "Nei takk",.. SURE: "Ja visst",.. OK: "Ok",.. SUCCESSFULLY_UNINSTALLED: "Du har avinstallert {0}.",.. SURVEY_OFFER: "Vi vil gjerne h.re fra deg. Kan du dele dine ideer om hvordan vi kan gj.re dette produktet enda bedre?",.. SORRY_TO_GO: "Det er synd at du ikke vil fortsette . bruke oss.",.. UNINSTALLING: "Vi avinstallerer programvaren n...",.. START_HEADER: "Vent! Vi vil savne deg hvis du velger . avinstallere",.. START_SUB_H
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2363
                                                                                                                                                                            Entropy (8bit):5.330164663060023
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:URHXIzXIV2xo3lID6XgocC7h7kBzyNkIK+2L0LgSPGxetBt/XktFOFVQA3a/:UhXOXgYGi6XgAgtIKtLeOw3FmAq/
                                                                                                                                                                            MD5:94FD0B4733A47B840735E1D3A97C347E
                                                                                                                                                                            SHA1:96CB962BBDD9DF336C83E377AF7BE40798B76F9F
                                                                                                                                                                            SHA-256:BC6272D53B4E2F610E7DCB3B2A9301FAFD4A50A0DF2FCA51F40C35FBE194D98A
                                                                                                                                                                            SHA-512:470CF5E899AB6DD7AA113FAE32F8187AE9B6AFE7E7A0C25BDFD48608EECD28D27D379517575C2FF52BB7D725FC8BE4462A0F7E394E67E7D5563F7BCBB9E4B9E7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Verwijdering kan pas worden voortgezet wanneer alle browservensters zijn gesloten.<br/>Klik op OK om alle browservensters automatisch te sluiten of op Annuleren om af te breken.",.. ADMIN_WARNING: "U kunt {0} niet verwijderen, omdat u bij de computer bent aangemeld als Gebruiker met beperkte rechten. Meld u aan als Windows-beheerder en probeer het opnieuw.",.. KEEP_FREE_PROTECTION: "Webbeveiliging houden",.. NO_THANKS_UNINSTALL: "Nee, installatie verwijderen",.. CANCEL: "Annuleren",.. NO_THANKS: "Nee, bedankt",.. SURE: "Goed",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "U hebt {0} verwijderd.",.. SURVEY_OFFER: "We horen graag van u. Kunt u ons laten weten hoe dit product nog verder kan worden verbeterd?",.. SORRY_TO_GO: "Wat jammer dat u ons gaat verlaten.",.. UNINSTALLING: "Uw software wordt nu verwijderd...",.. START_HEADER: "Wacht! We zullen u missen als u de software verwijdert",.. START_SUB_HE
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2456
                                                                                                                                                                            Entropy (8bit):5.639526314050624
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Ux6l/L182ZR1tM7T4K95K19ehLvfZhKXdWjpLTFi:U4lBXZjKWCfEeU
                                                                                                                                                                            MD5:DFFD53C36D72C8F2D4E492145350A5DA
                                                                                                                                                                            SHA1:EEA8B352FE8A3DC367EFBBF50B2212270A7248C8
                                                                                                                                                                            SHA-256:60C7AF2F7C8AF470204D02C8514B2E64B49673CF67B8D59D5D94F5B2C96A374D
                                                                                                                                                                            SHA-512:C8C080A865CE349A389E6D7E24B6630165701CE8D462538E86E547FCFB3DCD560F47315DBD3354DB745BEEBBD97E8E25DF5366F77F1DDC128DC00CB506E82E77
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Nie mo.na odinstalowa., dop.ki wszystkie okna przegl.darki nie zostan. zamkni.te.<br/>Kliknij przycisk OK, aby automatycznie zamkn.. wszystkie okna, lub przycisk Anuluj, aby przerwa. proces.",.. ADMIN_WARNING: "Nie mo.na zainstalowa. programu {0} z powodu zalogowania na komputer jako u.ytkownik z ograniczonymi uprawnieniami. Zaloguj si. jako administrator systemu Windows i spr.buj ponownie.",.. KEEP_FREE_PROTECTION: "Zachowaj ochron. w sieci Web",.. NO_THANKS_UNINSTALL: "Nie, dzi.kuj.. Odinstaluj.",.. CANCEL: "Anuluj",.. NO_THANKS: "Nie, dzi.kuj.",.. SURE: "Pewnie",.. OK: "Ok",.. SUCCESSFULLY_UNINSTALLED: "Program {0} zosta. pomy.lnie odinstalowany.",.. SURVEY_OFFER: "Chcemy pozna. Twoj. opini.. Jak mogliby.my ulepszy. nasz produkt?",.. SORRY_TO_GO: "Przykro nam, .e musimy si. rozsta..",.. UNINSTALLING: "Odinstalowujemy Twoje oprogramowanie...",.. START_HEADER: "Czekaj!
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2373
                                                                                                                                                                            Entropy (8bit):5.39733627694852
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UHC6Unw+8DeoRMzBDzXGZ077FG/BjS7kjd6AGBhofQR9Nv:UfUdkM1zk8Bw47kjZchofQDNv
                                                                                                                                                                            MD5:E546B885A419C18A25AB3E1527AAF57B
                                                                                                                                                                            SHA1:F2D3B303B8FFC113C380EF9A5CB13FCCE810D220
                                                                                                                                                                            SHA-256:0FF28375F3BE52A5A5690D84A5C132D8F7B618A26AF281026BF96F4631E3F06E
                                                                                                                                                                            SHA-512:258B309521A1EF4B3C1DFBEC927980861EE531B4FDAF71A46EAB18F24A8DC4B1347BEBE4E17B521F12BE3AD84CEEE8A1B720C7D35C08C35E6279FA8356C5E323
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "A desinstala..o poder. continuar somente se todas as janelas do navegador forem fechadas.<br/>Clique em OK para fechar todas as janelas do navegador automaticamente ou clique em Cancelar para interromper a opera..o.",.. ADMIN_WARNING: "N.o . poss.vel desinstalar o {0} porque voc. est. conectado ao computador como um Usu.rio Limitado. Entre como Administrador do Windows e tente novamente.",.. KEEP_FREE_PROTECTION: "Manter a prote..o na Web",.. NO_THANKS_UNINSTALL: "N.o, obrigado. Desinstale o programa",.. CANCEL: "Cancelar",.. NO_THANKS: "N.o, obrigado",.. SURE: "Claro",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "{0} foi desinstalado com .xito.",.. SURVEY_OFFER: "Queremos saber a sua opini.o. Deseja compartilhar suas ideias para tornar esse produto ainda melhor?",.. SORRY_TO_GO: "Lamentamos pela sua sa.da.",.. UNINSTALLING: "O seu software est. sendo desinstalado...",.. START_HEADER
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2369
                                                                                                                                                                            Entropy (8bit):5.4079735501786255
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UDlURTq+8ZxNHRSMMy7EVW14P9SZPkDPIjQ7AV2iEc5KQoID:UxUOitVQsDf7FQoQ
                                                                                                                                                                            MD5:149E0BBF2EDFCF809D2CCBD0B34FD0B5
                                                                                                                                                                            SHA1:18F49C57C8D9BC4778AE9F55DEB4B533BBD7F7C0
                                                                                                                                                                            SHA-256:D7186ADD85922E32B75780A52804D2EFF89C175B7A6F81AC2AC2B554C850A6F5
                                                                                                                                                                            SHA-512:6D8A9B6E94A6A725B9EEBE5D84740F9ED5450ECCC18252E43E3143CCE1DD4E229DD393062922134691234C5B80A86D5B4C9841FB68A8A1D7473E89AFAFEE313C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "N.o . poss.vel continuar com a desinstala..o sem fechar todas as janelas do browser.<br/>Prima Ok para fechar automaticamente todas as janelas do browser ou Cancelar para cancelar a opera..o.",.. ADMIN_WARNING: "N.o . poss.vel desinstalar o {0} porque tem sess.o iniciada no seu computador como Utilizador Limitado. Inicie sess.o como Administrador do Windows e tente novamente.",.. KEEP_FREE_PROTECTION: "Manter a prote..o Web gratuita",.. NO_THANKS_UNINSTALL: "N.o, obrigado, desinstalar",.. CANCEL: "Cancelar",.. NO_THANKS: "N.o, obrigado",.. SURE: "Claro",.. OK: "Ok",.. SUCCESSFULLY_UNINSTALLED: "Desinstalou o {0} com .xito.",.. SURVEY_OFFER: "Queremos ouvir a sua opini.o. Pode enviar os seus coment.rios para tornar este produto ainda melhor?",.. SORRY_TO_GO: "Temos pena que nos deixe.",.. UNINSTALLING: "Estamos a desinstalar o software...",.. START_HEADER: "Aguarde! Se desinstalar
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3465
                                                                                                                                                                            Entropy (8bit):5.097424545190096
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UxdXe3T+ZqUelORd3BZjNfGqhHmLgw0ZIsgUKacbkgmhVXAT1Wh9TEP:Uxt3xPfGqhHmkwKIyK+hx8
                                                                                                                                                                            MD5:31F821DCE9F7D669EFBECDE3185E050C
                                                                                                                                                                            SHA1:B9F6BFE74E7517283C9EC7115FC10F111D1F5429
                                                                                                                                                                            SHA-256:CE25AF25522FDE1E25816A9547D88C4508DB7A8D36820A0B69F49A44A6BE6BDC
                                                                                                                                                                            SHA-512:261F3A5C16E273E37E2C313F1CEBC2925E679C9673E1BBDBE370AB0636BF29584795E38B860E3193D61E2E3E6D366389BFE9CAAF35D9F10EAC6DA58CB7A65423
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "..... .......... ........, .......... ....... ... .... .........<br/>....... ...... .., ..... ............. ....... ... .... ........, .... ...... ......, ..... .......... .. .......... .........",.. ADMIN_WARNING: ".......... ....... {0}, ... ... .. ..... . ....... ... ............ . ............. ........ ....... . ....... ... ............. Windows . ......... ........",.. KEEP_FREE_PROTECTION: "......... ...-......",.. NO_THANKS_UNINSTALL: "..., ........ ....... ...-......",.. CANCEL: "......",.. NO_THANKS: "..., .......",.. SURE: "......",.. OK: "..",.. SUCCESSF
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2602
                                                                                                                                                                            Entropy (8bit):5.668373016806341
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Ujo34jWoRebkIk8Am7/fz8x9kJghJhuaO+PUi53yqUA29nsYvrOstk:UjP1Ik8AajJMaavUi5RVgsSisa
                                                                                                                                                                            MD5:D4F9C25D0D28EB10C7A96A40E38980C3
                                                                                                                                                                            SHA1:C15BBE6C5B6380E54F6B08FC69B092A0164E9C0D
                                                                                                                                                                            SHA-256:571E50354EC269C6BA06359A45B739A855B266B7C72C307A65F1E9D79CF9D33F
                                                                                                                                                                            SHA-512:CFD35A19285CE4404110303CC39B0164F206784386EE9B66361745471057B7725EC810D854B1DE83ACF361AF3534D344233A66464FCF750632CC90C49D7BC17E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "V odin.talovan. bude mo.n. pokra.ova. a. po zavret. v.etk.ch okien prehliada.a.<br/>Ak chcete automaticky zavrie. v.etky okn. prehliada.a, kliknite na tla.idlo OK. Ak chcete odin.talovanie zru.i., kliknite na tla.idlo Zru.i..",.. ADMIN_WARNING: "Aplik.ciu {0} nem..ete odin.talova., preto.e ste sa do po..ta.a prihl.sili ako pou..vate. s obmedzen.m. Prihl.ste sa ako spr.vca syst.mu Windows a sk.ste to znova.",.. KEEP_FREE_PROTECTION: "Ponecha. ochranu pred webom",.. NO_THANKS_UNINSTALL: "Nie, .akujem, odin.talova. ju",.. CANCEL: "Zru.i.",.. NO_THANKS: "Nie, .akujem",.. SURE: "Iste",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "Aplik.ciu {0} ste .spe.ne odin.talovali.",.. SURVEY_OFFER: "Radi by sme poznali v.. n.zor. M..ete sa s nami podeli. o svoje n.vrhy na zlep.enie tohto produktu?",.. SORRY_TO_GO: "Je n.m ..to, .e sa l..ime.",.. UNINSTALLIN
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2387
                                                                                                                                                                            Entropy (8bit):5.4861014984584076
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:Ub2RwcC6S2hGDlCEVFS/+uhRpTSQOa/YmAXXRTsa:UiKRE8ha/HhiQ70lX
                                                                                                                                                                            MD5:7736A64C15E4E9C7E15E0499E8E40DE5
                                                                                                                                                                            SHA1:A1F7B403C9E84B50220E047FF77B389A862CC0F3
                                                                                                                                                                            SHA-256:D5B86BECA01ED3110AA80F81DDBFD916732415157D1586925BBDFB3A07A3E9CB
                                                                                                                                                                            SHA-512:BEF67D2EA14F1A4223A678AEF4C50A1165130D7084E91F69B03C8A129DCFC8C2D52D5341F9B81F429F2AEACBD873C7B6746CB00B39308CED17ED11FBE85099EE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Nije mogu.e nastaviti deinstalaciju dok se ne zatvore svi prozori pregleda.a.<br/>Kliknite na dugme .U redu. da biste automatski zatvorili sve prozore pregleda.a ili kliknite na dugme .Otka.i. da biste odustali.",.. ADMIN_WARNING: "Ne mo.ete da deinstalirate {0} zato .to ste prijavljeni na ra.unar kao ograni.eni korisnik. Prijavite se kao Windows administrator i poku.ajte ponovo.",.. KEEP_FREE_PROTECTION: "Zadr.ite Veb za.titu",.. NO_THANKS_UNINSTALL: "Ne, hvala, deinstaliraj je",.. CANCEL: "Otka.i",.. NO_THANKS: "Ne, hvala",.. SURE: "Naravno",.. OK: "U redu",.. SUCCESSFULLY_UNINSTALLED: "Uspe.no ste deinstalirali {0}.",.. SURVEY_OFFER: ".elimo da .ujemo va.e mi.ljenje. Mo.ete li da podelite sa nama svoje ideje za pobolj.anje ovog proizvoda?",.. SORRY_TO_GO: ".ao nam je .to odlazite.",.. UNINSTALLING: "Sada deinstaliramo va. softver...",.. START_HEADER: "Sa.ekajte! Ak
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2300
                                                                                                                                                                            Entropy (8bit):5.474804605063888
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:U2OwbAtfP5E+Ht3zni7IL8wPt2i6W7GvCZCjXAPPeMHi2iwsuwmwOMJxAQ5S:ULwq7t38IfFN7JCaPeMCH4Q7AQo
                                                                                                                                                                            MD5:E4B03825A7303C09DBDF2742B4CDEC47
                                                                                                                                                                            SHA1:7EA5102618AB1081C5B73D57BB3E238F723E8EBB
                                                                                                                                                                            SHA-256:AC45BF99F99422FEA76F025AC059EE8DEDAF45A406716FDEC15DD2F09E9A4D4C
                                                                                                                                                                            SHA-512:31EAA59916A6D5908F5B419517F9781B6D87FC207972394F1C89B4F9E76D19DD42178B31AB123FC21B2BE10E4AA44E4E6B9220CD3F2F8EC13FEF90754A346EAE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "Avinstallationen kan inte forts.tta f.rr.n samtliga webbl.sarf.nster .r st.ngda.<br/>Tryck p. OK f.r att st.nga alla webbl.sarf.nster automatiskt, eller p. Avbryt f.r att avbryta.",.. ADMIN_WARNING: "Du kan inte avinstallera {0} eftersom du .r inloggad p. datorn som begr.nsad anv.ndare. Logga in som Windows-administrat.r och f.rs.k igen.",.. KEEP_FREE_PROTECTION: "Beh.ll ditt webbskydd",.. NO_THANKS_UNINSTALL: "Nej tack, avinstallera det",.. CANCEL: "Avbryt",.. NO_THANKS: "Nej tack",.. SURE: "Ja tack",.. OK: "OK",.. SUCCESSFULLY_UNINSTALLED: "{0} har avinstallerats.",.. SURVEY_OFFER: "Kontakta oss g.rna. Vill du dela dina id.er om hur vi kan g.ra produkten .nnu b.ttre?",.. SORRY_TO_GO: "Vi beklagar att du l.mnar oss.",.. UNINSTALLING: "Avinstallerar programvaran nu ...",.. START_HEADER: "V.nta! Om du avinstallerar kommer vi sakna dig",.. START_SUB_HEADER: "Och v.rre
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2590
                                                                                                                                                                            Entropy (8bit):5.547653990910053
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UrK+A3WqDVZRmSXdypNsXHp8QbTBtW+R+jNvSvp2DAw0kxnfcOKef3gtlvne1J:UW3WQyQXHpHHBw+R+x680GfF3gtlvQJ
                                                                                                                                                                            MD5:F4D6D9CCB77242DFED6772A64B4BBEF4
                                                                                                                                                                            SHA1:519EF1E4B31514FE2A50612CD086758CEEBA2EFE
                                                                                                                                                                            SHA-256:64C94A44411592C50D7D37587831D19D36FC5B8E7913D84666691BB9EE861F24
                                                                                                                                                                            SHA-512:CB19E90534BEC93426C6F92EB1CBBED852D54E3ADCF3B9E166718F509501A8600CBE4CF39EDE81E25DEE761D72BFA03CE8A8F495B1BADDD3496B235CE6F0C5CB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "T.m taray.c. pencereleri kapat.lmadan kald.rma i.lemine devam edilemez.<br/>T.m taray.c. pencerelerini otomatik olarak kapatmak i.in Tamam'a, i.lemi iptal etmek i.in ise .ptal'e bas.n.",.. ADMIN_WARNING: "Bilgisayar.n.zda S.n.rl. Kullan.c. olarak oturum a.t...n.z i.in {0} uygulamas.n. kald.ramazs.n.z. L.tfen Windows Y.neticisi olarak oturum a..n ve yeniden deneyin.",.. KEEP_FREE_PROTECTION: "Web korumas.n. tut",.. NO_THANKS_UNINSTALL: "Hay.r, te.ekk.rler, kald.rmak istiyorum",.. CANCEL: ".ptal",.. NO_THANKS: "Hay.r, te.ekk.rler",.. SURE: "Tabii ki",.. OK: "Tamam",.. SUCCESSFULLY_UNINSTALLED: "{0} uygulamas.n. ba.ar.yla kald.rd.n.z.",.. SURVEY_OFFER: "D...ncelerinizi ..renmek isteriz. Bu .r.n. daha iyi hale getirmek i.in neler yap.labilece.ine ili.kin d...ncelerinizi bizimle payla.abilir misiniz?",.. SORRY_TO_GO: "Gitti.iniz i.in .zg.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2207
                                                                                                                                                                            Entropy (8bit):6.3594701403436575
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UtM+PzEwQSBjFt9CNLX15qklwzATPXtrVeGTGB:UPftMtFzwzUtriB
                                                                                                                                                                            MD5:B59AAAAC52B618223883A3CCFACAB979
                                                                                                                                                                            SHA1:18E34DD3BE96FA167BDFBCA4AE98BF4179145FB7
                                                                                                                                                                            SHA-256:D2222A002F5A1701A470A7E10A1F8A6F6BDA13EDCB3B034A7A0C8C2DCCD6655F
                                                                                                                                                                            SHA-512:86DA8B7860ADB4ED779A57F5C9201D384E0AA28C1151A2862B45EBCA9C2DAA5A47C9C50B44290AED118018B7FA49C3A9DDF5D1273186938F8D0B2587E9CC08E1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: "........................<br/>...............................",.. ADMIN_WARNING: "..... {0}.................. .. Windows .............",.. KEEP_FREE_PROTECTION: "......",.. NO_THANKS_UNINSTALL: "........",.. CANCEL: "..",.. NO_THANKS: "....",.. SURE: "..",.. OK: "..",.. SUCCESSFULLY_UNINSTALLED: "...... {0}.",.. SURVEY_OFFER: "........... .....................?",.. SORRY_TO_GO: "............",.. UNINSTALLING: ".........",.. START_HEADER: "...! ................",.. START_SUB_HEADER: "............
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2271
                                                                                                                                                                            Entropy (8bit):6.363323658706558
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:UtQEPQWGitIGg3V4BxFrtYqbu1bRqAO5qgggF3pA5Bo:UCEjAqxHsG5eEpAro
                                                                                                                                                                            MD5:CC2579B3DFE06ACE43FEA4804C7ECE99
                                                                                                                                                                            SHA1:07CA624B77091EF516C39E27477B469624F7C607
                                                                                                                                                                            SHA-256:9D2A83637796F072C28218B4C5A9CB80820C1109CF1D64428706AECB99A6446F
                                                                                                                                                                            SHA-512:B4DB2369F1CB3951461840FD5CE7840067AFE79CF2C9B90834B4F683ED556462413AF948112EF6E21A7FB5E1F83F42E2ECED838C024DB8D064496AD4EBE761CC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUninstall_ = {.. BROWSER_RUNNING_WARNING: ".........................<br/>. [..] ............... [..] ...",.. ADMIN_WARNING: "....... {0}..... [......] ....... .. Windows ..................",.. KEEP_FREE_PROTECTION: ".. Web ..",.. NO_THANKS_UNINSTALL: ".............",.. CANCEL: "..",.. NO_THANKS: "....",.. SURE: "..",.. OK: "..",.. SUCCESSFULLY_UNINSTALLED: "....... {0}.",.. SURVEY_OFFER: ".......... .......................",.. SORRY_TO_GO: ".................",.. UNINSTALLING: ".............",.. START_HEADER: "................",.. START_S
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.421577842693986
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPLng:Yo6KUtjVLk4t94iU3KNoT8u8ayg
                                                                                                                                                                            MD5:9FE61AB675B400AEFAC96AA167CA4EB5
                                                                                                                                                                            SHA1:402D75F1A5334A0387653D1AB0C72C362653FC0E
                                                                                                                                                                            SHA-256:51990924DD2887EEA7AE572740D016EBBD970FA8015FD40BC2CBCBB63FE19A44
                                                                                                                                                                            SHA-512:7EC5B2692C2F2C8B42FE97AD45A8F7B0DB0F02875B0A362329B39EE33391D309EB179DE9C2C2B3513364111D0851E97253029F768C7B78BAFA7BF4771D5D2385
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.419897316300179
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPcD:Yo6KUtjVLk4t94iU3KNoT8u8a5
                                                                                                                                                                            MD5:A3672F0A0A41208730DD6E62E0AA0275
                                                                                                                                                                            SHA1:CC2892D7780CE64CDD877EC759130C477C0ADD18
                                                                                                                                                                            SHA-256:8C06426F664E2ACABAF1C6EB47752E255C90CADE05482494CA37E1D23EE4F138
                                                                                                                                                                            SHA-512:C790782CCBB777EAEEC1CF7FA4C99445713B45A4960FF9C113DC6D446D2B1D68ADF1CC2A14054072700F230A113CE4189FB0984A4FED0B9827A2872431CAF96E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.409948627721378
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPn:Yo6KUtjVLk4t94iU3KNoT8u8aa
                                                                                                                                                                            MD5:9EFDF51475A43968D6E4718EF377D114
                                                                                                                                                                            SHA1:BE68A01805A1E485F65A5710AD1DE92B16FB83C3
                                                                                                                                                                            SHA-256:4DD8335F3BC0D25322513392868B7E9CDA50107DE370AFD6ED6D0E1B00D75569
                                                                                                                                                                            SHA-512:836EC2DC8AAE109026B4CD1050DF9469FCE61AF45EF171F732D2182EB31F4C4F46018535F3D5A559C367FFEF0F8ACAD964D4783CA6C14A93FC86ABAD335CF32E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.413603514419358
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aP7:Yo6KUtjVLk4t94iU3KNoT8u8aW
                                                                                                                                                                            MD5:0E73429D670F5C9CEEA7AF17D2EF9999
                                                                                                                                                                            SHA1:C13A5D362F348ECB94B436B49136B3A94F413891
                                                                                                                                                                            SHA-256:FC6D0B1BCDDDCEE70D03D796A706DFAC88AC0B8BAD72FEA327EDFEE730D8B71E
                                                                                                                                                                            SHA-512:AD52364986752C1407E495027258EC5D3CE5C34E0D86029969DA0CFB93E66E2EA5BA5AEE523F63BAD0601FF601DA3CDAEACE24EC643B48F4B6055FC3710CBBAF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.413406832301877
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPpQ9vm:Yo6KUtjVLk4t94iU3KNoT8u8aA
                                                                                                                                                                            MD5:3F6135FDB0DEAC31D3BD26B3BCB3D9FA
                                                                                                                                                                            SHA1:56F00B405F7750AE50FF74C3751643B294EA9376
                                                                                                                                                                            SHA-256:F524FC64628283054B562D159184E28745C17A0C4F206E06E08427438B4DE5C2
                                                                                                                                                                            SHA-512:044FC79350664633EE117DCA61E2BBFDD93A1581246F022F0C790D0F278F7807B6B74AD90CDD9946E1D1983E7B2FB5CA12E80AF684088A1E414B6EA9DEA54BD2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.4161981543742375
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPY:Yo6KUtjVLk4t94iU3KNoT8u8aJ
                                                                                                                                                                            MD5:C390774B91883A1BFCC628C735864D0F
                                                                                                                                                                            SHA1:3CBF5604C05947E86B975BD95109FF1A00E2398D
                                                                                                                                                                            SHA-256:FAE5F9ED555CAF667336B07E6086F878947EAF75501A56C5E5B7848C0EB59630
                                                                                                                                                                            SHA-512:00611AE33EC58A991163DC3FC577912F7118DBFA7525C5716491759C9576EA2BE689CF07459E44BD0658A53169334964E8EBF64179EFD9FD21A936FA85FF4657
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.4133944203366635
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPY:Yo6KUtjVLk4t94iU3KNoT8u8at
                                                                                                                                                                            MD5:C369092A4D4530239D42F94D631F683D
                                                                                                                                                                            SHA1:D67FFDAB98A74C4E9A477BE6434A6B38D28E5508
                                                                                                                                                                            SHA-256:C0F9CCE38563A117907543C1EA522CF0D014102324A9EF46660A9B01833895E8
                                                                                                                                                                            SHA-512:17D6EC8C7DC17AA4D2F3A5B89C9CFCBF23903ADBE2AFC6ED938AA8A48C80B5778EB80B8BDA78D72BEE932AD56C4B5CCB743FEAB5D1B9D44D4541ADEBC9369FB3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.421392433119576
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPDH:Yo6KUtjVLk4t94iU3KNoT8u8aIH
                                                                                                                                                                            MD5:4488C6A7EAEC8F97DDD2FBFA467BB3B8
                                                                                                                                                                            SHA1:8DA32ADBB4CD5AE1B793AD8323C78F56EC1ECA41
                                                                                                                                                                            SHA-256:0568B7E9AC97003EDC3DC5E277A4D1925E0E442DC99544E67F3F7ACFF2C1388F
                                                                                                                                                                            SHA-512:7C358DEEAD1A3DD24CFF5B8CB174D5C457D9D898E51D49CD7A8DACDFEDD64DF831028BB73D69B79BD527FB857B4EE354A8C604A41CBF6FF514623378E8EB2EE9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.414224710526144
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPjgH:Yo6KUtjVLk4t94iU3KNoT8u8a6s
                                                                                                                                                                            MD5:EB13CD7B73F29F695F8D2D470D1562CF
                                                                                                                                                                            SHA1:4E9903DA07BF60BAF683C480EB5166AFE3CBA633
                                                                                                                                                                            SHA-256:B867441425FE2997BBF5A4FA90151AB1EC964F7C7821174CBCEBD01994AFB91D
                                                                                                                                                                            SHA-512:3561A7726CDF78AD4CB69CEC055AE51E97FAD3F627067DF65B2421A167DF5D040131714E02A72549EAA5825CBBA1FC927D0C5D06CBB1A31793101F166D11FDB6
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.413744033444191
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPPD:Yo6KUtjVLk4t94iU3KNoT8u8aq
                                                                                                                                                                            MD5:04ADB8773162AD4F83BB4B105D7A2D3C
                                                                                                                                                                            SHA1:F5491694EE4A57C273DA2149C55953763FAC8F61
                                                                                                                                                                            SHA-256:940BE99ABE6A2A19259F571D587EB1ABD3940D749DB8A68AC87CAD63C1DD921F
                                                                                                                                                                            SHA-512:2241980DADCD13883DC91A8675B722C64839E4D12792E2BA7F304D805D8718D7DA83307A9D4C0AE3A933EF60902A33197DA7C075F2271B8CEBD4011497D19E35
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.418902385318098
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPmp:Yo6KUtjVLk4t94iU3KNoT8u8azp
                                                                                                                                                                            MD5:8F21889C438D0E7FCD3FBB01936181F0
                                                                                                                                                                            SHA1:3FEC8424E930A0305DC5AFE5456D434667703642
                                                                                                                                                                            SHA-256:9EB1DDE93E8530B93D4A9FAEA2E2934A986621C6A1588DBC1C03E0EA762CE340
                                                                                                                                                                            SHA-512:81003B269E54CD0D48BAC9D28F9459B37F9B15C343849F4EEB7FB64B1CA3EFA6F3B065E778306663E7FF5E3884A7A623FAA549DE4472244D0D93C7AA4AF4BE9D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.4174628836720355
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPp+:Yo6KUtjVLk4t94iU3KNoT8u8aQ+
                                                                                                                                                                            MD5:09ACFE979DDC0083D223A2CD508C0D84
                                                                                                                                                                            SHA1:116BFB0C7B06BF851CC6D6DA0FEF578F008875E5
                                                                                                                                                                            SHA-256:DBB6582ACEAE46401F25DE2AC865AB4FEAC20248FEAA1AC48B41C706AD14AEA6
                                                                                                                                                                            SHA-512:B0F0CEF8F5ADB5675B79149383C7FBCB718FF614592DE6D0D5A010DCFF61C3E459C71A2A0B5A73D635475E3169F2281BC5094BA0A509F060375677EA342C4266
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.4034843296203325
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPH:Yo6KUtjVLk4t94iU3KNoT8u8aq
                                                                                                                                                                            MD5:679FF7B236A0BC9B892B1DB3CD04014B
                                                                                                                                                                            SHA1:2707E7226882896D6239EA175AD68ADDBA858F3D
                                                                                                                                                                            SHA-256:C8464B790741BFC9D24A96B7360AF3457BDFCC001AB48AE4636AEDBF18E66482
                                                                                                                                                                            SHA-512:88F146D83BC386788541583CC149EE59FF3746A6D391476CFEF2FA6C667C0B07B75988B6A729E7CC474A8023FF88AFAE364536A9E84E30E695FDE3935D54724E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.413672546832975
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPI:Yo6KUtjVLk4t94iU3KNoT8u8aR
                                                                                                                                                                            MD5:D0ABCD9FD9E845BF1290CDA39F3507BE
                                                                                                                                                                            SHA1:4D71FBD13F5830A246A676DF51F42AC52C8AA183
                                                                                                                                                                            SHA-256:420C537B799C6AE58B9E2F809B0FC191AA2E481644186F595469028D652B777F
                                                                                                                                                                            SHA-512:3C3FE99872F8C3AF2FF858A5133FE878F23DB0CF21DA99183D44B3BCD0CFD72A5DCE919BE6CB29992A5496FD654B8FD5EB4804D22A034123C2BC64B2A1BC22AA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2008
                                                                                                                                                                            Entropy (8bit):5.909488900192057
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:7vzEJoY7j197RD0AQUSRrNyEimWAwHM3+i3PZOHsciY/oY7BL+WPUJupxJXA0:/ZYt9iAQhRwEimWQ+i3YBLztgJ8xG0
                                                                                                                                                                            MD5:10683AB0B71EBE3C1F51A299B7864D2C
                                                                                                                                                                            SHA1:4416601198B6ABA9F187E0C1434EEAD892EC5C7B
                                                                                                                                                                            SHA-256:A0F936B24F8A84CB6E4B7417C7DD6CA49C6D71C44CBCA1D458461CCFA4BCC9F6
                                                                                                                                                                            SHA-512:748D3E6766123A46371754148D9B32766ECA7561A3F9DB7A3F34A92D2CFA59FACDACD4255486BC9A51F193F1E8104317D6DD2079AAC8AB2B524D6B9E8EEF66AB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: ".. ... ... ... .... ... .. .... ....",.. UT_WSS_TOAST_TITLE_COHORT_2: "McAfee. .. .... .. ",.. UT_WSS_TOAST_TITLE_2: "... .... ... {0}.(.) .. .. ..",.. UT_WSS_TOAST_TITLE_2_STRONG: "... ..",.. UT_WSS_TOAST_DESC_1_VAR_1: "McAfee. .. ..... .... VPN, .. .. .., Premium ...... ... .. . ... ......",.. UT_WSS_TOAST_DESC_1_VAR_2: ".. . ... ... ... .. ... . .. .... ......",.. UT_WSS_TOAST_DESC_2_VAR_2: ".. McAfee. .. ...... ......",.. UT_WSS_TOAST_DESC_COHORT_2: ".. .... ... ......, .. .. .., VPN, .. .. ... ... .... ......",.. UT_WSS_BUTTON_ACCEPT: ".. ....",.. UT_WSS_BU
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.418516889252441
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPKP:Yo6KUtjVLk4t94iU3KNoT8u8aF
                                                                                                                                                                            MD5:B3C02DEC4E232FC624AB0C1E55F6312B
                                                                                                                                                                            SHA1:4658B03C568897D0D1DA1245E243D95E86BEB868
                                                                                                                                                                            SHA-256:3EB1D58410DCCEC475EBF1DB6B892A52188691DACAEB2EC8E667FA64D3119DDF
                                                                                                                                                                            SHA-512:935768715B870599369B004E5B044A5673C3FBFB54F1FE53A36F1605D6FAD1399C2257661C3ED76F58232F60BF38B9A68F18CA7C5E7CE6E921A6C0641083CB1A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.418407979344233
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aP/isU:Yo6KUtjVLk4t94iU3KNoT8u8amisU
                                                                                                                                                                            MD5:52573AEC0D6D921E975497F0266F23BB
                                                                                                                                                                            SHA1:E445E213D9A958E02A09630C751E91D2DF68FB88
                                                                                                                                                                            SHA-256:9723D05E9B11A6FF8747957DF31E6FD0D37CE0A6CA1B5FF355D3E8D4C4E9AD2A
                                                                                                                                                                            SHA-512:0A08872AA6F3CBD7976D6BE5E5DBDA0DD7D4546C071F4D0D307E9A7987D6373BC8CDB3DF9C5224B2E69EC75CF1BB1095B4C02E6B41450D1C45C996D730EA3ABB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.411191886747714
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPdgd:Yo6KUtjVLk4t94iU3KNoT8u8ayO
                                                                                                                                                                            MD5:B6E853A5599D13BB5F612EF9AD8E497D
                                                                                                                                                                            SHA1:37A450E00707344D6B97F75B189C85E6FBDA64F3
                                                                                                                                                                            SHA-256:3CF0A5FB0F04EC78B4FDB3E5E305F633EA809EBD157AE825B1FDA59530019EFB
                                                                                                                                                                            SHA-512:69CB3F1F0D88293EE85555AFB296975AA57ABB975ED7B9E25453C90D7939FCE1D83CA42FA5990E33F6D23AFAA297FFF84F8CCF1E7739C15E67DF3D2201337DAE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.419642142736874
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPA:Yo6KUtjVLk4t94iU3KNoT8u8a9
                                                                                                                                                                            MD5:F2964EDBA338BF8C3448180A1103A0B9
                                                                                                                                                                            SHA1:80C7E663F9EC61A3C7D02AA651FB0E6825C09E06
                                                                                                                                                                            SHA-256:A8151AA386FFBA740FC887DE1B77717A9192789B371D4393CD29D60ED9B7EB88
                                                                                                                                                                            SHA-512:1534BE7ABCD235B79394993E499748944BF216D091768DCCEDA7484E76D64C46F3501BDEC69B7C12A9F76965892475584529C12FE8CB59EB0B34D6E2228BD70D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.416188183976697
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPT:Yo6KUtjVLk4t94iU3KNoT8u8a2
                                                                                                                                                                            MD5:B621CE9D127DEA90D5B356C0621533CD
                                                                                                                                                                            SHA1:4EADEE73CE9E83B86F2DE551054518AA5C2D2AEC
                                                                                                                                                                            SHA-256:D9FC7D632EEFA7C04DAA892858D730569E9ACCF79EEF69E20354A19B4A0C9548
                                                                                                                                                                            SHA-512:5F9C0E575C3B51C9D8264160937D07B2D04540DDD688EC9AF3C31981786F928CDEA5172832CF6F90F438B493E65413DCB879B92DEDAF86096D399FA53DAA5E20
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.421464808614118
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPb:Yo6KUtjVLk4t94iU3KNoT8u8a2
                                                                                                                                                                            MD5:78F2AC106B4B5DBA5BA1E3A49A1C2EBB
                                                                                                                                                                            SHA1:79D5B6D8AF4C28F41299619DA439893E0B9E911F
                                                                                                                                                                            SHA-256:66CAC992D653ACE527EC60F7134F481456C25CD62F1ACCDC0D2720D7EB5D987F
                                                                                                                                                                            SHA-512:F6A7E6C1E6D2BC678AEAFA25DD5609A2E8FFFCD92FA6752EECA69EC33B15ABF704D9099AA19C883385959369103541D82D20B16CB4BE9DE70855D8A5B589C8EF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.419498727672663
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aP3H:Yo6KUtjVLk4t94iU3KNoT8u8aq
                                                                                                                                                                            MD5:2E52C69A19D3C7EE73E3B4FEBF98F5D2
                                                                                                                                                                            SHA1:3E42280B017D03E04AD54E0BCEC0649BFB0088C6
                                                                                                                                                                            SHA-256:DDF44D25CF0196F680F43E9DE89CAF0ECFEE299DE1C943EB6DBCD6E1338CEEB2
                                                                                                                                                                            SHA-512:F28E167B0608DA1A7D49ECF6ECFC1A89B3A49F47867A49D6DF1B8A09E9D82EE93CE8F7284C9ABEE0B23F7E0C7F0F57D35AE097A478919164D8DB44A8CD284020
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.4174647835949745
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aP6r:Yo6KUtjVLk4t94iU3KNoT8u8a7
                                                                                                                                                                            MD5:1952E5DD26BCABA52EB1809DD35FC27D
                                                                                                                                                                            SHA1:869C956A9C66E2371B0F95E0AD6311323926D4A9
                                                                                                                                                                            SHA-256:41D6AC5C30C06E6F1342C699F0479115A2BE08ED8B0527A88E26751DC2A7DDF1
                                                                                                                                                                            SHA-512:D8520BD10CD7C26664BF16EF21853397A3824A88A90D07C413D06CCC1B7CD28E63672C3F10FC84C12E267089A2029371989A01B5517384C3B3624F55EBCF2552
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.407751420560367
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPqYL:Yo6KUtjVLk4t94iU3KNoT8u8aNYL
                                                                                                                                                                            MD5:CDAA2CC07FBA9C893F81D2FC43722BC1
                                                                                                                                                                            SHA1:81D8D73C23167AE95DFB4D4EEBFAD502DD7E8CF2
                                                                                                                                                                            SHA-256:94D40769CD5CFA698C1D20BD20BF8192141D612CFBAC077F3B40AC4E42A09930
                                                                                                                                                                            SHA-512:82A23AA8DA5E8B98EAE67D2705953AEF1673A0C5ECC5582435CE79681AB57B86528FE5279646350E85A4DA4E47463B4D0A32663D3C1FEF9A49BC3E2BA7AABA70
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.415854621104547
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPug:Yo6KUtjVLk4t94iU3KNoT8u8a7g
                                                                                                                                                                            MD5:DEC587EADBFCEF562C3FE22C8EE0D213
                                                                                                                                                                            SHA1:942A2388B313A96CBAC4F0A23556CA2C8E39ED7B
                                                                                                                                                                            SHA-256:D8D1560A39D5756E3613DCA69156E11D7899E589B861818D056F87E0B80B59AD
                                                                                                                                                                            SHA-512:BB68351E3C0AF86929E92A5A36BCD0BB55A390019AE9F0FAC159AF2019685C4DFE4C81251C51D849C359321A5AC301766E9474023795F7FD49E8CEF856AA5E0C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.418590506750218
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPZS1t:Yo6KUtjVLk4t94iU3KNoT8u8agO
                                                                                                                                                                            MD5:A594F29F65A7459ED90AC4A1087029BE
                                                                                                                                                                            SHA1:19BC2C3F3E7A5331E4A59F39F50121855905D4C2
                                                                                                                                                                            SHA-256:22D72E4BEEFE897605B4548656925F7790EEEF7317272CA35C26302821F5502F
                                                                                                                                                                            SHA-512:84C428B0B890BAFFE6B073F552F207F784302D4E5550137DC59D8D9BB1D44E5C465EC13A950A03C7A5F5337B4167D6CCBA36BA91091CBD839CBDA9AF7BE9ED66
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3601
                                                                                                                                                                            Entropy (8bit):5.40638253326414
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:YvEkE6KESqDxGRoHJjq2lEk1k4thVZ/gN8UC8Kw8om88uwlE2+aPPY:Yo6KUtjVLk4t94iU3KNoT8u8aeY
                                                                                                                                                                            MD5:67A1529C4568AE5C4E2AC3A63DF33C99
                                                                                                                                                                            SHA1:317DF42B5A1680B3A093580D423C60D4BAB37D6B
                                                                                                                                                                            SHA-256:7F9F04214166818007111A861D5812888B2E87772C7B5E84A7B511686C57D218
                                                                                                                                                                            SHA-512:7E7F88E083B6857C4427BA720431ABD030E6A84751F1388134206D077FD6EE7DA3434258246BB0BF0830B575F17473740A89D043CD65FD152B1F50A5291EE38D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrUpsellToast_ = {.. UT_WSS_TOAST_TITLE: "Life online is now a necessity and hackers are taking advantage",.. UT_WSS_TOAST_TITLE_COHORT_2: "Get McAfee. Total Protection ",.. UT_WSS_TOAST_TITLE_2: "{0} against hackers in these uncertain times",.. UT_WSS_TOAST_TITLE_2_STRONG: "Take a stand",.. UT_WSS_TOAST_DESC_1_VAR_1: "Ensure your family and devices are protected with VPN, Identity Theft Protection, premium antivirus, and more with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_1_VAR_2: "The online safety of your family and their connected devices matters now more than ever.",.. UT_WSS_TOAST_DESC_2_VAR_2: "Protect them now with McAfee. Total Protection.",.. UT_WSS_TOAST_DESC_COHORT_2: "Protect your digital life with award-winning antivirus, Identity Theft Protection, VPN, parental controls, and more.",.. UT_WSS_BUTTON_ACCEPT: "Get it now",.. UT_WSS_BUTTON_REMIND_LATER: "Remind me later",.. UT_WSS_BUTTON_DECLINE: "No, thanks",.. //AV Quick scan.. AV_RED_HEADER: "We
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1260
                                                                                                                                                                            Entropy (8bit):5.772215715910839
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPy7dadSybOjRlnkggpHlnEAKETUy6fQXKb6fMocWjq1EU:PyRaSgCLyZgfQaCMocWjen
                                                                                                                                                                            MD5:35584AC9B786234394C8B70C8FA6AC35
                                                                                                                                                                            SHA1:AC700C057336AA7C96548C1CE11D30D2D259F722
                                                                                                                                                                            SHA-256:11187D284C306769E3F08F01E6ED01C9F94299969607CAE708BAFD47A59FDB2E
                                                                                                                                                                            SHA-512:8555070A8F1F8D2C376B0341E92D631D1F040A80888E8830A577AA981F9EFE3827590F0F8D3332E4B0E46F5A34F53754BFBDDB2DCFB4978B21CD851ADAA7897C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Z.skejte aplikaci {0}",.. BANNER_RIGHT_TEXT: "Zrychlete proch.zen. internetu",.. TITLE_FIRST: "Zdr.uje v.s nep..jemn. automatick. p.ehr.v.n. vide. p.i pr.ci?",.. CONTENT_FIRST: "Proch.zejte internet rychleji pomoc. aplikace {0}. Zastav.me automaticky p.ehr.van. videa, kter. zpomaluj. prohl..en. webov.ch str.nek.",.. TITLE_SECOND: "Posledn. uji.t.n. . chcete zastavit automatick. p.ehr.v.n. vide.?",.. CONTENT_SECOND: "Aplikace {0} zastav. automaticky p.ehr.van. videa, kter. zpomaluj. prohl..en. webov.ch str.nek. Pokud o aplikaci Web Boost nem.te z.jem, nebudeme se znovu pt.t.",.. NO_THANKS: "Ne, d.kuji",.. YES_GET_IT: "Z.skat aplikaci Web Boost",.. LICENSE: "Licen.n. smlouva",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Prohl..en. o ochran. osobn.ch .daj.",.. PRIVACY_URL: "https://
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1184
                                                                                                                                                                            Entropy (8bit):5.493379571388782
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPVdSoggneOKTDy3DHZXQTDITDy3DHM1qrjgHMf8WpK8+kGdJIVj:P/SojnMDkD5+DWDkD/CMf8W74JGj
                                                                                                                                                                            MD5:205CFFD766ABF808BB30C34EE05B4ABA
                                                                                                                                                                            SHA1:09114D40CB7256F915BA7036C3FBDC836E95CA39
                                                                                                                                                                            SHA-256:54A11C149265195665A5683B9ED4DA615407D01C37B14EBDD48ADABD82B76281
                                                                                                                                                                            SHA-512:707CD9E4EB76B0E7A5C2E5D41E773E3EF11E9B863B6E1904F42E2BDE363BEBBE2B3AC103A69BB44A9774000A9B82AFA7932CA99CE05D91FA2496525E04F9FFE7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Hent {0}",.. BANNER_RIGHT_TEXT: "G.r browseren hurtigere",.. TITLE_FIRST: "Bliver du sinket af irriterende videoer, der afspilles automatisk?",.. CONTENT_FIRST: "Med {0} kan du surfe hurtigere p. nettet. Vi stopper automatisk afspilning af videoer, som s.nker hastigheden, n.r du surfer p. nettet.",.. TITLE_SECOND: "Vi sp.rger lige for sidste gang: Vil du stoppe automatisk afspilning af videoer?",.. CONTENT_SECOND: "{0} forhindrer automatisk afspilning af videoer, som s.nker hastigheden, n.r du surfer p. nettet. Hvis du ikke er interesseret i Web Boost, sp.rger vi dig ikke igen.",.. NO_THANKS: "Nej tak",.. YES_GET_IT: "Hent Web Boost",.. LICENSE: "Licensaftale",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Meddelelse om beskyttelse af personlige oplysninger",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "N.r du kl
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1153
                                                                                                                                                                            Entropy (8bit):5.4998219823651135
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPRPcuFic3c4kEZkxQ0jwkIWDBpfCdEIfkSWFHCn+Gx:PRkU3c4xZEjw1WLmhfBWF3Gx
                                                                                                                                                                            MD5:1769F0B2E4704D0A487D97B9CF07B526
                                                                                                                                                                            SHA1:31CA3771EC4F63FD2F8003379AC7226288AEE18F
                                                                                                                                                                            SHA-256:C1C718E195530D312DF8C0AB602FE8314F9E23691C23CF0C7DFA4451A4E7479C
                                                                                                                                                                            SHA-512:2CBCBF569CB781CFD7257641F247A0ED1648B4B2A59ADCEEFDA1371E0600F697695353902228DFB49AF70F2A30EAB9EB2E2F26FE573A9356991136CEC49DFBC7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "{0} herunterladen",.. BANNER_RIGHT_TEXT: "Surfen beschleunigen",.. TITLE_FIRST: "Wird Ihr Browser durch st.rende automatisch wiedergegebene Videos verlangsamt?",.. CONTENT_FIRST: "Surfen Sie schneller mit {0}. Wir stoppen die automatische Wiedergabe von Videos, die Ihren Webbrowser verlangsamen.",.. TITLE_SECOND: "Letzte Nachfrage: M.chten Sie die automatische Wiedergabe von Videos stoppen?",.. CONTENT_SECOND: "{0} stoppt die automatische Wiedergabe von Videos, die Ihren Webbrowser verlangsamen. Falls Sie nicht an Web Boost interessiert sind, fragen wir nicht mehr nach.",.. NO_THANKS: "Nein danke",.. YES_GET_IT: "Web Boost herunterladen",.. LICENSE: "Lizenzvertrag",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Datenschutzhinweise",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Durch Klicken auf {0} stimmen Sie Folgendem z
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1666
                                                                                                                                                                            Entropy (8bit):5.276007230044297
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPcdh0GeuxX+8PFGIPg+c8NS0I5mmiKfQOQryfRXCWkHW3uUIOM4ckS1:Pah0G1+8NHc8mv46fIWkHW3uUIScky
                                                                                                                                                                            MD5:750F6354F3C1DAAC685A13A2BBCAC0B7
                                                                                                                                                                            SHA1:0471C8CA5222DF85D04FF4C94957DC2A18D43D13
                                                                                                                                                                            SHA-256:FA9C971A81F8BD3695119C0D9172B79C8D1F37F3549422CC96025A8F8129058A
                                                                                                                                                                            SHA-512:649A64C9A72BFA316C3E71CE8315E759639FCA9735DDE910D9C67F26D29D5FA06E40DD3B42C527B7198C8439148036778E302285825741DD51FE2CB6637FB0EE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "......... .. {0}",.. BANNER_RIGHT_TEXT: ".......... ..........",.. TITLE_FIRST: "........... . .......... ........ ........... ...... ... .............. ...;",.. CONTENT_FIRST: "............ ........... .. .. {0}. .. ........... ... ........ ........... ...... ... ........... ... ......... ....",.. TITLE_SECOND: ".......... .......: ...... .. ......... ... ........ ........... ......;",.. CONTENT_SECOND: ".. {0} ......... ... ........ ........... ...... ... ........... ... ......... .... .. ... ... .......... .. .............
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1000
                                                                                                                                                                            Entropy (8bit):5.56075824951649
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPSdHKCjkAyNRtOzeWaAb5LOze8WRSonGfQX0CWP9A91C9uNhzu:P0/nyNRtlWhb5Ll8W2fQJWPu91EwS
                                                                                                                                                                            MD5:64583F0ABA7A4186E415D77218B7E672
                                                                                                                                                                            SHA1:28CB70402C9F58D0C1326A81CACF7A590ACDF150
                                                                                                                                                                            SHA-256:1FFA0B8D9DFAC39AD0E45D79FEC0BFD16C77185DAB792A906F88AD39FA0605B9
                                                                                                                                                                            SHA-512:08B8C6CAF3305DEA24B3FE1E8BF52EAD2161BB2445AF5D7ED7674530AD7D0ABE74A91F92DD25AB58429D8ADDF999193E419C0402C4747E4D996BD90A6F1019FF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Get {0}",.. BANNER_RIGHT_TEXT: "Speed up browsing",.. TITLE_FIRST: "Annoying auto-playing videos slowing you down?",.. CONTENT_FIRST: "Browse faster with {0}. We'll stop videos from auto-playing and slowing down your browsing.",.. TITLE_SECOND: "Checking one last time--want to stop auto-playing videos?",.. CONTENT_SECOND: "{0} stops videos from auto-playing and slowing down your browsing. If you're not interested in Web Boost, we won't ask again.",.. NO_THANKS: "No, thanks",.. YES_GET_IT: "Get Web Boost",.. LICENSE: "License Agreement",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Privacy Notice",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "By clicking {0}, you agree to our {1} and {2}."..}..//4720748BE27465304240FDBD315F2AAE6A7A79C5EE1211FA36CD7AB9BA8916B06BA6027F9DA702C2AD7805617C166B89D36A1B58D5D2A3B46BC73859E9F0EDD1++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1169
                                                                                                                                                                            Entropy (8bit):5.504340578436135
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPDV7dKPMce+abJtZ5hZUsMNei5hZGSHGNf9gnW+l5ww8:PJRCMceXbJrnAeingfGWWww8
                                                                                                                                                                            MD5:4E2EBF3C90B102D9AFD14F0245DABC5C
                                                                                                                                                                            SHA1:81064E6F4F70F4DC40920F8EF6636F0AFC1120F8
                                                                                                                                                                            SHA-256:785B165B34601A7D239BD554770BAF0B7AC050D5D665C5258056E946575DAE83
                                                                                                                                                                            SHA-512:068F3D29D2FE998D536ED9B8B2221D1D6E016F0EFB63C56FDE2721469E4EE12E7AD76CC0858C80085758BFA0401E83B09CF1ABE96844A03A8EB53CB8D0E87416
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Obtener {0}",.. BANNER_RIGHT_TEXT: "Acelerar navegaci.n",.. TITLE_FIRST: ".Los molestos v.deos de reproducci.n autom.tica entorpecen su trabajo?",.. CONTENT_FIRST: "Navegue m.s r.pido con {0}. Impediremos que los v.deos se reproduzcan autom.ticamente y ralenticen su navegaci.n por Internet.",.. TITLE_SECOND: "Se lo preguntamos por .ltima vez: .Desea detener la reproducci.n autom.tica de v.deos?",.. CONTENT_SECOND: "{0} impide que los v.deos se reproduzcan autom.ticamente y ralenticen su navegaci.n por Internet. Si no est. interesado en Web Boost, no volveremos a preguntar.",.. NO_THANKS: "No, gracias",.. YES_GET_IT: "Obtener Web Boost",.. LICENSE: "Acuerdo de licencia",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Aviso de privacidad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Al hacer clic en {0}, ac
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1126
                                                                                                                                                                            Entropy (8bit):5.509097532884307
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPydhtceEumJUqeJmyUe8EFXjeseZqSHGNf9gnW+l5wOrlAv2:PUhtceEumJUqePUeVtjes5fGWWw4O2
                                                                                                                                                                            MD5:653FA3D4DB0656089D8EE55D413CB59E
                                                                                                                                                                            SHA1:C61B475CF2E096DF6FC88059AB001BFCB9735365
                                                                                                                                                                            SHA-256:4041E229FEC34DB623A3A789400712CE248EC88188BF0CC468CB82DC4AC4B30E
                                                                                                                                                                            SHA-512:F94F389A8F87CAD019C3BDB60D8CF35B7EFCF4CC3065E937FE95FEC1F8E543AE48B5B869601EDBA1BA6EB1E38312E6452B43E7E5B446CDC6E4C6D6A3D1ED27E9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Obtenga {0}",.. BANNER_RIGHT_TEXT: "Acelere la navegaci.n",.. TITLE_FIRST: ".Los molestos videos de reproducci.n autom.tica lo ralentizan?",.. CONTENT_FIRST: "Navegue m.s r.pido con {0}. Detenga la reproducci.n autom.tica de videos que hacen m.s lenta su navegaci.n por la web.",.. TITLE_SECOND: "Su .ltima oportunidad: .desea detener la reproducci.n autom.tica de videos?",.. CONTENT_SECOND: "{0}detiene la reproducci.n autom.tica de videos que ralentizan su navegaci.n por la web. Si no est. interesado en Web Boost, no volveremos a preguntar.",.. NO_THANKS: "No, gracias",.. YES_GET_IT: "Obtener Web Boost",.. LICENSE: "Acuerdo de licencia",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Aviso de privacidad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Al hacer clic en {0}, acepta nuestro {1} y {2}."..}..//6865
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1104
                                                                                                                                                                            Entropy (8bit):5.521656371165339
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPNdI11Y5jxKjrdTcv+qjYbKjrdT7vVa6EafIWd+H1g29Tqd:Pnc65jxKjJAfEbKjJPgafIWoVg2li
                                                                                                                                                                            MD5:7774BF229837F1B9B7BF1D8735BE1714
                                                                                                                                                                            SHA1:F405A7A0329642844EADCF17A42C57B2B34130A1
                                                                                                                                                                            SHA-256:83D4E504D43FD0B2C10582E000E7246F9E250CF8CBC9F6C3C874938825029E04
                                                                                                                                                                            SHA-512:9578CBBEF03CEBBE7DEC6BF9B3B406E221B8596C90DAE554488524E9A09A0DB5BA0720ECF10DF2965A0E2F25660842C49A86314636A68171F27CDD3336E96C25
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Hanki {0}",.. BANNER_RIGHT_TEXT: "Nopeuta selailua",.. TITLE_FIRST: "Hidastavatko .rsytt.v.t automaattisesti k.ynnistyv.t videot menoasi?",.. CONTENT_FIRST: "{0} nopeuttaa selailua. Est. videoita k.ynnistym.st. automaattisesti ja hidastamasta selailuasi.",.. TITLE_SECOND: "Tarkistetaan viel. kerran . haluatko est.. automaattisesti k.ynnistyv.t videot?",.. CONTENT_SECOND: "{0} est.. videoita k.ynnistym.st. automaattisesti ja hidastamasta selailuasi. Jollet ole kiinnostunut Web Boostista, emme kysy asiasta uudelleen.",.. NO_THANKS: "Ei kiitos",.. YES_GET_IT: "Hanki Web Boost",.. LICENSE: "K.ytt.oikeussopimus",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Tietosuojaseloste",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Kun napsautat {0}, hyv.ksyt seuraavat: {1} ja {2}."..}..//2A309CCE73146E96FB63676D6B
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1197
                                                                                                                                                                            Entropy (8bit):5.4715773971999635
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPFd4FWZ8+GS85J9gUPIk6J9gU1qqKGfvW//aM6+pTI9HG:Pv4gZ8+GSYJmFJmsfvW1VTIU
                                                                                                                                                                            MD5:8E9C2CCDFB4A03F5521258D4DAD10A44
                                                                                                                                                                            SHA1:3DA1F19EBCAEAE171ED02143943898C613D6B016
                                                                                                                                                                            SHA-256:58E2C4AF21F2AECEF37F3787BD0FBDF9346601634802B617CCF1C9FA98BA5342
                                                                                                                                                                            SHA-512:3BBF2BB2BC7A2D3F76C7A2EF8722D5D683C43D751F31AD74E1431375E7561700118E876DAF5C0A86ED024A404DFFDFAFA2976318BA5DBD39396680562673281E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Obtenir {0}",.. BANNER_RIGHT_TEXT: "Acc.l.rer la navigation",.. TITLE_FIRST: "Votre navigation est-elle ralentie par la lecture automatique de vid.os?",.. CONTENT_FIRST: "Navigation plus rapide avec {0}. Nous bloquerons la lecture automatique des vid.os pour .viter un ralentissement de la navigation.",.. TITLE_SECOND: "Nous vous le demandons un derni.re fois.: souhaitez-vous bloquer la lecture automatique des vid.os?",.. CONTENT_SECOND: "{0} bloque la lecture automatique des vid.os pour .viter un ralentissement de la navigation. Nous ne vous sugg.rerons plus Web Boost si vous n'est pas int.ress..",.. NO_THANKS: "Non merci",.. YES_GET_IT: "Obtenir Web.Boost",.. LICENSE: "Contrat de licence",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Avis de confidentialit.",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "En
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1198
                                                                                                                                                                            Entropy (8bit):5.516846127697029
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPFd4n2vFhChN8zp42hBWxH+3wjq4CfjdW/kXT8n:Pv4n2vbCN8V5ohCfhWZ
                                                                                                                                                                            MD5:5AB999C61567AF63D8B300CB8F4AD48C
                                                                                                                                                                            SHA1:575CD8D48E6D0E8E47EF0F078B6ADDEE2499AF90
                                                                                                                                                                            SHA-256:6D862BC51900C77742443CB50C960F713F070ED23BE2267AEDBCDC763E800EA3
                                                                                                                                                                            SHA-512:DF151B291401FD228B2F63248556BF2AE1E1E6BDC914E39AA1390098DD0A146F597A935CF3A11CEE37F3474AEF9CEB439F122FE41CE008B7F3097A744A676725
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Obtenir {0}",.. BANNER_RIGHT_TEXT: "Acc.l.rer la navigation",.. TITLE_FIRST: "La lecture automatique des vid.os ralentit votre navigation.?",.. CONTENT_FIRST: "Naviguez plus rapidement gr.ce . {0}. Nous emp.cherons la lecture automatique des vid.os afin qu'elles ne ralentissent pas votre navigation.",.. TITLE_SECOND: "Derni.re v.rification.: vous souhaitez bloquer la lecture automatique des vid.os.?",.. CONTENT_SECOND: "{0} emp.che la lecture automatique des vid.os afin qu'elles ne ralentissent pas votre navigation. Si vous n'.tes pas int.ress. par Web Boost, nous ne vous demanderons plus.",.. NO_THANKS: "Non, merci",.. YES_GET_IT: "Obtenir Web Boost",.. LICENSE: "Accord de licence",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "D.claration de confidentialit.",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG:
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1126
                                                                                                                                                                            Entropy (8bit):5.5929737504614705
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPuddK6oPnF2h0fPnFvydoZSfgBoW7ZFb8unoVcD:PAoJmyh6fgBoW7ZBBn6cD
                                                                                                                                                                            MD5:D000EC780C028620DF149E57E85B4B96
                                                                                                                                                                            SHA1:FFA1AF0ED8D23282E734E2B61E8A5DC5E39830E2
                                                                                                                                                                            SHA-256:7478901B7DB0D175E9803B9CBC8F0B9BC6BDE51CF18F89D45C359B1E7863DB5F
                                                                                                                                                                            SHA-512:392CA51D2F7A575341CDD32F26C352AD59EB5E3A2C9809291371F61DEC7FB8ED8E2EDC43AC292DAD42E6306E68BD3AA9F977735D8F440C24C5BB0401C73040BE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Nabavite {0}",.. BANNER_RIGHT_TEXT: "Ubrzaj pregledavanje interneta",.. TITLE_FIRST: "Uznemiruju.e auto-igranje videozapisa koji vas usporavaju?",.. CONTENT_FIRST: "Br.e pretra.ujte pomo.u {0}. Sprije.ite automatsko reproduciranje videozapisa i usporavanje va.eg pregledavanja interneta.",.. TITLE_SECOND: "Najnovija provjera - .elite zaustaviti reprodukciju videozapisa?",.. CONTENT_SECOND: "{0} sprije.ite automatsko reproduciranje videozapisa i usporavanje va.eg pregledavanja interneta. Ako vas ne zanima Web Boost, ne.emo vi.e pitati.",.. NO_THANKS: "Ne, hvala",.. YES_GET_IT: "Nabavite Web Boost",.. LICENSE: "Licencni ugovor",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Obavijest o privatnosti",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Klikom na gumb {0} u nastavku prihva.ate sporazum {1} i {2}."..}..//60E0
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1214
                                                                                                                                                                            Entropy (8bit):5.686044216902248
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPUXeUzUbI0mSCkFThSCfHPMDy7n7fn6ocWPNyUhSJGC15:P6Ub06f6ocW1ycC15
                                                                                                                                                                            MD5:F04C3F700B1D9A618945BF197A592F94
                                                                                                                                                                            SHA1:8351E7E24C5287D36E604DAC386485A8A0AD8006
                                                                                                                                                                            SHA-256:83990FF4B3FD6A14475E16288AEAA1BA412ACE77312D1E6357091F37DF863936
                                                                                                                                                                            SHA-512:41E48C90A4D7795B6D6FD425E2B2E6C9E37CECA9A034ADFC3BC2F3E3DF2EE9ECD712EA3841B7B29BCDA750FF83CA7C1A1D8F654340CEC330B139201D6355A2B3
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "A {0} let.lt.se",.. BANNER_RIGHT_TEXT: "B.ng.sz.s felgyors.t.sa",.. TITLE_FIRST: "Bosszant., automatikusan elindul. vide.k lass.tj.k munk.j.t?",.. CONTENT_FIRST: "B.ng.sszen gyorsabban a {0} seg.ts.g.vel. Megakad.lyozzuk a vide.k automatikus lej.tsz.s.t, ami lelass.tja a b.ng.sz.st.",.. TITLE_SECOND: "M.g egyszer megk.rdezz.k: meg szeretn. akad.lyozni a vide.k automatikus lej.tsz.s.t?",.. CONTENT_SECOND: "A {0} megakad.lyozza a vide.k automatikus lej.tsz.s.t, ami lelass.tja a b.ng.sz.st. Ha nem .rdekli .nt a Web Boost, akkor nem k.rdezz.k meg .jra.",.. NO_THANKS: "K.sz.n.m, nem",.. YES_GET_IT: "A Web Boost let.lt.se",.. LICENSE: "Licencmeg.llapod.s",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Adatv.delmi k.zlem.ny",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1108
                                                                                                                                                                            Entropy (8bit):5.445177805596594
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPMd7T0JakK38gx/SS11ZuBWMfjkWFt8K3/oGhb9:PKX0Jah37yWMfjkWFyK3/vhb9
                                                                                                                                                                            MD5:96F813E0388159704675245E019001A9
                                                                                                                                                                            SHA1:67DCC82E84E8D9D76579321637F11E8A3D501F22
                                                                                                                                                                            SHA-256:675A9FBCA2B4FED8AC9C52403C833626F232FAB3B5A51ADAABD9A1008F2C1663
                                                                                                                                                                            SHA-512:2108451E99086CA1F383417A35F525BCDB36C594166665CF0FC9AEF04B823F623506E092DFF1846FFF66B0D2AAF007DCD8D05323B06DF28F15E5EF784800AC2D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Ottieni {0}",.. BANNER_RIGHT_TEXT: "Accelera la navigazione",.. TITLE_FIRST: "I fastidiosi video che si riproducono automaticamente ti rallentano?",.. CONTENT_FIRST: "Naviga pi. velocemente con {0}. Bloccheremo la riproduzione automatica dei video che ti rallentano la navigazione sul Web.",.. TITLE_SECOND: "Ultima verifica: vuoi bloccare la riproduzione automatica dei video?",.. CONTENT_SECOND: "{0} blocca la riproduzione automatica dei video che rallentano la navigazione sul Web. Se Web Boost non ti interessa, non te lo chiederemo pi..",.. NO_THANKS: "No, grazie",.. YES_GET_IT: "Ottieni Web Boost",.. LICENSE: "Contratto di licenza",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Notifica sulla privacy",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Facendo clic su {0}, accetti il {1} e la {2}."..}..//22509397807425AFADDB89
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1276
                                                                                                                                                                            Entropy (8bit):6.005430500861147
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cl/yRv8dFdqOdsgWOep2Ht+LRvcsvifh2AWtufn7ThXgwkIG:VyRv4dqqspnDRvbifwAWtsPJgwkj
                                                                                                                                                                            MD5:FB76FC02B19FB66CEA9BAC64C588FA14
                                                                                                                                                                            SHA1:B045AE1E35EDA30B7C5BC342C92DBF1EF974D7BD
                                                                                                                                                                            SHA-256:4591276FC32E0938D15E718FEDD49A5402A20001E1633DB642E49D43A4540EA1
                                                                                                                                                                            SHA-512:BDAE9375030813135A62F71EE81CE740BA771769A1E978C5B8E5C1DBD6B434BF69CBE2349E29682478BDCC0F56DDE99F50C0713743065F75383A1A7182DF232A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: ".....&reg; .......",.. BANNER_LEFT_TEXT: "{0} .....",.. BANNER_RIGHT_TEXT: ".........",.. TITLE_FIRST: ".......................",.. CONTENT_FIRST: "{0} ......... ...............................",.. TITLE_SECOND: "...........................",.. CONTENT_SECOND: "{0} ................................. ................................",.. NO_THANKS: "...",.. YES_GET_IT: "............",.. LICENSE: "......",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "........",.. PRIVACY_URL: "http
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1251
                                                                                                                                                                            Entropy (8bit):6.065152294905446
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cxJLqkS5WCtU2htU6iiZTjfbWIYlgkYJtu:rlKi0fbWIYOkiu
                                                                                                                                                                            MD5:01D7894C4F0A7D0A486FAADBBEF53BF3
                                                                                                                                                                            SHA1:6BCF3F14EE8DF64BB31B6C907D7E88D1D873EAAD
                                                                                                                                                                            SHA-256:DEE5AD1000D1CB76839D865FADEEDDA30479A0E84B33584983500475A3F22FAF
                                                                                                                                                                            SHA-512:7656A7F7717DC258E33CB7CE84B5CCFB373CD8078497DC45551E66DF992CFB0A7B4F7BE071432293FAFE0494305EFF70F65F82F7B340F936BF818B27FDE08B33
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; . .. ..",.. BANNER_LEFT_TEXT: "{0} ..",.. BANNER_RIGHT_TEXT: ".. .. ..",.. TITLE_FIRST: "... ... .. .... .. .. ... .....?",.. CONTENT_FIRST: "{0}.(.) ... .. ... ........ .... .. .... .. .. ... .... .....",.. TITLE_SECOND: "..... ........ ... .. ... .......?",.. CONTENT_SECOND: "{0}.(.) .... .... .. .... .. .. ... .... ..... . .. ... ... ..... .. .. ......",.. NO_THANKS: "...",.. YES_GET_IT: ". .. .. ..",.. LICENSE: ".... ..",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: ".. .. ....",.. PRIVACY_URL: "https://www.mcafee
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1112
                                                                                                                                                                            Entropy (8bit):5.496690529097096
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPymdI+c1iPRRj+7+yR+2nr4rtR++Moj+wnMfQwsHWpx4ZOX:Pyoqg5QJ/etrMojMfQPWX
                                                                                                                                                                            MD5:ED82B8B0815D33E2078D05A64EED3AEA
                                                                                                                                                                            SHA1:92C3E5E055B8C4F73A0C1884975E8E984CEBBB7F
                                                                                                                                                                            SHA-256:EBAF5162874B119EA995F85EB41BD0220F39ABEEFED3EB3D15864D60E01AC7C4
                                                                                                                                                                            SHA-512:7C46259AE5060CC6DC56B28ED7B004884B7753CE7BC3147E805BAD11A13191B058A8712D8B6E31B0675FB60FCB826D2B2CC579C3C6669830C946D445A04A24E1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "F. tak i {0}",.. BANNER_RIGHT_TEXT: "F. opp farten p. nettsurfingen",.. TITLE_FIRST: "Sinkes du av irriterende automatisk avspilling av videoer?",.. CONTENT_FIRST: "F. raskere nettsurfingen med {0}. Vi stopper videoer som spilles av automatisk, slik at de ikke sinker nettsurfingen din.",.. TITLE_SECOND: "Siste sjanse . vil du stoppe automatisk avspilling av videoer?",.. CONTENT_SECOND: "{0} stopper automatisk avspilling av videoer, slik at de ikke sinker nettsurfingen din. Hvis du ikke er interessert i Web Boost, vil vi ikke sp.rre deg igjen.",.. NO_THANKS: "Nei takk",.. YES_GET_IT: "F. tak i Web Boost",.. LICENSE: "Lisensavtale",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Personvernmerknad",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "N.r du klikker p. {0}, godtar du v.r {1} og {2}."..}..//496264484E8BED8A84
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1206
                                                                                                                                                                            Entropy (8bit):5.443359066757402
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPMdeWjkB8UjFpXIMtRBviSqLwz4tRBviV3rEFihdEMtB2pQXbEnWtB221G+p99:PKeWniFpYMtz1qDtzsr7djPuQQWPxGwj
                                                                                                                                                                            MD5:E2110B836D9B395F21EAF5A193846F1D
                                                                                                                                                                            SHA1:C8734B326942C1D16998261CFEA22D7E9931EE71
                                                                                                                                                                            SHA-256:877265F05C7E6ACB0CAF6EE86C831329F3357A1C5440EAF192A35755B7D6BE24
                                                                                                                                                                            SHA-512:F41B3B8701D113049ADFC23792CDB0DB9CC350B7F77D4483762C7521089B5D91F74BCC779D1F63E1553328EA9F824BA01B6187265EEE9D3AD78FE54F8EC8E91E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Download {0}",.. BANNER_RIGHT_TEXT: "Internetactiviteiten versnellen",.. TITLE_FIRST: "Trage prestaties door irritante video's die automatisch worden afgespeeld?",.. CONTENT_FIRST: "Sneller internetten met {0}. Wij voorkomen dat video's automatisch worden afgespeeld en uw internetactiviteiten vertragen.",.. TITLE_SECOND: "Weet u zeker dat u automatisch afspelen van video's wilt stoppen?",.. CONTENT_SECOND: "{0} voorkomt dat video's automatisch worden afgespeeld en uw internetactiviteiten vertragen. Als u geen interesse hebt in Web Boost, vragen we het niet meer.",.. NO_THANKS: "Nee, geen interesse",.. YES_GET_IT: "Web Boost downloaden",.. LICENSE: "Licentieovereenkomst",.. LICENSE_URL: "https://www.mcafee.com/consumer/nl-nl/policy/legal.html",.. PRIVACY: "Privacyverklaring",.. PRIVACY_URL: "https://www.mcafee.com/consumer/nl-nl/policy/legal.html",.. AGREEM
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1217
                                                                                                                                                                            Entropy (8bit):5.6700805556738585
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPGdrelNj+8d2gQwYsklKGoTE3abMfXMGGnWjM/z9eWlrERhH:PIrevjvd2gRcljfmWjteAH
                                                                                                                                                                            MD5:4AA248F4DBA9B7E937ED2DC6AE67D2C9
                                                                                                                                                                            SHA1:BADE0083A61CBAFDD4F3AA9C36629C090AD1A91B
                                                                                                                                                                            SHA-256:2AE4B9F55E29D26760929871A092AE41FB15A5C75E13022628946F2E8AB4783D
                                                                                                                                                                            SHA-512:CC60547BD2AB94F47B2E81DBEB076A32AFFEA3FB5D11A39AB2AF387D5E060AEEB216C68BF7DC865C5E5107BF5DFBB3460D9893FBAA021D9282A72FA94541A85F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Pobierz produkt {0}",.. BANNER_RIGHT_TEXT: "Przyspiesz przegl.danie Internetu",.. TITLE_FIRST: "Irytuj.ce automatycznie odtwarzane filmy spowalniaj. Ci prac.?",.. CONTENT_FIRST: "Szybciej przegl.daj Internet dzi.ki programowi {0}. Powstrzymamy automatyczne odtwarzanie film.w, kt.re spowalnia przegl.danie sieci.",.. TITLE_SECOND: "Sprawdzamy po raz ostatni . chcesz powstrzyma. filmy przed automatycznym odtwarzaniem?",.. CONTENT_SECOND: "Program {0} powstrzymuje automatyczne odtwarzanie film.w, kt.re spowalnia przegl.danie sieci. Je.li nie interesuje Ci. program Web Boost, nie spytamy ponownie.",.. NO_THANKS: "Nie, dzi.kuj..",.. YES_GET_IT: "Pobierz program Web Boost",.. LICENSE: "Umowa licencyjna",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Informacje o ochronie prywatno.ci",.. PRIVACY_URL: "https://www.mcafee.com/legal",..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1162
                                                                                                                                                                            Entropy (8bit):5.5107078162206635
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cP4djLetDhf8CL369L3yM03Byf9HWfOBIolfBLD:PmjLifLq9LCMhfBWGBIollD
                                                                                                                                                                            MD5:887A302F32B6C5833304E3DCF8CACBD9
                                                                                                                                                                            SHA1:C6BAB3BBDB718BBA28439D942059ACE2F698FAC6
                                                                                                                                                                            SHA-256:819990A8D3616CD8E75C4113DC58AFD3F63A9B1964C9BFF71410A15E9336178C
                                                                                                                                                                            SHA-512:D12E5F9F3E16EA4CCCD3513406FDA71806934653AB48149C5C769A44B449F036D2E1596B3EA1D252418812600AEE9B4E1C883E90B2AD4C9D8AE7D248096A81F9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Obtenha o {0}",.. BANNER_RIGHT_TEXT: "Acelere a sua navega..o",.. TITLE_FIRST: "O v.deos irritantes de reprodu..o autom.tica est.o atrapalhando voc.?",.. CONTENT_FIRST: "Navegue mais rapidamente com {0}. Interromperemos v.deos de reprodu..o autom.tica que desaceleram sua navega..o.",.. TITLE_SECOND: "Conferindo uma .ltima vez. Deseja interromper a reprodu..o autom.tica de v.deos?",.. CONTENT_SECOND: "{0} interrompe v.deos de reprodu..o autom.tica que desaceleram sua navega..o. Se n.o estiver interessado no Web Boost, n.o perguntaremos novamente.",.. NO_THANKS: "N.o, obrigado",.. YES_GET_IT: "Obtenha o Web Boost",.. LICENSE: "Contrato de Licen.a",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Aviso de privacidade",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Ao clicar em {0}, voc. concorda com
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1147
                                                                                                                                                                            Entropy (8bit):5.5124495727770295
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6dJkfeI3duQBCXV9j8/TfYGCAVXAxuQ3oKtcnEheASulWZhHjDkE6pRY8gHwGbq4:6cP3dWF+fYGGxf5SQ03x6Sf9HW3Xmfk2
                                                                                                                                                                            MD5:DF620B4314E93736FF7C71147BCE037A
                                                                                                                                                                            SHA1:243692569F8B832F918AC5006261D5572DD2B7C0
                                                                                                                                                                            SHA-256:65B5BF52B5491DC090F026A0323CEBB0B05D048FE85AB6B6EEE84BBDCE59CB69
                                                                                                                                                                            SHA-512:B23BC4D7E38985A271FB18FF4727D32654E7C8C9555B907998F75478F9D1030B390F246B8B0421F39EC0FA73C99074A7E32E95373EB9798F8AC44809B7EBFBDC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Obter o {0}",.. BANNER_RIGHT_TEXT: "Otimizar navega..o",.. TITLE_FIRST: "A reprodu..o autom.tica de v.deos . inc.moda e atrasa o seu trabalho?",.. CONTENT_FIRST: "Navegue mais rapidamente com o {0}. Impediremos a reprodu..o autom.tica de v.deos que reduz o desempenho da navega..o.",.. TITLE_SECOND: "Vamos confirmar mais uma vez, pretende impedir a reprodu..o autom.tica de v.deos?",.. CONTENT_SECOND: "O {0} impede a reprodu..o autom.tica de v.deos que reduz o desempenho da navega..o. Se n.o est. interessado no Web Boost, n.o perguntaremos novamente.",.. NO_THANKS: "N.o, obrigado",.. YES_GET_IT: "Obter o Web Boost",.. LICENSE: "Contrato de licen.a",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Aviso de privacidade",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Ao clicar em {0}, aceita o nosso {1}
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1673
                                                                                                                                                                            Entropy (8bit):5.253020883068515
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPMd9+PJr6H30J3vlfL4qR30NZHxsVyY3DM30NZH6Xho4qs35sngONfQrWWFw0B:PKgN6a39f9+sVX0Rws35BONfQrWWFLM0
                                                                                                                                                                            MD5:5DD3091205864CC054B2BED7AAC0C4FB
                                                                                                                                                                            SHA1:515AF5F30D759F6A499358188B3A6215DC3BFABA
                                                                                                                                                                            SHA-256:245289AC6A8466C5CEDD37475851622EFF28D4E4A9BD0475B09B9628ACD2F0B3
                                                                                                                                                                            SHA-512:8E57FBD23DFE6AFEC389FC89C9202BD36DBE7FF0ACFAF30A81183633D7A43825EC2075627B8B85DD9E1639925507598AA836BCC05F90C997B8D450D045A18897
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "........ {0}",.. BANNER_RIGHT_TEXT: "........ ........ ........ ...-......",.. TITLE_FIRST: ".......... .............. ............ ..... ...... ........?",.. CONTENT_FIRST: ".............. ...-........ ....... . ....... {0}. .. ........... .............. ............ ............, ..... ........ ........ ...-.......",.. TITLE_SECOND: "........ ....... .......... ............... ............ .....?",.. CONTENT_SECOND: "{0} ......... .............. ............ ............, ..... ........ ........ ...-....... .... ... .. .
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1171
                                                                                                                                                                            Entropy (8bit):5.761957648272607
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPGd2mcJsq8vMi8zJ0+46fQXwWjelzfhthovQo:PINesPtKFfQAWjwzjhmd
                                                                                                                                                                            MD5:558DE1A054602D76385CFBD74DB161F4
                                                                                                                                                                            SHA1:9052C94BF3728E795E9B357C0AA536E271CAFD0B
                                                                                                                                                                            SHA-256:6E1029A70C282EB6878477EA62417609947C9E4FD59CAF5CD5976F697DB21FB9
                                                                                                                                                                            SHA-512:EDBF31E8755EE5D4BAAA157C3DB387779E78EB587479C1324C071D9D06C279C09B3A52B444FCDBBE662BD3BEC841DF119983383314CC97AB054F0DFC4D7514E8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Z.ska. produkt {0}",.. BANNER_RIGHT_TEXT: "Ur.chli. prehliadanie",.. TITLE_FIRST: "Spoma.uje v.s otravn. automatick. prehr.vanie vide.?",.. CONTENT_FIRST: "Surfujte r.chlej.ie s {0}. Zastav.me automatick. prehr.vanie vide., ktor. v.s zbyto.ne spoma.uje.",.. TITLE_SECOND: "Naposledy sa p.tame: Chcete sa zbavi. otravn.ho automatick.ho prehr.vania vide.?",.. CONTENT_SECOND: "{0} zastav. otravn. automatick. prehr.vanie vide., ktor. v.s brzd.. Ak nem.te z.ujem o Web Boost, nebudeme sa op.ta. znova.",.. NO_THANKS: "Nie, .akujem",.. YES_GET_IT: "Z.ska. Web Boost",.. LICENSE: "Licen.n. zmluva",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Prehl.senie o pou..van. osobn.ch .dajov",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Kliknut.m na tla.idlo {0} ni..ie vyjadrujete s.hlas s
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1112
                                                                                                                                                                            Entropy (8bit):5.570641306627158
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPud3hBmY2dFwHPhtDmY2dFWoZ1fjjWxOxwzQ:PA3hBmY243mY2HfPWxOaU
                                                                                                                                                                            MD5:20B2EEA989F913978CB658F552C77CF0
                                                                                                                                                                            SHA1:A18E6054BB1B11B1CFC5461E22E69DBF112C7CC0
                                                                                                                                                                            SHA-256:74185F6279166C70E47A5B0E2C5F53E39364F916028296CCC30AA98D8349B915
                                                                                                                                                                            SHA-512:7F232B59898334536C2B07E2ABABDC2908868C2873CA0D28407A4AFCB254637D8F66C3D60D19F36386E0BFBC262D9A2564C55818CC6E7715CE2530D2EAF49F12
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "Nabavite {0}",.. BANNER_RIGHT_TEXT: "Ubrzaj pregledavanje interneta",.. TITLE_FIRST: "Uznemiravajuc.e auto-video snimke koje vas usporavaju?",.. CONTENT_FIRST: "Brzo pretra.ite {0}. Spre.ite automatsku reprodukciju videa i usporavanje va.eg pregledavanja interneta.",.. TITLE_SECOND: "Proveravate li poslednji put - .elite da zaustavite automatsko reprodukovanje video zapisa?",.. CONTENT_SECOND: "{0} spre.ite automatsku reprodukciju videa i usporavanje va.eg pregledavanja interneta. Ako vas ne zanima Web Boost, nec.emo ponovo da vas pitamo.",.. NO_THANKS: "Ne, hvala",.. YES_GET_IT: "Nabavite Web Boost",.. LICENSE: "Ugovor o licenciranju",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Obave.tenje o privatnosti",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Klikom na {0}, prihvatate {1} i {2}."..}..//04AE79C9BE25E98BB4
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1116
                                                                                                                                                                            Entropy (8bit):5.608523955833537
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPYodlhp2AtRW5Tm0XECCyK45Tam0XEEHh6qrTojI/HfMXGWNI5WmKO+bO:PYWXYAbWRmsEkTamsEEBbHYIffRWqpKQ
                                                                                                                                                                            MD5:29C1808A36FAB01F0A16BB89052E4603
                                                                                                                                                                            SHA1:C0602D3A5F476076300BEE133A012A9AA98A51CA
                                                                                                                                                                            SHA-256:3215360E7DCE6F598F5EDEF1BC6A2088715689683400E955A7C776C8DA85693D
                                                                                                                                                                            SHA-512:C71001668BF21DC36CF88FA68BE8BED8B214A6F45BE7C3418A578D58A0A39711FF1F29EF7FFE0DEB1CC060D5E6ED163E0F856D1B7B78535017AFA9B275A5A8FD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "H.mta {0}",.. BANNER_RIGHT_TEXT: ".ka hastigheten p. surfandet",.. TITLE_FIRST: ".r datorn l.ngsam p. grund av st.rande automatiska videoklipp?",.. CONTENT_FIRST: "Bl.ddra snabbare med {0}. Vi stoppar videoklipp fr.n att spelas automatiskt och sakta ner ditt webbsurfande.",.. TITLE_SECOND: "Vi fr.gar f.r sista g.ngen . vill du stoppa automatisk uppspelning av videoklipp?",.. CONTENT_SECOND: "{0} f.rhindrar videoklipp fr.n att spelas automatiskt och sakta ner ditt webbsurfande. Vi fr.gar inte igen om du inte .r intresserad av Web Boost.",.. NO_THANKS: "Nej tack",.. YES_GET_IT: "H.mta Web Boost",.. LICENSE: "Licensavtal",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Sekretesspolicy",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "Genom att klicka p. {0} godk.nner du v.rt {1} och {2}."..}..//FAC366FD80549C
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1173
                                                                                                                                                                            Entropy (8bit):5.6698292539374044
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cP/XRGHmeqM6+bBNLefXtexcJYOEvKxUew53ksNefXtexcJ6dp7hVE9tClfs2QU:P/XRGHmelbBFevBuv7ew53NevBS1nwOx
                                                                                                                                                                            MD5:A47E52695D26A9D44A52C95891C5DAAD
                                                                                                                                                                            SHA1:238E7986F01B4CD1EF0007FFDA47982F1F2DDA6A
                                                                                                                                                                            SHA-256:8A2BE15BAC94FC4C65F85AB47F1FFE82E1A9FF92E27536BA0E729654134ECA64
                                                                                                                                                                            SHA-512:A2AF1912171ACE4B619265DCA28FB0635BD948CE4496654340DBAF9AC30688FFB409DE3D4F4C30E89DFE71EB7B0BE22A7E71799BEA93A0F308DDDC2F3C7299A7
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: "{0} Uygulamas.n. Edinin",.. BANNER_RIGHT_TEXT: "Web'de gezinmeyi h.zland.r.n",.. TITLE_FIRST: "Otomatik olarak oynayan can s.k.c. videolar sizi yava.lat.yor mu?",.. CONTENT_FIRST: "{0} ile daha h.zl. g.z at.n. Otomatik olarak oynayan ve web'de gezinmenizi yava.latan videolar. durdururuz.",.. TITLE_SECOND: "Son kez soruyoruz, videolar.n otomatik olarak oynat.lmas.n. .nlemek ister misiniz?",.. CONTENT_SECOND: "{0} otomatik olarak oynayan ve web'de gezinmenizi yava.latan videolar. durdurur. Web Boost'la ilgilenmiyorsan.z tekrar sormayaca..z.",.. NO_THANKS: "Hay.r, te.ekk.rler",.. YES_GET_IT: "Web Boost'u Edinin",.. LICENSE: "Lisans S.zle.mesi",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "Gizlilik Bildirimi",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "{0} d..mesine t.klayarak {1} ve {2} ko.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1062
                                                                                                                                                                            Entropy (8bit):6.421114200378586
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cyPdC/0RFVLakZxaoK4K1nfmHWMm3YmSJSyrqs9GZujn:yVC/0VLvLVSf4WMPmMSyz9Hjn
                                                                                                                                                                            MD5:635F2A0611035E12DBD5A05796795F56
                                                                                                                                                                            SHA1:F0A32248F74D5EBCE6FBA778AEBB373A0754AE53
                                                                                                                                                                            SHA-256:B440D737480AECDBCC21AF7D7479CB7604F0DC245CE97F2C009DEF17967E0816
                                                                                                                                                                            SHA-512:1AAD70B7ECF4D2342406C1A93E124B0CC1D8AE06FAEAA63D0DCC4858C8F30DA62F6DD5D2A8E2DEA7D378442AF8D1B2A0A89D5AD3D373E877CCE70E0A3A225F4B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "...&reg; Web ..",.. BANNER_LEFT_TEXT: ".. {0}",.. BANNER_RIGHT_TEXT: "......",.. TITLE_FIRST: "....................?",.. CONTENT_FIRST: ".. {0} ........ ........................",.. TITLE_SECOND: "....... - ...........?",.. CONTENT_SECOND: "{0} ...................... .... Web ...............",.. NO_THANKS: "....",.. YES_GET_IT: ".. Web ..",.. LICENSE: "....",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: "....",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "...{0}.........{1}...{2}.."..}..//DA967F30A8397D87D36DCF865371223DB42D757877A05E23F893E2F4F82CF12F2293
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1018
                                                                                                                                                                            Entropy (8bit):6.3837742402318005
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6cPGdRXudZh7df/9cIDlcFesbfOKU6D8Gfg1WJ9xIKHk:PIBudv5H9cIDMy9opfg1WJzg
                                                                                                                                                                            MD5:9E05238B81150CA18CEF8E66BD797CE0
                                                                                                                                                                            SHA1:4421AA76C2A28C879E87A9242A6597D62E910297
                                                                                                                                                                            SHA-256:CB56CCA7ED6A897A9E261344CECBBFDB5D6F089487D476BF386A3B3AE1135A5A
                                                                                                                                                                            SHA-512:F68354A2B07F788E144B5C6EE8A9721FD33A6B72317CFCDBC7BF173622AFE8A82FB51A26029D152EB72CABD87D948E09D829888BE9F36A2710EF68D73125F04C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.var _lrWebBoost_ = {.. MCAFEE_WEB_BOOST: "McAfee&reg; Web Boost",.. BANNER_LEFT_TEXT: ".. {0}",.. BANNER_RIGHT_TEXT: "....",.. TITLE_FIRST: "...............",.. CONTENT_FIRST: "..{0}....... .....................",.. TITLE_SECOND: ".....................",.. CONTENT_SECOND: "{0} .................. ... Web Boost ..............",.. NO_THANKS: "......",.. YES_GET_IT: ".. Web Boost",.. LICENSE: "....",.. LICENSE_URL: "https://www.mcafee.com/legal",.. PRIVACY: ".....",.. PRIVACY_URL: "https://www.mcafee.com/legal",.. AGREEMENT_MSG: "...{0} ......... {1} . {2}."..}..//42C12F96FD2519022C33BDB7AC557CECFF9F9EFF2C6F5652DD1BC4DCC7995D9A6B8931EE4D5DC460A1E45462C6DCDB43541650932759178C
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.255815433151384
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+Acq:+sv+K5+CtTFCqsUz0AUoey+Acq
                                                                                                                                                                            MD5:09FE12E7B96C35AB16275AAC9490E159
                                                                                                                                                                            SHA1:0A7BF96950CCDDBDE7E96797E26684E8E0944DFE
                                                                                                                                                                            SHA-256:B93A8AD83FE4F8C51C5ABE313A28C5CBDB0E7DA2A551419EE7C341871EEF1A0E
                                                                                                                                                                            SHA-512:0A21B76054D7C96E3F651AAF414598878F2FC889CA3E7538014A7EC07FD106536136513AC0367321BB9E46A7BDD9D82E9D1A0DF3413FF6FB078E27C53AD9C59B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.258749941419516
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+fmO:+sv+K5+CtTFCqsUz0AUoey+v
                                                                                                                                                                            MD5:8D9FE269136A5DF4FFE099F9FE8B4002
                                                                                                                                                                            SHA1:F34E58A062622A0D99D16DC2232B98391B07FCDC
                                                                                                                                                                            SHA-256:66D643DA365997B123D65F98E68AD2AFF2547B8F25C0D68CC5D6DED8873798EB
                                                                                                                                                                            SHA-512:68C3925090228934195645BDDFE0AB7D91EEA63A47540E442A761B775CAC87929203A4056CC1BE2EB88E44B77E54D799EDFC79AF05ED7C839AE332C76D2549B9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.2549369997060795
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+ggDJZ:+sv+K5+CtTFCqsUz0AUoey+gmj
                                                                                                                                                                            MD5:E35D0D20EA41CD143C7D31A901FA8A32
                                                                                                                                                                            SHA1:CEA9DA88E29C7B7D5628A8406658033E1577F699
                                                                                                                                                                            SHA-256:872EF7BCC59BF8E5CF85C674ED0E633A5EB24E629A6503A32BFC8E15BC750FCF
                                                                                                                                                                            SHA-512:7A654D4EF451615BF749567FAD96922AC8E9767222D0F457028EF7E053081FA3889C54AB9E3C8A5EBD5EE4D66EF5CF0AE2A1B79C5E8A3C7BA26848C3EE437DFC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.258626910218937
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+aC:+sv+K5+CtTFCqsUz0AUoey+aC
                                                                                                                                                                            MD5:E1AB8C2442B2032745741C8387A44921
                                                                                                                                                                            SHA1:1F9788F1205BAB4ED35235F126A58EE8285F9B0A
                                                                                                                                                                            SHA-256:DF6AF6D8FC279CFDA071EB2EE78C2FCC056B03AE9F9FBBF714ED354B78E75432
                                                                                                                                                                            SHA-512:325F114C3ED7890F85411C2795F11D7756726FB8BD31F06EF57F5F6ACE58757BACD4057C6AB539839588E78D02779019FA23480EB1A846F1CBA3FE3EBB621129
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.26473179591435
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+HP:+sv+K5+CtTFCqsUz0AUoey+v
                                                                                                                                                                            MD5:7E536037355A4C8EA13AED6EDEF9DA4D
                                                                                                                                                                            SHA1:B115858D0A1155EF74593617F3FD530FB1A8291B
                                                                                                                                                                            SHA-256:B57458084F1C6289464D5D11749F3DE67CB44D997DE2843E5BCD357CE7DC1EBC
                                                                                                                                                                            SHA-512:D688AA9FFB3CEFC5A0E78D95817B760632965C9469DBAFBA3672B576E618FEA37745779C957E0DDD605FC4DEFAF053587F641D5F92E83098D234D108EC880092
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.24948020806169
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+rq:+sv+K5+CtTFCqsUz0AUoey+u
                                                                                                                                                                            MD5:AC41CD01C5C11D401371B80BCD2E9AEF
                                                                                                                                                                            SHA1:641298528F0449266F0057849D46B94B70052010
                                                                                                                                                                            SHA-256:A5990EACEF537A81CADC4611C4F6ED48307AB98CDBB62B3D602321BF730D90D8
                                                                                                                                                                            SHA-512:31B690DC064269D23CCBBC36463E968439CD229475517FBB0A7B5DEC5346DBE119DDEC68C16B84ADE7795DEB782B12434A995EF64B081984BC45758228C80EBD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.25725111754855
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+I27:+sv+K5+CtTFCqsUz0AUoey+I27
                                                                                                                                                                            MD5:D139AA10295D4D66CCA63FFCCE9034BC
                                                                                                                                                                            SHA1:07B2D175355CCC53FC778727B6B073C7A927CB23
                                                                                                                                                                            SHA-256:6246C9C3EE0BF94448B0B5548773B7FCAB27C7F94BF73C4CE3DA8502E6BD6132
                                                                                                                                                                            SHA-512:99A48E6E090ACCA0AF3EE6462503A1F6DC7405A2FCF9425F3834F790F4F7C9E54CAFF4AE2C9B3FF9509B9473A032CBC4381DA6636ACADAA351C96215A29D4A98
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.258169866605646
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+h+dyaZ:+sv+K5+CtTFCqsUz0AUoey+hm
                                                                                                                                                                            MD5:B85ABB5D7F27AC91BF9EF84B5C3F8DA5
                                                                                                                                                                            SHA1:3B02A6BFA38525E275AC11A5D39F27E923B83747
                                                                                                                                                                            SHA-256:12B221759491901EBB0A3F27B17BD615FD11F02061BBD171E1D8B022B3217721
                                                                                                                                                                            SHA-512:1081D7D0AA811A2A275AE3A9937B7C2AF79534BBDEA646467EC97460EA0E822D70BE97F76E7ECB02F39C0A86564860576E7F6593452D48D30F407FB1F18E07DE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.260510627760021
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+9pc/:+sv+K5+CtTFCqsUz0AUoey+9+
                                                                                                                                                                            MD5:73FF3BCCDF7C1CE2739C762A9D79BE79
                                                                                                                                                                            SHA1:145AE5141F73E99C8087141C52BDE36A716B09F4
                                                                                                                                                                            SHA-256:E4F4E6BCE8482DA96ABDEEF2319C6C211BF6ABF4D976C9A4AE01DD6B0E4EEF3A
                                                                                                                                                                            SHA-512:02CF71D13AC5C4DC34A9EFD39C31A9F2131C10F9E9623444CBDB9C8320CC899D5611282AC8CF07233CB8023C24D584D2DE0243E3BA0675223D52203169072263
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.25607038325692
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+kp+1:+sv+K5+CtTFCqsUz0AUoey+u+1
                                                                                                                                                                            MD5:5461449179F53521618D358AA2399C95
                                                                                                                                                                            SHA1:8114987C08ED15AA6372899C7405C728AF02365F
                                                                                                                                                                            SHA-256:9E6D35A5E3F71E7FB4D0503FED68181305CC5BF7557B3B532F29785AA7F3502D
                                                                                                                                                                            SHA-512:DADCC0160A219045C4C752BA688F6ECE9A9DBA099BAE80D2A843E5E965BF6B3019697DE2B5ED1F80AE584A55DAE4E226C889ED92DD6DA286312D57B520859349
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.260888352905892
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+jpOnumQOev:+sv+K5+CtTFCqsUz0AUoey+9ZmQ3
                                                                                                                                                                            MD5:604FF7C86E5A753DB6140217807081B1
                                                                                                                                                                            SHA1:78CFEE03DCFEBE9F3D21ACF10D643E93F0410947
                                                                                                                                                                            SHA-256:658D263EFFF36A0C8E57D58F5D146696266618D869732A4F57CBAACB8B937E9B
                                                                                                                                                                            SHA-512:764BE04E4F10B9C2C9A2BE69A10AD570AC146008DF9BD5485FC0DE81BCE96C084BD68F46A1BA24E51E6258498EBA3DDC3BB38DAF5178C79F9D4CD031A7CC411D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.266427629105407
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+eq8ee:+sv+K5+CtTFCqsUz0AUoey+eq/e
                                                                                                                                                                            MD5:568912B1E4655CDD8ABEF25C2D9EB64E
                                                                                                                                                                            SHA1:46936BCC2D6E924F4E608286447E93A9E7AFBA8A
                                                                                                                                                                            SHA-256:A4ADAFD5A6EE98640F4C45446436CCAA299CBB571C4EAF17207CA5EDD0BC4B88
                                                                                                                                                                            SHA-512:C723CE14D9E4C6B22C46ED9D1E8D1751D97778A671E055D1CF10A456C5CC096B52D660EB23E40BB61EA5F6B071F66BC6A015CEA50B481617AC3985B37A59688E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.2456289487653285
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+x6y:+sv+K5+CtTFCqsUz0AUoey+x1
                                                                                                                                                                            MD5:728DA5B1FBA9401D5954B173DB414DFC
                                                                                                                                                                            SHA1:ACA844DEBD3C8F284D19E16D50151E004DDDF656
                                                                                                                                                                            SHA-256:EC051DCCABF2CECEB0F216BB8911F5EED4E64AD598A228008F2AC72F769CB8B9
                                                                                                                                                                            SHA-512:2C4A9A746E937FCCAA161BFBC368DC5E17C37941A8DC8D7153865C43EFDE2C7395DB4BE6E0D95D56C22791DED84402960C301BEC21EEFC7A1939F81092FFC878
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.261577620433791
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+jBbNr:+sv+K5+CtTFCqsUz0AUoey+1B
                                                                                                                                                                            MD5:A4781D22BC1BA74F63A8E62AB9A4D987
                                                                                                                                                                            SHA1:89DB90647D0539C7B6A65ABE7049C5DEC4733B7D
                                                                                                                                                                            SHA-256:91B20B7B40EFBE8185F3BA2E3C53BBDC58AC0F68A028873D37951578C28BD08F
                                                                                                                                                                            SHA-512:7BB38C51ADFFC7EB2AA5F4E1753BAEC15043A54887B0793B9210F74FB577975663BB8BB5FFF9838B7A342D7908893972838E6A48A28AA8181C4059EE30A3599C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.249923494889432
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+X:+sv+K5+CtTFCqsUz0AUoey+X
                                                                                                                                                                            MD5:C875E4673332B21AF00F0A2F2A98A4D0
                                                                                                                                                                            SHA1:AB152736BFAAE6F3C0D1780730257DFBC65F0A4E
                                                                                                                                                                            SHA-256:C8B4304C22E2EDE9FE6A4D6DDACE9446D9F1F5A12806CDC4B030214C99A3973B
                                                                                                                                                                            SHA-512:EFD3411B3FF6B02C42B3373A8F2C2B9CE6D8E7443B8A4F5F43421166FA7737DAB4635446019EFDB0AA3796319494E874EF4E6AA51976583BC6F2FFFF9EE19980
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.249500943614529
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+9jC:+sv+K5+CtTFCqsUz0AUoey+9O
                                                                                                                                                                            MD5:FDCA9C26797C23FFBA696632DA5AD10A
                                                                                                                                                                            SHA1:5A11B096812CDFAB01732620C1801465D14BAC95
                                                                                                                                                                            SHA-256:6672D19A7833DCCF5139573657910053F040FCF05326CC112CB66C171AAB6FF7
                                                                                                                                                                            SHA-512:93ECA0BFDFFA98EFE26E9446650B8A8831DB80B1994D9855F527D4CB7DCBC098938F411B1EFDFCB4D61BF8B859C5A94B879C57D162CEFFED2D63DCE44A6F6CB0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.246937070314897
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+TDC:+sv+K5+CtTFCqsUz0AUoey+TW
                                                                                                                                                                            MD5:3EEA13D100ABAE41A13E345689E4F262
                                                                                                                                                                            SHA1:8C14A8874BDE4632FC85ECA470C4CD6179292BAF
                                                                                                                                                                            SHA-256:DA482FCE7F9444CB4750BA11B21162CAFC09ED16551074FF944065F7146A7DE1
                                                                                                                                                                            SHA-512:31435BB41CCDD3285A9279AEA89CBAD6FCFB703A9F783C88C93D21E1FB6C0498754EBA1E322800BECB546FFF1B7DBE348647D9C388AFFC42DDED9A792EF9A991
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.253179062882507
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+R3wlF:+sv+K5+CtTFCqsUz0AUoey+dQ
                                                                                                                                                                            MD5:48D45A955DC961FDF220ADE6DEF69793
                                                                                                                                                                            SHA1:5CD0F5BCA17D5C5626678F31D215CEEC6A27F96B
                                                                                                                                                                            SHA-256:9984C016483DF6E8B3552451534C4E18B42CD3D827F4C369BDD574BB5E5B1209
                                                                                                                                                                            SHA-512:B47FCE991257C036468A66B5DF2C72F1BF2D4FB95A607E3CFCB4A091134DBAFF567AD20592A615F1051171ABE4AFBD25E75F0B85A80B21A3BCE65803DB5BCABE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.262451795310626
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm++mq8p1Q:+sv+K5+CtTFCqsUz0AUoey++mXPQ
                                                                                                                                                                            MD5:D956575A64DE678908FFB8CEFC2D6B39
                                                                                                                                                                            SHA1:2ACE5530B16B6A90B51C23FB48147331EFC0C08F
                                                                                                                                                                            SHA-256:AADEA0781FF909FEA482CF7EF2298B1D7151BFE51C0966690F6EBC7E7A25994D
                                                                                                                                                                            SHA-512:058D20B8B1730C715992ADF60304277F307644236517ADF1E8A815E874EB965A3BCA6290593A832ACABBEDCDE35FE446BEBC8E96F9C5FC3DD6182CB8F19DE181
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.267063923875303
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+Of0H:+sv+K5+CtTFCqsUz0AUoey+H
                                                                                                                                                                            MD5:95C6E5167BF31C0F915EED7163A930B8
                                                                                                                                                                            SHA1:9A9A108F6E42BFBE92A27B1806569CAB962DDB9D
                                                                                                                                                                            SHA-256:EF1D54ACCC383DE429BB0487C045A63A01BDAB8FBFA0CFC807F9AD3836F76CB4
                                                                                                                                                                            SHA-512:80A3EBE515C43C40DE24E7A24FAA0AA83D756D6FA317FD58D5940DF776D04D19E35F3CD524C1EFC22F3C1CB05B9134BBA04904252B24C9FF955C2C99F4D10CC2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.257459656988995
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+cx:+sv+K5+CtTFCqsUz0AUoey+cx
                                                                                                                                                                            MD5:B55FCCA4A4CC4FDDF428CF3D41DC5FAD
                                                                                                                                                                            SHA1:489F21E89EA446A47D865B3A08090D1C545296A3
                                                                                                                                                                            SHA-256:D6C1C7C20335FB7CE04FA077F8462DE9B64D81E454CD5B695A376C06BDCF3563
                                                                                                                                                                            SHA-512:7539E9E912E567FC7FD471506B5980E07B25166E58B5FCC876989C29982665E7D2612524BFB8D8CEC78E2CB2E1EC9FCDEA8B771FDDEB88698F5B98373CFCAD30
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.250747676593963
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm++BH2+h:+sv+K5+CtTFCqsUz0AUoey+CH2+h
                                                                                                                                                                            MD5:93FCBA60FCE4A902457B19D483D1EF37
                                                                                                                                                                            SHA1:C20ACE7F4A5DAB11496ECAFE3810C2D0EEE11E60
                                                                                                                                                                            SHA-256:533CC246A0375F2330D0CEC542BEC87040A42BEDD2B0D693EC06EA12E785BCDC
                                                                                                                                                                            SHA-512:33D3483B1CE08CAB5161725DD0E8ACFEB130F953ADA9B65A208C36E4215E48B2C4432B95A1EA5BC118D9619610FC4369152F3C41006015939B67710F801B08FF
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.264120563543988
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+ugxH0OX:+sv+K5+CtTFCqsUz0AUoey+XKOX
                                                                                                                                                                            MD5:4E16F2DF0C5AE0730112815DBA14EA73
                                                                                                                                                                            SHA1:599CCA3A2CC02AE81BDA230ACBA2C7A2A7C4FAC9
                                                                                                                                                                            SHA-256:205A2633ACD1EC30491A5556172C5281E41C23B0237530EBDC8517CC0C64ECA7
                                                                                                                                                                            SHA-512:E286AC531471A82A92C2817AF2C06E079F79D71E3C0F4FC8007E59A8C0AB6A206BC170876B6AC336FDE56D0F6DF217B86119DAFEA3A3F87EA9B04D9D6D1B16A0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.2547729771089555
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+BiOBO:+sv+K5+CtTFCqsUz0AUoey+B7E
                                                                                                                                                                            MD5:C28AAD7101D47619F5A140E967C7285D
                                                                                                                                                                            SHA1:53101D540DAC65CA09EB40E2E0D214B11E90A11F
                                                                                                                                                                            SHA-256:77C27A824B50D0CC00591DD12513EA2648F1EE693A93E08D846CED2B467EE914
                                                                                                                                                                            SHA-512:DF65933B7625CB9109D53F2CAD260201CAFED80CA9597C6CF57797D4C121A1F445F6726D1EF457FDBEBC7CB12A3584A8E1EDFE075E39D9964EC4A115B87DB438
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.256845597743145
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+oj8:+sv+K5+CtTFCqsUz0AUoey+oo
                                                                                                                                                                            MD5:1CF522B93D68580DC403017497715104
                                                                                                                                                                            SHA1:820F27C0745DB2943E531FE66FD90A6320039849
                                                                                                                                                                            SHA-256:0C679C6DE3944586EA09F370506E398E220211E6D312B2A9F34CFA790F79AD04
                                                                                                                                                                            SHA-512:3663E24C57C87348D8600206CBF368F2E53A441967A5256467DE8E0609EA602A48E58F3FA790A29457E7F0E80F0F9F9A09E10046602C32323B8E41819562B68F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.252334490525137
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+Gg7:+sv+K5+CtTFCqsUz0AUoey+Gg7
                                                                                                                                                                            MD5:0D3BFE421022498BE9051237F86FC49D
                                                                                                                                                                            SHA1:7F1C25D6CF27ACE555540A5734D7FE8A2994E8FA
                                                                                                                                                                            SHA-256:E2ADEC91EB998B4D67F8237C8375E611011752C949017BB28394CA1849E62917
                                                                                                                                                                            SHA-512:4480837D5760DBD1FA9C94BFE93DD894D9A5F81AED3100F9C8E446B1537D6FB9A8071B4F0D68F577AD5510CD2BD1FF1DB3DC1AC22B38C96A0E06E6C338F367E2
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2380
                                                                                                                                                                            Entropy (8bit):5.252688604348839
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:atsGm+KQfpzm+RkPlLnFSpqsbSjufrW0GtUoefLm+5Lz:+sv+K5+CtTFCqsUz0AUoey+5H
                                                                                                                                                                            MD5:B11557016DF48AEB013C9E883C8B2894
                                                                                                                                                                            SHA1:4F58C7F0A0571AB3F62D564413C5B7580D1DB536
                                                                                                                                                                            SHA-256:7C066023DEFE028F546EBDF290A1B226BFDCE8903195AA811C12FEAFDA60D5D9
                                                                                                                                                                            SHA-512:2F3DC52C555ED1B4865FB69150E7308894ABC751F56832A805E7CEB05C1F61421FAF1A64F98C6022502182985FABDB33D008D7C7C11C84E45845C96667AB9C00
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:var _lrSecureSearchToast_ = {.. WA_ST_M_STATUS_P:"Protection Score",.. WA_ST_M_MESSAGE_TITLE:"Increase your protection score",.. WA_ST_M_MESSAGE_TITLE_V1:"Search safer online and boost your protection score",.. WA_ST_M_MESSAGE_DESC:"Your protection score helps you monitor your overall digital health and safety. Get search protection for safer online searches and boost your protection score.",.. WA_ST_M_MESSAGE_DESC_V1:"Turn on search protection for safer online searches and see your protection score increase. Feel confident knowing you can monitor your overall digital health and safety with Protection Score.",.. WA_ST_M_ONLINE_PROTECTION_STATUS:"ON",.. WA_ST_M_ONLINE_PROTECTION_TITLE:"Online browser protection",.. WA_ST_M_ONLINE_PROTECTION_FREE:"Free",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE:"Browser protection is your first line of defense against unsafe websites, links, downloads, malware, and more.",.. WA_ST_M_BROWSER_PROTECTION_MESSAGE_V1:"Browser protect
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2893
                                                                                                                                                                            Entropy (8bit):5.5085933045855295
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:+eV+P0Xb5sb0Po/U0cHLKDJea6xVIfXUckHUTkZ6yXbo06Ev+3TlJR9Y:+GLrPo/aHLZBIfsn8JY
                                                                                                                                                                            MD5:2D4A669FDE1A14F55CDD7EB0EF287C59
                                                                                                                                                                            SHA1:A43F895B5E2C6242AB0F4432D447B3E9838CD49D
                                                                                                                                                                            SHA-256:91D67E5AA2345B028163226FE40999E64CFE7B9EA231794E0268E636FD0E7D71
                                                                                                                                                                            SHA-512:F87E4D980DF816E2FCCCBC3E374EFCD3FD8CB3C4B2DC27610FAB2BD320899C9578ED054EC2B769293DE8CB17AC2EAEC5B205321615F9A15168FF60E407FF3A8D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ.......... 6...9.......9...'...B...6...B.......X...6...9.......9...'...B...+...L.......9...B...6...9.......9...'...6.......B...&...B...L....tostring)[BL]: is_aj_blocked: end, returning .is_active1[BL]: is_aj_blocked: standalone installation.get_oem_implementation.[BL]: is_aj_blocked: start.info.log.core........O6...9.......9...'...6.......B...'...6.......B...&...B...6...9...9.......9...+...-.......B.......X...6...9.......9...'...B...+...L...-...B.......X...6...9.......9...'...B...+...L...6...9...9.......9...+...-.......'...B.......X...6...9.......9...'...6.......B...&...B...+...L...4...6...9.......9...'...B...'.......J.........Ewacore:mfw\packages\webadvisor\aj_toasts\wa-aj-toast-toggle.html8[BL]: aj_logic.get_template: returning toggle toastJ[BL]: aj_logic.get_template: current extension annotation setting is .ALL..GetBrowserSetting1[BL]: aj_logic.get_template: suite is active;[BL]: aj_logic.get_template: AJ toast was seen already.does_browser_setting_exist.BrowserUtils.utils. and
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1804
                                                                                                                                                                            Entropy (8bit):5.794129827458554
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:5y/BcaU1lu6t2gCqXXm3Oh0KxAACL/w6ns:5y/BcYUtiS0KxApL/s
                                                                                                                                                                            MD5:D57F36EB1F2C6F2685EB68A6939F718F
                                                                                                                                                                            SHA1:70BCA36AA02B54ED2B80C084F3E15B3D39E7821A
                                                                                                                                                                            SHA-256:600D76503BEBF9EAC51F5F6FBE4265E362F11EDA723DFC8DDE006D579AC4419A
                                                                                                                                                                            SHA-512:F4F48C102E397EF639311F40A97B8C97ED905143434C3F4B918B5A5837FC7EFE4DB1A3290FF7D0702E9A0680D3D6689CE7CCB8222985E765E5BAA1ECB8F1732B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..8.......=...=...=...K....providerName.providerId.priority........+...L...........+...L...........+...L...........+...L...........+...L...........K...........K...........+...L............6...9.......9...'...6.......B...&...B...'...5...'...J...]file:///[WA_FILES]/mfw\packages_web_view\webadvisor\wa-ss-toast-variants-rebranding.html..."secure_search_toast_variation..?wacore:mfw\packages\webadvisor\wa-ss-toast-rebranding.html.tostring0[BL]: calling get_toast_template_path with .info.log.core........'...L....default........'...L....DefaultSearch........+...L............6...9.......9...'...6.......B...'...6.......B...&...B...6...-...B...X...6...9...9.......9...+...............B...E...R...K......SetBrowserSetting.BrowserUtils.utils.ipairs., browser_type=.tostringM[BL] calling Base_provider:fill_url_settings_with_the_same_url with url=.info.log.core......%.?6...9.......X...6...4...=...6...9.......X...6...'...B...5...7...6...9...3...B...7...6...3...=...6...3...=...6...3...=...6...3...=...6
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4540
                                                                                                                                                                            Entropy (8bit):5.7215463842427425
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:/15UBuCYLAbf/uKwWbQ+YMVVnM/EdvsyJfQMGUu7:/3AX6SZVMEd3ZQDUu7
                                                                                                                                                                            MD5:CD798E5EF0695CE45913CFE9FF24DA07
                                                                                                                                                                            SHA1:F93D5CE576A5D9F3758E8DEC89B2956BB666CFA7
                                                                                                                                                                            SHA-256:9817B919A08CB4C5393364AE0E8F1B68D36E0F929DEBCD08F9539CAEF703A6FF
                                                                                                                                                                            SHA-512:9A8C4926558E2DCABD9EFE661C926428C7B9AA328D29D4CB833124EE8E95737ADC6060A307FBE53F93859C294C9F24D62C2088E812C9567FE926DFEDBF8B065B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........;6...9.......9...'...B...6.......9...6...9...9...9...9...-...B.......X...6...9.......9...'...B...+...L...6.......9...6...9...9...9...9...-...B.......X...6...9.......9...'...6.......B...'...&...B...+...L...6...9.......9...'...B...+...L......common_checks: end., won't proceed.'.tostring$common_checks: extension state .get_extension_state*common_checks: registry entry present.edge.BrowserType.BrowserUtils.utils!has_extension_registry_entry.browserSettings.common_checks: start.info.log.core.........'6...9.......9...'...B.......X...-...B.......X...6...9.......9...'...B...K...6.......9...+...'...-...B...6.......9...'.......B...6...9.......9...'...B...K.......!schedule_edge_ext_check: end.on_edge_check.SetEventTimer.timerFactory.edge_onboarding_check.GetOption.settings2schedule_edge_ext_check: common checks failed#schedule_edge_ext_check: start.info.log.core......E...6...9.......9...'...B.......X...-...+...B...-...B.......X...6...9.......9...'...B...K...6.......9...+...'...+...B.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3446
                                                                                                                                                                            Entropy (8bit):5.580599253252745
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:8QlNSU52MBNIsd+eE+Zo1PsLjgjg2kYIf0TfdXdWXbiA:8YSU5pd+IZo1PBg2kYw0TfdXdWuA
                                                                                                                                                                            MD5:174EA661C9AE5700F50E0C6C8B298909
                                                                                                                                                                            SHA1:1625F68F91A0D3D0981AE33AA127B2C8B4261E51
                                                                                                                                                                            SHA-256:EDBAC1B754DDAA727AD3CDBDDF97FACB4FABF4A4F4BBDBE9C943961D951CA1C8
                                                                                                                                                                            SHA-512:F884D0DC98EA0A1816D241751D6E56A0E2434B1F5435726ABD03338A4F99469A3F95D0AC4A8465ED89BCA458D38050804F2685A1E47AAF896312880941DF2ACB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........T6...9.......9...'...B...6.......9...6...9...9...9...9...B.......X...6...9.......9...'...6.......B...&...B...+...L...6.......B...).J.....X...6...9.......9...'...6.......B...'...&...B...+...L...6...9...9...9...9...6.......9...6...9...9...9...9...6...9...9...9...B.......X...6...9.......9...'...B...+...L...6...9.......9...'...B...+...L....common_ff_toast_checks endBcommon_ff_toast_checks: WA extension is installed and enabled.ff_wa_ext_id.get_extension_state.ext_enabled.ExtensionState$ supports registry installation%common_ff_toast_checks: version .tonumber.tostringIcommon_ff_toast_checks: failed to get Firefox major version . Error .err.ff.BrowserType.BrowserUtils.utils.get_browser_major_version.browserSettings!common_ff_toast_checks start.info.log.core......#.l6...9.......9...'...B...6...6.......9...+...'...)...B...A...6...9...B...6...6.......9...+...'...)...B...A...6...9...9...9...............B.......X...6...9.......9...'...B...K...5...6...9...9...9...=...6.......9...+...'
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2880
                                                                                                                                                                            Entropy (8bit):5.680378484791574
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:qChuRIL5WuR0dyMGhKzG2VzWGLk5a2TB+2QSusUAwJjfRkmypUy8NqXRUsUc+LcI:qChuzuOGo9zk5FTAdSQgRUsUc+LcU0Ut
                                                                                                                                                                            MD5:6042C4E797DB58361D3649E6FA0BE845
                                                                                                                                                                            SHA1:ABAB0A1839EB6F478FDC6AE90CEF2FFEEC62689C
                                                                                                                                                                            SHA-256:9493F3374C1CE55BBAF24A7F0E13E20ED21827E76F3A3E1EFF14A2519BBD7FD8
                                                                                                                                                                            SHA-512:CB804CF67A710E2782FAE66CAE9F75C50F79AC2EA87D39BB4F33FA64875EA9FB488D014D82E83A51554FB15F56884F49FD3EE651B24EA90FC17DF36A8517DACA
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...9...8.......X...8...L.......X...+...6.......9...............B.......X.......X...+...<...L...6.......)...B...K....error.include.external.loaded.package.........5...'...6.......B...X...6...........B...E...R...K....require.ipairs.MFW\core\.....logger.dkjson.json.utils\stringUtils.utils\browserUtils.class.win32helper.utils\common_utils.........5...6.......B...X...6...6...8...'.......&...B...E...R...K....Module does not exist: ._G.assert.ipairs.....external.settings.subdb.telemetry.utility.browserSettings.registry.timerFactory.........5...'...6.......B...X...6...........B...E...R...K....require.ipairs.logic\.....usage_calculation.MiscUtils.providers_selector.base_provider.ss_logic.oem_business_logic.ff_monitor.type_tag_utils.tests_logic.aj_logic.edge_onboarding.oem_utils\oem_util.oem_utils\oem_utils_wss.oem_utils\oem_utils_wps oem_utils\oem_util_selector.oem_utils\affid_monitor........d6...9.......9...'...B...'...6.......9...B.......&...6...9.......9...'.......&...B...6...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5319
                                                                                                                                                                            Entropy (8bit):5.745975256849087
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:XXleAMNJLtWOVh7jqJlkN48gkaxwSCTNOUnPmZ6Fnr6uoS9:nl07tWOGJlkJgkaOBNOUPxFrLoi
                                                                                                                                                                            MD5:E1C40EBE2C5D157FCBD18C89655653B5
                                                                                                                                                                            SHA1:1A4B6AFC1F430F6D5E9B5231AB1A6106F2F3C062
                                                                                                                                                                            SHA-256:F80EA2075917CA238EF3B46D9277BC1E905C10546E65996B3FEC603B81FF4633
                                                                                                                                                                            SHA-512:78606799678830D27DF7CF33E3DFF4DCA4B8EB449517B507D909B9714A1060265B1AC2FFC0387DB8C12B1BB00C3C4B980EDDF32017B1876DC12E7CC2FE9B09B8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........$6...9...9...9...6...9...9...9...B...)...-...9...'.......B...6...9...9...9.......6...9...9...9...........)...B.......X...+...L...-...9.......D......string.GEO_ISO2.SYSGEOTYPE.GetGeoInfoA.char[?].new.GEOCLASS_NATION.SYSGEOCLASS.GetUserGeoID.kernel32.Win32.core..........6.......9...+...'...'...B.......X...6...9.......9...'...B...6...9...9...9...B.......L....GetUserLevelGeo.MiscUtils.utilsH[BL] GetGeo: Got empty value of SystemGEO, falling back to user GEO.warn.log.core..SystemGEO.GetOption.settings.........6...9...9...-...9...9...)...)...'...B...A...9.......X...+...X...+...L......handle+{B3251298-6CD7-4C88-A541-A62A7500D233}.OpenMutexA.C.Win32Handle.Win32.core........8-..."... .......X...+...X...+...6.......B.......X.*.....X...6.......9...+.......6...6...9...9...9...........B...A...A...X...6.......9...+.......'...B...6.......B.......X...6.......B.......X...6.......9...+...........B...L......(current<setting).days_elapsed.common_utils.utils.core.tostring.SetOption.settings.st
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9815
                                                                                                                                                                            Entropy (8bit):5.839563999700545
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:76Qa+8YiRGQLtdF4ivOiTSzDSEoNw0FKgv/a6auYc4HGLJUgd:76Qa+8YAGQLdHONHOKgHPoc4mLGgd
                                                                                                                                                                            MD5:DED78D399D6009980BE422242A9BBD8E
                                                                                                                                                                            SHA1:35B6F92F31D06ABF5F81EE11E4AA41B5AF5E20E8
                                                                                                                                                                            SHA-256:BAF9C732E0AE7A53AB4B01EAD3122559AC3E42CA9BF014136275C8FA69B1242F
                                                                                                                                                                            SHA-512:D852CE53905C84FDA63BC74FAAABDC2512FEC11E2B7ED8B9470D378F589461EE49D21E188D3D4FC21E2E1A2F6DCABCD8162D4F74D8BF9909A1139BCEA650C62F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........J6.......9...+...'...)...B...6.......B.......6...9.......9...'...6.......B...&...B.......X...6.......9...+...'...6...6...9...B...A...A...6.......9...+...'...'...B...+...L...6.......9...+...'...)...B.......X...6.......9...+...'...'...B...+...L...6...9...9...9...6...6...9...B...A...........'...D....MinimumDaysElapsed.MiscUtils.utils.(interval=0)3*DEFER_SEARCH_MINIMUM_DAYS_AFTER_WSS_UNINSTALL.(just set).OEM_WSSUninstallDateState.time.os.SetOption.tostring.[BL] *WSSUninstallDate = .info.log.core.tonumber.*WSSUninstallDate.GetOption.settings.........V6.......9...+...'...+...B...6.......9...+...'...)...B...6.......9...+...'...'...B...6.......9...+...'...'...B...6.......9...+...'...'...B...6.......9...+...'...'...B...6.......9...+...'...'...B...6.......9...+...'.......B...6...9...9.......9.......B.......X...6...9.......9...'...6.......B...&...B...K...6.......9...+...'.......&...'...B...K....NoError.RecoveryAttemptLastError_.tostringA[BL]: SetSearchOfferAllowed: nil browser string
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1779
                                                                                                                                                                            Entropy (8bit):5.569415025810661
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:FVI5znjQm2soNtKCSTeiijbeTOx/6ATk0pdpy6cSVIBmD/JF8vor:fIpjzatN2U80FIBKBtr
                                                                                                                                                                            MD5:5728F2F5B792DB52879923AA04B66F14
                                                                                                                                                                            SHA1:621A4FD5A6F5CD74B8F9279DB8E8C9BE53618C55
                                                                                                                                                                            SHA-256:6FE5698A9FB8ECE4B1234606B51F23725FE82DE21BED3E8B964E07021C549886
                                                                                                                                                                            SHA-512:F8D87D29E49E04C8B236B43D564DD9D787549AB95E0D4C1BB24976DC32E519053BD13C3BFC6DEC0F16FBF3FE303E0E9207ADDDA56B5F1ADBC45BE7F75CA789F9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ............6...9.......9...'...B...6.......9...+...'...B.......X...6...9.......9...'...B...K...6.......9...+...'...+...B.......X...6...9.......9...'...B...K...6...B.......X...6...9.......9...'...B...K.......9...B.......X...6...9.......9...'...B...K...6.......B...6...9.......9...'.......&...B...+...6.......9...+...-...B.......X...6...6.......9...+...-...'...B...A...6...9.......9...'.......&...B.......X...6.......9...+...-.......B...+...X...6...9.......9...'...B...6.......9...+...-.......B...+.......X...6...9.......9...'...B...6.......9...B...6...9.......9...'...B...K......wps_affid_check_impl end.apply_customization.wps_utils1wps_affid_check_impl: applying customization3wps_affid_check_impl: affid is not updated yet.SetOption6wps_affid_check_impl: current WA saved aff_id is .0)wps_affid_check_impl: wps aff_id is .tostring,wps_affid_check_impl: wps aff_id is nil.get_aff_id4wps_affid_check_impl: wps implimentation is nil.oem_utils_wps2wps_affid_check_impl: affid override disabled.affi
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):560
                                                                                                                                                                            Entropy (8bit):5.070909170520725
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6f0a/55P8Z+U3bTs3IdtnugLBGgiO6CaMAEWfIJw8nGAOdg:68aMZdTs0ugLBx2ChAEWfF8d8g
                                                                                                                                                                            MD5:3FA88847EE0F13538ABEC9AD10F2EE73
                                                                                                                                                                            SHA1:6BC7F487FD4D06AB255B892BB33DF6FE038B0621
                                                                                                                                                                            SHA-256:D8A3B76B9B3793DE75F2DB4A5011FDEDBE873BF4C50B3C0C69CB937076801381
                                                                                                                                                                            SHA-512:430C5ED86BC477678D1A74384EC14A25A3AD6EF34D29ECF87F9146A1702DFE23BCE63746EBCB90B69F5D0F02103349E24A2CD9AAA2FC0AE2D81BC199609CA0EC
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........K...........+...L...........+...L...........+...L...........+...L...........+...L...........+...L...........+...L..........."6...9.......X...6...'...B...6...9...3...B...7...6...3...=...6...3...=...6...3...=...6...3...=...6...3...=...6...3...=...6...3...=...K.....is_active..get_expiry_date..get_activation_date..get_install_date..is_trial_active..is_trial..is_installed.oem_util..class.core.class.require.core._G...//0C88CD92C38CC31371E2A7FFEF24E36ED213BABD85DC71FD564CF5CAA71EDCF41046765B4EB07BF8B13B0624816E7C09F18C9A2148C8D43D962748870C87EC73++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):672
                                                                                                                                                                            Entropy (8bit):5.329052509256524
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:6DmOMYinnQlYelgLOphYfR2MQyPiOhYfQIMBFSWbB4Fd/0/b/UtmEmgh:6nVMeNwfR2MQsmfQIMBFXG1QUtmyh
                                                                                                                                                                            MD5:C459A560CB78933ACAC76514E2408D5A
                                                                                                                                                                            SHA1:FA5086A115872496C2D59EF500FDBE123F7B8C52
                                                                                                                                                                            SHA-256:D8C8985978EDCA7FF9CCF655D4BF3823C8428C8AEE16DC51F5564DDB1F0AFB2F
                                                                                                                                                                            SHA-512:001BA39B437B7804508B81B4D560F8C73924A9F9FE882195CDF2B780E3C6F21DE09BD9940A115434B98D59D1DFC635EE891BFF59C23A86ED57D89EFFDB899D2C
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........46...9.......9...'...B...6...B.......X...6...9.......9...'...B.......9...B.......X...6...9.......9...'...B...L...6...B.......X...6...9.......9...'...B.......9...B.......X...6...9.......9...'...B...L...+...L...0[BL]: get_oem_implementation: wps installed2[BL]: get_oem_implementation: wps_oem not nil.oem_utils_wps0[BL]: get_oem_implementation: wss installed.is_installed2[BL]: get_oem_implementation: wss_oem not nil.oem_utils_wss([BL]: get_oem_implementation: start.info.log.core+.......3...7...K....get_oem_implementation....//836C5B03D9868F1E7E3E80AF6F0A8B8EBCB0FD233926B88E4C5C83320CF9F3A7CB133D48875B0A53A6F9F32262D69227F8387C864E9257C874D53016B35D51F9++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5508
                                                                                                                                                                            Entropy (8bit):5.601274527465085
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:WHn6Gmsvuo4xjk8mxfFDMkJH40m9sjvqFXf+2rWVH9b5lRUwsqt:U6vcJvmAtYeUwsqt
                                                                                                                                                                            MD5:15D0398B9F76392BDA31A64E92EBEF60
                                                                                                                                                                            SHA1:D49B2128B16A9948D16C39ABB8650592137C2EE2
                                                                                                                                                                            SHA-256:6633C5E2D1E16325A6172E260EEE73186B1063D63911F21F18141D255040A1A9
                                                                                                                                                                            SHA-512:403A09F1FF6F6000893B4D49BAD0CA9FD796C3B10BBC94C6B54AA7B7E869B858E6E73210A9FB99B9D717B587C5E5E413488C3088C788A8B80F5D6FF22BBC7E80
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........?6...9.......9...'...6.......B...&...B...6.......9...-...B.......X...6.......9...-...B.......6...9.......9...'...B.......X...6...9.......9...'...B...K...6.......B...6...9.......9...'.......&...B...6...9.......9.......B...6...9.......9...'...B...=...K........wps_data5[BL]: oem_utils_wps:constructor: parse succeeded.decode.json1[BL]: oem_utils_wps:constructor: setting is 0[BL]: oem_utils_wps:constructor nil setting([BL]: oem_utils_wps:fallback to v1 .get_setting.wps_utils.tostring.[BL]: oem_utils_wps:constructor. self is .info.log.core........;6.......B...6...9.......9...'.......&...B.......9...-...B...6...9.......9...'...6.......B...'...6.......B...'...6.......B...'...6.......B...'...6.......B...'...6.......B...'...6.......B...&...B...6...9...5...=...=...=...=...=...=...D......sec.min.hour.day.month.year....sec..hour..day..month..year..min..time.os...:. .-([BL]: wps_date_to_lua: parsed date .match)[BL]: wps_date_to_lua: input string .info.log.core.tostring.........6...9....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2385
                                                                                                                                                                            Entropy (8bit):5.565249107581106
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:eYWhvpfcvH72EQvevwdH85FkRkBjvFV4sl2V:2lpfEH7hQ6wdeFkRkBbz4slQ
                                                                                                                                                                            MD5:2F92638A462617B9BF64DFD7C4D1D401
                                                                                                                                                                            SHA1:C407EB5D173957076EA2985E2AC6F581DBA98E59
                                                                                                                                                                            SHA-256:41F4E60EFEC88CA3AF71D5E26398E7A35609B81EC2A6E62E2D5CDA27D9433156
                                                                                                                                                                            SHA-512:1F6FE9D172EC60199669F32E6E7996B901D8078B1FFB9D76B3F9A9F04CA15235276517E38CE55192EEAE4C05629308003C983752848EAB5E562F5EBD85F9D95E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........6...9.......9...'...B...6...9...9...9...D....IsSuiteInstalled.common_utils.utils%[BL]: oem_utils_wss:is_installed.info.log.core.........6...9.......9...'...B...6...9...9...9...D....check_wss_trial.common_utils.utils![BL]: oem_utils_wss:is_trial.info.log.core.........6...9.......9...'...B...6...9...9...9...D....is_active_wss_trial.common_utils.utils([BL]: oem_utils_wss:is_trial_active.info.log.core........46...9.......9...'...B...6.......9...'...'...B...6.......B.......X...6...9.......9...'...B...+...L.......X...6...9.......9...'...B...+...L...6...9...9...9.......B.......X...6...9.......9...'...B...+...L...L...:[BL]: oem_utils_wss:get_install_date null expiry time.SubDBTimeToOsDate.common_utils.utils>[BL]: oem_utils_wss:get_install_date data is empty string.;[BL]: oem_utils_wss:get_install_date data not a string.string.type.installed.vso.GetProperty.subdb)[BL]: oem_utils_wss:get_install_date.info.log.core........L6...9.......9...'...B...6.......9...'...'...B...6.......B...
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5694
                                                                                                                                                                            Entropy (8bit):5.849470354833383
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:2/dh6DsRoC42BeCpx7Pd0e+VOleAGrLNPF0pBtw9CJ5ohtbKI3Ht:2/dhLRqyPvd0ZOlOXNP2p3bJ+hVZ3t
                                                                                                                                                                            MD5:9CB4856CFB3739CC2218002F4FD729A6
                                                                                                                                                                            SHA1:BF36999CE3FB36B6E479957B5220D9DDE5C4CC20
                                                                                                                                                                            SHA-256:787B1152F9A87D32B0A3073B1015D270B5D849B41A41C95012C2A41270BB87A7
                                                                                                                                                                            SHA-512:AB5FC590F4DCF0F8E951F7A9ABEB0E1C30F9EA4743589CFF10A15A8C62FBEDAA1FAD9D04E3BC201871ABB03759D5308712CE1CE8BC66970173ABB33918641738
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........E6...9.......9...'...6.......B...&...B...6...9...9...9.......B.......X...+...L...6.......9...+...'...6...9...B...6...9.......X...6.......9...+...'...'...B...6...9...9...9...'.......B...6...9...9...9...B...8.......X...+...L...6...9.......9...'...6.......B...'...&...B...+...L.... end"[BL] should_be_selected_impl .GetGeo.,.Tokenize.common_utils.AU,DE.BingCountrySet.Bing.Yahoo.SearchProviderCodes.ProviderForced.GetOption.settings.ShouldSelectBingOverYahoo.MiscUtils.utils.tostring&[BL] should_be_selected_impl for .info.log.core........-6...9.......9...'...B...6.......9.......6...9...9...9.......B...A...6...9.......9...'...6.......B...&...B...6...9...9...9...9.......X...6...9...9...9...9.......X...+...X...+...L....ext_not_accepted.ext_disabled.ExtensionState.BrowserUtils.tostring4y_for_b_extension_criteria: extension state is .get_search_extension_id.MiscUtils.utils.get_extension_state.browserSettings&y_for_b_extension_criteria: start.info.log.core........e6.......9...+...'...).
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):18145
                                                                                                                                                                            Entropy (8bit):5.8898803796156605
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:0baPqTqj5R2F46vdSGGgOqkmzLKh0hyKc1BSF63i8IOB6VNplF9az:0b4qTq1R2F4WgGGgOqkmzqkyKc1Bqd8p
                                                                                                                                                                            MD5:1BDB3B40489026FD4B88B72CB1728E6F
                                                                                                                                                                            SHA1:0D5565819D96ECB2F422C103CE9CC75D72C1F746
                                                                                                                                                                            SHA-256:A80EE525C4ABD87F5089FFC31076702C68A76DF9642ECF316E1AC974E292E2BB
                                                                                                                                                                            SHA-512:C66982AD355155C528DC41B759E1870CC1BF536D0C4C617A60B629FF2CFE19F671DCCFD22226058E6C44E3630E3D3590A338BEFDC3152D6BA30681BDC350F7FE
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ.........."6...9...9...9...B...-...8.......X...+...L...6.......9.......6.......9...+...'...'...B...A.......X...6.......9...+...'...+...D...+...L....."*EMEA_COUNTRY_SUPPORT_ENABLED.HU *EMEA_COUNTRY_SUPPORT_REGEX.GetOption.settings.RegexTest.utility.GetGeo.MiscUtils.utils.core........16.......9...+...'...-...B...6.......9...+...'...'...B.......X...6...9.......9...'.......&...B.......X.......'.......&...X.......6...9.......9...'.......&...B.......X...-...'.......'...&...>...K........).*..^http(s)?://(us\.|ar\.|at\.|au\.|br\.|ca\.|ch\.|fr\.|fi\.|de\.|dk\.|hk\.|in\.|it\.|kr\.|mx\.|no\.|es\.|se\.|tw\.|uk\.|cf\.|cl\.|co\.|id\.|nl\.|nz\.|pe\.|ph\.|sg\.|th\.|pl\.|tr\.|espanol\.|ve\.|vn\.|malaysia\.)?search\.yahoo\.(com|co\.jp)/search.*(\?|&)fr=(mcasa|mcsaoff|mcsaoffblock|slv8-mcafee|$AdjustRegex: regex addition is .|,AdjustRegex: got special chrome frcode .info.log.core..YAHOO_CH_FR_CODE_REGEX_ADD.*YAHOO_FF_FR_CODE.GetOption.settingsG.......6.......9...B.......K......get_config.smart_toast_s
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1917
                                                                                                                                                                            Entropy (8bit):5.844687996879564
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:iFZZRFnYQrEfyAb/taw2mx/YH8tEiwtRU1VWk+gj99:iFz/REfyAb/Yw2mx/G8tEiwtyok+gjn
                                                                                                                                                                            MD5:5F7613E39C466B29459B809F692398D6
                                                                                                                                                                            SHA1:FD6F702282C45FEC65CCD2F7A84763FB9EA91447
                                                                                                                                                                            SHA-256:FCDE3D311F9B801860D2E34DFD79F30C1649EA27F8F6F56F399F43134D6FF670
                                                                                                                                                                            SHA-512:B37D26C12A53C78FF7A962B69C3B7E6E45A52897472410AA7473E5F77D361B9DA7B813534995694CBDA33B6CBB35F344B7A520B14FC8E02144D1EF478671149F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........`6...9.......9...'...6.......B...&...B...4...6...6...B...H...6...9...........B...F...R...6...9.......B...).......)...M...6...8...8.......9.......B.......X...L...O...6...9...6...9...9.......9...'.......6...9...B.......X.'.6...9.......9...'...B...6.......9...+...'...'...B...6...9...9.......9...+...'.......'...B...6...9...9.......9...+...'.......)...B...6.......9...'.......B...+...L....(empty)(fill_url_settings_with_the_same_url.Base_provider.SetBrowserSettingInt.(Unknown).ProviderToastedName.SetBrowserSettingL^http(s)?:\/\/(www\.)?yandex\.(com|ru)\/search\/(\?|&)fake_param=fake.*.SECURE_SEARCH_REGEXES.SetOption.settingsI[BL] ssProviderSelector.GetSSProvider nullifying settings for Yandex.Yahoo.ProviderToasted*GetUserBrowserSettingWithSystemBackup.BrowserUtils.utils.Yandex.SearchProviderCodes.ShouldBeSelected.sort.insert.table.ss_providers.pairs.tostring/[BL] ssProviderSelector.GetSSProvider for .info.log.core.........6...9.......9...'...6.......B...'...6.......B...&...B...6.
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1079
                                                                                                                                                                            Entropy (8bit):5.59753508033406
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6XKNbPMFjBgrexyj1yA9yqlyt4KU8qyHm6nqJq8Uf+E3Vxcz+nr:f0b6yy1P9xlUUDixMq8Ufxxd
                                                                                                                                                                            MD5:C52D3C82D16896F10A24ED0F18962E8B
                                                                                                                                                                            SHA1:B829FEBB4A81259B67C1CAFF710E881EC976B08B
                                                                                                                                                                            SHA-256:36233C98FF348E0040319E8A125AC24988ED59A7C52F3F5805F543A5A61186B4
                                                                                                                                                                            SHA-512:B0A63CD117B5C97929D774FC2B0208C8A3F4BE7A7C2B1138F76BE4825164F48FC6CF068374D61FB2493E2BE4E312A53D22ECA2979DE6F9721CC64E2C8DDCFA69
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........J6...9.......9...'...B...6...9.......B.......X.5.9.......X.2.4...6...9...B...H...6.......B.......X...9.......X...6...9.......9...'...9...&...B...9...=...X...6...9.......9...'.......&...B...<...F...R...6...9.......9...'...6...9.......9.......B...&...B...L...X...6...9.......9...'...B...+...L...K...Q[BL]: smart_toast_search_setting:get_config: Smart search settings not found.encode.jsonF[BL]: smart_toast_search_setting:get_config: Processed settings: ][BL]: smart_toast_search_setting:get_config: Unknown setting or malformed data for key: H[BL]: smart_toast_search_setting:get_config: Found frcode setting: .frcode.table.type.pairs.search_settings.get_config smart_toast_config_selectorO[BL]: smart_toast_search_setting:get_config: Getting smart search settings.info.log.core.........6...9.......X...6...6...9...6...B...=...6...3...=...6...2...L.....get_config smart_toast_config_selector.class.core.smart_toast_search_setting._G...//F0A6836976F59F59578A7F23C605584C8A2C452DF6247868F42
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):811
                                                                                                                                                                            Entropy (8bit):5.5627366010630785
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6ni3JB40xJB888hUeJBlznqJq8UtTgc6e:+i3JLxJOXUeJrzMq8UtTgc6e
                                                                                                                                                                            MD5:E607C870DDB1433C445E1C46E3766C99
                                                                                                                                                                            SHA1:66F3A4BB2A953FB4750EA0DAF512A5DB077CC050
                                                                                                                                                                            SHA-256:5DD2F9C2FBA8C7B96D5BBBBC6DA6DA646AAFCF16522C4DC22195AA22D4E6F072
                                                                                                                                                                            SHA-512:5188642411431160F1C2046624B64C0ADD278082D3686ABC32FBC1A6495BFFE90B4460FBE5D72DACD56B0799F0D1BE480B43407CD4B60AB250048454CAD20761
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........06...9.......9...'...B...6...9.......B.......X...9.......X...9...9...9...9...9...9...6...9.......9...'...6...9.......9...9...B...&...B...............J...X...6...9.......9...'...B...,...J...K...J[BL]: smart_toast_template:get_config: Smart toast template not found.encode.jsonB[BL]: smart_toast_template:get_config: Toast template found: .web_view2_template.template_data.template.toast_template.get_config smart_toast_config_selectorH[BL]: smart_toast_template:get_config: Getting smart toast template.info.log.core.........6...9.......X...6...6...9...6...B...=...6...3...=...6...2...L.....get_config smart_toast_config_selector.class.core.smart_toast_template._G...//A5D557B96D3D8EF81D45E71E298E1D15E70890FAE0CFBB872033838E2F034A97DB01EAB7B0A563393BFF010FB182CD70A3DDEB2EBE978785C7097A4DF6F51E0F++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):903
                                                                                                                                                                            Entropy (8bit):5.527964649762146
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:6VPcljcvIPYljlAEltlXfgNUIqlLnqJq8U6r+SGj9:Zlj85WEBYNUIqNMq8U6fGx
                                                                                                                                                                            MD5:0E81B6D2373D30AEB9B86784E94C9AB4
                                                                                                                                                                            SHA1:B4C833E6D6C26C652F24CCC4EB784D66D5E42E3D
                                                                                                                                                                            SHA-256:4C172C578AFAE4F866C3AD5258230906B171B2937FEFB48F5B1D06917A572576
                                                                                                                                                                            SHA-512:F98B9A9E843BD86BF9A388A92B0E5D54D594635B69A233D49FE48286B2FCE59EA1976DCD305CEA4E0FE5D7D75D15D9240CD567E68FE59645A7CFBBFD8F1DE0D1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........<6...9.......9...'...B...6...9.......B.......X.'.9.......X.$.4...6...9...9...B...X...6...9.......9...'.......&...B...6...9...........B...E...R...6...9.......9...'...6...9.......9.......B...&...B...L...X...6...9.......9...'...B...+...L...K...E[BL]: smart_toast_trigger:get_config: Trigger settings not found.encode.jsonG[BL]: smart_toast_trigger:get_config: Processed trigger settings: .insert.tableB[BL]: smart_toast_trigger:get_config: Found trigger setting: .triggers.ipairs.trigger_setting.get_config smart_toast_config_selectorC[BL]: smart_toast_trigger:get_config: Getting trigger settings.info.log.core.........6...9.......X...6...6...9...6...B...=...6...3...=...6...2...L.....get_config smart_toast_config_selector.class.core.smart_toast_trigger._G...//894BE453DE029DD5840552784029DC188B404F167CC065ABC224735C9BA01F79CCFBD988E2ADEAB24C6180B9A534AA2FE0BEF10C4D408CA840AD3D221C87D0DA++
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):49012
                                                                                                                                                                            Entropy (8bit):5.056113680206571
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:+wf+IsIWUHHe4QmwgUwTjNxHS/lpliu/ATe:DDsRU+4ZXBnBu/Ay
                                                                                                                                                                            MD5:215D687FAA6F35A92EB6FC31CA5CCD46
                                                                                                                                                                            SHA1:614E6B7F747C7FBD9AAE75FC1B3C2C13E1CFE521
                                                                                                                                                                            SHA-256:7BBCDD6D869930E31FBD7FA2721009557BF84EB81E7CBC6ADBD040B05EA674B5
                                                                                                                                                                            SHA-512:758D4ECAB869CA1F356B22D4FB613C050DE02B035EAAD87F3B90B335203E5DC91275F1E931CF2FE5F1DC72015B7164ABFEDBFFE177FACE3FAC3D2011AB19BA89
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ...........5...9...=...-...9...9...8...=...-...9...9...8...=...-...9...9...8...=...L..........toast_template.search_settings.trigger_setting.config_setting....config_id..search_settings..trigger_setting..toast_template..config_id..........6...9.......9...'...B...6.......9...+...'...+...B.......X...6...9.......9...'...B...K...4...4...6...6...9...B...H.(.6.......B...6...9...........B...4...6.......B...X...6...9.......B...9...<...E...R...6...9...<...6.......B.......<...6...9.......9...'.......'.......'...&...B...F...R...6.......9...+...'...6...9.......9.......B...A...6.......9...+...'...6...9.......9.......B...A...6.......9...+...'...+...B.......X...6...9.......B...:...6...9.......9...'...6.......B...&...B...6.......9...+...'.......B...6...9.......9...'...B...K...I[BL]: smart_toast_config_manager.initialize: Initialization complete.SetOptionInt..[BL]: smart_toast_config_manager.initialize: client_config_version is not set, defaulting to the least available version = .sort&smart_toast_c
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2203
                                                                                                                                                                            Entropy (8bit):5.472780090169697
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:kVInVFaoLKmuO8UVUoDUJU0UvrUsmU2FXvoIHEUj3UQtUQqDUHUQTUQKDrUMUYq4:QInVlmhhUVU2UJU0UvrUPUIvoIHEq3Ur
                                                                                                                                                                            MD5:DF2352EEA6BE71F1B5D79F10662739E3
                                                                                                                                                                            SHA1:8A413AF42DE3D7EF4950A7E52BA337805DCAF38B
                                                                                                                                                                            SHA-256:0D645C681D19923BD277955F389DF56E4F7EF99BFB758C47FE05E0625BD84B0D
                                                                                                                                                                            SHA-512:4043E355B56787F8742F1D5C9224753C306489FD0CA71EE7AEC49DD7B87745E7DCAD417A26C849CD08E31BFDFEEF1781FDF142AB98AFD31A789E70FBF86AFD5F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........]6...9.......9...'...B...6.......9...+...'...'...B...6.......9...+...'...+...B.......X.......X.......X...6...9.......9...'...B...6...+...=...6...+...=...1...6.......9...+...-...+...B...K...6...=...6...=...6...9...6.......B...6.......B...A.......-.......X...6...9.......9...'...B...6.......9...+...-...+...B...X...6...9.......9...'...B...6.......9...+...-...+...B...1...K.......P[BL]: smart_toast_config_selector.initialize: Configuration loading failed!U[BL]: smart_toast_config_selector.initialize: Configuration loaded successfully!.tonumber.get_configuration.smart_toast_config_manager.SetOption.config_version.config_id smart_toast_config_selector^[BL]: smart_toast_config_selector.initialize: Config ID or Config Version is nil or empty&smart_toast_client_config_version..smart_toast_config_id.GetOption.settingsB[BL]: smart_toast_config_selector.initialize: Initializing....info.log.core........]6.......9...+...'...'...B...6.......9...+...'...+...B.......X.......X.......X...6...9
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):34823
                                                                                                                                                                            Entropy (8bit):5.86515989822727
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:IhyM9PIgux64k9yq5nwbpVnk+XQqXMrWD7C7Us7hUfmE:WP9wZOfZh+L57C7Us7hUL
                                                                                                                                                                            MD5:27735FFCAFD79E2DD7FAA14983E7B047
                                                                                                                                                                            SHA1:3EF73EF114D0F8BAACC6A8DD0E95D9C4D7CF34B6
                                                                                                                                                                            SHA-256:FE72597C6E27D3A31E893B754D793AFD614B1501250880812E306ADC286168EB
                                                                                                                                                                            SHA-512:4A798E5E861198A11D2D8D4FE991AB2E9B0556701A7BFA90424B27B0808E4029A0819162B2BBF0D417111EF6FA0CCF892F7499420F6EDAA37A3A78C61D80787E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........76...9...9.......9.......B.......X...6...9.......9...'.......&...B...K...6...9...6...9...9.......9.......B...A...6.......9...+...'.......&...6.......9.......B...A...6.......9...+...'.......&...6.......9.......B...A...K....GetCurrentMinVersion.MinBrowserVersion_.GetCurrentMaxVersion.browserSettings.MaxBrowserVersion_.SetOptionInt.settings.GetBrowserStr.lower.stringLInvalid browser type passed to UpdateSupportedBrowserVersionDimensions.info.log.IsValidBrowser.BrowserUtils.utils.core........%6...6.......9...+...'...-...9...B...A...6...9.......9...'...6.......B...&...B...-...9.......X...-...9.......X...6...9.......9...'...B...-...9...L.....7[BL]: alt_triggers_get_cohort: setting cohort to 0.logon_unlock.tostring6[BL]: alt_triggers_get_cohort: settings value is .info.log.core.regular.alt_triggers_cohort.GetOption.settings.tonumber>.......6.......B...X.......X...+...L...E...R...+...L....ipairs@.......6.......9...B.......K......get_config.smart_toast_trigger........-...-...-...D
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1783
                                                                                                                                                                            Entropy (8bit):5.633941139078878
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:2mDrfjaG7ffgaIddgL9tlVewikdQ9THVK9LySRk:2mfraG7foLddqhiDVPwk
                                                                                                                                                                            MD5:6DD0F5422A0B0A63DE2B7E6672159761
                                                                                                                                                                            SHA1:BFC28D332AC773FBDCDCD008B64C937C904E8539
                                                                                                                                                                            SHA-256:0E3B4BB44790636DCD295570E7B70AFD6EDA5724EB1D6C3F1850213368F23552
                                                                                                                                                                            SHA-512:D0AF0F8D018C6F715BC6767F5F740232B744A19C2EEB6931067057BBEF3010DC1B53FBD7432E951B1EC908679A36F02C07937C878CC8FFE292B779734F6807A1
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........)...6...9.......9...'...B...6...9...9...9...9.......X...6...9.......9...'...6.......B...&...B...6...9...9...)...J...6.......9...+...'...+...B.......X...6...9.......9...'...B...6...9...9...)...J...6.......9...+...'...)...B...6...9...B...).......X...6...9.......9...'...B.......6.......9...+...'.......B...X.*.6...9...9...9...........B.......6.......9...+...'...)...B...6...9.......9...'...6.......B...'...6.......B...&...B.......X...6...9.......9...'...B...6...9...9.......J...6...9...'...B...9...6.......9...+...'. .)...B...6.......9...+...'.!.)...B...6...9.......9...'.".6.......B...'.#.6.......B...'.$.6.......B...&...B.......X.......X...6...9.......9...'.%.B...6...9...9.&.....J...6...9.......9...'.'.B...6...9...9.(.....J....ignore_within_timeframe.tests_logic.tt_check: end.no_toastAtests_logic.tt_check: time of date is out of limit. No toast., higher limit ., lower limit *tests_logic.tt_check: current hour - .tt_higher_hour.tt_lower_hour.hour.*t.date.ignore_threshold_passed?tests
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2150
                                                                                                                                                                            Entropy (8bit):5.8901240226380915
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:USmjnzqGkwl85sHGX6lVwas7aeKCRMB52R7N3hWpL:U12UGuORaehk5ONx+L
                                                                                                                                                                            MD5:8842D40DEDEC7911CE6FCE164CBD02C0
                                                                                                                                                                            SHA1:8AA59AF52E797479B0ED72BE3B9ACA363360A2B2
                                                                                                                                                                            SHA-256:8A4F20A6DAD25234A22C3F19D87BAB56E18CA3A59507F945FE580A001B6FFBE1
                                                                                                                                                                            SHA-512:11C80C711E63A047046F0A8ECFEBA879E8B8EA097D255F19E8009EC6C1E4371CBF08A34AD8CCDD76E9072BA87084DBB6CCA4793D2C288BEE9CB2A830504BAC0A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ........$...6.......9...+...'...'...B...)...6...9...9...9...B.......X...6...9.......)...B.......6.......9...+...'...+...B.......X...6...9.......)...B.......6.......9...+...'...+...B.......X...6...9.......)...B.......6.......9...+...'...)...B...6...9.......'...B.......X...'...X...6...9...........B.......X...'...X.......6.......B...6...9...9...9...9.......X...'...6.......9...+...'...+...B.......X.).6...9.......9...'...B...6...9...9...9...B...6.......9.......B...'.......X...6.......9.......B.......'. .........6.......B...........'.!.6.......B...'.".....&...L...'.#.........6.......B...........'.!.6.......B...&...L....type=E.M.G.type=G.EscapeA..MD5Hash.utility#get_analytics_hashed_device_id.MiscUtils&make_type_tag: G type tag enabled.info.log.g_type_tag_enabled.5.edge.BrowserType.BrowserUtils.tostring.find.%d+.match.string.*Experiment.*Freemium.*Orphaned.bor.bit.IsSuiteInstalled.common_utils.utils.core.0.*Affid.GetOption.settings..........'...6...9.......'...B.......X...6...9.......'...B
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2030
                                                                                                                                                                            Entropy (8bit):5.596807579263866
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:fhO0Zf/+V+JJUh10pF/M1KsAwTh4Bdj5minH30vY3I+J:Q0nW0cUsABQiH/b
                                                                                                                                                                            MD5:6EE000A68CBB4BFB9D2E138103B6DD57
                                                                                                                                                                            SHA1:54A356A89FF249F9810081EC4D5681760AB0BDDE
                                                                                                                                                                            SHA-256:8B5185E2590714C3B30E2F1A4F9670441AB0E864E81E0013E6B707FDF9FA5225
                                                                                                                                                                            SHA-512:0FAC66C1D3E9889B06E8FF4C1BAA30867F062DA01097A3A44800BA34DEFBDE8A30DD06E9F1B9E227B9F4EBE3CB2CCE6A922C9DEFBB36668147F485A9A130DFC4
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.LJ..........P6.......B...6...9.......9...'.......&...B...6...6...9...9.......9...+...-.......)...B...A.......X...6...9.......9...'.......&...B...K...6...9...B...6...9...9.......9...+...-...........B...6...6...9...9.......9...+...-.......)...B...A.......X...6...9...9.......9...+...-...........B...6...9.......9...'.......&...B...K.......)calc_on_browser_start: end. Browser .SetBrowserSetting.time.os=calc_on_browser_start: session started already. Browser .GetBrowserSetting.BrowserUtils.utils.tonumber+calc_on_browser_start: start. Browser .info.log.core.tostring...........6.......B...6...9.......9...'.......&...B...6...6...9...9.......9...+...-.......)...B...A.......X...6...9.......9...'.......&...B...K...6...9...B...!...6...9...9.......9...+...-.......)...B...6...6...9...9.......9...+...-.......)...B...A... ...6...9...9.......9...+...-...........B...6...6...9...9.......9...+...-.......)...B...A...6...6.......9...+...'.......B...A...6...9...!...6...9...9...9...#...B...6...9...!...6...9..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4541672
                                                                                                                                                                            Entropy (8bit):6.544760213696757
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:vmZNRHnBao2l7VKSm+iKQB0Aulh8fGLDXVL5rtORei/vV+VnW8l+Homj1vy4iYuw:CB+j3lh8eLDXVd6znfIeuegdk
                                                                                                                                                                            MD5:9CD903BA6980812F23811F8622DF893F
                                                                                                                                                                            SHA1:29A00C25A8624935B31309446AF15ACDAE463477
                                                                                                                                                                            SHA-256:32EB612688981D2CBB469F54AC0F8CBD7F70698872269582DA9D5C7F7150B416
                                                                                                                                                                            SHA-512:13567F64002D9F1080F6D72C4FD21700CEB44084F3E3F719C4D5AA5C3BF9DF22C989BC10B55DA3734F9AFF43DB72EE1F5FC2DA5DBEBC3EEDA81610475E471000
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$........E#..+p..+p..+p..qe.+p&./q..+p&.(q..+p&..q..+p...q..+pF..q..+p.(q..+p.-q..+pE./q..+p..+p..+p.*q..+p..*pj.+p./q..+pH./q..+pqv.q..+p.."q..+p..+q..+p...p..+p..)q..+pRich..+p................PE..d....XWg.........." ...$.(4.........P1,......................................0G.......E...`A.........................................C@.<....R@.......F.X.....D..x....D.......F.Ph..0.<.p.....................<.(.....9.@............@4..... =@......................text...<'4......(4................. ..`.rdata..~5...@4..6...,4.............@..@.data...,.....@..:...b@.............@....pdata...x....D..z....A.............@..@.didat..@.....F.......D.............@..._RDATA..\.....F.......D.............@..@.rsrc...X.....F.......D.............@..@.reloc..Ph....F..j....D.............@..B................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1785632
                                                                                                                                                                            Entropy (8bit):7.942738490429967
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:NSI3oiG08swq0fhLy0fEg6IGJIlq+S6O8:NSCG08sw3YyEg6IiYq8
                                                                                                                                                                            MD5:080FF9263F39F62DBDAE513C66B7B9D2
                                                                                                                                                                            SHA1:32DF585659003B10E7ED769932727D53480B9C34
                                                                                                                                                                            SHA-256:326CBB6CD7D6062B850337A50200C805CDCBF59A6E05818990E6352AC68B4935
                                                                                                                                                                            SHA-512:7A7A21D05FA8D2562A0598B254A25A49099AFA5EBD072DE391D9EE8DC30F57CD2830816C8A2B5997AE74C0B9924185334B15EC5CC3587B74C2E7957296E6E02B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......I.c......................................................9..............................................[...........Rich............................PE..L....R/`.....................t.......t............@..........................P............@.................................l)..x....`..,............... +...0..p.......T...................<...........@...............H....(..`....................text.../........................... ..`.rdata.............................@..@.data...\....@.......(..............@....rsrc...,....`.......2..............@..@.reloc..p....0......................@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):27336
                                                                                                                                                                            Entropy (8bit):5.57578184442293
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:384:UBhBT/W58RrB3M65lWHqXPDenaKb6ki29d1ikN42niSJIVE8E9VF0NyJlP:uBr3M65Kr22Psu/2ExP
                                                                                                                                                                            MD5:5E8BFBB3A3DC1E55C7D024E6C1ED51C5
                                                                                                                                                                            SHA1:5676951B6835B3426365F73A5FAF398BA705B611
                                                                                                                                                                            SHA-256:C5C3A970925D4BA60CE859F90ED37A206BD658B88F852BAC3B182BED75A9C9ED
                                                                                                                                                                            SHA-512:F14CDB2AF7B6FCAA7A3C675D512871AF019B83764E848B23EA765EB3B702BC36BF56B9D2D9B93898354F893F7819A706798B1EC3229559770159992C8E3F54FD
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Q=.0S..0S..0S..O...0S..OQ..0S.Rich.0S.........PE..L....XWg...........!...$.....>...............................................`......._....@.......................................... ..\:...........@...*..............p............................................................................rdata..x...........................@..@.rsrc...\:... ...<..................@..@.............XWg........o................XWg.........................XWg........l................XWg............................................RSDS../.|.zH.?.iDv......C:\jenkins\workspace\ebAdvisor_WABinary_release_4.1.1\build\Win32\Release\Resource.pdb......................GCTL....p....rdata..p........rdata$voltmd............rdata$zzzdbg.... ..`....rsrc$01....`!.......rsrc$02....................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):926176
                                                                                                                                                                            Entropy (8bit):6.441613709559614
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12288:kt3osXFOyxMZettus7ZuOE0KQsX/N1atFNRGpLSb0+JV/juMxqOAgzhlt21koJJO:kNFgtqntVbuuqOAgzD0yAJ1vo
                                                                                                                                                                            MD5:F7C7039D19E16D05B6194D74E128DFE4
                                                                                                                                                                            SHA1:177F53976B4C50DAD0046D9CDBAB9DDC8D605302
                                                                                                                                                                            SHA-256:B3B36669F7A96042A822BC563BD7D7A45D3F48F2724CB2B3E111ECB188B35ADC
                                                                                                                                                                            SHA-512:E0EAE14E0CE552D50C05C63232A2CB687144DE6C14CE56BA417F2A648E7D64B0B543847534543147C4738F17689962ED322EE966EF738EC19FC440AFF3456716
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........i..i..i.....i....'i.....i.7...i.7...i.7...i.....i.....i..i..h.....i...(..i.....i.Rich.i.................PE..d....YWg.........."....$.`..........Pv.........@....................................A.....`.................................................P...........p................I..........`...p.......................(.......@............p.. ...8........................text...L_.......`.................. ..`.rdata...p...p...r...d..............@..@.data............H..................@....pdata..............................@..@.didat..............................@..._RDATA..\...........................@..@.rsrc...p...........................@..@.reloc..............................@..B........................................................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1976248
                                                                                                                                                                            Entropy (8bit):6.542602737128031
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24576:HSvhHKsJFPGimmqxvsH4CYWI4dq9kuuNCykGo9Fcx1KfhEkSwJ2a5BATvEsIkut:YhDFPDmm+NjiuLGo9FxfvnJ2+2TxzQ
                                                                                                                                                                            MD5:A22A9096CB688D8C18EAFBEB7C939B3C
                                                                                                                                                                            SHA1:4A4F617248784355F03B25C1902655B034426BE9
                                                                                                                                                                            SHA-256:9429B653F74FE7B130DBDF9FCBF0604D3A65F46F7DD62EB6A7F819EAE4425C15
                                                                                                                                                                            SHA-512:075A2DF44E2DDCE200A6E01AC4A2E8111163541CEF224940E4DE36C79BC6D943DC0D0EB2593773609A6379BD4041B28F82E15FA2248057614E8A8261776C2453
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.........B.I.,KI.,KI.,K..)J..,K..(JG.,K../JC.,K../JD.,K..(J_.,K..-JZ.,K..)J%.,K..(J[.,KI.-K2.,K..(JH.,KS.%J..,KS.,JH.,KS..KH.,KS..JH.,KRichI.,K........................PE..d...qYWg.........." ...$.....v.......................................................x....`A........................................."..T...."..........h....p...........m.......$..$...p.......................(....W..@...............P...x!..@....................text...,........................... ..`.rdata..2<.......>..................@..@.data....$...@.......$..............@....pdata.......p......................@..@.didat..0....`......................@..._RDATA..\....p......................@..@.rsrc...h...........................@..@.reloc...$.......&..................@..B................................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):4248888
                                                                                                                                                                            Entropy (8bit):6.51552548631765
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:cGy5W9wQakZKTrZICtWT/kCdT++jhpATJHqb2dyyr5certCHev7WYrLw:h2O0ltSdcHqUychCHcY
                                                                                                                                                                            MD5:E04ADD7D426AEFD853FEDADAD1B77C81
                                                                                                                                                                            SHA1:B2BE74907C18B4595AC59DE8C5FFB26BBEF6C05B
                                                                                                                                                                            SHA-256:807A1C4AFAB2337C2E741EF2449C3B273583183B12FC7EC6311D72FB5C49CEF5
                                                                                                                                                                            SHA-512:CA579755FD707F0929440D918DA95149B6A8B8BB62F79F58F75BA0120A9D570245374B5F5392C44B5C92F8A434803362A40BD6B579ADD1CA6E355BE9B40A036A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.......uU.14..14..14..zL...4...J..!4...J..;4...J..G4.....94..+K..04..zL..<4..zL..*4...A..#4..zL..(4...A..04...A..%4..14...5.....`4..+K...4..+K..04..+Ks.04..+K..04..Rich14..........PE..d....XWg.........." ...$../...........(.......................................C.......A...`A..........................................;.P...P.;.......C.X.....@..P....@.8.....C..t....8.p.....................8.(... Z5.@............./.`.....;......................text...../......./................. ..`.rdata..*0..../..2..../.............@..@.data.........;.......;.............@....pdata...P....@..R...J=.............@..@.didat........B.......?.............@..._RDATA..\.....B.......?.............@..@.rsrc...X.....C.......?.............@..@.reloc...t....C..v....?.............@..B................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):904488
                                                                                                                                                                            Entropy (8bit):6.4427020541085485
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12288:4/fhi2sqy1ccu9jbG5QJ0zJERddh6y/m1Qdg8dvNVll86NH7oWLC3ftPZ+o6MC9Q:gpihoBvjlllNH7oW+vVs4C9thc
                                                                                                                                                                            MD5:C75ACD4F363FEC78A32439364E82021C
                                                                                                                                                                            SHA1:4ACD52C71D6CE05E42CC92439DF5D3F7BFA7C35B
                                                                                                                                                                            SHA-256:40DFF9FE25E79607D897598995FF7127CEF17826B7E55795C1953B6520524C37
                                                                                                                                                                            SHA-512:39E9305D4686AC1E5995B0EEC6C40922D428B0732D71763FFD5934A295B498315216D2F55AD0543CB7E604625F01DF9A089A694533C01CD9448A24A7A9B951FE
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........i..i..i.....i....8i.....i.(...i.(...i.(...i.....i.....i..i..h.....i...(..i.....i.Rich.i.................PE..d....ZWg.........."....$. ..........._.........@.............................p.......b....`.........................................................@..p...............(I...P..........p.......................(...p...@............0..............................text............ .................. ..`.rdata...h...0...j...$..............@..@.data............F..................@....pdata..............................@..@.didat....... .......f..............@..._RDATA..\....0.......h..............@..@.rsrc...p....@.......j..............@..@.reloc.......P.......n..............@..B........................................................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5846872
                                                                                                                                                                            Entropy (8bit):6.5127665295159405
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:98304:vewckSLoQ9RmaHxsLDXuUnnX3qI1JQ72QQqVU:WwckSFbmaRsLDXu0nXa8++qVU
                                                                                                                                                                            MD5:198765D6A4572DA3AA27FB5586F983FC
                                                                                                                                                                            SHA1:C6585ED626337107F5902CC9BCD790B452C3196D
                                                                                                                                                                            SHA-256:3309A24532E7814A46B593D237CD0EDB96FE29F479D38E0C265CE08ED2F81E97
                                                                                                                                                                            SHA-512:FFBE8931EAECB7803A36DDB566B1896BB8D2B9C517AEA8E7D642E0FD495E1397EAC307C1A6870073B38AD4ED4A5BDF2B231135E3CC69D193D184A516D609B83F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$..........V....................G.......G.......G.......................$.......................).......'........B........................................,.............Rich....................PE..d....ZWg.........." ...$.xB.........P.8.......................................\......4Z...`A..........................................Q.<...,.R.@.....[.P....@X..^...FX.X.....[......M.p.....................M.(... .I.@.............B.......Q......................text....vB......xB................. ..`.rdata..Z.....B......|B.............@..@.data........@R......"R.............@....pdata...^...@X..`...:T.............@..@.didat..p.....[.......W.............@..._RDATA..\.....[.......W.............@..@.rsrc...P.....[.......W.............@..@.reloc.......[.......W.............@..B........................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2998832
                                                                                                                                                                            Entropy (8bit):6.549731823097714
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24576:0b8E4leMHenRm5Xht5Ljzjj5EIGEjwRiNuoWV6Oh0lhSMXlgQtLoUA405SwFzSKH:LE4le9RC5LjzvAEjN7W4bDdGzSKguZbT
                                                                                                                                                                            MD5:3AA2D9539FE8D506B25EB3E3122BF191
                                                                                                                                                                            SHA1:7A8832272DCE3E8BC37D13B3735F94EAF71DD256
                                                                                                                                                                            SHA-256:36CA61C3EEB21785BB61C5C969D638377B6E1EC0898FFF5794AD67999C179B7C
                                                                                                                                                                            SHA-512:CE2EF98F134EBC741EC1C4431A9399D46C953F568213BE11037D52F1C1D4D275DF24EE182B1914F71550FE7F570A32CDF2215140B514E7F258976A837E44678D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.........aw...$...$...$...%..$...%-..$P..%..$P..%...$P..%...$...%...$...%..$...%..$...$...$>..%...$...$...$...%...$...%...$...$...$...$...$...%...$Rich...$........................PE..d....YWg.........."....$.......................@..........................................`...........................................$.(.....$......p'.8.....%.PW...2-.0....`..h/....!.p.....................!.(...@...@.....................#. ....................text....~.......................... ..`.rdata..............................@..@.data...4....@$......*$.............@....pdata..PW....%..X....$.............@..@.didat.......P'.......&.............@..._RDATA..\....`'.......&.............@..@.rsrc...8....p'.......&.............@..@.reloc..h/...`...0....-.............@..B................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2751968
                                                                                                                                                                            Entropy (8bit):6.543746013265706
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:mNSSVGmcW/5GNyfDpK8CMjnlQTvvcmkT9zO1XqS9hzKtkdbCn2Go:ehGmmKphCMjnlYvCS99K9nw
                                                                                                                                                                            MD5:9A4C26D4AA627CA1C69D40C9091B4A74
                                                                                                                                                                            SHA1:686E3ED1EF9910487492EB99F686FB8463FC2F79
                                                                                                                                                                            SHA-256:DAB9D341F72C74C9EB35803119C96AFAD4AFAC8F312D84E2A077944CADF1C41F
                                                                                                                                                                            SHA-512:1F2ADEC01039FBDD2B80A0001758B3D040C07912CC2BF41701DDB9C0AC49E34BEBD5C21C9EA03865639B1BCF596B3000D26AA033EA0245AF8DD0EA5A66E14773
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.......x.m.<p..<p..<p..w...+p..w....p...../p.....0p.....Dp..w....p..w...+p..&....p..<p..=p......op..<p...q..&...Lp..&...=p..&...=p..<p..=p..&...=p..Rich<p..........................PE..d...TWWg.........."....$.l..........@..........@..............................*.....c.*...`...........................................%.$....%.......(......0'..F...v)......p*..)..0:#.p....................;#.(....E!.@...............x...p{%......................text...nk.......l.................. ..`.rdata.../.......0...p..............@..@.data....s....%.......%.............@....pdata...F...0'..H...:&.............@..@.didat........(.......'.............@..._RDATA..\.....(.......'.............@..@.rsrc.........(.......'.............@..@.reloc...)...p*..*...L).............@..B................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):9912
                                                                                                                                                                            Entropy (8bit):3.922084693018274
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:192:/QL4RLAq8F9BeGgTcNTRCNPx6RlrC052ic8:P1IX2X8
                                                                                                                                                                            MD5:439B5C6870BF60683B2108830F0C0EE8
                                                                                                                                                                            SHA1:6D8686ADBBD7EDB119EE26FCAD89C7A33FB73360
                                                                                                                                                                            SHA-256:9A17EA1B5BCFC3C587C42A948D492A9BB862592ED557C6AA4208093A102EE84A
                                                                                                                                                                            SHA-512:992E9A7991F51AC017F508E03E6F71C94F65BFAEFC47FB5FCDBFE3AEE2DBD6715B88C97623DC7AC1417C6799E2BF7568A56D5013D68508BA0FDCB9A50227BC41
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:/* Uninstaller UI */..(function (wa, $) {.. var ui = wa.UI = wa.UI || {},.. _instrument = wa.Utils.Instrument,.. _lrt = wa.Utils.Lang.ResType,.. _l = wa.Utils.Lang(_lrt.UNINSTALL).get,.. _core = wa.Core,.. _window = _core.Window,.. _webAdvisor = _core.WebAdvisor,.. _productNameHtml = _webAdvisor.getProductNameHtml(),.. _data = _core.data;.... ui.Uninstaller = function () {.. var checkProgressInterval,.. checkUpdaterInterval,.. checkUpdaterNumRetries ,.. buttonOkId = "wa-uninstaller-button-ok",.. buttonCancelId = "wa-uninstaller-button-cancel",.. buttonCancelCss = "wa-button cancel",.. buttonOkCss = "wa-button ok",.. version = _webAdvisor.getVersion(),.. el = {.. $header: $("#wa-uninstaller-header"),.. $content: $("#wa-uninstaller-content"),.. $footer: $("#wa-uninstaller-footer")..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):3558
                                                                                                                                                                            Entropy (8bit):4.798796773500084
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:96:UKQqFbbgRjujt6whhzIr3EfygNkd9ZcRx1+zRMJ9NDG4lzDU8:FxFb8Rjujt6wr8r3EqgNkFcRx1+zRMJZ
                                                                                                                                                                            MD5:F63DD51791AA934B2F6D65EA309C24CA
                                                                                                                                                                            SHA1:ABBD3F7BCA2A16B227DE767B8A2BDFE5BCDBAD3A
                                                                                                                                                                            SHA-256:C2E9C443AAB40E56EBBFDC8314C9395B621C400598B636023D39D2856FCBAD27
                                                                                                                                                                            SHA-512:067054925488064E54A17E4EC92D45606ED8C41BAF169C6758E94B47CCD2CD33E8CF39B877FF912B1A389AC0483DD9320E99A3C4F8F8E727421F09E510AB2A03
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:body {.. background-color: #ffffff;.. overflow: hidden;..}....#wa-uninstaller {.. width: 600px;.. height: 473px;.. border: 1px solid #BAC6EA;..}....#wa-uninstaller-header {.. height: 48px;.. display: table;.. width: 100%;.. background-color: #F5F6FA;.. border-bottom: 1px solid #BBC7E7;..}.... #wa-uninstaller-header > div {.. display: table-cell;.. }.... #wa-uninstaller-header .title {.. vertical-align: middle;.. }....#wa-uninstaller-header-close {.. float: right;.. position: relative;.. top: 12px;.. right: 12px;.. cursor: pointer;..}......#wa-uninstaller-content {.. margin: 24px 30px 0px 30px;.. color: #404040;.. font-size: 12px;.. height: 67%;..}....#wa-uninstaller-start h3 {.. font-size: 16px;.. font-weight: bold;.. color: #53565A;.. margin-bottom: 5px;..}..#wa-uninstaller-start h5 {.. font-size: 14px;.. font-weight: 400;.. color: #53565A;.. margin: 0px;..}....#wa-uninstaller-st
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1304
                                                                                                                                                                            Entropy (8bit):5.275006435536822
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:csYzTEL0GNVMz7jVMz7EVMz7VMz/VMzlLVMCdLG7OLG3LGt1LGzAdpKJz/To:3OTEL0Sv265iCdLG6LG3LGt1LGzArKds
                                                                                                                                                                            MD5:FCD0694DAA6D877837A41C6B7990F0F3
                                                                                                                                                                            SHA1:D43BB82B88775AAC31939AED1C94880283353AD5
                                                                                                                                                                            SHA-256:A9A6391E0C62AE8A4B5B4849D53E1EFD6FA9928AAABBADA99EC64F78545AF4F9
                                                                                                                                                                            SHA-512:4CD94146C2A594944A93C25F0128E244196B99895DAF15E5FC2CC40A52C49F779095D364143CB8203816597E704E12CDA955DB72E1A0DEC16FC697C07DA82EFB
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:.<html>..<head>.. <title>WebAdvisor</title>.. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />.. <meta http-equiv="X-UA-Compatible" content="IE=11" />.. <link type="text/css" rel="stylesheet" href="wacore:mfw\\packages\\builtin\\wa-common.css" />.. <link type="text/css" rel="stylesheet" href="wacore:wa-uninstall.css" />.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\jquery-1.9.0.min.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-uninstall-#loc#.js"></script>.. <script type="text/javascript" src="wacore:jslang\\wa-res-shared-#loc#.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-utils.js"></script>.. <script type="text/javascript" src="wacore:mfw\\packages\\builtin\\wa-core.js"></script>.. <script type="text/javascript" src="wacore:wa-ui-uninstall.js"></script>..</head>..<body>.. <div id="wa-uninstaller">.. <div id="wa-uninstaller-header
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:MS Windows icon resource - 11 icons, 48x48, 16 colors, 4 bits/pixel, 32x32, 16 colors, 4 bits/pixel
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):99892
                                                                                                                                                                            Entropy (8bit):3.9749743269785345
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:768:JLBqG5eVRjB/jZRj0t4kgU1l50AIDP88+2Y:JLBh5eWgU1B8+2Y
                                                                                                                                                                            MD5:236FC5ABB597615A608DAB7BE98D5FBC
                                                                                                                                                                            SHA1:18D3D1CF56898B264A24DE24DC13E4B9B7EED768
                                                                                                                                                                            SHA-256:06ADAB20CB028B5DC61762691E8C8A6157EB1199526F7C773338B9BF51BD63C6
                                                                                                                                                                            SHA-512:155766AA5659BB9E298AEDE4064832168002EEDEE836710C2259446FC35437AD70C04454DEF2D9EB40A83A029351EA1726D65ACBDB8FE8217C016FD4986F7F4E
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:......00......h....... ......................(.......00.............. ......................h...~"........ .n....'........ .(...TC..00.... ..%..|K.. .... .....$q........ .h......(...0...`...........................................................................................................p......................9Yx...................yyy9Y..................yyY.yy57...............s.....y.yy.............y9Y9Y5..9y.w.............9yyy.....................y.9qy....yy5............yyy.yqy.y.Y9yp...........y.xy....9yyY5....yY9.y.9.......yq....p....9yyqqyp......y.yy5.p...YyY9..p.......yy9Y.Y.........p..............p...Yyy.p...............p...99Yw............y9S.0...................yy..p....yY8............yyS.p...y9y.............y1......y.Y8............yYy.p...................y9yyp...................yyY.p...yyy.............y9yq....9Y.w............yyY9p...................y9yYp...................yyY9p...................y9q.....................yyYyp.......................p.............P.....
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):676
                                                                                                                                                                            Entropy (8bit):4.824937383394461
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:ShnHvOaKiUlLAjxOw+aJ/0u74odpE5vvi7B4BLpMZhNl/PKqlKuV:ShnPOaKioAjxEaN94MpEJq7SBlMZ79oi
                                                                                                                                                                            MD5:D4525EEF75A5ED31DD1463E94E63EE32
                                                                                                                                                                            SHA1:9D2B35EF3800BF1CD34F6AFE03EDF1B02F75B7EA
                                                                                                                                                                            SHA-256:E8BE10CE45725068D0B6F7B90C1F86C90B0F949B9FB4229CF9EE4A82DF9980E8
                                                                                                                                                                            SHA-512:E92548F4F2B49138BEFE5800DD459F0A9DB3062B32661D98BD9E393D2510E9B41822ABCA3FDF179A7EBCA6B8899E0634B668FDDD1D1A1E67D8A5876F11C85D18
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "name": "siteadvisor.mcafee.chrome.extension",.. "description": "Chrome Native Messaging API Host",.. "path": "BrowserHost.exe",.. "type": "stdio",.. "allowed_origins": [.. "chrome-extension://fheoggkfdfchfphceeifdbepaooicaho/",.. "chrome-extension://klekeajafkkpokaofllcadenjdckhinm/",.. "chrome-extension://enppghjcblldgigemljohkgpcompnjgh/",.. "chrome-extension://mfifoblohohmjoaiclakcbicbeklikgl/",.. "chrome-extension://kanjcmmieblbpbihaafnedamppkhfadn/",.. "chrome-extension://jhnkplodgdopckiblgedcpoidpgcdbfi/",.. "chrome-extension://bgdpakbfhblhpnbhhajplljnioenlpnk/",.. "chrome-extension://hkflippjghmgogabcfmijhamoimhapkh/".. ]..}..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):332
                                                                                                                                                                            Entropy (8bit):5.199984426997364
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:3FHWb4FPe8e/ihvqbRVnRUvFFwF1pl8q96DJqHmAf2U2LhGdFm/dwwuEYOi:1Hi7Gv6iK1re/3dwwBi
                                                                                                                                                                            MD5:ED06108D883C1FFED6910F55AC4A5A3D
                                                                                                                                                                            SHA1:7974E1658801A128A23C0B2737545F2AB5C5F3F2
                                                                                                                                                                            SHA-256:B659E0167E9CEBFB8A031F259D840577B3897ABF3E91C2ABBE3E8F947598FF47
                                                                                                                                                                            SHA-512:075F93DE9A8065B939BD947D23F2D3F1EA793AFA492CA030B0B24C4FB223F85846A37DF908ED5DD08987AFFA60AB3ECB6ACA512C777F05E9DD7849976868D6E8
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "name": "siteadvisor.mcafee.chrome.extension",.. "description": "Firefox Native Messaging Host",.. "path": "BrowserHost.exe",.. "type": "stdio",.. "allowed_extensions": [.. "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}",.. "{DFC8025B-FC38-42B1-9E3A-DFA474F33D93}",.. "{C1DB8E20-28BB-4222-8020-FB40187BA1A6}".. ].. }
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):675
                                                                                                                                                                            Entropy (8bit):4.830153549273225
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12:JaWhnHvOaKiUlLAjxOw+aJ/0u74odpE5vvi7B4BLpMZhNl/PKqlKuV:JaWhnPOaKioAjxEaN94MpEJq7SBlMZ7R
                                                                                                                                                                            MD5:B09DB140B1A6360DC1D7F6BCF9D85B22
                                                                                                                                                                            SHA1:09839EFA3B9055D51BFE566E9F5F8B7529B085D2
                                                                                                                                                                            SHA-256:395D1298C7E5A9D6A7F45A0A84F89A0652DE890F202812FE3EF0DA830F24A98C
                                                                                                                                                                            SHA-512:F1539E728D9F7DB8870CE58D2B4C49431DB288DD4D26D3C3D52374BB1B856001E8BF541650CF77813308060EDC57939E35E0B21D99EE18F0D2681FE052E91145
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "name": "webadvisor.mcafee.chrome.extension",.. "description": "Chrome Native Messaging API Host",.. "path": "BrowserHost.exe",.. "type": "stdio",.. "allowed_origins": [.. "chrome-extension://fheoggkfdfchfphceeifdbepaooicaho/",.. "chrome-extension://klekeajafkkpokaofllcadenjdckhinm/",.. "chrome-extension://enppghjcblldgigemljohkgpcompnjgh/",.. "chrome-extension://mfifoblohohmjoaiclakcbicbeklikgl/",.. "chrome-extension://kanjcmmieblbpbihaafnedamppkhfadn/",.. "chrome-extension://jhnkplodgdopckiblgedcpoidpgcdbfi/",.. "chrome-extension://bgdpakbfhblhpnbhhajplljnioenlpnk/",.. "chrome-extension://hkflippjghmgogabcfmijhamoimhapkh/".. ]..}..
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):331
                                                                                                                                                                            Entropy (8bit):5.221057694206649
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:3FHWEas4FPe8e/ihvqbRVnRUvFFwF1pl8q96DJqHmAf2U2LhGdFm/dwwuEYOi:1HZaW7Gv6iK1re/3dwwBi
                                                                                                                                                                            MD5:49D8FD2B7CDD52D1CD2F2F3F019A597D
                                                                                                                                                                            SHA1:62548306CE140C5336570EB02D4AF566121CFC65
                                                                                                                                                                            SHA-256:B114F82CBCB910A1F282E823266801468571F3F2DB9802AFFD3C758F933CE9C2
                                                                                                                                                                            SHA-512:3F9FA7C2D56A3BA12690D1D2107FC12D66CC6294D0C1A5003221E4B7A6C6481197BFD05CDEFFDE09F2D2AEF55132CE8CBEB40953AD25A96BF40675907FE68B16
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{.. "name": "webadvisor.mcafee.chrome.extension",.. "description": "Firefox Native Messaging Host",.. "path": "BrowserHost.exe",.. "type": "stdio",.. "allowed_extensions": [.. "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}",.. "{DFC8025B-FC38-42B1-9E3A-DFA474F33D93}",.. "{C1DB8E20-28BB-4222-8020-FB40187BA1A6}".. ].. }
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):646112
                                                                                                                                                                            Entropy (8bit):6.615158378781579
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12288:e1btYO+v7ftQNF8XpEB3iePkNEoj+rgSfshPyMjEmjM0ZQ1w:0b3g4oj+pMjEmw0OS
                                                                                                                                                                            MD5:E771F356A7E30D21457CDA44836F8DBB
                                                                                                                                                                            SHA1:99B8069134AFB4471D42721CD01AE6E430E473B6
                                                                                                                                                                            SHA-256:D4C1E8B473B11BE236DFC772A694F1C2B360A844613F7FB2B9FCD5ADD761B056
                                                                                                                                                                            SHA-512:90600A4E49097668A5B7C4792FECE1D20584E16BEC0C2950CA8626529CD6F61F6281154B309246C62168805A7AC3B7881F51AC783421B9178218F7487DBEB7D5
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................P...........!..L.!This program cannot be run in DOS mode....$.......#..~g.-g.-g.-<..,h.-<..,..-V.}-e.-..}-f.-5..,?.-5..,w.-5..,~.-..,f.-<..,..-<..,w.-s..,e.-..,k.-...,h.-g.-B.-..K-b.-.,f.-.,..-...,j.-...,f.-...-f.-...,f.-Richg.-................PE..L...x1.e...........!......................... ......................................e<....@.........................P.......(........p..@................?.......^...A..p...................@C......pB..@............ ...............................text............................... ..`.rdata..V.... ......................@..@.data....Y.......@..................@....rsrc...@....p.......8..............@..@.reloc...^.......`...<..............@..B........................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):804776
                                                                                                                                                                            Entropy (8bit):6.352926794265583
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:12288:ESMUeSJFVwoykQGh5YHWSGBjfWeVoNErPgdo:ESbRJFBykQ8YHWvFWeVKErPg
                                                                                                                                                                            MD5:25EBD76F4F56BF3791735C1D5E539577
                                                                                                                                                                            SHA1:B4A89100A510E9BE58446F74300C34536A9EFD29
                                                                                                                                                                            SHA-256:EAD25990DBD86BCDB82A61921DBC19356AE9740E75F9B10767DD99AEB09BCA50
                                                                                                                                                                            SHA-512:D416B3FCA1CB7E2D04A5826D2DC2DE0DEC3F4663636C6758AA399FB7E9D26CCAAC3E5F6E19F159695A4AEE02C13B7263818195A51CF6C92785A6364CDDF9474C
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................P...........!..L.!This program cannot be run in DOS mode....$.........Wm.9>.9>.9>..:?.9>..<?P.9>...>.9>..<?..9>..=?..9>..:?.9>S.<?.9>..=?..9>..8?..9>..8?.9>V.<?.9>r.<?.9>.8>.9>3].>.9>y.=?.9>y.<?..9>).0?.9>).9?.9>)..>.9>).;?.9>Rich.9>........................PE..d...R1.e.........." ......................................................................`.................................................x........P..@........x.......E...`...... ...p.......................(.......8............0..(............................text............................... ..`.rdata.. ....0......................@..@.data...Tt...@...L..."..............@....pdata...x.......z...n..............@..@_RDATA.......@......................@..@.rsrc...@....P......................@..@.reloc.......`......................@..B........................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\uihost.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:modified
                                                                                                                                                                            Size (bytes):280
                                                                                                                                                                            Entropy (8bit):5.243093782568966
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:rtRtVT4tR1Rbz6RM0RcRJ1VGuxbtRtVTAR1Rbz6RM0RcRJ1VGugAR3:ZRtVcRbbs8J1VxJRtV0Rbbs8J1V33
                                                                                                                                                                            MD5:8A73FD033CB2CA5665A166AB09298C0A
                                                                                                                                                                            SHA1:ED910A8788A056F7963BCBEA85223A2B423CC9EC
                                                                                                                                                                            SHA-256:83A7F001DC2148CDA1EC6F49ED3D68029727056BDB5E6F76FD0A6CAF73D353D4
                                                                                                                                                                            SHA-512:0371B6EB82F508A416B41019606B95B18E5B6961F0A488811D4E992683F9B74092E4D79B69ECD77894BFBF8F6BDC44CFB6A1F731454E65E3D6EB1B6B4B2E8924
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:[ERR][20241227 06:54:54.775][wps_utils_scriptable.cpp@58]: Failed to get value of WPS setting CloudSDK.cache: GET /subscription/v3/details..[ERR][20241227 06:54:54.780][wps_utils_scriptable.cpp@58]: Failed to get value of WPS setting CloudSDK.cache: GET /subscription/v1/details..
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):236
                                                                                                                                                                            Entropy (8bit):5.014401872227007
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:rtRtVTRtER1Rbz6RM0Rcz468tRtVTmW4tER1Rbz6RM0Rcz46I:ZRtVNtERbbsZtRtVYERbbsZz
                                                                                                                                                                            MD5:54BDE59CE466F48553B8C202028344DA
                                                                                                                                                                            SHA1:4C7C5B0668CC00F366383378656D4750386DDF7C
                                                                                                                                                                            SHA-256:665984F4B72EB491B75669CD5F60CCE22C8960AF21029A6BC2C7931C2998E089
                                                                                                                                                                            SHA-512:2289E9B11357B18D18DC4D057AE2A0B2EE0074A70B11E93616856C47065AA14785562007D6EB899E1194CED492B76B019F9FEAFFE125F5B8257854F34E04DA84
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:[ERR][20241227 06:55:03.237][wps_utils_scriptable.cpp@58]: Failed to get value of WPS setting ai.audio.opt_in.status..[ERR][20241227 06:55:03.243][wps_utils_scriptable.cpp@58]: Failed to get value of WPS setting ai.audio.opt_in.status..
                                                                                                                                                                            Process:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1362
                                                                                                                                                                            Entropy (8bit):4.932188287453056
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:PM4rt5bnSrtJeMrtgJrt14yrtv9rtZMUrt2IBrty6rtZnrtUsM8rt0yBrtbMNrtp:k4ZpSZ/ZSZ9ZFZZHZdBZ7ZZZnM8ZLZby
                                                                                                                                                                            MD5:166ED944DC90A391DDD53CCD92A3B28A
                                                                                                                                                                            SHA1:D51D1F78FBAD54356574B935E1775406C4984407
                                                                                                                                                                            SHA-256:F02B0BC4CF1A533A96F35B5D4E07144DAC95D2E681021CC7F7A89526CA3D67D1
                                                                                                                                                                            SHA-512:DC22AD53481A1498F602216EB6878DCB2C403935979C030831E2D817BBDF6627C082FA1E26A749138A1CA632F3F4F234EBEB301F4D9DF4CB7EFEBCDD161E5133
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:[ERR][20241227 06:54:52.104][ProcessUtils.cpp@186]: Failed to open process with id 0. Error 87..[ERR][20241227 06:54:52.110][ProcessUtils.cpp@186]: Failed to open process with id 4. Error 5..[ERR][20241227 06:54:52.115][ProcessUtils.cpp@186]: Failed to open process with id 92. Error 5..[ERR][20241227 06:54:52.120][ProcessUtils.cpp@186]: Failed to open process with id 332. Error 5..[ERR][20241227 06:54:52.122][ProcessUtils.cpp@186]: Failed to open process with id 420. Error 5..[ERR][20241227 06:54:52.124][ProcessUtils.cpp@186]: Failed to open process with id 496. Error 5..[ERR][20241227 06:54:52.127][ProcessUtils.cpp@186]: Failed to open process with id 504. Error 5..[ERR][20241227 06:54:52.129][ProcessUtils.cpp@186]: Failed to open process with id 632. Error 5..[ERR][20241227 06:54:52.132][ProcessUtils.cpp@186]: Failed to open process with id 1584. Error 5..[ERR][20241227 06:54:52.139][ProcessUtils.cpp@186]: Failed to open process with id 3512. Error 5..[ERR][20241227 06:54:52.143][Pro
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):212
                                                                                                                                                                            Entropy (8bit):5.122285207485882
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:rtRtVTeyk2JM0RG0DKhSnO1tRtVTPawZVjwOrADGq:ZRtVSyk2JTDFnOHRtVbNrjhroZ
                                                                                                                                                                            MD5:7472CDBA3B78BA6CEE286ADAA36167F8
                                                                                                                                                                            SHA1:7F5F58564F69E8B8631AE4E4A88427855BE30CC1
                                                                                                                                                                            SHA-256:01A8647DBEE1E5B16BC2CFF063BEB3E324EF9F6075F05D01C031915E1491EE52
                                                                                                                                                                            SHA-512:38B8F04569E95E3A951B86275C385CCD878875A4A902FDA8967600B647C5986318DDF0B429C5927A7F279966E45CFE36AAB020BD08421954CAC775D86290373D
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:[ERR][20241227 06:53:23.712][ProcessUtils.cpp@210]: Failed to get executable filename for process with id 4048. Error 31..[ERR][20241227 06:53:53.199][HttpsDownloadFile.cpp@200]: Unable to open HTTP transaction..
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe
                                                                                                                                                                            File Type:Certificate, Version=3
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1398
                                                                                                                                                                            Entropy (8bit):7.676048742462893
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24:ujsZPSIPSUcnA3/46giyfV4Hxk7P3Gus6acCQ4CXmW5mOgs:ujul2nQ4XfVkk7P3g6dB42mVs
                                                                                                                                                                            MD5:E94FB54871208C00DF70F708AC47085B
                                                                                                                                                                            SHA1:4EFC31460C619ECAE59C1BCE2C008036D94C84B8
                                                                                                                                                                            SHA-256:7B9D553E1C92CB6E8803E137F4F287D4363757F5D44B37D52F9FCA22FB97DF86
                                                                                                                                                                            SHA-512:2E15B76E16264ABB9F5EF417752A1CBB75F29C11F96AC7D73793172BD0864DB65F2D2B7BE0F16BBBE686068F0C368815525F1E39DB5A0D6CA3AB18BE6923B898
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:0..r0..Z.......vS..uFH....JH:N.0...*.H........0S1.0...U....BE1.0...U....GlobalSign nv-sa1)0'..U... GlobalSign Code Signing Root R450...200318000000Z..450318000000Z0S1.0...U....BE1.0...U....GlobalSign nv-sa1)0'..U... GlobalSign Code Signing Root R450.."0...*.H.............0.........-.0.z.=.r.:K..a....g.7..~.....C..E..cW]....%..h.K..K.J...j..a'..D...?".O.....(..].Y.......,.3$.P:A..{.M.X8.........,..C...t...{.3..Yk....Z.{..U......L...u.o.a.tD....t..h.l&>.......0....|U..p\$x %.gg...N4.kp..8...........;.gC....t./.....7=gl.E\.a.A.....w.FGs.....+....X.W..Z..%....r=....;D.&.........E.......Bng~B.qb...`.d....!N+.mh...tsg1z...yn|..~FoM..+."D...7..aW...$..1s..5WG~.:E.-.Q.....7.e...k.w....?.0.o1..@........PvtY..m.2...~...u..J.,....+B..j6..L.............:.c...$d.......B0@0...U...........0...U.......0....0...U.........F...x9...C.VP..;0...*.H.............^+.t.4D_vH(@....n..%.{...=..v...0 ..`.....x.+.2..$.RR......9n....CA}..[.]...&..tr&....=;jR.<../.{.3.E.....
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):264
                                                                                                                                                                            Entropy (8bit):3.1580880771941966
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6:kK9XccUlhPQGhipWhliK8al0GQcmqe3KQjMIo1l2L/:a/hQGIWzyZ3qe3KQjxoK
                                                                                                                                                                            MD5:86F9DDD0C7D3960D20E973CDC5790AF2
                                                                                                                                                                            SHA1:3AF689AD7BD3474A63EFDBC22AEF6D8410B78EC6
                                                                                                                                                                            SHA-256:BB4102A1E5AEB7AC6BA5554C498FB001356D4DD3D64AFB90014E04102006DCD5
                                                                                                                                                                            SHA-512:2E2B9A411B34A30401931B951E9E69B5C2296771FDB398286D996250587BDB9A3EFBDC921032E85C840AD390AB922760614D19B04009450B875BCF355C482796
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:p...... ....v.....#.GX..(....................................................... ...............................v...h.t.t.p.:././.s.e.c.u.r.e...g.l.o.b.a.l.s.i.g.n...c.o.m./.c.a.c.e.r.t./.c.o.d.e.s.i.g.n.i.n.g.r.o.o.t.r.4.5...c.r.t...".6.2.f.a.3.3.e.5.-.5.7.6."...
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1768
                                                                                                                                                                            Entropy (8bit):4.387798711970492
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:48:YqRyRrRs2RDtRCRa7jRzRMR9R89R/R5DR3RoRXsRWEIiRTR4RbR8xRSRGjRIjRK1:FCFVDjS49QzqZ5NhMXwWELdc18XiWMK1
                                                                                                                                                                            MD5:9F974F37C6D2E65618B43735A39A3222
                                                                                                                                                                            SHA1:29664AB40F388E00AFE959EBF9D840BEA0DD59DD
                                                                                                                                                                            SHA-256:18894BB2111DCEF31F92F19A3244457C58A14BFC5C04688F3DB803492DA9F706
                                                                                                                                                                            SHA-512:D829E225B290ECE8BFA583558D4AD68A7BD0825F78EA5CE8A3FC01F12BC0FCF16F6371082050085461583DF978251422F6556BED78830EFF20C83BC7B9FDE8F9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:{"features":{"01979299c8cd":{"state":"enabled"},"03b8357e5a08":{"state":"enabled"},"06fbbd0b7bf7":{"state":"enabled"},"0f9cf8758bcc":{"state":"disabled"},"1c4dddb65bac":{"state":"enabled"},"1d24dceb937a":{"state":"enabled"},"2114dc8bd72a":{"state":"enabled"},"26f7e2d59ecf":{"state":"enabled"},"278deecb29a1":{"state":"enabled"},"3389f6c15eb9":{"state":"enabled"},"3993848b2bd9":{"state":"enabled"},"3fc0872a857b":{"state":"enabled"},"40db6e644d2c":{"state":"disabled"},"50796754ffc7":{"state":"enabled"},"5448a57d6689":{"state":"disabled"},"54a846ecd4f2":{"state":"enabled"},"56d717ae3ad6":{"state":"enabled"},"5a28d66c82cd":{"state":"enabled"},"5ee708e89d7b":{"state":"disabled"},"603cade21cf7":{"state":"enabled"},"654296fe9d6c":{"state":"enabled"},"6713f3df0bed":{"state":"enabled"},"804beb213cf7":{"state":"enabled"},"818c3ef12d0b":{"state":"enabled","dna_filter":{"required_dna":["64336fb81a04836eb8108d24fbca3aa3682db0a5"],"forbidden_dna":["5b3eb4a6c335a0659d16d1a189ca155e4441ea14"]}},"8be49a
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5749656
                                                                                                                                                                            Entropy (8bit):6.87182727947214
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:98304:D5hxDU6666666666666666666666666666666x666666666666666fwwwwwwwwwx:glR9/Fuz0kxKZ51eajz8L
                                                                                                                                                                            MD5:71AD4FFF7C190194C8A544776B54DCC5
                                                                                                                                                                            SHA1:088B5A1ACF87DDD917C1094D09A039E886DF1F32
                                                                                                                                                                            SHA-256:37490D7B909307CF474A081D16D87320BFC05CD0D382B4CE0D2AEC4459CEA9D9
                                                                                                                                                                            SHA-512:FDF302EDDBA55C899883EFE11DF17977529DAD6DC6D4C73E3811C01F98C9677DE25A02C3AAFA772DCA78ED6D59A8BD062FEC521D7CE385458DEC02B4C971A557
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....5eg.........."......d...*S...................@...........................W......JX...@.................................8%..P.........R...........W..)....W..6...".......................!.......................'...............................text...kb.......d.................. ..`.rdata...............h..............@..@.data...$5...P.......8..............@....tls.................V..............@....rsrc.....R.......R..X..............@..@.reloc...6....W..8...ZW.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe
                                                                                                                                                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5749656
                                                                                                                                                                            Entropy (8bit):6.87182727947214
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:98304:D5hxDU6666666666666666666666666666666x666666666666666fwwwwwwwwwx:glR9/Fuz0kxKZ51eajz8L
                                                                                                                                                                            MD5:71AD4FFF7C190194C8A544776B54DCC5
                                                                                                                                                                            SHA1:088B5A1ACF87DDD917C1094D09A039E886DF1F32
                                                                                                                                                                            SHA-256:37490D7B909307CF474A081D16D87320BFC05CD0D382B4CE0D2AEC4459CEA9D9
                                                                                                                                                                            SHA-512:FDF302EDDBA55C899883EFE11DF17977529DAD6DC6D4C73E3811C01F98C9677DE25A02C3AAFA772DCA78ED6D59A8BD062FEC521D7CE385458DEC02B4C971A557
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....5eg.........."......d...*S...................@...........................W......JX...@.................................8%..P.........R...........W..)....W..6...".......................!.......................'...............................text...kb.......d.................. ..`.rdata...............h..............@..@.data...$5...P.......8..............@....tls.................V..............@....rsrc.....R.......R..X..............@..@.reloc...6....W..8...ZW.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=store
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2231022
                                                                                                                                                                            Entropy (8bit):7.916336856210854
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:HVAbw20R7FagtTxP8OqC1Wsf5FFRgzvpiwBPo3ozeNhzit:1A10R0ATp885FbwwwBPo3oSNhzu
                                                                                                                                                                            MD5:93E74A1DFA2153FB7C32CBB1D6065517
                                                                                                                                                                            SHA1:D8322D53232137462D1654C1FFF556884C709C66
                                                                                                                                                                            SHA-256:72EED7F97751D0159D216B68D2A29E56C8502F00E3ED40219E9D8B4C97A3E69E
                                                                                                                                                                            SHA-512:4C60D01A04A6066BFA925A9B19FF4594A4B345BC77F836EED29AD1CC7AC849BAC4CAC5814E11B82C956E980CF7B357A76B5C76A7F31E5A4B089901A78A74585B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:PK.........X.YB8.Mp.".p.".....OperaSetup.exeMZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......N....m...m...m..A....m..A....m...._m.....m.....m..A....m..A....m...m...m....\m....X..m...m0..m.....m..Rich.m..........PE..L.....if...............'..........................@..................................J"...@.................................H...d.......x...........P.!. +.......1...C...............................C..@...............0............................text............................... ..`.rdata..z...........................@..@.data....K..........................@....rsrc...x...........................@..@.reloc...1.......2..................@..B............................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):2230896
                                                                                                                                                                            Entropy (8bit):7.916392235343025
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:49152:UVAbw20R7FagtTxP8OqC1Wsf5FFRgzvpiwBPo3ozeNhzim:4A10R0ATp885FbwwwBPo3oSNhz5
                                                                                                                                                                            MD5:7576A1BF33EDB92CE3CAC344DE107AFB
                                                                                                                                                                            SHA1:7E14BBDCB24AA7AFF21E9E0FAC9EC8232C6EB0F2
                                                                                                                                                                            SHA-256:BCA7E687A39AC52D8DDB0E95F0886BA3D194FF55A11CDF09FC2B0DA9EBBAD572
                                                                                                                                                                            SHA-512:800D79688C27B7E2C5DBB33434FAD5D6A14063088DAF4E281C86465BBDCA8532C88E56574DD810D00D2DB271B23C226E9FA65C653AFC81DF1B6ACF88C4455D0A
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......N....m...m...m..A....m..A....m...._m.....m.....m..A....m..A....m...m...m....\m....X..m...m0..m.....m..Rich.m..........PE..L.....if...............'..........................@..................................J"...@.................................H...d.......x...........P.!. +.......1...C...............................C..@...............0............................text............................... ..`.rdata..z...........................@..@.data....K..........................@....rsrc...x...........................@..@.reloc...1.......2..................@..B........................................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):527389
                                                                                                                                                                            Entropy (8bit):7.995975187354872
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:12288:ib5kasT/hWZEu58IbccPqwozk/2rYJb69+J2W:M5kzT/hWZjfbccPOzk/aIb3J2W
                                                                                                                                                                            MD5:F68008B70822BD28C82D13A289DEB418
                                                                                                                                                                            SHA1:06ABBE109BA6DFD4153D76CD65BFFFAE129C41D8
                                                                                                                                                                            SHA-256:CC6F4FAF4E8A9F4D2269D1D69A69EA326F789620FB98078CC98597F3CB998589
                                                                                                                                                                            SHA-512:FA482942E32E14011AE3C6762C638CCB0A0E8EC0055D2327C3ACC381DDDF1400DE79E4E9321A39A418800D072E59C36B94B13B7EB62751D3AEC990FB38CE9253
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:PK.........\zX...............saBSI.exe.Z.pT.u.+i..eW c....&....l.....Y[...-@`....e.....;r.T...MJ3.a.]..h:.VF?.u...T...+..()..;...v..[v...........]....s......[..!.....A!?N..?%&!.....1...}AS...U)._t4.;z........9r....A..G...86l}.....EVk.J......t.[E....w...x..+Wx...gg.Qz>...f...8.q^.?..)~..o..B.!z...)....m.{7..F...w....O.+.l*z..].......I.......v..=....S.i.=.r..J.....!.xI2D...!.5..S..r...Rz..@`......Ol....]4..(......]..K..%.I,.8?]"..Y..k|...%.W.#.p....5.li....r.A.5-......X....B.e.J.s.9...s."..S.NE.Fq...D\...0!....v..../..{....sL(6l.E8g...G...!V......^..|.Dp.k....W-B9.."B-.-...h.(..4.9>..&.3.2<.V.x.|T...Ke}.b.G.&1...!..>..P(..2~....~...S....B.d.$......,...O..B9.`.....X}B......B9.`a.8..0....l..B......|..0.b....N...0....%.^.`..0....{...MY.....4..H.'......Il....(..&.e.:&.X=$...+..P..na...C.~]...n...2..n..a0.U...>.0..2.....`..4...<.0.e..a._f0...[.....2..i._c0..i.^....(.).G.|.....$....^.YR..R...<.`..*...l'@..2...V[..0..B*.s......2x...........`'.(.Y...\.`..$
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe
                                                                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):23918680
                                                                                                                                                                            Entropy (8bit):7.990645224140664
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:393216:PyviTGPqMd2s5jqwcJFOM75FbVgmaccebfTBRL7WIJDFX6ZeplPVGUI4uK:aaAv5jq9O657x9+IJZ22PRI4uK
                                                                                                                                                                            MD5:7DD0FAA9C00391333B2A12D21CA028BF
                                                                                                                                                                            SHA1:2987248DB6382971D36F80EA45C0EE654C672CD4
                                                                                                                                                                            SHA-256:E4B5817742A53DCCC24CD2A266223045D03DA537B815CB03B782D4E6BAED5020
                                                                                                                                                                            SHA-512:CE700D9F59800C5A440D6DAFB1844F60B793B254A2186CC3B39654C9341AC7EAAC31D4A3F97B202AD40D17AAB21D6B3F277E38179237996D617A8968DCD164C4
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......t.K=0.%n0.%n0.%nk.&o:.%nk.!o".%nk. o..%nb.!o .%nb.&o:.%nb. oj.%nk.$o5.%n0.$n..%n..,o<.%n...n1.%n..'o1.%nRich0.%n........................PE..d...^2.f.........."...........f................@..............................j.......m...`..................................................$..(........'d.....|2....i.XX....j.....p...p.......................(.......8...............p...."..`....................text............................... ..`.rdata..V...........................@..@.data....1...@......................@....pdata..|2.......4...6..............@..@_RDATA...............j..............@..@.rsrc....'d......(d..l..............@..@.reloc........j.......i.............@..B................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1184128
                                                                                                                                                                            Entropy (8bit):6.623147525519113
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:24576:WF66IUpqM/XAl0drYaL6NFEXXN6abiklqOYadJ0CbmpV4CsCa0wDisO4qG:k/M0drYaIaXXOAqOYadJ0Cbmrhq0wTb5
                                                                                                                                                                            MD5:143255618462A577DE27286A272584E1
                                                                                                                                                                            SHA1:EFC032A6822BC57BCD0C9662A6A062BE45F11ACB
                                                                                                                                                                            SHA-256:F5AA950381FBCEA7D730AA794974CA9E3310384A95D6CF4D015FBDBD9797B3E4
                                                                                                                                                                            SHA-512:C0A084D5C0B645E6A6479B234FA73C405F56310119DD7C8B061334544C47622FDD5139DB9781B339BB3D3E17AC59FDDB7D7860834ECFE8AAD6D2AE8C869E1CB9
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.......2..}vn..vn..vn..-../xn..-../.n..$../bn..$../on..G2r.tn..$../.n..-../on..-../wn..-../yn...../wn...../~n...../Zn..vn..=o...../{n...../hn....p.wn...../wn..Richvn..................PE..L...V..e.....................h...... .............@..................................1....@.............................................p...............................p...................@.......X...@...............0....... ....................text............................... ..`.rdata..............................@..@.data..............................@....didat...............T..............@....rsrc...p............V..............@..@.reloc...............Z..............@..B................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5199768
                                                                                                                                                                            Entropy (8bit):6.865067632860383
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:98304:r6666666666666666666666666666666x666666666666666fwwwwwwwwwwwwwwi:HlR9/Fuz0kxKZ51eajz8f
                                                                                                                                                                            MD5:41DAEDCDA16A5341463070DBAC45624A
                                                                                                                                                                            SHA1:8A2F6B3653D92A09A49BAECE476B53988FBF0C52
                                                                                                                                                                            SHA-256:733701D47B47B544D0B96343B521266702BD8E43EDCB7C799C9CBAF07C7E3838
                                                                                                                                                                            SHA-512:7EBF69ED5D16EA1909890E6B714630975BC2CC7E3E4075C903CE6C33901B300FF632B1BBDF61558E4487D6FFF3D7DB78122A0BFA82E4CD57057685E1D1F7D159
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....5eg.........."!.....\8.........0.).......................................Q.......O...@A..........................@.m.....@......0C.@=............O..)...pO.....|k@......................j@.....8w8...............@.$...,.@.`....................text....[8......\8................. ..`.rdata..d....p8......`8.............@..@.data........ A..B....A.............@....rodata.......B......HA............. ..`.tls..........C......JA.............@...CPADinfo0.....C......LA.............@...malloc_h..... C......NA............. ..`.rsrc...@=...0C..>...PA.............@..@.reloc.......pO.......M.............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5199768
                                                                                                                                                                            Entropy (8bit):6.865067632860383
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:98304:r6666666666666666666666666666666x666666666666666fwwwwwwwwwwwwwwi:HlR9/Fuz0kxKZ51eajz8f
                                                                                                                                                                            MD5:41DAEDCDA16A5341463070DBAC45624A
                                                                                                                                                                            SHA1:8A2F6B3653D92A09A49BAECE476B53988FBF0C52
                                                                                                                                                                            SHA-256:733701D47B47B544D0B96343B521266702BD8E43EDCB7C799C9CBAF07C7E3838
                                                                                                                                                                            SHA-512:7EBF69ED5D16EA1909890E6B714630975BC2CC7E3E4075C903CE6C33901B300FF632B1BBDF61558E4487D6FFF3D7DB78122A0BFA82E4CD57057685E1D1F7D159
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....5eg.........."!.....\8.........0.).......................................Q.......O...@A..........................@.m.....@......0C.@=............O..)...pO.....|k@......................j@.....8w8...............@.$...,.@.`....................text....[8......\8................. ..`.rdata..d....p8......`8.............@..@.data........ A..B....A.............@....rodata.......B......HA............. ..`.tls..........C......JA.............@...CPADinfo0.....C......LA.............@...malloc_h..... C......NA............. ..`.rsrc...@=...0C..>...PA.............@..@.reloc.......pO.......M.............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe
                                                                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5199768
                                                                                                                                                                            Entropy (8bit):6.865067632860383
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:98304:r6666666666666666666666666666666x666666666666666fwwwwwwwwwwwwwwi:HlR9/Fuz0kxKZ51eajz8f
                                                                                                                                                                            MD5:41DAEDCDA16A5341463070DBAC45624A
                                                                                                                                                                            SHA1:8A2F6B3653D92A09A49BAECE476B53988FBF0C52
                                                                                                                                                                            SHA-256:733701D47B47B544D0B96343B521266702BD8E43EDCB7C799C9CBAF07C7E3838
                                                                                                                                                                            SHA-512:7EBF69ED5D16EA1909890E6B714630975BC2CC7E3E4075C903CE6C33901B300FF632B1BBDF61558E4487D6FFF3D7DB78122A0BFA82E4CD57057685E1D1F7D159
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....5eg.........."!.....\8.........0.).......................................Q.......O...@A..........................@.m.....@......0C.@=............O..)...pO.....|k@......................j@.....8w8...............@.$...,.@.`....................text....[8......\8................. ..`.rdata..d....p8......`8.............@..@.data........ A..B....A.............@....rodata.......B......HA............. ..`.tls..........C......JA.............@...CPADinfo0.....C......LA.............@...malloc_h..... C......NA............. ..`.rsrc...@=...0C..>...PA.............@..@.reloc.......pO.......M.............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5199768
                                                                                                                                                                            Entropy (8bit):6.865067632860383
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:98304:r6666666666666666666666666666666x666666666666666fwwwwwwwwwwwwwwi:HlR9/Fuz0kxKZ51eajz8f
                                                                                                                                                                            MD5:41DAEDCDA16A5341463070DBAC45624A
                                                                                                                                                                            SHA1:8A2F6B3653D92A09A49BAECE476B53988FBF0C52
                                                                                                                                                                            SHA-256:733701D47B47B544D0B96343B521266702BD8E43EDCB7C799C9CBAF07C7E3838
                                                                                                                                                                            SHA-512:7EBF69ED5D16EA1909890E6B714630975BC2CC7E3E4075C903CE6C33901B300FF632B1BBDF61558E4487D6FFF3D7DB78122A0BFA82E4CD57057685E1D1F7D159
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....5eg.........."!.....\8.........0.).......................................Q.......O...@A..........................@.m.....@......0C.@=............O..)...pO.....|k@......................j@.....8w8...............@.$...,.@.`....................text....[8......\8................. ..`.rdata..d....p8......`8.............@..@.data........ A..B....A.............@....rodata.......B......HA............. ..`.tls..........C......JA.............@...CPADinfo0.....C......LA.............@...malloc_h..... C......NA............. ..`.rsrc...@=...0C..>...PA.............@..@.reloc.......pO.......M.............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):5199768
                                                                                                                                                                            Entropy (8bit):6.865067632860383
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:98304:r6666666666666666666666666666666x666666666666666fwwwwwwwwwwwwwwi:HlR9/Fuz0kxKZ51eajz8f
                                                                                                                                                                            MD5:41DAEDCDA16A5341463070DBAC45624A
                                                                                                                                                                            SHA1:8A2F6B3653D92A09A49BAECE476B53988FBF0C52
                                                                                                                                                                            SHA-256:733701D47B47B544D0B96343B521266702BD8E43EDCB7C799C9CBAF07C7E3838
                                                                                                                                                                            SHA-512:7EBF69ED5D16EA1909890E6B714630975BC2CC7E3E4075C903CE6C33901B300FF632B1BBDF61558E4487D6FFF3D7DB78122A0BFA82E4CD57057685E1D1F7D159
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....5eg.........."!.....\8.........0.).......................................Q.......O...@A..........................@.m.....@......0C.@=............O..)...pO.....|k@......................j@.....8w8...............@.$...,.@.`....................text....[8......\8................. ..`.rdata..d....p8......`8.............@..@.data........ A..B....A.............@....rodata.......B......HA............. ..`.tls..........C......JA.............@...CPADinfo0.....C......LA.............@...malloc_h..... C......NA............. ..`.rsrc...@=...0C..>...PA.............@..@.reloc.......pO.......M.............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):164864
                                                                                                                                                                            Entropy (8bit):6.201995701481623
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3072:q3CSE9n0WjsAGX5Gn39yf19leo13plmJXTD:qM90WoAGJqe1neceJj
                                                                                                                                                                            MD5:662DE59677AECAC08C7F75F978C399DA
                                                                                                                                                                            SHA1:1F85D6BE1FA846E4BC90F7A29540466CF3422D24
                                                                                                                                                                            SHA-256:1F5A798DDE9E1B02979767E35F120D0C669064B9460C267FB5F007C290E3DCEB
                                                                                                                                                                            SHA-512:E1186C3B3862D897D9B368DA1B2964DBA24A3A8C41DE8BB5F86C503A0717DF75A1C89651C5157252C94E2AB47CE1841183F5DDE4C3A1E5F96CB471BF20B3FDD0
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Antivirus:
                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........>..dm..dm..dm..gl..dm..alj.dm..`l..dm..`l..dm..gl..dm..al..dm..el..dm..em..dm+.ml..dm+.dl..dm+..m..dm+.fl..dmRich..dm........PE..d.....3f.........." .................S....................................................`..........................................^......._..x...............@....................;..p............................;..8............................................text............................... ..`.rdata..............................@..@.data........p.......T..............@....pdata..@............`..............@..@_RDATA...............x..............@..@.rsrc................z..............@..@.reloc...............|..............@..B........................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            File Type:data
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):40
                                                                                                                                                                            Entropy (8bit):3.29546184423832
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3:FkWXlk+/d:9k+/d
                                                                                                                                                                            MD5:AA7EB888CBFDFF3C2AFA69EDE14325DB
                                                                                                                                                                            SHA1:C57472D4C940101A728ACDBBA55EDA254EED2F9E
                                                                                                                                                                            SHA-256:490639A210C989DCCA95D87B886BD2E7E3EB49A4FB47E40CFAA5562C7669BE4D
                                                                                                                                                                            SHA-512:A33BC3AD82A9F95B4DD579A1408724F01164E184DD8D04B4438E2D8CE442EEF39FC2E3A1C0E385D842E44CC151DD62D5C50ED900AAF29140AAF7D559B10CB59B
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:sdPC......................f..L..7*.H*@
                                                                                                                                                                            Process:C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):14367504
                                                                                                                                                                            Entropy (8bit):7.99998755488004
                                                                                                                                                                            Encrypted:true
                                                                                                                                                                            SSDEEP:196608:EjIR4+xyDwcRFCRX437dw2cPi223hnjKB2eEAwniPH4Ts96thCCg:EUScCMhO22Rne0TAwiPHyswtICg
                                                                                                                                                                            MD5:C573674682E11C129478994F7E9CC492
                                                                                                                                                                            SHA1:BE2C95E3281FB415BD02F206C89CEBB2443A9BEF
                                                                                                                                                                            SHA-256:959121DB3E849C4CCE6041A0A845C6CDAD11C46C9CEF8802DD2684D395216119
                                                                                                                                                                            SHA-512:ADDC9C18B7D1F5F6D397018B54C2BD2BBB100C5E5BFA3A1B29D24DCC5A3A84690F3A82438A3A0411638D5D714C6F91CF3A561C1A5BB24CAA69FD1DE0FFB9333F
                                                                                                                                                                            Malicious:true
                                                                                                                                                                            Preview:PK...........F.M.g9...9......gta5.themepack.3.BQ.2..7n~L..xb...sL...bB)....U....o................PT.y$.V.l.{......<4d<f`7....j$...QM......C..q^...\GY.2V...O.>.6..5..EM..A..^e..H.K...-.._.'..g../.1.gN..v~a.....9.=...H....eL..qz.......j[.s......u.A.....#/w.<I..(>....T..p(.!..8.{.h.*.w.OzU.$;b\p....3_..[yqp.......S9.......TJ.G\..yV3...,n.'/..8.-Zf..k....5."...,._.I..3:..).a..>.f.A...=zW.Y8?.t..D}~?.j.`.P.).[.X.-.I(....x...6.Al...$^P......ky:<.E.2.....Ei..tLWo{O...i.[%|........L..\........w.l. .]..M..+.D.?dg..... .Y.3X ..,.....>H+.D.j.0..b=..\;......W....3_V5u*q..QY#.).mi.......,.{..Mhj..D..5..}..H...+..ng............/.....C._c.s...y2.. .po.*.....&...v...S...F{.....W..]..X.Gji.~....!{...W...5.v`..>cGv,E.....h...XIyv.9...+...E.q.j4.......c.4V.r..q.a.O=.a.+.,hY..Mm....].....Vq.0}.7[...#l..|;.v5.....LZ.u.....z..A.+..jB.@nka...`j..,q..v.;M..g......{.c.....K..M..~.4..P....d..EN...&...:...q)~...O.........M$n...9-.-.*.A..D.W.p...w.4..xY.{^<..Qb..
                                                                                                                                                                            Process:C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                                                            File Type:MS Windows registry file, NT/2000 or above
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):1835008
                                                                                                                                                                            Entropy (8bit):4.418961089893108
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:6144:7Svfpi6ceLP/9skLmb0OTMWSPHaJG8nAgeMZMMhA2fX4WABlEnNd0uhiTw:mvloTMW+EZMM6DFyn03w
                                                                                                                                                                            MD5:9E28CF9E8538A757E3DFAE7FAA0418DA
                                                                                                                                                                            SHA1:5DB2F313DC1F63C0C959C1972316570EB74222BA
                                                                                                                                                                            SHA-256:CFB1F69F1CFB7C78A5A281180451E4B7891A917ECA33D61497EE846C486EFEED
                                                                                                                                                                            SHA-512:2DF2917A00F9CC59D670C891C7E4B234611B07C6921FB0F49680BB4A0BEE1DF5A5FF87D0B33331DDD43EDA505F88B6C464EBDAAD8FD7B00CEF570688281D1F7F
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:regf>...>....\.Z.................... ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e....c...b...#.......c...b...#...........c...b...#......rmtmjVl}GX................................................................................................................................................................................................................................................................................................................................................{I........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                            Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                            Category:dropped
                                                                                                                                                                            Size (bytes):16
                                                                                                                                                                            Entropy (8bit):3.625
                                                                                                                                                                            Encrypted:false
                                                                                                                                                                            SSDEEP:3:8gOFjJyn:8rFjJy
                                                                                                                                                                            MD5:5ADF91C8A8FF93FC99A0FA8E0EFB55FF
                                                                                                                                                                            SHA1:F9A76DA0DD77CFDE37995DABE28E125B5D586CCA
                                                                                                                                                                            SHA-256:9D90C44779D34C3152AB6065AD474667CCBF3B3193068CF39421F0750E418FEC
                                                                                                                                                                            SHA-512:A32E554FDE18AB616BE4739D3B830DC793ADAA58CBB03E997A36A75BABA9B4C41FF8A673897AF2C07B3EEB5D3DD3BC0362662CBC275E6A3D5DC5925B996B4EB9
                                                                                                                                                                            Malicious:false
                                                                                                                                                                            Preview:File Not Found..
                                                                                                                                                                            File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                            Entropy (8bit):7.065545961874544
                                                                                                                                                                            TrID:
                                                                                                                                                                            • Win32 Executable (generic) a (10002005/4) 98.81%
                                                                                                                                                                            • Windows ActiveX control (116523/4) 1.15%
                                                                                                                                                                            • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                                                                                                            • DOS Executable Generic (2002/1) 0.02%
                                                                                                                                                                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                                                                            File name:grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                                                            File size:4'547'440 bytes
                                                                                                                                                                            MD5:1d5608c770dd48f9f15c6a303c08cdd5
                                                                                                                                                                            SHA1:70b377e6d25ae801d563ccab02cfae72467f3027
                                                                                                                                                                            SHA256:d93ea0680d85088ea784e5eb3ab1d0bbb220e7500d8b4e3cc760a00ed7040a47
                                                                                                                                                                            SHA512:25802824694a5bd7d6dda5ed6b4d136f63af2f3c0c61e6b96337d65477c5395e72edb6c96a6220cf5b52c0320cbea7e07f0c967f8e1d9e445c5879a8cdc46998
                                                                                                                                                                            SSDEEP:98304:PXYa9wNbSZ0DwYWjA4m1w6ItL4tbqWFy0FLOAkGkzdnEVomFHKnP94:PXYHbSeGAbqWFy0FLOyomFHKnPO
                                                                                                                                                                            TLSH:D026BF317D8E4865D07203717D98FA7992EEBD7427B603C312987B2D7A316C21A3B927
                                                                                                                                                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........7...V...V...V.......V.......V......"V.......V.......V...V...U..5....V..5....V..5...YW.......V....P..V...V8..V.......V..Rich.V.
                                                                                                                                                                            Icon Hash:0c0c2d33ceec80aa
                                                                                                                                                                            Entrypoint:0x5cc736
                                                                                                                                                                            Entrypoint Section:.text
                                                                                                                                                                            Digitally signed:true
                                                                                                                                                                            Imagebase:0x400000
                                                                                                                                                                            Subsystem:windows gui
                                                                                                                                                                            Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                                                                                                                                            DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                                                                                                                                            Time Stamp:0x675B0AE1 [Thu Dec 12 16:10:09 2024 UTC]
                                                                                                                                                                            TLS Callbacks:
                                                                                                                                                                            CLR (.Net) Version:
                                                                                                                                                                            OS Version Major:6
                                                                                                                                                                            OS Version Minor:0
                                                                                                                                                                            File Version Major:6
                                                                                                                                                                            File Version Minor:0
                                                                                                                                                                            Subsystem Version Major:6
                                                                                                                                                                            Subsystem Version Minor:0
                                                                                                                                                                            Import Hash:d5023f4f4bfc0938fe40ae2fce32146a
                                                                                                                                                                            Signature Valid:true
                                                                                                                                                                            Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                                                                                                                                                                            Signature Validation Error:The operation completed successfully
                                                                                                                                                                            Error Number:0
                                                                                                                                                                            Not Before, Not After
                                                                                                                                                                            • 10/12/2024 01:00:00 29/08/2025 01:59:59
                                                                                                                                                                            Subject Chain
                                                                                                                                                                            • CN=Softonic International SA, O=Softonic International SA, L=Barcelona, S=Barcelona, C=ES
                                                                                                                                                                            Version:3
                                                                                                                                                                            Thumbprint MD5:9C50EC8F97C66FA028EC9F5E4073EA52
                                                                                                                                                                            Thumbprint SHA-1:672CBF5F682998567C379342CE7D0F608CA01E94
                                                                                                                                                                            Thumbprint SHA-256:E5E6BD651B41764FDDB9363F7D1281B7D56F0E5C9E0AF5638F3FF23C362E8CEB
                                                                                                                                                                            Serial:0D91F83CF9254DECA709E526D25D647C
                                                                                                                                                                            Instruction
                                                                                                                                                                            call 00007F4E14D89F5Bh
                                                                                                                                                                            jmp 00007F4E14D88F8Fh
                                                                                                                                                                            cmp ecx, dword ptr [006A5000h]
                                                                                                                                                                            jne 00007F4E14D89113h
                                                                                                                                                                            ret
                                                                                                                                                                            jmp 00007F4E14D89B1Ah
                                                                                                                                                                            push ebp
                                                                                                                                                                            mov ebp, esp
                                                                                                                                                                            push esi
                                                                                                                                                                            mov esi, 006B34E4h
                                                                                                                                                                            push esi
                                                                                                                                                                            call dword ptr [006192E8h]
                                                                                                                                                                            mov eax, dword ptr [ebp+08h]
                                                                                                                                                                            push esi
                                                                                                                                                                            and dword ptr [eax], 00000000h
                                                                                                                                                                            call dword ptr [006192ECh]
                                                                                                                                                                            push 006B34E0h
                                                                                                                                                                            call dword ptr [006192E4h]
                                                                                                                                                                            pop esi
                                                                                                                                                                            pop ebp
                                                                                                                                                                            ret
                                                                                                                                                                            push ebp
                                                                                                                                                                            mov ebp, esp
                                                                                                                                                                            push esi
                                                                                                                                                                            mov esi, 006B34E4h
                                                                                                                                                                            push esi
                                                                                                                                                                            call dword ptr [006192E8h]
                                                                                                                                                                            mov ecx, dword ptr [006A4FF0h]
                                                                                                                                                                            mov eax, dword ptr [ebp+08h]
                                                                                                                                                                            inc ecx
                                                                                                                                                                            mov dword ptr [006A4FF0h], ecx
                                                                                                                                                                            push esi
                                                                                                                                                                            mov dword ptr [eax], ecx
                                                                                                                                                                            mov eax, dword ptr fs:[0000002Ch]
                                                                                                                                                                            mov ecx, dword ptr [006B3844h]
                                                                                                                                                                            mov ecx, dword ptr [eax+ecx*4]
                                                                                                                                                                            mov eax, dword ptr [006A4FF0h]
                                                                                                                                                                            mov dword ptr [ecx+00000004h], eax
                                                                                                                                                                            call dword ptr [006192ECh]
                                                                                                                                                                            push 006B34E0h
                                                                                                                                                                            call dword ptr [006192E4h]
                                                                                                                                                                            pop esi
                                                                                                                                                                            pop ebp
                                                                                                                                                                            ret
                                                                                                                                                                            push ebp
                                                                                                                                                                            mov ebp, esp
                                                                                                                                                                            push esi
                                                                                                                                                                            push edi
                                                                                                                                                                            mov edi, 006B34E4h
                                                                                                                                                                            push edi
                                                                                                                                                                            call dword ptr [006192E8h]
                                                                                                                                                                            mov esi, dword ptr [ebp+08h]
                                                                                                                                                                            cmp dword ptr [esi], 00000000h
                                                                                                                                                                            jne 00007F4E14D8911Eh
                                                                                                                                                                            or dword ptr [esi], FFFFFFFFh
                                                                                                                                                                            jmp 00007F4E14D89138h
                                                                                                                                                                            call 00007F4E14D89141h
                                                                                                                                                                            jmp 00007F4E14D89101h
                                                                                                                                                                            cmp dword ptr [esi], FFFFFFFFh
                                                                                                                                                                            je 00007F4E14D89106h
                                                                                                                                                                            mov eax, dword ptr fs:[0000002Ch]
                                                                                                                                                                            mov ecx, dword ptr [00003844h]
                                                                                                                                                                            NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x29fd7c0x1b8.rdata
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x2b60000x17a790.rsrc
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x453a000x2970.reloc
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x4310000x2ab54.reloc
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x278b900x70.rdata
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_TLS0x278c000x18.rdata
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x278ad00x40.rdata
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_IAT0x2190000xad4.rdata
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                            .text0x10000x217b900x217c0043ae2514338dc5be9eaa74920d024267unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                            .rdata0x2190000x8a9c20x8aa007dcf97089dd8e8a94c8eab0385f8aa67False0.3306505015779982data5.55540170775215IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                            .data0x2a40000x1103c0xbc009689965d4e29b44ae5d67f194fb22ad9False0.17357878989361702data5.0572620597695455IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                            .rsrc0x2b60000x17a7900x17a800733c9b4898750bc966204919f11db84bFalse0.6004311323480845data7.556668326057487IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                            .reloc0x4310000x2ab540x2ac00184a0fefdbb7af1adfbdffc81521fe1eFalse0.4727647569444444data6.570291216132274IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd0e80x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd0f00x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1580x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd0f80x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd0e00x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1000x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1180x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1300x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1380x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1400x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1480x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1500x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1100x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1080x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1200x2dataEnglishUnited States5.0
                                                                                                                                                                            AFX_DIALOG_LAYOUT0x2cd1280x2dataEnglishUnited States5.0
                                                                                                                                                                            IMAGE_BLOB0x412c800x6846PNG image data, 512 x 512, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8773132539147374
                                                                                                                                                                            IMAGE_BLOB20x4194c80x57e4PNG image data, 512 x 512, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9663111111111111
                                                                                                                                                                            IMAGE_BLOB30x41ecb00x6050PNG image data, 512 x 512, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9756245944192083
                                                                                                                                                                            LOCALE0x424d080xb1fXML 1.0 document, ASCII text, with very long lines (345), with CRLF line terminatorsEnglishUnited States0.4130663856691254
                                                                                                                                                                            LOCALE0x4258280xb1fXML 1.0 document, Unicode text, UTF-8 text, with very long lines (344), with CRLF line terminatorsEnglishUnited States0.4260625219529329
                                                                                                                                                                            LOCALE0x4263480xa65XML 1.0 document, ASCII text, with very long lines (344), with CRLF line terminatorsEnglishUnited States0.4269071777527245
                                                                                                                                                                            LOCALE0x426db00xac8XML 1.0 document, Unicode text, UTF-8 text, with very long lines (343), with CRLF line terminatorsEnglishUnited States0.43623188405797103
                                                                                                                                                                            LOCALE0x4278780xafcXML 1.0 document, Unicode text, UTF-8 text, with very long lines (346), with CRLF line terminatorsEnglishUnited States0.4317211948790896
                                                                                                                                                                            LOCALE0x4283780xb1aXML 1.0 document, Unicode text, UTF-8 text, with very long lines (367), with CRLF line terminatorsEnglishUnited States0.45918367346938777
                                                                                                                                                                            LOCALE0x428e980xaf3XML 1.0 document, Unicode text, UTF-8 text, with very long lines (353), with CRLF line terminatorsEnglishUnited States0.4659293613985016
                                                                                                                                                                            LOCALE0x4299900xa94XML 1.0 document, Unicode text, UTF-8 text, with very long lines (356), with CRLF line terminatorsEnglishUnited States0.4324224519940916
                                                                                                                                                                            LOCALE0x42a4280xb98XML 1.0 document, Unicode text, UTF-8 text, with very long lines (426), with CRLF line terminatorsEnglishUnited States0.4366576819407008
                                                                                                                                                                            LOCALE0x42afc00xaa2XML 1.0 document, Unicode text, UTF-8 text, with very long lines (349), with CRLF line terminatorsEnglishUnited States0.44305657604702425
                                                                                                                                                                            LOCALE0x42ba680xb6bXML 1.0 document, Unicode text, UTF-8 text, with very long lines (381), with CRLF line terminatorsEnglishUnited States0.43345877523092713
                                                                                                                                                                            LOCALE0x42c5d80xad7XML 1.0 document, Unicode text, UTF-8 text, with very long lines (365), with CRLF line terminatorsEnglishUnited States0.43963963963963965
                                                                                                                                                                            LOCALE0x42d0b00xb00XML 1.0 document, Unicode text, UTF-8 text, with very long lines (406), with CRLF line terminatorsEnglishUnited States0.43785511363636365
                                                                                                                                                                            LOCALE0x42dbb00xb1aXML 1.0 document, Unicode text, UTF-8 text, with very long lines (367), with CRLF line terminatorsEnglishUnited States0.45918367346938777
                                                                                                                                                                            LOCALE0x42e6d00xde9XML 1.0 document, Unicode text, UTF-8 text, with very long lines (366), with CRLF line terminatorsEnglishUnited States0.41224375175512495
                                                                                                                                                                            LOCALE0x42f4c00xadaXML 1.0 document, Unicode text, UTF-8 text, with very long lines (348), with CRLF line terminatorsEnglishUnited States0.4474442044636429
                                                                                                                                                                            LOCALE0x424d000x3ASCII text, with CRLF line terminatorsEnglishUnited States3.6666666666666665
                                                                                                                                                                            PNG0x2de8e80x77PNG image data, 4 x 4, 8-bit/color RGB, non-interlacedEnglishUnited States0.9915966386554622
                                                                                                                                                                            PNG0x2db2280x2f5PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0145310435931307
                                                                                                                                                                            PNG0x2db7a80x301PNG image data, 70 x 31, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0143042912873863
                                                                                                                                                                            PNG0x2db5200x287PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.017001545595054
                                                                                                                                                                            PNG0x2de1980x36ePNG image data, 22 x 40, 8-bit/color RGB, non-interlacedEnglishUnited States1.0125284738041003
                                                                                                                                                                            PNG0x2dd0b00x15dPNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0315186246418337
                                                                                                                                                                            PNG0x2dd2100x13ePNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0345911949685536
                                                                                                                                                                            PNG0x2dd3500x115PNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.03971119133574
                                                                                                                                                                            PNG0x2dd4680x12aPNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0302013422818792
                                                                                                                                                                            PNG0x2dcea00x20cPNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0209923664122138
                                                                                                                                                                            PNG0x2de7e80xfdPNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0276679841897234
                                                                                                                                                                            PNG0x2de5080xa6PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                                                                                                                                            PNG0x2de5b00x7cPNG image data, 3 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9919354838709677
                                                                                                                                                                            PNG0x2de6300x96PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.0133333333333334
                                                                                                                                                                            PNG0x2de6c80x91PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006896551724138
                                                                                                                                                                            PNG0x2de7600x84PNG image data, 15 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States0.9848484848484849
                                                                                                                                                                            PNG0x2f23b00xa3PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0122699386503067
                                                                                                                                                                            PNG0x2eddf80x771PNG image data, 13 x 156, 8-bit/color RGB, non-interlacedEnglishUnited States1.005774278215223
                                                                                                                                                                            PNG0x2e87980x697PNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.006520450503853
                                                                                                                                                                            PNG0x2e8e300x342PNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.013189448441247
                                                                                                                                                                            PNG0x2f1f500x45fPNG image data, 24 x 72, 8-bit/color RGB, non-interlacedEnglishUnited States1.0098302055406614
                                                                                                                                                                            PNG0x2ee7400x1a3PNG image data, 20 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.026252983293556
                                                                                                                                                                            PNG0x2eb3000xac8PNG image data, 24 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039855072463768
                                                                                                                                                                            PNG0x2ebdc80x37cPNG image data, 8 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0123318385650224
                                                                                                                                                                            PNG0x2ecf180xa50PNG image data, 24 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0041666666666667
                                                                                                                                                                            PNG0x2ed9680x48ePNG image data, 9 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009433962264151
                                                                                                                                                                            PNG0x2ec1480xa50PNG image data, 24 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0041666666666667
                                                                                                                                                                            PNG0x2ecb980x380PNG image data, 8 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0122767857142858
                                                                                                                                                                            PNG0x2e36500xab0PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0040204678362572
                                                                                                                                                                            PNG0x2e4b900xb1fPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0038637161924833
                                                                                                                                                                            PNG0x2e41000xa8ePNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0040710584752035
                                                                                                                                                                            PNG0x2e56b00xb30PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003840782122905
                                                                                                                                                                            PNG0x2e72d00x3a6PNG image data, 48 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011777301927195
                                                                                                                                                                            PNG0x2e76780x111bPNG image data, 38 x 114, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025119890385932
                                                                                                                                                                            PNG0x2e9a400x3d1PNG image data, 23 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0112589559877174
                                                                                                                                                                            PNG0x2e9e180x21bPNG image data, 11 x 88, 8-bit/color RGB, non-interlacedEnglishUnited States1.0204081632653061
                                                                                                                                                                            PNG0x2ea0380xb12PNG image data, 50 x 273, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003881439661256
                                                                                                                                                                            PNG0x2eab500x7acPNG image data, 50 x 162, 8-bit/color RGBA, non-interlacedEnglishUnited States1.005600814663951
                                                                                                                                                                            PNG0x2e65880xd43PNG image data, 50 x 264, 8-bit/color RGB, non-interlacedEnglishUnited States1.003240058910162
                                                                                                                                                                            PNG0x2e61e00x3a4PNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011802575107296
                                                                                                                                                                            PNG0x2f25100x320PNG image data, 14 x 246, 8-bit/color RGBA, non-interlacedEnglishUnited States1.01375
                                                                                                                                                                            PNG0x2f28300x31fPNG image data, 14 x 246, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0137672090112642
                                                                                                                                                                            PNG0x2eee300x2bdPNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0156918687589158
                                                                                                                                                                            PNG0x2eebb80x273PNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0175438596491229
                                                                                                                                                                            PNG0x2ee8e80x2c9PNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0154277699859748
                                                                                                                                                                            PNG0x2ee5d80x163PNG image data, 70 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0112676056338028
                                                                                                                                                                            PNG0x2ef0f00x152PNG image data, 41 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.032544378698225
                                                                                                                                                                            PNG0x2e91780x38aPNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0121412803532008
                                                                                                                                                                            PNG0x2e95080x532PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082706766917293
                                                                                                                                                                            PNG0x2e0ed80x19cPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8810679611650486
                                                                                                                                                                            PNG0x2e10780x2296PNG image data, 72 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001242376327084
                                                                                                                                                                            PNG0x2ff4f00x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                                                                                                                                            PNG0x3025300x1c4PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8252212389380531
                                                                                                                                                                            PNG0x3020080x522PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.008371385083714
                                                                                                                                                                            PNG0x2ffb900x2475PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.000750026786671
                                                                                                                                                                            PNG0x2fc2a80x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                                                                                                                                            PNG0x2ff3280x1c3PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8314855875831486
                                                                                                                                                                            PNG0x2fee200x505PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0085603112840467
                                                                                                                                                                            PNG0x2fc9480x24d3PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0004243131430997
                                                                                                                                                                            PNG0x3026f80x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                                                                                                                                            PNG0x3057c00x1c7PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.832967032967033
                                                                                                                                                                            PNG0x3052880x536PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082458770614693
                                                                                                                                                                            PNG0x302d980x24f0PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0011632825719121
                                                                                                                                                                            PNG0x2f60680x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                                                                                                                                            PNG0x2f8fc00x1c5PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8388520971302428
                                                                                                                                                                            PNG0x2f8ae00x4d9PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.008863819500403
                                                                                                                                                                            PNG0x2f67080x23d3PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                                                                                                                                            PNG0x2f2b500x189PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0279898218829517
                                                                                                                                                                            PNG0x2f2ce00x1bcPNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States0.7027027027027027
                                                                                                                                                                            PNG0x2f2f680x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                                                                                                                                            PNG0x2f5ea00x1c4PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.827433628318584
                                                                                                                                                                            PNG0x2f59b00x4efPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0087094220110848
                                                                                                                                                                            PNG0x2f36080x23a2PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0007673755755317
                                                                                                                                                                            PNG0x2f2ea00xc5PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0253807106598984
                                                                                                                                                                            PNG0x3059880x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                                                                                                                                            PNG0x308a200x1baPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8212669683257918
                                                                                                                                                                            PNG0x3085380x4e4PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0087859424920127
                                                                                                                                                                            PNG0x3060280x250fPNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0005270369979973
                                                                                                                                                                            PNG0x2f91880x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                                                                                                                                            PNG0x2fc0e00x1c2PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8288888888888889
                                                                                                                                                                            PNG0x2fbbf00x4e9PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0087509944311854
                                                                                                                                                                            PNG0x2f98280x23c6PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.000436776588775
                                                                                                                                                                            PNG0x2f24580xb5PNG image data, 15 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0165745856353592
                                                                                                                                                                            PNG0x2e34c80x186PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028205128205128
                                                                                                                                                                            PNG0x2e33100x1b5PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States0.6864988558352403
                                                                                                                                                                            PNG0x2ee5700x66PNG image data, 1 x 46, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9803921568627451
                                                                                                                                                                            PNG0x2f03880xf9PNG image data, 90 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0321285140562249
                                                                                                                                                                            PNG0x2f07880x17c3PNG image data, 86 x 240, 8-bit/color RGBA, non-interlacedEnglishUnited States0.992931119513398
                                                                                                                                                                            PNG0x2f04880x283PNG image data, 86 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171073094867806
                                                                                                                                                                            PNG0x2f07100x71PNG image data, 5 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9823008849557522
                                                                                                                                                                            PNG0x2efc680x71dPNG image data, 16 x 48, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0060406370126305
                                                                                                                                                                            PNG0x2ef4d00x794PNG image data, 16 x 48, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0056701030927835
                                                                                                                                                                            PNG0x2ef2480x284PNG image data, 7 x 39, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0170807453416149
                                                                                                                                                                            PNG0x2dbab00x203PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.021359223300971
                                                                                                                                                                            PNG0x2dbcb80x1b5PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0251716247139588
                                                                                                                                                                            PNG0x2dbf480xb2PNG image data, 2 x 20, 8-bit/color RGB, non-interlacedEnglishUnited States1.0168539325842696
                                                                                                                                                                            PNG0x2dbe700xd1PNG image data, 11 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9760765550239234
                                                                                                                                                                            PNG0x2dc0000x21cPNG image data, 21 x 42, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0203703703703704
                                                                                                                                                                            PNG0x2dc2200x21cPNG image data, 21 x 42, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0203703703703704
                                                                                                                                                                            PNG0x2dc4400x1aePNG image data, 21 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0186046511627906
                                                                                                                                                                            PNG0x2dc5f00x13aPNG image data, 16 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0222929936305734
                                                                                                                                                                            PNG0x2dc8d80x13fPNG image data, 21 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0344827586206897
                                                                                                                                                                            PNG0x2dca180x135PNG image data, 16 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9967637540453075
                                                                                                                                                                            PNG0x2dc7300xdbPNG image data, 21 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0228310502283104
                                                                                                                                                                            PNG0x2dc8100xc6PNG image data, 16 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0252525252525253
                                                                                                                                                                            PNG0x2dcb500x1a9PNG image data, 21 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0141176470588236
                                                                                                                                                                            PNG0x2dcd000x19bPNG image data, 16 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0194647201946472
                                                                                                                                                                            PNG0x2deb000x2296PNG image data, 72 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001242376327084
                                                                                                                                                                            PNG0x2e0d980x13ePNG image data, 72 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0345911949685536
                                                                                                                                                                            PNG0x2de9e80x115PNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.03971119133574
                                                                                                                                                                            PNG0x2de9600x83PNG image data, 35 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0076335877862594
                                                                                                                                                                            PNG0x2de0c80xcePNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0242718446601942
                                                                                                                                                                            PNG0x2dd5980xb30PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003840782122905
                                                                                                                                                                            PNG0x3110500x25fPNG image data, 72 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0181219110378912
                                                                                                                                                                            PNG0x310e380x79PNG image data, 4 x 4, 8-bit/color RGB, non-interlacedEnglishUnited States0.9752066115702479
                                                                                                                                                                            PNG0x30d6f00x170PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9755434782608695
                                                                                                                                                                            PNG0x30d9680x26bPNG image data, 70 x 31, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0177705977382876
                                                                                                                                                                            PNG0x30d8600x105PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9731800766283525
                                                                                                                                                                            PNG0x3109680xe6PNG image data, 22 x 38, 8-bit/color RGB, non-interlacedEnglishUnited States1.0260869565217392
                                                                                                                                                                            PNG0x30fab00x38dPNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012101210121012
                                                                                                                                                                            PNG0x30fe400x265PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0179445350734095
                                                                                                                                                                            PNG0x3101580x11aPNG image data, 30 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0319148936170213
                                                                                                                                                                            PNG0x3100a80xaaPNG image data, 2 x 19, 8-bit/color RGB, non-interlacedEnglishUnited States1.011764705882353
                                                                                                                                                                            PNG0x3102780x12aPNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0268456375838926
                                                                                                                                                                            PNG0x30f8a00x209PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.021113243761996
                                                                                                                                                                            PNG0x310d400xf5PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0244897959183674
                                                                                                                                                                            PNG0x3123000xa6PNG image data, 54 x 31, 8-bit/color RGB, non-interlacedEnglishUnited States1.0180722891566265
                                                                                                                                                                            PNG0x3121b00x150PNG image data, 54 x 124, 8-bit/color RGB, non-interlacedEnglishUnited States1.0327380952380953
                                                                                                                                                                            PNG0x310a500xacPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0174418604651163
                                                                                                                                                                            PNG0x310b000x89PNG image data, 3 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                                                                                                                                            PNG0x310b900x98PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006578947368421
                                                                                                                                                                            PNG0x310c280x91PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006896551724138
                                                                                                                                                                            PNG0x310cc00x7dPNG image data, 15 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.008
                                                                                                                                                                            PNG0x3272c00xa6PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                                                                                                                                            PNG0x3272000xbcPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0159574468085106
                                                                                                                                                                            PNG0x3221b80xa07PNG image data, 13 x 156, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004285157771718
                                                                                                                                                                            PNG0x319bf80x1de1PNG image data, 52 x 336, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0014380964832004
                                                                                                                                                                            PNG0x31b9e00x1bePNG image data, 38 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0246636771300448
                                                                                                                                                                            PNG0x31bba00x53bPNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082150858849888
                                                                                                                                                                            PNG0x326dc00x440PNG image data, 22 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010110294117647
                                                                                                                                                                            PNG0x3230480x12ePNG image data, 20 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0298013245033113
                                                                                                                                                                            PNG0x3206500x5b1PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0075497597803706
                                                                                                                                                                            PNG0x320c080x408PNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0106589147286822
                                                                                                                                                                            PNG0x3218880x471PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009674582233949
                                                                                                                                                                            PNG0x321d000x4b7PNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0091135045567523
                                                                                                                                                                            PNG0x3210100x481PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0095403295750216
                                                                                                                                                                            PNG0x3214980x3ecPNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0109561752988048
                                                                                                                                                                            PNG0x313d100x452PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0099457504520795
                                                                                                                                                                            PNG0x3145080x414PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010536398467433
                                                                                                                                                                            PNG0x3141680x39ePNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011879049676026
                                                                                                                                                                            PNG0x3149200x48dPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009442060085837
                                                                                                                                                                            PNG0x317e700x1b3PNG image data, 15 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.025287356321839
                                                                                                                                                                            PNG0x3180280xeaPNG image data, 32 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0299145299145298
                                                                                                                                                                            PNG0x3181180x1ae0PNG image data, 38 x 114, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0015988372093023
                                                                                                                                                                            PNG0x31cad00xb43PNG image data, 22 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0038154699965314
                                                                                                                                                                            PNG0x31d6180x609PNG image data, 11 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0071197411003237
                                                                                                                                                                            PNG0x31dc280x18aePNG image data, 43 x 234, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0017410572966128
                                                                                                                                                                            PNG0x31f4d80x1177PNG image data, 43 x 135, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0024602997092373
                                                                                                                                                                            PNG0x3158800x25ecPNG image data, 43 x 330, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0011330861145447
                                                                                                                                                                            PNG0x314db00xacbPNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039811798769454
                                                                                                                                                                            PNG0x3274100xbc8PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036472148541113
                                                                                                                                                                            PNG0x327fd80xc2ePNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035279025016035
                                                                                                                                                                            PNG0x323e200x5ddPNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0073284477015323
                                                                                                                                                                            PNG0x3238880x597PNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0076869322152342
                                                                                                                                                                            PNG0x3232900x5f8PNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.007198952879581
                                                                                                                                                                            PNG0x322e100x237PNG image data, 54 x 69, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0194003527336861
                                                                                                                                                                            PNG0x3244000x588PNG image data, 22 x 44, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0077683615819208
                                                                                                                                                                            PNG0x31c0e00x4b6PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0091210613598673
                                                                                                                                                                            PNG0x31c5980x532PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082706766917293
                                                                                                                                                                            PNG0x3123a80x5fePNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0071707953063884
                                                                                                                                                                            PNG0x3129a80xdd3PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9960440802486578
                                                                                                                                                                            PNG0x3137800x7cPNG image data, 1 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9919354838709677
                                                                                                                                                                            PNG0x3345e80x13c1PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021752026893416
                                                                                                                                                                            PNG0x336fa80x37dPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0123180291153415
                                                                                                                                                                            PNG0x336c100x395PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0119956379498365
                                                                                                                                                                            PNG0x3359b00x125ePNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023394300297745
                                                                                                                                                                            PNG0x3317d00x13b4PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021808088818398
                                                                                                                                                                            PNG0x3342780x369PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126002290950744
                                                                                                                                                                            PNG0x333ea80x3ccPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0113168724279835
                                                                                                                                                                            PNG0x332b880x1320PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002246732026144
                                                                                                                                                                            PNG0x3373280x13acPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021842732327244
                                                                                                                                                                            PNG0x339d100x364PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012672811059908
                                                                                                                                                                            PNG0x3399500x3baPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0115303983228512
                                                                                                                                                                            PNG0x3386d80x1274PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023285351397122
                                                                                                                                                                            PNG0x32bee00x139fPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021899263388414
                                                                                                                                                                            PNG0x32e8600x380PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0122767857142858
                                                                                                                                                                            PNG0x32e5080x352PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0129411764705882
                                                                                                                                                                            PNG0x32d2800x1288PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002318718381113
                                                                                                                                                                            PNG0x328c080x211PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0207939508506616
                                                                                                                                                                            PNG0x328e200x2e4PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0148648648648648
                                                                                                                                                                            PNG0x3291e00x13adPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021838395870557
                                                                                                                                                                            PNG0x32bb780x365PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126582278481013
                                                                                                                                                                            PNG0x32b8000x374PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                                                                                                                                            PNG0x32a5900x126bPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023329798515377
                                                                                                                                                                            PNG0x3291080xd4PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028301886792453
                                                                                                                                                                            PNG0x33a0780x1394PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00219473264166
                                                                                                                                                                            PNG0x33cb100x374PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                                                                                                                                            PNG0x33c7180x3f4PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0108695652173914
                                                                                                                                                                            PNG0x33b4100x1304PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0022596548890714
                                                                                                                                                                            PNG0x32ebe00x1397PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021934197407776
                                                                                                                                                                            PNG0x3314580x373PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0124575311438277
                                                                                                                                                                            PNG0x3311180x33dPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0132689987937273
                                                                                                                                                                            PNG0x32ff780x119ePNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002439024390244
                                                                                                                                                                            PNG0x3273680xa6PNG image data, 15 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                                                                                                                                            PNG0x313af80x211PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0207939508506616
                                                                                                                                                                            PNG0x3138000x2f7PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0144927536231885
                                                                                                                                                                            PNG0x322c280x16ePNG image data, 9 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.030054644808743
                                                                                                                                                                            PNG0x322d980x73PNG image data, 5 x 5, 8-bit/color RGB, non-interlacedEnglishUnited States0.9826086956521739
                                                                                                                                                                            PNG0x3231780x117PNG image data, 11 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.021505376344086
                                                                                                                                                                            PNG0x322bc00x67PNG image data, 2 x 55, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9902912621359223
                                                                                                                                                                            PNG0x325f900xcePNG image data, 90 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0242718446601942
                                                                                                                                                                            PNG0x3263800xa40PNG image data, 86 x 240, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9733231707317073
                                                                                                                                                                            PNG0x3260600x283PNG image data, 86 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171073094867806
                                                                                                                                                                            PNG0x3262e80x93PNG image data, 5 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0136054421768708
                                                                                                                                                                            PNG0x3256200x96aPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004564315352697
                                                                                                                                                                            PNG0x324c800x99bPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0044733631557543
                                                                                                                                                                            PNG0x3249880x2f7PNG image data, 11 x 45, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0144927536231885
                                                                                                                                                                            PNG0x30dbd80x1ffPNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0215264187866928
                                                                                                                                                                            PNG0x30ddd80x1f7PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.021868787276342
                                                                                                                                                                            PNG0x30e0680xb6PNG image data, 2 x 20, 8-bit/color RGB, non-interlacedEnglishUnited States1.010989010989011
                                                                                                                                                                            PNG0x30dfd00x94PNG image data, 11 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0135135135135136
                                                                                                                                                                            PNG0x30e1200x3e6PNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0110220440881763
                                                                                                                                                                            PNG0x30e5080x3e6PNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0110220440881763
                                                                                                                                                                            PNG0x30e8f00x315PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0139416983523448
                                                                                                                                                                            PNG0x30ec080x259PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0183028286189684
                                                                                                                                                                            PNG0x30f0680x205PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0212765957446808
                                                                                                                                                                            PNG0x30f2700x176PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0294117647058822
                                                                                                                                                                            PNG0x30ee680x124PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0136986301369864
                                                                                                                                                                            PNG0x30ef900xd7PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                                                                                                                                            PNG0x30f3e80x28fPNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.016793893129771
                                                                                                                                                                            PNG0x30f6780x225PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0200364298724955
                                                                                                                                                                            PNG0x3112b00xdd3PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9960440802486578
                                                                                                                                                                            PNG0x3120880x123PNG image data, 72 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0378006872852235
                                                                                                                                                                            PNG0x310f400x10bPNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.0337078651685394
                                                                                                                                                                            PNG0x310eb80x83PNG image data, 35 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0076335877862594
                                                                                                                                                                            PNG0x3108380x12fPNG image data, 9 x 9, 8-bit/color RGB, non-interlacedEnglishUnited States1.0264026402640265
                                                                                                                                                                            PNG0x3103a80x48dPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009442060085837
                                                                                                                                                                            PNG0x344f180x261PNG image data, 72 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0180623973727423
                                                                                                                                                                            PNG0x344d000x79PNG image data, 4 x 4, 8-bit/color RGB, non-interlacedEnglishUnited States0.9752066115702479
                                                                                                                                                                            PNG0x3419300x1b5PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9931350114416476
                                                                                                                                                                            PNG0x341c080x293PNG image data, 70 x 31, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0166919575113809
                                                                                                                                                                            PNG0x341ae80x11aPNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9716312056737588
                                                                                                                                                                            PNG0x3448200xdePNG image data, 22 x 38, 8-bit/color RGB, non-interlacedEnglishUnited States1.027027027027027
                                                                                                                                                                            PNG0x3439380x38dPNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012101210121012
                                                                                                                                                                            PNG0x343cc80x265PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0179445350734095
                                                                                                                                                                            PNG0x343fe00x124PNG image data, 30 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0308219178082192
                                                                                                                                                                            PNG0x343f300xaaPNG image data, 2 x 19, 8-bit/color RGB, non-interlacedEnglishUnited States1.011764705882353
                                                                                                                                                                            PNG0x3441080x12aPNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0268456375838926
                                                                                                                                                                            PNG0x3437280x209PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.021113243761996
                                                                                                                                                                            PNG0x344c080xf5PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0244897959183674
                                                                                                                                                                            PNG0x3463800x9fPNG image data, 54 x 31, 8-bit/color RGB, non-interlacedEnglishUnited States1.0125786163522013
                                                                                                                                                                            PNG0x3462380x148PNG image data, 54 x 124, 8-bit/color RGB, non-interlacedEnglishUnited States1.0335365853658536
                                                                                                                                                                            PNG0x3449000xacPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0174418604651163
                                                                                                                                                                            PNG0x3449b00x8bPNG image data, 3 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.014388489208633
                                                                                                                                                                            PNG0x344a400xa4PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.0
                                                                                                                                                                            PNG0x344ae80x94PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.0067567567567568
                                                                                                                                                                            PNG0x344b800x87PNG image data, 15 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0
                                                                                                                                                                            PNG0x35b9c80xa6PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                                                                                                                                            PNG0x35b9000xc5PNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0203045685279188
                                                                                                                                                                            PNG0x3567200xa54PNG image data, 13 x 156, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004160363086233
                                                                                                                                                                            PNG0x34dfd00x1edaPNG image data, 52 x 336, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001392757660167
                                                                                                                                                                            PNG0x34feb00x1cbPNG image data, 38 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0239651416122004
                                                                                                                                                                            PNG0x3500800x53bPNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082150858849888
                                                                                                                                                                            PNG0x35b4080x4f3PNG image data, 22 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0086819258089976
                                                                                                                                                                            PNG0x3576280x11aPNG image data, 20 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.024822695035461
                                                                                                                                                                            PNG0x354bd00x5afPNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0075601374570446
                                                                                                                                                                            PNG0x3551800x3ffPNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010752688172043
                                                                                                                                                                            PNG0x355de80x461PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0098126672613739
                                                                                                                                                                            PNG0x3562500x4ccPNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.008957654723127
                                                                                                                                                                            PNG0x3555800x474PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0096491228070175
                                                                                                                                                                            PNG0x3559f80x3efPNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0109235352532273
                                                                                                                                                                            PNG0x347fa80x44aPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0100182149362478
                                                                                                                                                                            PNG0x3487980x41fPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0104265402843602
                                                                                                                                                                            PNG0x3483f80x39bPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0119176598049837
                                                                                                                                                                            PNG0x348bb80x4a1PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009282700421941
                                                                                                                                                                            PNG0x34c1180x1b3PNG image data, 15 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.025287356321839
                                                                                                                                                                            PNG0x34c2d00xf9PNG image data, 32 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.036144578313253
                                                                                                                                                                            PNG0x34c3d00x1bfaPNG image data, 38 x 114, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001535883831332
                                                                                                                                                                            PNG0x3510500xb43PNG image data, 22 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0038154699965314
                                                                                                                                                                            PNG0x351b980x609PNG image data, 11 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0071197411003237
                                                                                                                                                                            PNG0x3521a80x18aePNG image data, 43 x 234, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0017410572966128
                                                                                                                                                                            PNG0x353a580x1177PNG image data, 43 x 135, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0024602997092373
                                                                                                                                                                            PNG0x349b280x25ecPNG image data, 43 x 330, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0011330861145447
                                                                                                                                                                            PNG0x3490600xac7PNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039869517941282
                                                                                                                                                                            PNG0x35bb280xa82PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004089219330855
                                                                                                                                                                            PNG0x35c5b00xac7PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039869517941282
                                                                                                                                                                            PNG0x3583d00x5d3PNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0073775989268947
                                                                                                                                                                            PNG0x357e580x575PNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0078740157480315
                                                                                                                                                                            PNG0x3578680x5eaPNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0072655217965654
                                                                                                                                                                            PNG0x3574000x222PNG image data, 54 x 69, 8-bit/color RGBA, non-interlacedEnglishUnited States1.02014652014652
                                                                                                                                                                            PNG0x3589a80x588PNG image data, 22 x 44, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0077683615819208
                                                                                                                                                                            PNG0x3505c00x552PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0080763582966226
                                                                                                                                                                            PNG0x350b180x532PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082706766917293
                                                                                                                                                                            PNG0x3464200x624PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.006997455470738
                                                                                                                                                                            PNG0x346a480xf6fPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0027841052898
                                                                                                                                                                            PNG0x3479b80x98PNG image data, 1 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.013157894736842
                                                                                                                                                                            PNG0x3671380x13c1PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021752026893416
                                                                                                                                                                            PNG0x3694880x37dPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0123180291153415
                                                                                                                                                                            PNG0x3690f00x395PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0119956379498365
                                                                                                                                                                            PNG0x3685000xbeaPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036065573770492
                                                                                                                                                                            PNG0x3649880x13b4PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021808088818398
                                                                                                                                                                            PNG0x366dc80x369PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126002290950744
                                                                                                                                                                            PNG0x3669f80x3ccPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0113168724279835
                                                                                                                                                                            PNG0x365d400xcb2PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0033846153846153
                                                                                                                                                                            PNG0x3698080x13acPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021842732327244
                                                                                                                                                                            PNG0x36bb780x364PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012672811059908
                                                                                                                                                                            PNG0x36b7b80x3baPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0115303983228512
                                                                                                                                                                            PNG0x36abb80xbffPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035818951481603
                                                                                                                                                                            PNG0x35fd400x139fPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021899263388414
                                                                                                                                                                            PNG0x3620300x380PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0122767857142858
                                                                                                                                                                            PNG0x361cd80x352PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0129411764705882
                                                                                                                                                                            PNG0x3610e00xbf8PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035900783289817
                                                                                                                                                                            PNG0x35d0780x1e3PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0227743271221532
                                                                                                                                                                            PNG0x35d2600x3d2PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0112474437627812
                                                                                                                                                                            PNG0x35d7100x13adPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021838395870557
                                                                                                                                                                            PNG0x35f9d80x365PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126582278481013
                                                                                                                                                                            PNG0x35f6600x374PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                                                                                                                                            PNG0x35eac00xb9aPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0037037037037038
                                                                                                                                                                            PNG0x35d6380xd4PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028301886792453
                                                                                                                                                                            PNG0x36bee00x1394PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00219473264166
                                                                                                                                                                            PNG0x36e2d80x374PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                                                                                                                                            PNG0x36dee00x3f4PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0108695652173914
                                                                                                                                                                            PNG0x36d2780xc62PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034700315457412
                                                                                                                                                                            PNG0x3623b00x1397PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021934197407776
                                                                                                                                                                            PNG0x3646100x373PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0124575311438277
                                                                                                                                                                            PNG0x3642d00x33dPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0132689987937273
                                                                                                                                                                            PNG0x3637480xb84PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0003392130257802
                                                                                                                                                                            PNG0x35ba700xb1PNG image data, 15 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0169491525423728
                                                                                                                                                                            PNG0x347dc80x1daPNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0232067510548524
                                                                                                                                                                            PNG0x347a500x375PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0124293785310734
                                                                                                                                                                            PNG0x3571e00x1a5PNG image data, 9 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0261282660332542
                                                                                                                                                                            PNG0x3573880x71PNG image data, 5 x 5, 8-bit/color RGB, non-interlacedEnglishUnited States0.9911504424778761
                                                                                                                                                                            PNG0x3577480x11aPNG image data, 11 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0283687943262412
                                                                                                                                                                            PNG0x3571780x67PNG image data, 2 x 55, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9902912621359223
                                                                                                                                                                            PNG0x35a5c80xe0PNG image data, 90 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.03125
                                                                                                                                                                            PNG0x35a9c80xa40PNG image data, 86 x 240, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9733231707317073
                                                                                                                                                                            PNG0x35a6a80x283PNG image data, 86 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171073094867806
                                                                                                                                                                            PNG0x35a9300x93PNG image data, 5 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0136054421768708
                                                                                                                                                                            PNG0x359c400x985PNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00451374640952
                                                                                                                                                                            PNG0x3592700x9caPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00438946528332
                                                                                                                                                                            PNG0x358f300x339PNG image data, 11 x 45, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0133333333333334
                                                                                                                                                                            PNG0x341ea00x214PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0206766917293233
                                                                                                                                                                            PNG0x3420b80x22ePNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0197132616487454
                                                                                                                                                                            PNG0x3423800xb3PNG image data, 2 x 20, 8-bit/color RGB, non-interlacedEnglishUnited States1.011173184357542
                                                                                                                                                                            PNG0x3422e80x95PNG image data, 11 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9932885906040269
                                                                                                                                                                            PNG0x3424380x414PNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010536398467433
                                                                                                                                                                            PNG0x3428500x414PNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010536398467433
                                                                                                                                                                            PNG0x342c680x1fbPNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0216962524654833
                                                                                                                                                                            PNG0x342e680x179PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0159151193633953
                                                                                                                                                                            PNG0x3431b00x179PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0053050397877985
                                                                                                                                                                            PNG0x3433300x114PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0289855072463767
                                                                                                                                                                            PNG0x342fe80x10ePNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011111111111111
                                                                                                                                                                            PNG0x3430f80xb6PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0054945054945055
                                                                                                                                                                            PNG0x3434480x17ePNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0287958115183247
                                                                                                                                                                            PNG0x3435c80x15cPNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0201149425287357
                                                                                                                                                                            PNG0x3451800xf6fPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0027841052898
                                                                                                                                                                            PNG0x3460f00x143PNG image data, 72 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0340557275541795
                                                                                                                                                                            PNG0x344e080x110PNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.0294117647058822
                                                                                                                                                                            PNG0x344d800x87PNG image data, 35 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0074074074074073
                                                                                                                                                                            PNG0x3446e00x13bPNG image data, 9 x 9, 8-bit/color RGB, non-interlacedEnglishUnited States1.0253968253968253
                                                                                                                                                                            PNG0x3442380x4a1PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009282700421941
                                                                                                                                                                            PNG0x3762e80x25ePNG image data, 72 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.018151815181518
                                                                                                                                                                            PNG0x3760d00x79PNG image data, 4 x 4, 8-bit/color RGB, non-interlacedEnglishUnited States0.9752066115702479
                                                                                                                                                                            PNG0x3730680x167PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9972144846796658
                                                                                                                                                                            PNG0x3732f00x278PNG image data, 70 x 31, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0174050632911393
                                                                                                                                                                            PNG0x3731d00x11aPNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9680851063829787
                                                                                                                                                                            PNG0x375c100xd4PNG image data, 22 x 38, 8-bit/color RGB, non-interlacedEnglishUnited States1.0235849056603774
                                                                                                                                                                            PNG0x374d580x38dPNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012101210121012
                                                                                                                                                                            PNG0x3750e80x265PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0179445350734095
                                                                                                                                                                            PNG0x3754000x11aPNG image data, 30 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0319148936170213
                                                                                                                                                                            PNG0x3753500xaaPNG image data, 2 x 19, 8-bit/color RGB, non-interlacedEnglishUnited States1.011764705882353
                                                                                                                                                                            PNG0x3755200x12aPNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0268456375838926
                                                                                                                                                                            PNG0x374b480x209PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.021113243761996
                                                                                                                                                                            PNG0x375fd80xf5PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0244897959183674
                                                                                                                                                                            PNG0x3775a00xa6PNG image data, 54 x 31, 8-bit/color RGB, non-interlacedEnglishUnited States1.0180722891566265
                                                                                                                                                                            PNG0x3774500x150PNG image data, 54 x 124, 8-bit/color RGB, non-interlacedEnglishUnited States1.0327380952380953
                                                                                                                                                                            PNG0x375ce80xacPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0174418604651163
                                                                                                                                                                            PNG0x375d980x8bPNG image data, 3 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                                                                                                                                            PNG0x375e280x98PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006578947368421
                                                                                                                                                                            PNG0x375ec00x91PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006896551724138
                                                                                                                                                                            PNG0x375f580x7dPNG image data, 15 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.008
                                                                                                                                                                            PNG0x38d4200xa6PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                                                                                                                                            PNG0x38d3600xbdPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0105820105820107
                                                                                                                                                                            PNG0x3883600xa07PNG image data, 13 x 156, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004285157771718
                                                                                                                                                                            PNG0x37f9400x1de1PNG image data, 52 x 336, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0014380964832004
                                                                                                                                                                            PNG0x3817280x1bePNG image data, 38 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0246636771300448
                                                                                                                                                                            PNG0x3818e80x53bPNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082150858849888
                                                                                                                                                                            PNG0x38cef00x46cPNG image data, 22 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0097173144876326
                                                                                                                                                                            PNG0x3891f00xafPNG image data, 20 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171428571428571
                                                                                                                                                                            PNG0x3862700x701PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0061349693251533
                                                                                                                                                                            PNG0x3869780x498PNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0093537414965987
                                                                                                                                                                            PNG0x3878580x5c1PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0074677528852682
                                                                                                                                                                            PNG0x387e200x539PNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082273747195214
                                                                                                                                                                            PNG0x386e100x5c7PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0074374577417173
                                                                                                                                                                            PNG0x3873d80x47fPNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009556907037359
                                                                                                                                                                            PNG0x3795880x585PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0077848549186128
                                                                                                                                                                            PNG0x379ff80x546PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0081481481481482
                                                                                                                                                                            PNG0x379b100x4e1PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0088070456365092
                                                                                                                                                                            PNG0x37a5400x5b0PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.007554945054945
                                                                                                                                                                            PNG0x37dbb80x1b3PNG image data, 15 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.025287356321839
                                                                                                                                                                            PNG0x37dd700xeaPNG image data, 32 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0299145299145298
                                                                                                                                                                            PNG0x37de600x1ad9PNG image data, 38 x 114, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0016004655899897
                                                                                                                                                                            PNG0x3826f00xb43PNG image data, 22 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0038154699965314
                                                                                                                                                                            PNG0x3832380x609PNG image data, 11 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0071197411003237
                                                                                                                                                                            PNG0x3838480x18aePNG image data, 43 x 234, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0017410572966128
                                                                                                                                                                            PNG0x3850f80x1177PNG image data, 43 x 135, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0024602997092373
                                                                                                                                                                            PNG0x37b5c80x25ecPNG image data, 43 x 330, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0011330861145447
                                                                                                                                                                            PNG0x37aaf00xad3PNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039696860339227
                                                                                                                                                                            PNG0x38d5700xbc8PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036472148541113
                                                                                                                                                                            PNG0x38e1380xc2ePNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035279025016035
                                                                                                                                                                            PNG0x389f480x5ddPNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0073284477015323
                                                                                                                                                                            PNG0x3899b00x597PNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0076869322152342
                                                                                                                                                                            PNG0x3893b80x5f8PNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.007198952879581
                                                                                                                                                                            PNG0x388fc80x228PNG image data, 54 x 69, 8-bit/color RGBA, non-interlacedEnglishUnited States1.019927536231884
                                                                                                                                                                            PNG0x38a5280x588PNG image data, 22 x 44, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0077683615819208
                                                                                                                                                                            PNG0x381e280x38aPNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0121412803532008
                                                                                                                                                                            PNG0x3821b80x532PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082706766917293
                                                                                                                                                                            PNG0x3776480x32fPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0134969325153373
                                                                                                                                                                            PNG0x3779780xef8PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9950417536534447
                                                                                                                                                                            PNG0x3788700x7cPNG image data, 1 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9919354838709677
                                                                                                                                                                            PNG0x39aed00x13c1PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021752026893416
                                                                                                                                                                            PNG0x39d8900x37dPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0123180291153415
                                                                                                                                                                            PNG0x39d4f80x395PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0119956379498365
                                                                                                                                                                            PNG0x39c2980x125ePNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023394300297745
                                                                                                                                                                            PNG0x3980b80x13b4PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021808088818398
                                                                                                                                                                            PNG0x39ab600x369PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126002290950744
                                                                                                                                                                            PNG0x39a7900x3ccPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0113168724279835
                                                                                                                                                                            PNG0x3994700x1320PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002246732026144
                                                                                                                                                                            PNG0x39dc100x13acPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021842732327244
                                                                                                                                                                            PNG0x3a05f80x364PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012672811059908
                                                                                                                                                                            PNG0x3a02380x3baPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0115303983228512
                                                                                                                                                                            PNG0x39efc00x1274PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023285351397122
                                                                                                                                                                            PNG0x3927c80x139fPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021899263388414
                                                                                                                                                                            PNG0x3951480x380PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0122767857142858
                                                                                                                                                                            PNG0x394df00x352PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0129411764705882
                                                                                                                                                                            PNG0x393b680x1288PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002318718381113
                                                                                                                                                                            PNG0x38ed680x99dPNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004469727752946
                                                                                                                                                                            PNG0x38f7080x2e6PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0148247978436657
                                                                                                                                                                            PNG0x38fac80x13adPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021838395870557
                                                                                                                                                                            PNG0x3924600x365PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126582278481013
                                                                                                                                                                            PNG0x3920e80x374PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                                                                                                                                            PNG0x390e780x126bPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023329798515377
                                                                                                                                                                            PNG0x38f9f00xd4PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028301886792453
                                                                                                                                                                            PNG0x3a09600x1394PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00219473264166
                                                                                                                                                                            PNG0x3a33f80x374PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                                                                                                                                            PNG0x3a30000x3f4PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0108695652173914
                                                                                                                                                                            PNG0x3a1cf80x1304PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0022596548890714
                                                                                                                                                                            PNG0x3954c80x1397PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021934197407776
                                                                                                                                                                            PNG0x397d400x373PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0124575311438277
                                                                                                                                                                            PNG0x397a000x33dPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0132689987937273
                                                                                                                                                                            PNG0x3968600x119ePNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002439024390244
                                                                                                                                                                            PNG0x38d4c80xa6PNG image data, 15 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                                                                                                                                            PNG0x378be80x99dPNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004469727752946
                                                                                                                                                                            PNG0x3788f00x2f7PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0144927536231885
                                                                                                                                                                            PNG0x388dd00x17ePNG image data, 9 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0287958115183247
                                                                                                                                                                            PNG0x388f500x71PNG image data, 5 x 5, 8-bit/color RGB, non-interlacedEnglishUnited States0.9911504424778761
                                                                                                                                                                            PNG0x3892a00x117PNG image data, 11 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.021505376344086
                                                                                                                                                                            PNG0x388d680x67PNG image data, 2 x 55, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9902912621359223
                                                                                                                                                                            PNG0x38c0b80xd7PNG image data, 90 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0232558139534884
                                                                                                                                                                            PNG0x38c4b00xa40PNG image data, 86 x 240, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9733231707317073
                                                                                                                                                                            PNG0x38c1900x283PNG image data, 86 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171073094867806
                                                                                                                                                                            PNG0x38c4180x93PNG image data, 5 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0136054421768708
                                                                                                                                                                            PNG0x38b7480x96aPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004564315352697
                                                                                                                                                                            PNG0x38ada80x99bPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0044733631557543
                                                                                                                                                                            PNG0x38aab00x2f7PNG image data, 11 x 45, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0144927536231885
                                                                                                                                                                            PNG0x3735680x1d3PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.019271948608137
                                                                                                                                                                            PNG0x3737400x1f8PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0138888888888888
                                                                                                                                                                            PNG0x3739d00x67PNG image data, 2 x 20, 8-bit/color RGB, non-interlacedEnglishUnited States0.9514563106796117
                                                                                                                                                                            PNG0x3739380x95PNG image data, 11 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                                                                                                                                            PNG0x373a380x39dPNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011891891891892
                                                                                                                                                                            PNG0x373dd80x39dPNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011891891891892
                                                                                                                                                                            PNG0x3741780x1c1PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.024498886414254
                                                                                                                                                                            PNG0x3743400x153PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0324483775811208
                                                                                                                                                                            PNG0x3746580x15fPNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0113960113960114
                                                                                                                                                                            PNG0x3747b80x100PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.03515625
                                                                                                                                                                            PNG0x3744980x108PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.018939393939394
                                                                                                                                                                            PNG0x3745a00xb6PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010989010989011
                                                                                                                                                                            PNG0x3748b80x151PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.032640949554896
                                                                                                                                                                            PNG0x374a100x135PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.029126213592233
                                                                                                                                                                            PNG0x3765480xdd3PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9960440802486578
                                                                                                                                                                            PNG0x3773200x129PNG image data, 72 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0303030303030303
                                                                                                                                                                            PNG0x3761d80x10bPNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.0337078651685394
                                                                                                                                                                            PNG0x3761500x87PNG image data, 35 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0074074074074073
                                                                                                                                                                            PNG0x375ae00x12fPNG image data, 9 x 9, 8-bit/color RGB, non-interlacedEnglishUnited States1.0264026402640265
                                                                                                                                                                            PNG0x3756500x48dPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009442060085837
                                                                                                                                                                            PNG0x3a50c80xdd1PNG image data, 72 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003109980209217
                                                                                                                                                                            PNG0x3aa7800xd61PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0032116788321168
                                                                                                                                                                            PNG0x3ab4e80x265PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0179445350734095
                                                                                                                                                                            PNG0x3ab7500xbb9PNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036654448517162
                                                                                                                                                                            PNG0x3ac3100xc66PNG image data, 10 x 28, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034656584751103
                                                                                                                                                                            PNG0x3acf780xb90PNG image data, 10 x 28, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0037162162162163
                                                                                                                                                                            PNG0x3d01b00xb07PNG image data, 5 x 5, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003896563939072
                                                                                                                                                                            PNG0x3cf6600xb50PNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0037983425414365
                                                                                                                                                                            PNG0x3b84d00x2885PNG image data, 42 x 348, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0010604453870626
                                                                                                                                                                            PNG0x3bad580xd8ePNG image data, 38 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031700288184437
                                                                                                                                                                            PNG0x3bbae80x53bPNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082150858849888
                                                                                                                                                                            PNG0x3cccc00x4f3PNG image data, 22 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0086819258089976
                                                                                                                                                                            PNG0x3c03380x130fPNG image data, 22 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0022545603607296
                                                                                                                                                                            PNG0x3c16480xe74PNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002972972972973
                                                                                                                                                                            PNG0x3c44f80x11baPNG image data, 22 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002423975319524
                                                                                                                                                                            PNG0x3c56b80xecePNG image data, 11 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0029023746701846
                                                                                                                                                                            PNG0x3c24c00x11baPNG image data, 22 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002423975319524
                                                                                                                                                                            PNG0x3c36800xe74PNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002972972972973
                                                                                                                                                                            PNG0x3adb080x1206PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023840485478976
                                                                                                                                                                            PNG0x3afe400x11bcPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0024229074889868
                                                                                                                                                                            PNG0x3aed100x112aPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025034137460174
                                                                                                                                                                            PNG0x3b10000x127aPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023255813953489
                                                                                                                                                                            PNG0x3b4ba00xd3ePNG image data, 15 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003244837758112
                                                                                                                                                                            PNG0x3b58e00xbacPNG image data, 32 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036813922356091
                                                                                                                                                                            PNG0x3b70600x146aPNG image data, 56 x 69, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021048603138156
                                                                                                                                                                            PNG0x3bc0280x122fPNG image data, 22 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023630504833512
                                                                                                                                                                            PNG0x3bd2580xdecPNG image data, 11 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0030864197530864
                                                                                                                                                                            PNG0x3be0480x1100PNG image data, 42 x 228, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025275735294117
                                                                                                                                                                            PNG0x3bf1480x11edPNG image data, 42 x 140, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023970363913706
                                                                                                                                                                            PNG0x3b33380x1864PNG image data, 42 x 330, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0003203074951954
                                                                                                                                                                            PNG0x3b22800x10b5PNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025718961889174
                                                                                                                                                                            PNG0x3cd1b80x124bPNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023489216314327
                                                                                                                                                                            PNG0x3ce4080x1256PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023434171282488
                                                                                                                                                                            PNG0x3c83d80xf2cPNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002832131822863
                                                                                                                                                                            PNG0x3c74f80xedePNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0028901734104045
                                                                                                                                                                            PNG0x3c65880xf69PNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0027883396704689
                                                                                                                                                                            PNG0x3c93080xe20PNG image data, 22 x 44, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0030420353982301
                                                                                                                                                                            PNG0x3d0cb80xdc7PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031187978451943
                                                                                                                                                                            PNG0x3a5ea00xbaePNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036789297658864
                                                                                                                                                                            PNG0x3a6a500xd91PNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003167290526922
                                                                                                                                                                            PNG0x3a77e80xb12PNG image data, 1 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003881439661256
                                                                                                                                                                            PNG0x3dcd880xbc3PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036532713384259
                                                                                                                                                                            PNG0x3dc0e80xc9fPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003404518724853
                                                                                                                                                                            PNG0x3db3680xd7dPNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031856356791196
                                                                                                                                                                            PNG0x3da7700xbf7PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035912504080966
                                                                                                                                                                            PNG0x3d9ad80xc96PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034140285536934
                                                                                                                                                                            PNG0x3d8d480xd8cPNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031718569780854
                                                                                                                                                                            PNG0x3df3700xbdaPNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036255767963085
                                                                                                                                                                            PNG0x3de6d00xca0PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034034653465347
                                                                                                                                                                            PNG0x3dd9500xd80PNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031828703703705
                                                                                                                                                                            PNG0x3d5b680xbe2PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036160420775806
                                                                                                                                                                            PNG0x3d4ed80xc8cPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034246575342465
                                                                                                                                                                            PNG0x3d41580xd7bPNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031874818893074
                                                                                                                                                                            PNG0x3d35700xbe7PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036101083032491
                                                                                                                                                                            PNG0x3d28d80xc94PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034161490683229
                                                                                                                                                                            PNG0x3d1b580xd80PNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031828703703705
                                                                                                                                                                            PNG0x3d1a800xd4PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028301886792453
                                                                                                                                                                            PNG0x3e19680xbd0PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003637566137566
                                                                                                                                                                            PNG0x3e0cd00xc97PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034129692832765
                                                                                                                                                                            PNG0x3dff500xd7aPNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031884057971014
                                                                                                                                                                            PNG0x3d81680xbdaPNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036255767963085
                                                                                                                                                                            PNG0x3d74d80xc8fPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003421461897356
                                                                                                                                                                            PNG0x3d67500xd86PNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031773541305604
                                                                                                                                                                            PNG0x3a83000x1908PNG image data, 50 x 178, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9887640449438202
                                                                                                                                                                            PNG0x3a9c080xb75PNG image data, 3 x 61, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0037504261847938
                                                                                                                                                                            PNG0x3b64900xbd0PNG image data, 9 x 51, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003637566137566
                                                                                                                                                                            PNG0x3cb7500x1570PNG image data, 18 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0020043731778425
                                                                                                                                                                            PNG0x3ca1280x1623PNG image data, 18 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0019410622904534
                                                                                                                                                                            STYLE_XML0x2d64200x4e01HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.1839851770243878
                                                                                                                                                                            STYLE_XML0x308be00x4b09HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.20396689052006872
                                                                                                                                                                            STYLE_XML0x33ce880x4aa6HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.20460491889063318
                                                                                                                                                                            STYLE_XML0x36e6500x4a18HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.20397511598481655
                                                                                                                                                                            STYLE_XML0x3a37700x1955HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.1918272937548188
                                                                                                                                                                            RT_CURSOR0x2d4c880x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4805194805194805
                                                                                                                                                                            RT_CURSOR0x2d4dc00xb4Targa image data - Map 32 x 65536 x 1 +16 "\001"EnglishUnited States0.7
                                                                                                                                                                            RT_CURSOR0x2d4ea00x134AmigaOS bitmap font "(", fc_YSize 4294967264, 5120 elements, 2nd "\377\360?\377\377\370\177\377\377\374\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdEnglishUnited States0.36363636363636365
                                                                                                                                                                            RT_CURSOR0x2d4ff00x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.35714285714285715
                                                                                                                                                                            RT_CURSOR0x2d51400x134dataEnglishUnited States0.37337662337662336
                                                                                                                                                                            RT_CURSOR0x2d52900x134dataEnglishUnited States0.37662337662337664
                                                                                                                                                                            RT_CURSOR0x2d53e00x134Targa image data 64 x 65536 x 1 +32 "\001"EnglishUnited States0.36688311688311687
                                                                                                                                                                            RT_CURSOR0x2d55300x134Targa image data 64 x 65536 x 1 +32 "\001"EnglishUnited States0.37662337662337664
                                                                                                                                                                            RT_CURSOR0x2d56800x134Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.36688311688311687
                                                                                                                                                                            RT_CURSOR0x2d57d00x134Targa image data - RGB - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.38636363636363635
                                                                                                                                                                            RT_CURSOR0x2d59200x134dataEnglishUnited States0.44155844155844154
                                                                                                                                                                            RT_CURSOR0x2d5a700x134dataEnglishUnited States0.4155844155844156
                                                                                                                                                                            RT_CURSOR0x2d5bc00x134AmigaOS bitmap font "(", fc_YSize 4294966847, 3840 elements, 2nd "\377?\374\377\377\300\003\377\377\300\003\377\377\340\007\377\377\360\017\377\377\370\037\377\377\374?\377\377\376\177\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdEnglishUnited States0.5422077922077922
                                                                                                                                                                            RT_CURSOR0x2d5d100x134dataEnglishUnited States0.2662337662337662
                                                                                                                                                                            RT_CURSOR0x2d5e600x134dataEnglishUnited States0.2824675324675325
                                                                                                                                                                            RT_CURSOR0x2d5fb00x134dataEnglishUnited States0.3246753246753247
                                                                                                                                                                            RT_CURSOR0x40b8500x134dataEnglishUnited States0.20454545454545456
                                                                                                                                                                            RT_CURSOR0x40b9a00x134dataEnglishUnited States0.2857142857142857
                                                                                                                                                                            RT_CURSOR0x40baf00x134dataEnglishUnited States0.4675324675324675
                                                                                                                                                                            RT_CURSOR0x40bc400x134dataEnglishUnited States0.2532467532467532
                                                                                                                                                                            RT_CURSOR0x40bd900x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.40584415584415584
                                                                                                                                                                            RT_CURSOR0x40bee00x134dataEnglishUnited States0.4383116883116883
                                                                                                                                                                            RT_CURSOR0x40c0300x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4967532467532468
                                                                                                                                                                            RT_CURSOR0x40c1800x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.39285714285714285
                                                                                                                                                                            RT_CURSOR0x40c2d00x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4512987012987013
                                                                                                                                                                            RT_CURSOR0x40c4200x134dataEnglishUnited States0.37337662337662336
                                                                                                                                                                            RT_CURSOR0x40c5700x134dataEnglishUnited States0.4448051948051948
                                                                                                                                                                            RT_CURSOR0x40c6c00x134dataEnglishUnited States0.525974025974026
                                                                                                                                                                            RT_BITMAP0x3e4f900x62cDevice independent bitmap graphic, 324 x 9 x 4, image size 1476EnglishUnited States0.2430379746835443
                                                                                                                                                                            RT_BITMAP0x3e4ea80xe8Device independent bitmap graphic, 16 x 16 x 4, image size 128EnglishUnited States0.5818965517241379
                                                                                                                                                                            RT_BITMAP0x3e55c00x4a0Device independent bitmap graphic, 144 x 15 x 4, image size 1080EnglishUnited States0.3783783783783784
                                                                                                                                                                            RT_BITMAP0x3e5a600x197aDevice independent bitmap graphic, 144 x 15 x 24, image size 6482, resolution 2834 x 2834 px/mEnglishUnited States0.380098129408157
                                                                                                                                                                            RT_BITMAP0x3e73e00xc8Device independent bitmap graphic, 13 x 12 x 4, image size 96EnglishUnited States0.51
                                                                                                                                                                            RT_BITMAP0x3e76b80xc8Device independent bitmap graphic, 13 x 12 x 4, image size 96EnglishUnited States0.515
                                                                                                                                                                            RT_BITMAP0x3e79900xc8Device independent bitmap graphic, 13 x 12 x 4, image size 96EnglishUnited States0.43
                                                                                                                                                                            RT_BITMAP0x3e7c680xc8Device independent bitmap graphic, 13 x 12 x 4, image size 96EnglishUnited States0.44
                                                                                                                                                                            RT_BITMAP0x3e83a80x182aDevice independent bitmap graphic, 128 x 16 x 24, image size 6146, resolution 2834 x 2834 px/mEnglishUnited States0.2924345295829292
                                                                                                                                                                            RT_BITMAP0x3e7f400x468Device independent bitmap graphic, 128 x 16 x 4, image size 1024EnglishUnited States0.3058510638297872
                                                                                                                                                                            RT_BITMAP0x3e9bd80x528Device independent bitmap graphic, 16 x 16 x 8, image size 256EnglishUnited States0.4803030303030303
                                                                                                                                                                            RT_BITMAP0x3ea4300x528Device independent bitmap graphic, 16 x 16 x 8, image size 256EnglishUnited States0.4765151515151515
                                                                                                                                                                            RT_BITMAP0x3eac880x158Device independent bitmap graphic, 32 x 15 x 4, image size 240EnglishUnited States0.41569767441860467
                                                                                                                                                                            RT_BITMAP0x3eade00x188Device independent bitmap graphic, 48 x 12 x 4, image size 288EnglishUnited States0.39285714285714285
                                                                                                                                                                            RT_BITMAP0x3ebb980x1e8Device independent bitmap graphic, 48 x 16 x 4, image size 384EnglishUnited States0.5081967213114754
                                                                                                                                                                            RT_BITMAP0x3ec6a80xad2Device independent bitmap graphic, 29 x 31 x 24, image size 2730, resolution 2834 x 2834 px/mEnglishUnited States0.18736462093862816
                                                                                                                                                                            RT_BITMAP0x3ed1800xad2Device independent bitmap graphic, 29 x 31 x 24, image size 2730, resolution 2834 x 2834 px/mEnglishUnited States0.1844765342960289
                                                                                                                                                                            RT_BITMAP0x3edc580xb0aDevice independent bitmap graphic, 31 x 29 x 24, image size 2786, resolution 2834 x 2834 px/mEnglishUnited States0.19497523000707714
                                                                                                                                                                            RT_BITMAP0x3ee7680x7e2Device independent bitmap graphic, 25 x 26 x 24, image size 1978, resolution 2834 x 2834 px/mEnglishUnited States0.24033696729435083
                                                                                                                                                                            RT_BITMAP0x3eef500xb0aDevice independent bitmap graphic, 31 x 29 x 24, image size 2786, resolution 2834 x 2834 px/mEnglishUnited States0.1935598018400566
                                                                                                                                                                            RT_BITMAP0x3efa600x134Device independent bitmap graphic, 17 x 17 x 4, image size 204EnglishUnited States0.37337662337662336
                                                                                                                                                                            RT_BITMAP0x3ebd800x928Device independent bitmap graphic, 48 x 16 x 24, image size 0, resolution 2834 x 2834 px/mEnglishUnited States0.533703071672355
                                                                                                                                                                            RT_BITMAP0x3ea1000x32aDevice independent bitmap graphic, 16 x 16 x 24, image size 770, resolution 2834 x 2834 px/mEnglishUnited States0.7518518518518519
                                                                                                                                                                            RT_BITMAP0x3ea9580x32aDevice independent bitmap graphic, 16 x 16 x 24, image size 770, resolution 2834 x 2834 px/mEnglishUnited States0.3790123456790123
                                                                                                                                                                            RT_BITMAP0x3eaf680xc2aDevice independent bitmap graphic, 64 x 16 x 24, image size 3074, resolution 2834 x 2834 px/mEnglishUnited States0.42485549132947975
                                                                                                                                                                            RT_BITMAP0x3e74a80x20aDevice independent bitmap graphic, 13 x 12 x 24, image size 482, resolution 2834 x 2834 px/mEnglishUnited States0.9367816091954023
                                                                                                                                                                            RT_BITMAP0x3e77800x20aDevice independent bitmap graphic, 13 x 12 x 24, image size 482, resolution 2834 x 2834 px/mEnglishUnited States0.4482758620689655
                                                                                                                                                                            RT_BITMAP0x3e7a580x20aDevice independent bitmap graphic, 13 x 12 x 24, image size 482, resolution 2834 x 2834 px/mEnglishUnited States0.33524904214559387
                                                                                                                                                                            RT_BITMAP0x3e7d300x20aDevice independent bitmap graphic, 13 x 12 x 24, image size 482, resolution 2834 x 2834 px/mEnglishUnited States0.3371647509578544
                                                                                                                                                                            RT_BITMAP0x3efb980x32aDevice independent bitmap graphic, 16 x 16 x 24, image size 770, resolution 2834 x 2834 px/mEnglishUnited States0.6320987654320988
                                                                                                                                                                            RT_BITMAP0x3efec80x2256Device independent bitmap graphic, 324 x 9 x 24, image size 8750, resolution 2834 x 2834 px/mEnglishUnited States0.0608646188850967
                                                                                                                                                                            RT_BITMAP0x3f21200x602aDevice independent bitmap graphic, 192 x 32 x 32, image size 24578, resolution 2834 x 2834 px/mEnglishUnited States0.2250385896498497
                                                                                                                                                                            RT_BITMAP0x3f81500x2028Device independent bitmap graphic, 128 x 16 x 32, image size 0EnglishUnited States0.24708454810495628
                                                                                                                                                                            RT_BITMAP0x3fa1780x13daDevice independent bitmap graphic, 35 x 36 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.11570247933884298
                                                                                                                                                                            RT_BITMAP0x3fb5580x13daDevice independent bitmap graphic, 35 x 36 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.10999606454151908
                                                                                                                                                                            RT_BITMAP0x3fc9380x13daDevice independent bitmap graphic, 36 x 35 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.11511216056670602
                                                                                                                                                                            RT_BITMAP0x3fdd180xeb2Device independent bitmap graphic, 31 x 30 x 32, image size 3722, resolution 2834 x 2834 px/mEnglishUnited States0.13157894736842105
                                                                                                                                                                            RT_BITMAP0x3febd00x13daDevice independent bitmap graphic, 36 x 35 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.11983471074380166
                                                                                                                                                                            RT_BITMAP0x3fffb00x13daDevice independent bitmap graphic, 35 x 36 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.27371113734750097
                                                                                                                                                                            RT_BITMAP0x4013900x13daDevice independent bitmap graphic, 35 x 36 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.2699724517906336
                                                                                                                                                                            RT_BITMAP0x4027700x13daDevice independent bitmap graphic, 36 x 35 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.2426210153482881
                                                                                                                                                                            RT_BITMAP0x403b500xeb2Device independent bitmap graphic, 31 x 30 x 32, image size 3722, resolution 2834 x 2834 px/mEnglishUnited States0.3413078149920255
                                                                                                                                                                            RT_BITMAP0x404a080x13daDevice independent bitmap graphic, 36 x 35 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.23868555686737505
                                                                                                                                                                            RT_BITMAP0x405de80x5a66Device independent bitmap graphic, 77 x 75 x 32, image size 23102, resolution 2834 x 2834 px/mEnglishUnited States0.046365914786967416
                                                                                                                                                                            RT_BITMAP0x2d62200xb8Device independent bitmap graphic, 12 x 10 x 4, image size 80EnglishUnited States0.44565217391304346
                                                                                                                                                                            RT_BITMAP0x2d62d80x144Device independent bitmap graphic, 33 x 11 x 4, image size 220EnglishUnited States0.37962962962962965
                                                                                                                                                                            RT_ICON0x2cd3580xa68Device independent bitmap graphic, 64 x 128 x 4, image size 2048EnglishGreat Britain0.1174924924924925
                                                                                                                                                                            RT_ICON0x2cddc00x668Device independent bitmap graphic, 48 x 96 x 4, image size 1152EnglishGreat Britain0.15792682926829268
                                                                                                                                                                            RT_ICON0x2ce4280x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512EnglishGreat Britain0.23387096774193547
                                                                                                                                                                            RT_ICON0x2ce7100x128Device independent bitmap graphic, 16 x 32 x 4, image size 128EnglishGreat Britain0.39864864864864863
                                                                                                                                                                            RT_ICON0x2ce8380x1628Device independent bitmap graphic, 64 x 128 x 8, image size 4096, 256 important colorsEnglishGreat Britain0.08339210155148095
                                                                                                                                                                            RT_ICON0x2cfe600xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsEnglishGreat Britain0.1023454157782516
                                                                                                                                                                            RT_ICON0x2d0d080x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsEnglishGreat Britain0.10649819494584838
                                                                                                                                                                            RT_ICON0x2d15b00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishGreat Britain0.08475103734439834
                                                                                                                                                                            RT_ICON0x2d3b580x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishGreat Britain0.09920262664165103
                                                                                                                                                                            RT_ICON0x40c8480x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640EnglishUnited States0.33198924731182794
                                                                                                                                                                            RT_ICON0x40cb300x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.41216216216216217
                                                                                                                                                                            RT_ICON0x40cc800x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.42905405405405406
                                                                                                                                                                            RT_ICON0x40cda80x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640EnglishUnited States0.2661290322580645
                                                                                                                                                                            RT_ICON0x40d0b80x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512EnglishUnited States0.18010752688172044
                                                                                                                                                                            RT_ICON0x40d3a00x128Device independent bitmap graphic, 16 x 32 x 4, image size 128EnglishUnited States0.35135135135135137
                                                                                                                                                                            RT_ICON0x40d4c80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsEnglishUnited States0.06092057761732852
                                                                                                                                                                            RT_ICON0x40dd700x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsEnglishUnited States0.07658959537572255
                                                                                                                                                                            RT_ICON0x40e2d80xca8Device independent bitmap graphic, 32 x 64 x 24, image size 3072EnglishUnited States0.042901234567901236
                                                                                                                                                                            RT_ICON0x40ef800x368Device independent bitmap graphic, 16 x 32 x 24, image size 768EnglishUnited States0.10550458715596331
                                                                                                                                                                            RT_ICON0x40f3480x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.6400709219858156
                                                                                                                                                                            RT_ICON0x40f7b00x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.5
                                                                                                                                                                            RT_MENU0x40f9000x11cdataEnglishUnited States0.573943661971831
                                                                                                                                                                            RT_DIALOG0x2cb1500x140dataEnglishUnited States0.553125
                                                                                                                                                                            RT_DIALOG0x2cb2900x190dataEnglishUnited States0.475
                                                                                                                                                                            RT_DIALOG0x2caed00x134dataEnglishUnited States0.6038961038961039
                                                                                                                                                                            RT_DIALOG0x2cb4200xf0dataEnglishUnited States0.6125
                                                                                                                                                                            RT_DIALOG0x2cb0080x148dataEnglishUnited States0.5640243902439024
                                                                                                                                                                            RT_DIALOG0x2cb5100x2fcdataEnglishUnited States0.39397905759162305
                                                                                                                                                                            RT_DIALOG0x2cbca00x1e2dataEnglishUnited States0.4979253112033195
                                                                                                                                                                            RT_DIALOG0x2cc5c00x198dataEnglishUnited States0.5416666666666666
                                                                                                                                                                            RT_DIALOG0x2cc7580x1fedataEnglishUnited States0.4666666666666667
                                                                                                                                                                            RT_DIALOG0x2cc9580x190dataEnglishUnited States0.485
                                                                                                                                                                            RT_DIALOG0x2ccae80x198dataEnglishUnited States0.5416666666666666
                                                                                                                                                                            RT_DIALOG0x2ccc800x222dataEnglishUnited States0.46886446886446886
                                                                                                                                                                            RT_DIALOG0x2cb8100x276dataEnglishUnited States0.42063492063492064
                                                                                                                                                                            RT_DIALOG0x2cba880x218dataEnglishUnited States0.42723880597014924
                                                                                                                                                                            RT_DIALOG0x2cbe880x238dataEnglishUnited States0.3961267605633803
                                                                                                                                                                            RT_DIALOG0x2cc0c00x4fcdataEnglishUnited States0.26880877742946707
                                                                                                                                                                            RT_DIALOG0x3e2c280x13cdataEnglishUnited States0.5949367088607594
                                                                                                                                                                            RT_DIALOG0x3e2d680x1a4dataEnglishUnited States0.5380952380952381
                                                                                                                                                                            RT_DIALOG0x3e25900xe6dataEnglishUnited States0.6347826086956522
                                                                                                                                                                            RT_DIALOG0x3e26780x390dataEnglishUnited States0.4418859649122807
                                                                                                                                                                            RT_DIALOG0x3e2a080x21cdataEnglishUnited States0.5037037037037037
                                                                                                                                                                            RT_DIALOG0x3e2f100x390dataEnglishUnited States0.4692982456140351
                                                                                                                                                                            RT_DIALOG0x3e32a00x1dcdataEnglishUnited States0.5441176470588235
                                                                                                                                                                            RT_DIALOG0x3e34800x346dataEnglishUnited States0.46897374701670647
                                                                                                                                                                            RT_DIALOG0x3e37c80x334dataEnglishUnited States0.43658536585365854
                                                                                                                                                                            RT_DIALOG0x3e25380x58dataEnglishUnited States0.8068181818181818
                                                                                                                                                                            RT_DIALOG0x3e3b000x23cdataEnglishUnited States0.5122377622377622
                                                                                                                                                                            RT_DIALOG0x3e44d00x1c2dataEnglishUnited States0.5066666666666667
                                                                                                                                                                            RT_DIALOG0x3e3d400x160dataEnglishUnited States0.5994318181818182
                                                                                                                                                                            RT_DIALOG0x3e3ea00xb2dataEnglishUnited States0.7191011235955056
                                                                                                                                                                            RT_DIALOG0x3e3f580x3d4dataEnglishUnited States0.3408163265306122
                                                                                                                                                                            RT_DIALOG0x3e43300x19edataEnglishUnited States0.6280193236714976
                                                                                                                                                                            RT_DIALOG0x3e46980x1a2dataEnglishUnited States0.5741626794258373
                                                                                                                                                                            RT_DIALOG0x3e48400x34dataEnglishUnited States0.8076923076923077
                                                                                                                                                                            RT_DIALOG0x3e48780x2a8dataEnglishUnited States0.5338235294117647
                                                                                                                                                                            RT_DIALOG0x3e4b200x382dataEnglishUnited States0.48552338530066813
                                                                                                                                                                            RT_DIALOG0x2d61000xe8dataEnglishUnited States0.6336206896551724
                                                                                                                                                                            RT_DIALOG0x2d61e80x34dataEnglishUnited States0.9038461538461539
                                                                                                                                                                            RT_STRING0x40fa200x44dataEnglishUnited States0.6323529411764706
                                                                                                                                                                            RT_STRING0x4115400x32cdataEnglishUnited States0.4125615763546798
                                                                                                                                                                            RT_STRING0x4118700x248dataEnglishUnited States0.5085616438356164
                                                                                                                                                                            RT_STRING0x4125680x84dataEnglishUnited States0.5833333333333334
                                                                                                                                                                            RT_STRING0x411ab80x2a8dataEnglishUnited States0.36176470588235293
                                                                                                                                                                            RT_STRING0x411d600x20edataEnglishUnited States0.3155893536121673
                                                                                                                                                                            RT_STRING0x411f700x24cdataEnglishUnited States0.4370748299319728
                                                                                                                                                                            RT_STRING0x4125f00x3cdataEnglishUnited States0.65
                                                                                                                                                                            RT_STRING0x4121c00x16edataEnglishUnited States0.39344262295081966
                                                                                                                                                                            RT_STRING0x4123300xa6Matlab v4 mat-file (little endian) T, numeric, rows 0, columns 0EnglishUnited States0.7228915662650602
                                                                                                                                                                            RT_STRING0x4126300x184dataEnglishUnited States0.4742268041237113
                                                                                                                                                                            RT_STRING0x4127b80x66dataEnglishUnited States0.696078431372549
                                                                                                                                                                            RT_STRING0x412a600x1d6Matlab v4 mat-file (little endian) S, numeric, rows 0, columns 0EnglishUnited States0.35319148936170214
                                                                                                                                                                            RT_STRING0x4128200x186dataEnglishUnited States0.5384615384615384
                                                                                                                                                                            RT_STRING0x4129a80xb2dataEnglishUnited States0.6179775280898876
                                                                                                                                                                            RT_STRING0x412c380x48Matlab v4 mat-file (little endian) a, numeric, rows 0, columns 0EnglishUnited States0.7083333333333334
                                                                                                                                                                            RT_STRING0x4123d80x18cdataEnglishUnited States0.398989898989899
                                                                                                                                                                            RT_STRING0x40fa680x82StarOffice Gallery theme p, 536899072 objects, 1st nEnglishUnited States0.7153846153846154
                                                                                                                                                                            RT_STRING0x40faf00x2adataEnglishUnited States0.5476190476190477
                                                                                                                                                                            RT_STRING0x40fb200x184dataEnglishUnited States0.48711340206185566
                                                                                                                                                                            RT_STRING0x40fca80x4eedataEnglishUnited States0.375594294770206
                                                                                                                                                                            RT_STRING0x4105280x264dataEnglishUnited States0.3333333333333333
                                                                                                                                                                            RT_STRING0x4102480x2dadataEnglishUnited States0.3698630136986301
                                                                                                                                                                            RT_STRING0x410f700x8adataEnglishUnited States0.6594202898550725
                                                                                                                                                                            RT_STRING0x4101980xacdataEnglishUnited States0.45348837209302323
                                                                                                                                                                            RT_STRING0x410e600xdedataEnglishUnited States0.536036036036036
                                                                                                                                                                            RT_STRING0x4107900x4a8dataEnglishUnited States0.3221476510067114
                                                                                                                                                                            RT_STRING0x410c380x228dataEnglishUnited States0.4003623188405797
                                                                                                                                                                            RT_STRING0x410f400x2cdataEnglishUnited States0.5227272727272727
                                                                                                                                                                            RT_STRING0x4110000x53edataEnglishUnited States0.2965722801788376
                                                                                                                                                                            RT_GROUP_CURSOR0x40c4080x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40c1680x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
                                                                                                                                                                            RT_GROUP_CURSOR0x40b9880x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40bad80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40bc280x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40bd780x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40bec80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40c0180x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40c2b80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40c5580x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40c6a80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x40c7f80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d4e780x22Lotus unknown worksheet or configuration, revision 0x2EnglishUnited States1.0294117647058822
                                                                                                                                                                            RT_GROUP_CURSOR0x2d56680x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d4fd80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d55180x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d53c80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d5cf80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d52780x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d59080x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d51280x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d57b80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d5a580x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d5ba80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d5e480x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d5f980x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_CURSOR0x2d60e80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                                                                                                                                            RT_GROUP_ICON0x2d4c000x84dataEnglishGreat Britain0.6666666666666666
                                                                                                                                                                            RT_GROUP_ICON0x40cc580x22dataEnglishUnited States1.0588235294117647
                                                                                                                                                                            RT_GROUP_ICON0x40d0900x22dataEnglishUnited States1.0588235294117647
                                                                                                                                                                            RT_GROUP_ICON0x40f2e80x5adataEnglishUnited States0.7555555555555555
                                                                                                                                                                            RT_GROUP_ICON0x40f8d80x22dataEnglishUnited States1.1176470588235294
                                                                                                                                                                            RT_VERSION0x2ccea80x234dataEnglishUnited States0.48404255319148937
                                                                                                                                                                            RT_MANIFEST0x42ffa00x7f0XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1972), with CRLF line terminatorsEnglishUnited States0.32234251968503935
                                                                                                                                                                            None0x2cd1600x1f1dataEnglishUnited States0.17706237424547283
                                                                                                                                                                            None0x40c8100x1cdataEnglishUnited States1.2857142857142858
                                                                                                                                                                            None0x40c8300x18dataEnglishUnited States1.2916666666666667
                                                                                                                                                                            DLLImport
                                                                                                                                                                            KERNEL32.dllGetTimeFormatW, GetDateFormatW, GetConsoleMode, GetConsoleOutputCP, SetFilePointerEx, GetTimeZoneInformation, ExitProcess, GetStdHandle, GetFileType, SetStdHandle, VirtualQuery, VirtualAlloc, GetSystemInfo, HeapQueryInformation, GetCommandLineW, GetCommandLineA, FreeLibraryAndExitThread, ExitThread, CreateThread, RtlUnwind, GetCPInfo, CompareStringEx, IsValidLocale, LCMapStringEx, GetStringTypeW, GetModuleHandleExW, CloseThreadpoolWork, SubmitThreadpoolWork, CreateThreadpoolWork, FreeLibraryWhenCallbackReturns, TryAcquireSRWLockExclusive, QueryPerformanceFrequency, InitOnceBeginInitialize, InitOnceComplete, AreFileApisANSI, FindFirstFileExW, FormatMessageA, RaiseException, LCMapStringW, EnumSystemLocalesW, ReadConsoleW, IsValidCodePage, GetACP, GetOEMCP, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, WriteConsoleW, GetStartupInfoW, IsDebuggerPresent, InitializeSListHead, GetSystemTimeAsFileTime, QueryPerformanceCounter, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, IsProcessorFeaturePresent, SleepConditionVariableSRW, WakeAllConditionVariable, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, GetUserDefaultLCID, SearchPathW, GetProfileIntW, GetTickCount64, GetWindowsDirectoryW, FindResourceExW, GetDriveTypeW, SetErrorMode, GetFileTime, GetFileSizeEx, GetFileAttributesExW, GetCurrentDirectoryW, GetFileAttributesW, VirtualProtect, GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetLocaleInfoW, GlobalFlags, LocalReAlloc, GlobalHandle, GlobalReAlloc, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, InitializeCriticalSection, GlobalGetAtomNameW, InitializeCriticalSectionAndSpinCount, GetThreadLocale, lstrcmpiW, DuplicateHandle, WriteFile, UnlockFile, SetFilePointer, SetEndOfFile, ReadFile, LockFile, GetVolumeInformationW, GetFullPathNameW, GetFileSize, FlushFileBuffers, CreateFileW, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, FileTimeToLocalFileTime, lstrcpyW, WritePrivateProfileStringW, GetPrivateProfileStringW, GetPrivateProfileIntW, lstrcmpA, GetCurrentThread, ResumeThread, SetThreadPriority, CompareStringW, GlobalFindAtomW, GlobalAddAtomW, lstrcmpW, GlobalDeleteAtom, LoadLibraryW, LoadLibraryA, LoadLibraryExW, GetProcAddress, GetModuleHandleA, FreeLibrary, GetSystemDirectoryW, GetCurrentThreadId, EncodePointer, OutputDebugStringA, GetCurrentProcessId, CopyFileW, MulDiv, GlobalSize, SetLastError, GetExitCodeProcess, IsWow64Process, GetModuleHandleW, CreateProcessW, GlobalFree, GetVersionExW, LocalAlloc, WaitForSingleObject, FindClose, GetModuleFileNameW, GetCurrentProcess, FindNextFileW, FindFirstFileW, GetTickCount, GetWindowsDirectoryA, GlobalMemoryStatusEx, SizeofResource, Process32FirstW, GetDiskFreeSpaceExW, Process32NextW, CreateToolhelp32Snapshot, GetUserDefaultLocaleName, GetLocaleInfoEx, VerifyVersionInfoW, VerSetConditionMask, LocalFree, FormatMessageW, GlobalUnlock, GlobalLock, GlobalAlloc, MoveFileExW, CloseHandle, OutputDebugStringW, CreateMutexW, RemoveDirectoryW, GetTempFileNameW, DeleteFileW, MultiByteToWideChar, GetTempPathW, GetEnvironmentVariableW, CreateDirectoryW, WideCharToMultiByte, GetProcessHeap, DeleteCriticalSection, DecodePointer, HeapAlloc, FindResourceW, LoadResource, HeapReAlloc, LockResource, GetLastError, Sleep, HeapSize, InitializeCriticalSectionEx, LeaveCriticalSection, EnterCriticalSection, HeapFree
                                                                                                                                                                            USER32.dllGetKeyNameTextW, EnumDisplayMonitors, SystemParametersInfoW, LoadCursorW, SetLayeredWindowAttributes, MapDialogRect, SetWindowContextHelpId, SetCursor, ShowOwnedPopups, PostQuitMessage, DrawIconEx, IsRectEmpty, InflateRect, DrawFocusRect, GetSysColorBrush, SetWindowRgn, DrawFrameControl, DrawEdge, GetCursorPos, TranslateMessage, GetMessageW, SetMenuItemInfoW, GetMenuCheckMarkDimensions, SetMenuItemBitmaps, EnableMenuItem, CheckMenuItem, OffsetRect, SetRectEmpty, SendDlgItemMessageA, LoadMenuW, GetDesktopWindow, GetActiveWindow, GetNextDlgTabItem, EndDialog, CreateDialogIndirectParamW, IsDialogMessageW, SetWindowTextW, CheckDlgButton, MoveWindow, LockWindowUpdate, MapVirtualKeyW, GetDoubleClickTime, GetIconInfo, CopyIcon, GetMenuDefaultItem, UnregisterClassW, EnableWindow, ShowWindow, GetMonitorInfoW, MonitorFromWindow, WinHelpW, GetScrollInfo, SetScrollInfo, CallNextHookEx, UnhookWindowsHookEx, SetWindowsHookExW, GetWindow, GetTopWindow, GetClassLongW, SetWindowLongW, PtInRect, EqualRect, CopyRect, MapWindowPoints, AdjustWindowRectEx, GetWindowTextLengthW, GetWindowTextW, RemovePropW, GetPropW, SetPropW, ShowScrollBar, SetMenuDefaultItem, SetClipboardData, EmptyClipboard, SetParent, MonitorFromPoint, IsZoomed, SetCapture, ReleaseCapture, DeleteMenu, MessageBeep, WindowFromPoint, NotifyWinEvent, SetCursorPos, SetRect, UnionRect, BringWindowToTop, DestroyMenu, SetScrollRange, GetScrollPos, GetMenuItemInfoW, CharUpperW, IntersectRect, RealChildWindowFromPoint, CopyImage, GetAsyncKeyState, CreatePopupMenu, TrackMouseEvent, DestroyIcon, LoadImageW, OpenClipboard, EnableScrollBar, SendMessageW, IsIconic, AppendMenuW, GetClientRect, RemoveMenu, LoadIconW, DrawIcon, GetSystemMetrics, GetWindowRect, PostMessageW, GetSystemMenu, InvalidateRect, KillTimer, SetTimer, GetParent, GetMenuStringW, GetMenuState, GetSubMenu, GetMenuItemID, GetMenuItemCount, InsertMenuW, IsWindowEnabled, MessageBoxW, GetWindowLongW, GetWindowThreadProcessId, GetLastActivePopup, DrawTextW, DrawTextExW, GrayStringW, TabbedTextOutW, GetDC, GetWindowDC, ReleaseDC, BeginPaint, EndPaint, ClientToScreen, ScreenToClient, GetSysColor, FillRect, DrawStateW, UpdateWindow, GetClassNameW, LoadBitmapW, RegisterWindowMessageW, DispatchMessageW, PeekMessageW, GetMessagePos, GetMessageTime, DefWindowProcW, CallWindowProcW, RegisterClassW, GetClassInfoW, GetClassInfoExW, CreateWindowExW, IsWindow, IsMenu, IsChild, DestroyWindow, SetWindowPos, GetWindowPlacement, SetWindowPlacement, BeginDeferWindowPos, DeferWindowPos, EndDeferWindowPos, IsWindowVisible, GetDlgItem, GetDlgCtrlID, SetFocus, GetFocus, GetKeyState, GetCapture, GetMenu, SetMenu, TrackPopupMenu, SetActiveWindow, GetForegroundWindow, SetForegroundWindow, ValidateRect, RedrawWindow, ScrollWindow, SetScrollPos, ModifyMenuW, DestroyAcceleratorTable, SetClassLongW, GetUpdateRect, CloseClipboard, WaitMessage, CharNextW, CopyAcceleratorTableW, InvalidateRgn, GetNextDlgGroupItem, IsClipboardFormatAvailable, ToUnicodeEx, GetKeyboardLayout, GetKeyboardState, LoadAcceleratorsW, CreateAcceleratorTableW, UpdateLayeredWindow, HideCaret, InvertRect, FrameRect, SubtractRect, RegisterClipboardFormatW, CharUpperBuffW, TranslateAcceleratorW, InsertMenuItemW, UnpackDDElParam, ReuseDDElParam, PostThreadMessageW, IsCharLowerW, MapVirtualKeyExW, DrawMenuBar, DefFrameProcW, DefMDIChildProcW, TranslateMDISysAccel, GetComboBoxInfo, CreateMenu, DestroyCursor, GetWindowRgn, GetScrollRange
                                                                                                                                                                            GDI32.dllLineTo, PtVisible, RectVisible, RestoreDC, SaveDC, SelectClipRgn, ExtSelectClipRgn, SelectObject, SelectPalette, SetBkColor, SetBkMode, SetMapMode, GetLayout, SetPolyFillMode, SetROP2, SetTextColor, SetTextAlign, MoveToEx, TextOutW, ExtTextOutW, SetViewportExtEx, SetViewportOrgEx, SetWindowExtEx, SetWindowOrgEx, OffsetViewportOrgEx, OffsetWindowOrgEx, ScaleViewportExtEx, ScaleWindowExtEx, CombineRgn, CreateEllipticRgn, CreateRectRgnIndirect, Ellipse, GetBkColor, GetTextColor, GetTextExtentPoint32W, IntersectClipRect, CreatePolygonRgn, Polygon, Polyline, GetTextMetricsW, CreateCompatibleBitmap, CreateDIBitmap, EnumFontFamiliesW, GetTextCharsetInfo, GetMapMode, SetRectRgn, DPtoLP, RealizePalette, SetPixel, StretchBlt, CreateDIBSection, SetDIBColorTable, CreateRoundRectRgn, Rectangle, GetRgnBox, OffsetRgn, RoundRect, CreatePalette, GetPaletteEntries, EnumFontFamiliesExW, GetNearestPaletteIndex, GetSystemPaletteEntries, LPtoDP, ExtFloodFill, SetPaletteEntries, FillRgn, FrameRgn, GetBoundsRect, PtInRegion, GetViewportOrgEx, GetWindowOrgEx, SetPixelV, GetTextFaceW, GetWindowExtEx, GetViewportExtEx, GetStockObject, GetPixel, GetObjectType, GetClipBox, ExcludeClipRect, Escape, DeleteObject, CreateRectRgn, CreatePatternBrush, CreatePen, CreateHatchBrush, DeleteDC, CreateFontIndirectW, CreateSolidBrush, GetObjectW, CopyMetaFileW, CreateDCW, GetDeviceCaps, BitBlt, CreateBitmap, CreateCompatibleDC, PatBlt, SetLayout
                                                                                                                                                                            MSIMG32.dllAlphaBlend, TransparentBlt
                                                                                                                                                                            WINSPOOL.DRVDocumentPropertiesW, OpenPrinterW, ClosePrinter
                                                                                                                                                                            ADVAPI32.dllCryptDestroyHash, RegQueryValueExA, RegEnumValueW, RegQueryValueW, RegEnumKeyW, RegDeleteValueW, RegDeleteKeyW, CryptAcquireContextW, CryptCreateHash, CryptHashData, RegOpenKeyExA, CryptGetHashParam, CryptReleaseContext, RegCreateKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegEnumKeyExW, RegOpenKeyExW, RegGetValueW, RegQueryValueExW, RegCloseKey
                                                                                                                                                                            SHELL32.dllDragFinish, DragQueryFileW, SHAppBarMessage, SHGetFileInfoW, SHGetDesktopFolder, SHBrowseForFolderW, SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHGetMalloc, ShellExecuteW, SHGetKnownFolderPath, SHGetFolderPathW
                                                                                                                                                                            COMCTL32.dllInitCommonControlsEx
                                                                                                                                                                            SHLWAPI.dllPathRemoveFileSpecW, StrFormatKBSizeW, PathStripToRootW, PathIsUNCW, PathFindFileNameW, PathFindExtensionW, PathAppendW, PathIsDirectoryEmptyW, PathFileExistsW, PathIsDirectoryW
                                                                                                                                                                            UxTheme.dllDrawThemeText, IsAppThemed, OpenThemeData, CloseThemeData, GetThemePartSize, GetThemeSysColor, DrawThemeBackground, GetThemeColor, GetCurrentThemeName, DrawThemeParentBackground, GetWindowTheme, IsThemeBackgroundPartiallyTransparent
                                                                                                                                                                            ole32.dllRegisterDragDrop, IsAccelerator, OleTranslateAccelerator, OleDestroyMenuDescriptor, OleCreateMenuDescriptor, OleUninitialize, OleInitialize, CoFreeUnusedLibraries, CoInitializeEx, OleLockRunning, RevokeDragDrop, CoLockObjectExternal, OleGetClipboard, DoDragDrop, OleIsCurrentClipboard, CreateILockBytesOnHGlobal, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CoGetClassObject, CoDisconnectObject, CLSIDFromProgID, CLSIDFromString, CoCreateGuid, ReleaseStgMedium, OleDuplicateData, CoTaskMemAlloc, CoCreateInstance, CoUninitialize, CoInitialize, CreateStreamOnHGlobal, CoTaskMemFree, CoRevokeClassObject, CoRegisterMessageFilter, OleFlushClipboard
                                                                                                                                                                            OLEAUT32.dllSafeArrayDestroy, VariantCopy, VariantTimeToSystemTime, SystemTimeToVariantTime, VariantChangeType, VariantClear, VariantInit, SysAllocStringLen, SysFreeString, SysAllocStringByteLen, SysAllocString, SysStringLen, OleCreateFontIndirect, LoadTypeLib, VarBstrFromDate
                                                                                                                                                                            oledlg.dllOleUIBusyW
                                                                                                                                                                            gdiplus.dllGdipSetInterpolationMode, GdipCreateBitmapFromHBITMAP, GdipDrawImageI, GdipBitmapUnlockBits, GdipBitmapLockBits, GdipCreateBitmapFromScan0, GdipGetImagePaletteSize, GdipGetImagePalette, GdipGetImagePixelFormat, GdipGetImageHeight, GdipGetImageWidth, GdipGetImageGraphicsContext, GdipCreateBitmapFromStream, GdiplusShutdown, GdiplusStartup, GdipLoadImageFromStream, GdipDeleteGraphics, GdipCreateFromHDC, GdipFree, GdipDisposeImage, GdipDrawImageRectI, GdipAlloc, GdipCloneImage
                                                                                                                                                                            WINHTTP.dllWinHttpQueryDataAvailable, WinHttpCloseHandle, WinHttpSetOption, WinHttpConnect, WinHttpCrackUrl, WinHttpSendRequest, WinHttpOpenRequest, WinHttpReadData, WinHttpQueryHeaders, WinHttpOpen, WinHttpReceiveResponse, WinHttpAddRequestHeaders
                                                                                                                                                                            WININET.dllInternetOpenW, HttpQueryInfoW, InternetCloseHandle, InternetReadFile, InternetOpenUrlW
                                                                                                                                                                            VERSION.dllVerQueryValueW
                                                                                                                                                                            ntdll.dllRtlGetVersion
                                                                                                                                                                            OLEACC.dllAccessibleObjectFromWindow, LresultFromObject, CreateStdAccessibleObject
                                                                                                                                                                            IMM32.dllImmReleaseContext, ImmGetOpenStatus, ImmGetContext
                                                                                                                                                                            WINMM.dllPlaySoundW
                                                                                                                                                                            Language of compilation systemCountry where language is spokenMap
                                                                                                                                                                            EnglishUnited States
                                                                                                                                                                            EnglishGreat Britain
                                                                                                                                                                            Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

                                                                                                                                                                            Click to jump to process

                                                                                                                                                                            Click to jump to process

                                                                                                                                                                            Click to dive into process behavior distribution

                                                                                                                                                                            Click to jump to process

                                                                                                                                                                            Target ID:0
                                                                                                                                                                            Start time:05:09:03
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe
                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                            Commandline:"C:\Users\user\Desktop\grand-theft-auto-5-theme-1-installer_qb8W-j1.exe"
                                                                                                                                                                            Imagebase:0xc10000
                                                                                                                                                                            File size:4'547'440 bytes
                                                                                                                                                                            MD5 hash:1D5608C770DD48F9F15C6A303C08CDD5
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Reputation:low
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:4
                                                                                                                                                                            Start time:05:09:56
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe
                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                            Commandline:"C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe" /affid 91088 PaidDistribution=true CountryCode=US
                                                                                                                                                                            Imagebase:0xd00000
                                                                                                                                                                            File size:1'184'128 bytes
                                                                                                                                                                            MD5 hash:143255618462A577DE27286A272584E1
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Reputation:moderate
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:5
                                                                                                                                                                            Start time:05:09:56
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe
                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                            Commandline:"C:\Users\user\AppData\Local\Temp\ISVD440.tmp\OperaSetup\OperaSetup.exe" --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b
                                                                                                                                                                            Imagebase:0xf90000
                                                                                                                                                                            File size:2'230'896 bytes
                                                                                                                                                                            MD5 hash:7576A1BF33EDB92CE3CAC344DE107AFB
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Reputation:low
                                                                                                                                                                            Has exited:false

                                                                                                                                                                            Target ID:6
                                                                                                                                                                            Start time:05:09:58
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                            Commandline:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --silent --allusers=0 --otd=utm.medium:apb,utm.source:ais,utm.campaign:opera_new_b --server-tracking-blob=NDg5MmM0M2NiZmYxOTc2MjY3ZDE3MGIyMzA3NGYyODVjNDZhOGNmNjg5YTA1ZDg5NTRhNThiN2MxZWIzZDk4OTp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijoib3BlcmEiLCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInRpbWVzdGFtcCI6IjE3MzUwMzgwMTIuNzc0NSIsInVzZXJhZ2VudCI6InB5dGhvbi1yZXF1ZXN0cy8yLjMyLjMiLCJ1dG0iOnt9LCJ1dWlkIjoiYWFmNjZmNDQtNWMyYy00ZmJmLTg0YmQtN2Y2OTE0MGY0MGRiIn0=
                                                                                                                                                                            Imagebase:0xa30000
                                                                                                                                                                            File size:5'749'656 bytes
                                                                                                                                                                            MD5 hash:71AD4FFF7C190194C8A544776B54DCC5
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Reputation:low
                                                                                                                                                                            Has exited:false

                                                                                                                                                                            Target ID:7
                                                                                                                                                                            Start time:05:09:58
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                            Commandline:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x32c,0x330,0x334,0x308,0x340,0x6bef9d44,0x6bef9d50,0x6bef9d5c
                                                                                                                                                                            Imagebase:0xa30000
                                                                                                                                                                            File size:5'749'656 bytes
                                                                                                                                                                            MD5 hash:71AD4FFF7C190194C8A544776B54DCC5
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Reputation:low
                                                                                                                                                                            Has exited:false

                                                                                                                                                                            Target ID:8
                                                                                                                                                                            Start time:05:09:58
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe
                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                            Commandline:"C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\setup.exe" --version
                                                                                                                                                                            Imagebase:0x140000
                                                                                                                                                                            File size:5'749'656 bytes
                                                                                                                                                                            MD5 hash:71AD4FFF7C190194C8A544776B54DCC5
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Reputation:low
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:9
                                                                                                                                                                            Start time:05:09:59
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                            Commandline:"C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe" --backend --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --consent-given=0 --general-interests=0 --general-location=0 --personalized-content=0 --personalized-ads=0 --launchopera=1 --showunbox=0 --installfolder="C:\Users\user\AppData\Local\Programs\Opera" --profile-folder --language=en-GB --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pintostartmenu=1 --run-at-startup=1 --show-intro-overlay --server-tracking-data=server_tracking_data --initial-pid=1408 --package-dir-prefix="C:\Users\user\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_20241227050959" --session-guid=878fa370-40e0-48bb-911a-de2b24f3f5ca --server-tracking-blob="MTZmNWMzYjllYmU1ODE2ZGQ1N2E1NWMxYWU1OTAyMTkyMDM2ZjNhNmZmZmE4NmM3ZGJhNTQ2Yjk2MzU4Y2FmMjp7ImNvdW50cnkiOiJVUyIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijp7Im5hbWUiOiJvcGVyYSJ9LCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cyIsInN5c3RlbSI6eyJwbGF0Zm9ybSI6eyJhcmNoIjoieDg2XzY0Iiwib3BzeXMiOiJXaW5kb3dzIiwib3BzeXMtdmVyc2lvbiI6IjEwIiwicGFja2FnZSI6IkVYRSJ9fSwidGltZXN0YW1wIjoiMTczNTAzODAxMi43NzQ1IiwidXNlcmFnZW50IjoicHl0aG9uLXJlcXVlc3RzLzIuMzIuMyIsInV0bSI6eyJjYW1wYWlnbiI6Im9wZXJhX25ld19iIiwibWVkaXVtIjoiYXBiIiwic291cmNlIjoiYWlzIn0sInV1aWQiOiJhYWY2NmY0NC01YzJjLTRmYmYtODRiZC03ZjY5MTQwZjQwZGIifQ== " --silent --desktopshortcut=1 --wait-for-package --initial-proc-handle=F005000000000000
                                                                                                                                                                            Imagebase:0xa30000
                                                                                                                                                                            File size:5'749'656 bytes
                                                                                                                                                                            MD5 hash:71AD4FFF7C190194C8A544776B54DCC5
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Reputation:low
                                                                                                                                                                            Has exited:false

                                                                                                                                                                            Target ID:10
                                                                                                                                                                            Start time:05:09:59
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe
                                                                                                                                                                            Wow64 process (32bit):true
                                                                                                                                                                            Commandline:C:\Users\user\AppData\Local\Temp\7zS4664E5C2\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector-2.opera.com/ --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=115.0.5322.119 --initial-client-data=0x320,0x324,0x328,0x2fc,0x338,0x6b309d44,0x6b309d50,0x6b309d5c
                                                                                                                                                                            Imagebase:0xa30000
                                                                                                                                                                            File size:5'749'656 bytes
                                                                                                                                                                            MD5 hash:71AD4FFF7C190194C8A544776B54DCC5
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Reputation:low
                                                                                                                                                                            Has exited:false

                                                                                                                                                                            Target ID:11
                                                                                                                                                                            Start time:05:11:11
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\installer.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:"C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\\installer.exe" /setOem:Affid=91088 /s /thirdparty /upgrade
                                                                                                                                                                            Imagebase:0x7ff697230000
                                                                                                                                                                            File size:23'918'680 bytes
                                                                                                                                                                            MD5 hash:7DD0FAA9C00391333B2A12D21CA028BF
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Reputation:low
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:12
                                                                                                                                                                            Start time:05:11:13
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Program Files\McAfee\Temp2744101987\installer.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:"C:\Program Files\McAfee\Temp2744101987\installer.exe" /setOem:Affid=91088 /s /thirdparty /upgrade
                                                                                                                                                                            Imagebase:0x7ff75cbd0000
                                                                                                                                                                            File size:3'079'968 bytes
                                                                                                                                                                            MD5 hash:9B6FDFBC11B51E810F01598730A002F4
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:13
                                                                                                                                                                            Start time:05:11:25
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Program Files\McAfee\WebAdvisor\servicehost.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:"C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe"
                                                                                                                                                                            Imagebase:0x7ff74d710000
                                                                                                                                                                            File size:926'176 bytes
                                                                                                                                                                            MD5 hash:F7C7039D19E16D05B6194D74E128DFE4
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Has exited:false

                                                                                                                                                                            Target ID:14
                                                                                                                                                                            Start time:05:11:26
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Program Files\McAfee\WebAdvisor\uihost.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:"C:\Program Files\McAfee\WebAdvisor\UIHost.exe"
                                                                                                                                                                            Imagebase:0x7ff6be4d0000
                                                                                                                                                                            File size:904'488 bytes
                                                                                                                                                                            MD5 hash:C75ACD4F363FEC78A32439364E82021C
                                                                                                                                                                            Has elevated privileges:false
                                                                                                                                                                            Has administrator privileges:false
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Has exited:false

                                                                                                                                                                            Target ID:15
                                                                                                                                                                            Start time:05:11:36
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Program Files\McAfee\WebAdvisor\updater.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:"C:\Program Files\McAfee\WebAdvisor\updater.exe"
                                                                                                                                                                            Imagebase:0x7ff7b5d50000
                                                                                                                                                                            File size:2'751'968 bytes
                                                                                                                                                                            MD5 hash:9A4C26D4AA627CA1C69D40C9091B4A74
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Antivirus matches:
                                                                                                                                                                            • Detection: 0%, ReversingLabs
                                                                                                                                                                            Has exited:false

                                                                                                                                                                            Target ID:16
                                                                                                                                                                            Start time:05:11:36
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:C:\Windows\system32\cmd.exe /c dir "C:\Program Files (x86)\McAfee Security Scan" 2>nul
                                                                                                                                                                            Imagebase:0x7ff61aa40000
                                                                                                                                                                            File size:289'792 bytes
                                                                                                                                                                            MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:17
                                                                                                                                                                            Start time:05:11:36
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                            Imagebase:0x7ff6d64d0000
                                                                                                                                                                            File size:862'208 bytes
                                                                                                                                                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:18
                                                                                                                                                                            Start time:05:11:41
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:C:\Windows\system32\cmd.exe /c IF EXIST "C:\Program Files\McAfee\WebAdvisor\Download" ( DEL "C:\Program Files\McAfee\WebAdvisor\Download\*.bak" )
                                                                                                                                                                            Imagebase:0x7ff61aa40000
                                                                                                                                                                            File size:289'792 bytes
                                                                                                                                                                            MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:19
                                                                                                                                                                            Start time:05:11:41
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                            Imagebase:0x7ff6d64d0000
                                                                                                                                                                            File size:862'208 bytes
                                                                                                                                                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:20
                                                                                                                                                                            Start time:05:11:41
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:C:\Windows\system32\cmd.exe /c DEL "C:\Program Files\McAfee\WebAdvisor\*.tmp"
                                                                                                                                                                            Imagebase:0x7ff61aa40000
                                                                                                                                                                            File size:289'792 bytes
                                                                                                                                                                            MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Target ID:21
                                                                                                                                                                            Start time:05:11:41
                                                                                                                                                                            Start date:27/12/2024
                                                                                                                                                                            Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                            Imagebase:0x7ff6d64d0000
                                                                                                                                                                            File size:862'208 bytes
                                                                                                                                                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                            Has exited:true

                                                                                                                                                                            Reset < >

                                                                                                                                                                              Execution Graph

                                                                                                                                                                              Execution Coverage:14.7%
                                                                                                                                                                              Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                              Signature Coverage:2.4%
                                                                                                                                                                              Total number of Nodes:289
                                                                                                                                                                              Total number of Limit Nodes:14
                                                                                                                                                                              execution_graph 1125 df863f 1128 df84af 1125->1128 1129 df84ee 1128->1129 1130 df84dc 1128->1130 1140 df835f 1129->1140 1155 ddd77f GetModuleHandleW 1130->1155 1134 df852b 1138 df8540 1141 df836b ___free_lconv_mon 1140->1141 1163 dfa940 EnterCriticalSection 1141->1163 1143 df8375 1164 df83c7 1143->1164 1145 df8382 1168 df83a0 1145->1168 1148 df8546 1247 df8577 1148->1247 1150 df8550 1151 df8564 1150->1151 1152 df8554 GetCurrentProcess TerminateProcess 1150->1152 1153 df8590 3 API calls 1151->1153 1152->1151 1154 df856c ExitProcess 1153->1154 1156 ddd78b 1155->1156 1156->1129 1157 df8590 GetModuleHandleExW 1156->1157 1158 df85cf GetProcAddress 1157->1158 1159 df85f0 1157->1159 1158->1159 1162 df85e3 1158->1162 1160 df84ed 1159->1160 1161 df85f6 FreeLibrary 1159->1161 1160->1129 1161->1160 1162->1159 1163->1143 1165 df83d3 ___free_lconv_mon 1164->1165 1166 df8437 1165->1166 1171 dfa1d6 1165->1171 1166->1145 1246 dfa988 LeaveCriticalSection 1168->1246 1170 df838e 1170->1134 1170->1148 1172 dfa1e2 __EH_prolog3 1171->1172 1175 df9f2d 1172->1175 1174 dfa209 1174->1166 1176 df9f39 ___free_lconv_mon 1175->1176 1183 dfa940 EnterCriticalSection 1176->1183 1178 df9f47 1184 dfa0e6 1178->1184 1183->1178 1185 dfa105 1184->1185 1187 df9f54 1184->1187 1185->1187 1191 dfc93d 1185->1191 1188 df9f7c 1187->1188 1245 dfa988 LeaveCriticalSection 1188->1245 1190 df9f65 1190->1174 1192 dfc948 RtlFreeHeap 1191->1192 1193 dfc972 1191->1193 1192->1193 1194 dfc95d GetLastError 1192->1194 1193->1187 1195 dfc96a ___free_lconv_mon 1194->1195 1197 def550 1195->1197 1200 dfdfe8 GetLastError 1197->1200 1199 def555 1199->1193 1201 dfdffe 1200->1201 1202 dfe004 1200->1202 1223 e00d5e 1201->1223 1220 dfe008 SetLastError 1202->1220 1228 e00d9d 1202->1228 1209 dfe04e 1212 e00d9d ___free_lconv_mon 2 API calls 1209->1212 1210 dfe03d 1211 e00d9d ___free_lconv_mon 2 API calls 1210->1211 1213 dfe04b 1211->1213 1214 dfe05a 1212->1214 1218 dfc93d ___free_lconv_mon 8 API calls 1213->1218 1215 dfe05e 1214->1215 1216 dfe075 1214->1216 1217 e00d9d ___free_lconv_mon 2 API calls 1215->1217 1240 dfdcc5 1216->1240 1217->1213 1218->1220 1220->1199 1222 dfc93d ___free_lconv_mon 8 API calls 1222->1220 1224 e00b0b ___free_lconv_mon GetProcAddress 1223->1224 1225 e00d7a 1224->1225 1226 e00d83 1225->1226 1227 e00d95 TlsGetValue 1225->1227 1226->1202 1229 e00b0b ___free_lconv_mon GetProcAddress 1228->1229 1230 e00db9 1229->1230 1231 dfe020 1230->1231 1232 e00dd7 TlsSetValue 1230->1232 1231->1220 1233 dfc8e0 1231->1233 1239 dfc8ed ___free_lconv_mon 1233->1239 1234 dfc92d 1236 def550 ___free_lconv_mon 9 API calls 1234->1236 1235 dfc918 RtlAllocateHeap 1237 dfc92b 1235->1237 1235->1239 1236->1237 1237->1209 1237->1210 1238 e078c5 ___free_lconv_mon EnterCriticalSection LeaveCriticalSection 1238->1239 1239->1234 1239->1235 1239->1238 1241 dfdb59 ___free_lconv_mon EnterCriticalSection LeaveCriticalSection 1240->1241 1242 dfdd33 1241->1242 1243 dfdc6b ___free_lconv_mon 10 API calls 1242->1243 1244 dfdd5c 1243->1244 1244->1222 1245->1190 1246->1170 1250 e01218 1247->1250 1249 df857c 1249->1150 1251 e01227 1250->1251 1252 e01234 1251->1252 1254 e00b90 1251->1254 1252->1249 1257 e00b0b 1254->1257 1256 e00bac 1256->1252 1258 e00b3b 1257->1258 1260 e00b37 ___free_lconv_mon 1257->1260 1259 e00b55 GetProcAddress 1258->1259 1258->1260 1259->1260 1260->1256 1261 df08f6 1262 df0902 ___free_lconv_mon 1261->1262 1263 df0909 GetLastError ExitThread 1262->1263 1264 df0916 1262->1264 1275 dfde97 GetLastError 1264->1275 1270 df0932 1329 df0b6b 1270->1329 1276 dfdead 1275->1276 1277 dfdeb3 1275->1277 1279 e00d5e ___free_lconv_mon 2 API calls 1276->1279 1278 e00d9d ___free_lconv_mon 2 API calls 1277->1278 1281 dfdeb7 SetLastError 1277->1281 1280 dfdecf 1278->1280 1279->1277 1280->1281 1283 dfc8e0 ___free_lconv_mon 10 API calls 1280->1283 1285 dfdf4c 1281->1285 1286 df091b 1281->1286 1284 dfdee4 1283->1284 1287 dfdefd 1284->1287 1288 dfdeec 1284->1288 1343 de49a7 1285->1343 1325 e011de 1286->1325 1291 e00d9d ___free_lconv_mon 2 API calls 1287->1291 1290 e00d9d ___free_lconv_mon 2 API calls 1288->1290 1296 dfdefa 1290->1296 1293 dfdf09 1291->1293 1297 dfdf0d 1293->1297 1298 dfdf24 1293->1298 1300 dfc93d ___free_lconv_mon 10 API calls 1296->1300 1303 e00d9d ___free_lconv_mon 2 API calls 1297->1303 1301 dfdcc5 ___free_lconv_mon 10 API calls 1298->1301 1300->1281 1305 dfdf2f 1301->1305 1303->1296 1307 dfc93d ___free_lconv_mon 10 API calls 1305->1307 1307->1281 1326 df0926 1325->1326 1327 e011ee 1325->1327 1326->1270 1337 e01046 1326->1337 1327->1326 1512 e00bd0 1327->1512 1515 df09ab 1329->1515 1338 e00b0b ___free_lconv_mon GetProcAddress 1337->1338 1339 e01062 1338->1339 1339->1270 1354 dfc6a9 1343->1354 1346 de49b7 1348 de49e0 1346->1348 1349 de49c1 IsProcessorFeaturePresent 1346->1349 1390 df863f 1348->1390 1350 de49cd 1349->1350 1384 def22e 1350->1384 1393 dfc5d7 1354->1393 1357 dfc6ee 1358 dfc6fa ___free_lconv_mon 1357->1358 1359 dfdfe8 ___free_lconv_mon 10 API calls 1358->1359 1360 dfc74a 1358->1360 1361 dfc75c 1358->1361 1367 dfc72b 1358->1367 1359->1367 1362 def550 ___free_lconv_mon 10 API calls 1360->1362 1364 dfc792 ___free_lconv_mon 1361->1364 1407 dfa940 EnterCriticalSection 1361->1407 1363 dfc74f 1362->1363 1404 def42a 1363->1404 1369 dfc7cf 1364->1369 1370 dfc8cc 1364->1370 1380 dfc7fd 1364->1380 1367->1360 1367->1361 1383 dfc734 1367->1383 1376 dfde97 37 API calls 1369->1376 1369->1380 1372 dfc8d7 1370->1372 1412 dfa988 LeaveCriticalSection 1370->1412 1374 df863f 17 API calls 1372->1374 1375 dfc8df 1374->1375 1378 dfc7f2 1376->1378 1377 dfde97 37 API calls 1381 dfc852 1377->1381 1379 dfde97 37 API calls 1378->1379 1379->1380 1408 dfc878 1380->1408 1382 dfde97 37 API calls 1381->1382 1381->1383 1382->1383 1383->1346 1385 def24a 1384->1385 1386 def276 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 1385->1386 1387 def347 1386->1387 1504 ddc740 1387->1504 1389 def365 1389->1348 1391 df84af 17 API calls 1390->1391 1392 de49ea 1391->1392 1394 dfc5e3 ___free_lconv_mon 1393->1394 1399 dfa940 EnterCriticalSection 1394->1399 1396 dfc5f1 1400 dfc633 1396->1400 1399->1396 1403 dfa988 LeaveCriticalSection 1400->1403 1402 de49ac 1402->1346 1402->1357 1403->1402 1413 def376 1404->1413 1407->1364 1409 dfc87c 1408->1409 1410 dfc844 1408->1410 1503 dfa988 LeaveCriticalSection 1409->1503 1410->1377 1410->1381 1410->1383 1412->1372 1414 def388 1413->1414 1419 def3ad 1414->1419 1416 def3a0 1430 de6ea0 1416->1430 1420 def3bd 1419->1420 1421 def3c4 1419->1421 1436 de7160 GetLastError 1420->1436 1426 def3d2 1421->1426 1440 def205 1421->1440 1424 def3f9 1424->1426 1443 def457 IsProcessorFeaturePresent 1424->1443 1426->1416 1427 def429 1428 def376 37 API calls 1427->1428 1429 def436 1428->1429 1429->1416 1431 de6eac 1430->1431 1432 de6ec3 1431->1432 1469 de71b0 1431->1469 1434 de71b0 37 API calls 1432->1434 1435 de6ed6 1432->1435 1434->1435 1435->1383 1437 de7179 1436->1437 1447 dfe099 1437->1447 1441 def229 1440->1441 1442 def210 GetLastError SetLastError 1440->1442 1441->1424 1442->1424 1444 def463 1443->1444 1445 def22e 8 API calls 1444->1445 1446 def478 GetCurrentProcess TerminateProcess 1445->1446 1446->1427 1448 dfe0ac 1447->1448 1449 dfe0b2 1447->1449 1450 e00d5e ___free_lconv_mon 2 API calls 1448->1450 1451 e00d9d ___free_lconv_mon 2 API calls 1449->1451 1467 de7195 SetLastError 1449->1467 1450->1449 1452 dfe0cc 1451->1452 1453 dfc8e0 ___free_lconv_mon 10 API calls 1452->1453 1452->1467 1454 dfe0dc 1453->1454 1455 dfe0f9 1454->1455 1456 dfe0e4 1454->1456 1458 e00d9d ___free_lconv_mon 2 API calls 1455->1458 1457 e00d9d ___free_lconv_mon 2 API calls 1456->1457 1459 dfe0f0 1457->1459 1460 dfe105 1458->1460 1464 dfc93d ___free_lconv_mon 10 API calls 1459->1464 1461 dfe109 1460->1461 1462 dfe118 1460->1462 1465 e00d9d ___free_lconv_mon 2 API calls 1461->1465 1463 dfdcc5 ___free_lconv_mon 10 API calls 1462->1463 1466 dfe123 1463->1466 1464->1467 1465->1459 1468 dfc93d ___free_lconv_mon 10 API calls 1466->1468 1467->1421 1468->1467 1470 de71be GetLastError 1469->1470 1471 de71ff 1469->1471 1472 de71cd 1470->1472 1471->1432 1473 dfe099 10 API calls 1472->1473 1474 de71ea SetLastError 1473->1474 1474->1471 1475 de7206 1474->1475 1476 de49a7 35 API calls 1475->1476 1477 de720b 1476->1477 1480 de558d 1477->1480 1479 de7247 1479->1432 1490 de96cb 1480->1490 1482 de559f 1483 de55b4 1482->1483 1485 de55e7 1482->1485 1489 de55cf 1482->1489 1484 def3ad 37 API calls 1483->1484 1484->1489 1486 de567e 1485->1486 1497 de9615 1485->1497 1487 de9615 37 API calls 1486->1487 1487->1489 1489->1479 1491 de96e3 1490->1491 1492 de96d0 1490->1492 1491->1482 1493 def550 ___free_lconv_mon 10 API calls 1492->1493 1494 de96d5 1493->1494 1495 def42a 37 API calls 1494->1495 1496 de96e0 1495->1496 1496->1482 1498 de963a 1497->1498 1499 de9626 1497->1499 1498->1486 1499->1498 1500 def550 ___free_lconv_mon 10 API calls 1499->1500 1501 de962f 1500->1501 1502 def42a 37 API calls 1501->1502 1502->1498 1503->1410 1505 ddc749 IsProcessorFeaturePresent 1504->1505 1506 ddc748 1504->1506 1508 ddd168 1505->1508 1506->1389 1511 ddd12b SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 1508->1511 1510 ddd24b 1510->1389 1511->1510 1513 e00b0b ___free_lconv_mon GetProcAddress 1512->1513 1514 e00bec 1513->1514 1514->1326 1516 dfdfe8 ___free_lconv_mon 10 API calls 1515->1516 1519 df09b6 1516->1519 1517 df09f8 ExitThread 1518 df09cf 1521 df09e2 1518->1521 1522 df09db CloseHandle 1518->1522 1519->1517 1519->1518 1524 e01081 1519->1524 1521->1517 1523 df09ee FreeLibraryAndExitThread 1521->1523 1522->1521 1523->1517 1525 e00b0b ___free_lconv_mon GetProcAddress 1524->1525 1526 e0109a 1525->1526 1526->1518 1527 ddc736 1530 ddd581 1527->1530 1529 ddc73b 1529->1529 1531 ddd597 1530->1531 1533 ddd5a0 1531->1533 1534 ddd534 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 1531->1534 1533->1529 1534->1533

                                                                                                                                                                              Callgraph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              • Opacity -> Relevance
                                                                                                                                                                              • Disassembly available
                                                                                                                                                                              callgraph 0 Function_00DF835F 11 Function_00DF83C7 0->11 16 Function_00DFA940 0->16 88 Function_00DDCF20 0->88 92 Function_00DF83A0 0->92 1 Function_00DFDB59 1->16 40 Function_00DFDB9F 1->40 1->88 2 Function_00DFC5D7 2->16 71 Function_00DFC633 2->71 2->88 3 Function_00DFA1D6 50 Function_00DDCE0D 3->50 65 Function_00DDCE3F 3->65 77 Function_00DF9F2D 3->77 4 Function_00DEF457 76 Function_00DEF22E 4->76 5 Function_00E063EC 6 Function_00DEF550 34 Function_00DFDFE8 6->34 7 Function_00E0646F 20 Function_00E06446 7->20 8 Function_00E078F1 8->16 59 Function_00E0793F 8->59 78 Function_00DF83AC 8->78 8->88 9 Function_00DFDE4C 9->7 41 Function_00E062A4 9->41 44 Function_00E06227 9->44 10 Function_00DE96CB 10->6 81 Function_00DEF42A 10->81 11->3 54 Function_00DF8306 11->54 11->78 11->88 12 Function_00DF8546 23 Function_00DF8577 12->23 49 Function_00DF8590 12->49 13 Function_00DFDCC5 13->1 33 Function_00DFDC6B 13->33 14 Function_00DDC740 85 Function_00DDD12B 14->85 15 Function_00DE6E40 17 Function_00DDD77F 18 Function_00DF9F7C 53 Function_00DFA988 18->53 19 Function_00E078C5 19->8 21 Function_00E01046 70 Function_00E00B0B 21->70 22 Function_00DFC878 22->53 79 Function_00E05513 23->79 86 Function_00E01218 23->86 24 Function_00DEF376 24->15 80 Function_00DEF3AD 24->80 91 Function_00DE6EA0 24->91 25 Function_00DF08F6 25->21 31 Function_00DF0B6B 25->31 38 Function_00E011DE 25->38 45 Function_00DFDE97 25->45 66 Function_00DF7ABA 25->66 25->88 26 Function_00DF9EF1 27 Function_00E0554E 64 Function_00DFC93D 27->64 28 Function_00E013CE 29 Function_00E00BD0 29->70 30 Function_00DFC6EE 30->6 30->16 30->22 30->34 30->45 30->53 58 Function_00DFC681 30->58 60 Function_00DF863F 30->60 61 Function_00DFC63F 30->61 30->78 30->81 30->88 31->6 31->28 31->81 82 Function_00DF09AB 31->82 32 Function_00E05ED4 51 Function_00E05C33 32->51 32->64 33->9 33->16 67 Function_00DFDCB9 33->67 33->88 34->13 36 Function_00E00D5E 34->36 39 Function_00DFC8E0 34->39 34->64 89 Function_00E00D9D 34->89 35 Function_00DFA0E6 35->64 36->70 37 Function_00DE7160 43 Function_00DFE099 37->43 38->29 42 Function_00E05525 38->42 39->6 39->19 39->26 40->53 41->27 48 Function_00E059AD 41->48 41->64 83 Function_00E06415 41->83 43->13 43->36 43->39 43->64 43->89 44->5 45->13 45->36 45->39 45->64 87 Function_00DE49A7 45->87 45->89 46 Function_00DF7C15 47 Function_00DE9615 47->6 47->81 48->64 51->64 52 Function_00DE558D 52->10 52->47 62 Function_00DE54BF 52->62 52->80 55 Function_00DEF205 56 Function_00DDD581 68 Function_00DDD534 56->68 57 Function_00DE1C80 59->53 74 Function_00DF84AF 60->74 63 Function_00E01081 63->70 64->6 72 Function_00DEF4B3 64->72 66->34 67->53 69 Function_00DDC736 69->56 70->46 71->53 73 Function_00DE71B0 73->43 73->52 73->87 74->0 74->12 74->17 74->49 75 Function_00E00B90 75->70 76->14 76->57 90 Function_00DDD823 76->90 77->16 77->18 77->35 77->88 80->4 80->24 80->37 80->55 81->24 82->34 82->63 83->32 83->64 84 Function_00DFC6A9 84->2 86->42 86->75 87->30 87->60 87->76 87->84 89->70 91->73 92->53

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DFDFE8: GetLastError.KERNEL32(00000000,?,00DEF555,00DFC932,?,?,00DFDEE4,00000001,00000364,?,00000006,000000FF,?,00DF091B,00EAF328,0000000C), ref: 00DFDFEC
                                                                                                                                                                                • Part of subcall function 00DFDFE8: SetLastError.KERNEL32(00000000), ref: 00DFE08E
                                                                                                                                                                              • CloseHandle.KERNEL32(?,?,?,00DF0B78,?,?,00DF0954,00000000), ref: 00DF09DC
                                                                                                                                                                              • FreeLibraryAndExitThread.KERNEL32(?,?,?,?,00DF0B78,?,?,00DF0954,00000000), ref: 00DF09F2
                                                                                                                                                                              • ExitThread.KERNEL32 ref: 00DF09FB
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000000.00000002.2737509626.0000000000C11000.00000020.00000001.01000000.00000003.sdmp, Offset: 00C10000, based on PE: true
                                                                                                                                                                              • Associated: 00000000.00000002.2737239598.0000000000C10000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738280074.0000000000EB4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738312292.0000000000EB6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738344622.0000000000EBF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000000EC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000001002000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_0_2_c10000_grand-theft-auto-5-theme-1-installer_qb8W-j1.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorExitLastThread$CloseFreeHandleLibrary
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1991824761-0
                                                                                                                                                                              • Opcode ID: 6bea2d1f44c7bd167099405e978a0098fd5010db89fe691130d48ebf30833457
                                                                                                                                                                              • Instruction ID: 69bdb90d1c85fd60ac4f470a88cb853eb01b5b83bffceb7484d3d9ffe9e9566d
                                                                                                                                                                              • Opcode Fuzzy Hash: 6bea2d1f44c7bd167099405e978a0098fd5010db89fe691130d48ebf30833457
                                                                                                                                                                              • Instruction Fuzzy Hash: F6F054315006496BEB716B358808A2B3E99AF04361F1EC714FA75D71E3EB70DD86CA70

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              APIs
                                                                                                                                                                              • GetCurrentProcess.KERNEL32(00000002,?,00DF8540,00DE49EA,00DE49EA,?,00000002,E8A71C29,00DE49EA,00000002), ref: 00DF8557
                                                                                                                                                                              • TerminateProcess.KERNEL32(00000000,?,00DF8540,00DE49EA,00DE49EA,?,00000002,E8A71C29,00DE49EA,00000002), ref: 00DF855E
                                                                                                                                                                              • ExitProcess.KERNEL32 ref: 00DF8570
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000000.00000002.2737509626.0000000000C11000.00000020.00000001.01000000.00000003.sdmp, Offset: 00C10000, based on PE: true
                                                                                                                                                                              • Associated: 00000000.00000002.2737239598.0000000000C10000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738280074.0000000000EB4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738312292.0000000000EB6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738344622.0000000000EBF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000000EC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000001002000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_0_2_c10000_grand-theft-auto-5-theme-1-installer_qb8W-j1.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Process$CurrentExitTerminate
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1703294689-0
                                                                                                                                                                              • Opcode ID: 394d3df9ae16c183b7c3d95ecfde17bb9a79111f55ef835124c72c5119fd37c8
                                                                                                                                                                              • Instruction ID: de1f52d3096b3c61a2a156e34e56a69dab22bd7039448bf92dd76c93ce0ad478
                                                                                                                                                                              • Opcode Fuzzy Hash: 394d3df9ae16c183b7c3d95ecfde17bb9a79111f55ef835124c72c5119fd37c8
                                                                                                                                                                              • Instruction Fuzzy Hash: FED06732400208BFCF117F61EC0996D3F25EB44355F559010BA0956132DF319A5AEAA5

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              APIs
                                                                                                                                                                              • GetLastError.KERNEL32(00EAF328,0000000C), ref: 00DF0909
                                                                                                                                                                              • ExitThread.KERNEL32 ref: 00DF0910
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000000.00000002.2737509626.0000000000C11000.00000020.00000001.01000000.00000003.sdmp, Offset: 00C10000, based on PE: true
                                                                                                                                                                              • Associated: 00000000.00000002.2737239598.0000000000C10000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738280074.0000000000EB4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738312292.0000000000EB6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738344622.0000000000EBF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000000EC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000001002000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_0_2_c10000_grand-theft-auto-5-theme-1-installer_qb8W-j1.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorExitLastThread
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1611280651-0
                                                                                                                                                                              • Opcode ID: b87511ad1d5047cc7a450ce6f0efb38640e778e04292ca5630f713de30c2b7d8
                                                                                                                                                                              • Instruction ID: bd9ecf4879ef9fb8ba2be35f02787fbb55c0ae87f0e2b588b1fb22a43d9c4ab1
                                                                                                                                                                              • Opcode Fuzzy Hash: b87511ad1d5047cc7a450ce6f0efb38640e778e04292ca5630f713de30c2b7d8
                                                                                                                                                                              • Instruction Fuzzy Hash: 71F0AF71A00208EFDB14ABB0C84AA7E3B75EF04710F155089F505AB2A3DB745945CB71

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 40 dfc93d-dfc946 41 dfc948-dfc95b RtlFreeHeap 40->41 42 dfc975-dfc976 40->42 41->42 43 dfc95d-dfc974 GetLastError call def4b3 call def550 41->43 43->42
                                                                                                                                                                              APIs
                                                                                                                                                                              • RtlFreeHeap.NTDLL(00000000,00000000,?,00E05C4C,?,00000000,?,?,00E05EED,?,00000007,?,?,00E0643B,?,?), ref: 00DFC953
                                                                                                                                                                              • GetLastError.KERNEL32(?,?,00E05C4C,?,00000000,?,?,00E05EED,?,00000007,?,?,00E0643B,?,?), ref: 00DFC95E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000000.00000002.2737509626.0000000000C11000.00000020.00000001.01000000.00000003.sdmp, Offset: 00C10000, based on PE: true
                                                                                                                                                                              • Associated: 00000000.00000002.2737239598.0000000000C10000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738280074.0000000000EB4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738312292.0000000000EB6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738344622.0000000000EBF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000000EC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000001002000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_0_2_c10000_grand-theft-auto-5-theme-1-installer_qb8W-j1.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorFreeHeapLast
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 485612231-0
                                                                                                                                                                              • Opcode ID: c5ce048f4eff0f9e581dc50f154f996d80c47942c53e0e3921e127bc268eb986
                                                                                                                                                                              • Instruction ID: 5ae9cb9de2d5568b91080f85949109e5550d3d1f719f6968574f266006a9a227
                                                                                                                                                                              • Opcode Fuzzy Hash: c5ce048f4eff0f9e581dc50f154f996d80c47942c53e0e3921e127bc268eb986
                                                                                                                                                                              • Instruction Fuzzy Hash: CCE086326002086FCB213FA6FD0CB553A5CDF41356F158020F61CA60A1DA7589568BB4

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 48 dfc8e0-dfc8eb 49 dfc8ed-dfc8f7 48->49 50 dfc8f9-dfc8ff 48->50 49->50 51 dfc92d-dfc938 call def550 49->51 52 dfc918-dfc929 RtlAllocateHeap 50->52 53 dfc901-dfc902 50->53 57 dfc93a-dfc93c 51->57 54 dfc92b 52->54 55 dfc904-dfc90b call df9ef1 52->55 53->52 54->57 55->51 61 dfc90d-dfc916 call e078c5 55->61 61->51 61->52
                                                                                                                                                                              APIs
                                                                                                                                                                              • RtlAllocateHeap.NTDLL(00000008,?,?,?,00DFDEE4,00000001,00000364,?,00000006,000000FF,?,00DF091B,00EAF328,0000000C), ref: 00DFC921
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000000.00000002.2737509626.0000000000C11000.00000020.00000001.01000000.00000003.sdmp, Offset: 00C10000, based on PE: true
                                                                                                                                                                              • Associated: 00000000.00000002.2737239598.0000000000C10000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738280074.0000000000EB4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738312292.0000000000EB6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738344622.0000000000EBF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000000EC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000001002000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_0_2_c10000_grand-theft-auto-5-theme-1-installer_qb8W-j1.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AllocateHeap
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1279760036-0
                                                                                                                                                                              • Opcode ID: 0714c39ede393f03a34bb81c099c876defca0be084fc7e2a86c28183793ec12d
                                                                                                                                                                              • Instruction ID: 1921068f77bfa794101b65a12ec6618cb7173b7b889b1dd1693659e4251fc1cb
                                                                                                                                                                              • Opcode Fuzzy Hash: 0714c39ede393f03a34bb81c099c876defca0be084fc7e2a86c28183793ec12d
                                                                                                                                                                              • Instruction Fuzzy Hash: F1F02B3251022C67DB211B268E01BBA3748DF44361B1BE021BE45A6180CA60DC21CAF0

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 64 dfa1d6-dfa204 call ddce3f call df9f2d 68 dfa209-dfa20e call ddce0d 64->68
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000000.00000002.2737509626.0000000000C11000.00000020.00000001.01000000.00000003.sdmp, Offset: 00C10000, based on PE: true
                                                                                                                                                                              • Associated: 00000000.00000002.2737239598.0000000000C10000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738280074.0000000000EB4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738312292.0000000000EB6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738344622.0000000000EBF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000000EC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000001002000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_0_2_c10000_grand-theft-auto-5-theme-1-installer_qb8W-j1.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: H_prolog3
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 431132790-0
                                                                                                                                                                              • Opcode ID: 24c0e906399a15fdbbf07cbadcdf675918b8daf705fb448831f645f939f0202b
                                                                                                                                                                              • Instruction ID: b46dc684d034767f64f0bc2f8fb12511ed14bf50ae8107c40a7518aa9a1379fb
                                                                                                                                                                              • Opcode Fuzzy Hash: 24c0e906399a15fdbbf07cbadcdf675918b8daf705fb448831f645f939f0202b
                                                                                                                                                                              • Instruction Fuzzy Hash: FBE075B6C5020E9ADB10DBD4C552BEFBBB8AF04300F504466A205E6141EA745744CBB1

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              APIs
                                                                                                                                                                              • IsDebuggerPresent.KERNEL32(?,?,?,?,?,00000000), ref: 00DEF326
                                                                                                                                                                              • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,00000000), ref: 00DEF330
                                                                                                                                                                              • UnhandledExceptionFilter.KERNEL32(-00000327,?,?,?,?,?,00000000), ref: 00DEF33D
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000000.00000002.2737509626.0000000000C11000.00000020.00000001.01000000.00000003.sdmp, Offset: 00C10000, based on PE: true
                                                                                                                                                                              • Associated: 00000000.00000002.2737239598.0000000000C10000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738280074.0000000000EB4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738312292.0000000000EB6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738344622.0000000000EBF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000000EC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000001002000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_0_2_c10000_grand-theft-auto-5-theme-1-installer_qb8W-j1.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3906539128-0
                                                                                                                                                                              • Opcode ID: 10103d972620e0f17bbef0aa72cea285aa8e1304cc00814737c9f80d312fc4c7
                                                                                                                                                                              • Instruction ID: 964ced952547e21e5a7c79ffae03bdb9d26c139cfc93c0cef7a49a7b094bc855
                                                                                                                                                                              • Opcode Fuzzy Hash: 10103d972620e0f17bbef0aa72cea285aa8e1304cc00814737c9f80d312fc4c7
                                                                                                                                                                              • Instruction Fuzzy Hash: 4731D375901218ABCB21EF65D888B8CBBB8FF08310F5051EAE41CA7261E7709F858F54

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 160 df8590-df85cd GetModuleHandleExW 161 df85cf-df85e1 GetProcAddress 160->161 162 df85f0-df85f4 160->162 161->162 165 df85e3-df85ee 161->165 163 df85ff-df860c 162->163 164 df85f6-df85f9 FreeLibrary 162->164 164->163 165->162
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,E8A71C29,?,?,00000000,00E0E1B0,000000FF,?,00DF856C,00000002,?,00DF8540,00DE49EA), ref: 00DF85C5
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00DF85D7
                                                                                                                                                                              • FreeLibrary.KERNEL32(00000000,?,?,00000000,00E0E1B0,000000FF,?,00DF856C,00000002,?,00DF8540,00DE49EA), ref: 00DF85F9
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000000.00000002.2737509626.0000000000C11000.00000020.00000001.01000000.00000003.sdmp, Offset: 00C10000, based on PE: true
                                                                                                                                                                              • Associated: 00000000.00000002.2737239598.0000000000C10000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738195496.0000000000E29000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738280074.0000000000EB4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738312292.0000000000EB6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738344622.0000000000EBF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000000EC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              • Associated: 00000000.00000002.2738371112.0000000001002000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_0_2_c10000_grand-theft-auto-5-theme-1-installer_qb8W-j1.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                              • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                              • API String ID: 4061214504-1276376045
                                                                                                                                                                              • Opcode ID: 04c27987cb21f0f89aca05e13c3784b8791ccb7aa0614d4e341b251aec1aac06
                                                                                                                                                                              • Instruction ID: 721bdce72eb8d3dd271869113e7535cd9a829388a1eed6f47d3d913137956657
                                                                                                                                                                              • Opcode Fuzzy Hash: 04c27987cb21f0f89aca05e13c3784b8791ccb7aa0614d4e341b251aec1aac06
                                                                                                                                                                              • Instruction Fuzzy Hash: DA01623294465AEFDB119B51DC09BAEBBB8FB04B14F048526E921B26D0DF749904CA94

                                                                                                                                                                              Execution Graph

                                                                                                                                                                              Execution Coverage:6.5%
                                                                                                                                                                              Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                              Signature Coverage:8.4%
                                                                                                                                                                              Total number of Nodes:2000
                                                                                                                                                                              Total number of Limit Nodes:53
                                                                                                                                                                              execution_graph 97445 da61fa 97446 da6206 ___scrt_is_nonwritable_in_current_image 97445->97446 97447 da620c 97446->97447 97448 da6223 97446->97448 97476 d8d73d 97447->97476 97456 d9582c EnterCriticalSection 97448->97456 97451 da6233 97457 da627a 97451->97457 97453 da623f 97479 da6270 LeaveCriticalSection ___scrt_uninitialize_crt 97453->97479 97454 da6211 97456->97451 97458 da6288 97457->97458 97459 da629f 97457->97459 97460 d8d73d __Wcrtomb 14 API calls 97458->97460 97480 da2e1c 97459->97480 97462 da628d 97460->97462 97462->97453 97463 da62a9 97485 da6972 97463->97485 97466 da638c 97468 da639a 97466->97468 97472 da6365 97466->97472 97467 da6337 97469 da6351 97467->97469 97467->97472 97470 d8d73d __Wcrtomb 14 API calls 97468->97470 97488 da65bd 24 API calls 4 library calls 97469->97488 97475 da62ee __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z 97470->97475 97472->97475 97489 da63fe 18 API calls 2 library calls 97472->97489 97473 da635d 97473->97475 97475->97453 97541 da1e00 14 API calls 2 library calls 97476->97541 97478 d8d742 97478->97454 97479->97454 97481 da2e28 97480->97481 97482 da2e3d 97480->97482 97483 d8d73d __Wcrtomb 14 API calls 97481->97483 97482->97463 97484 da2e2d 97483->97484 97484->97463 97490 da67ea 97485->97490 97487 da62c4 97487->97466 97487->97467 97487->97475 97488->97473 97489->97475 97491 da67f6 ___scrt_is_nonwritable_in_current_image 97490->97491 97492 da67fe 97491->97492 97493 da6816 97491->97493 97523 d8d72a 14 API calls __Wcrtomb 97492->97523 97494 da68c7 97493->97494 97499 da684b 97493->97499 97526 d8d72a 14 API calls __Wcrtomb 97494->97526 97496 da6803 97498 d8d73d __Wcrtomb 14 API calls 97496->97498 97504 da680b 97498->97504 97513 daace1 EnterCriticalSection 97499->97513 97500 da68cc 97502 d8d73d __Wcrtomb 14 API calls 97500->97502 97502->97504 97503 da6851 97505 da688a 97503->97505 97506 da6875 97503->97506 97504->97487 97514 da68f6 97505->97514 97507 d8d73d __Wcrtomb 14 API calls 97506->97507 97509 da687a 97507->97509 97524 d8d72a 14 API calls __Wcrtomb 97509->97524 97510 da6885 97525 da68bf LeaveCriticalSection __wsopen_s 97510->97525 97513->97503 97527 daaf5d 97514->97527 97516 da6908 97517 da6910 97516->97517 97518 da6921 SetFilePointerEx 97516->97518 97519 d8d73d __Wcrtomb 14 API calls 97517->97519 97520 da6915 97518->97520 97521 da6939 GetLastError 97518->97521 97519->97520 97520->97510 97538 d8d707 14 API calls 2 library calls 97521->97538 97523->97496 97524->97510 97525->97504 97526->97500 97528 daaf6a 97527->97528 97529 daaf7f 97527->97529 97539 d8d72a 14 API calls __Wcrtomb 97528->97539 97535 daafa4 97529->97535 97540 d8d72a 14 API calls __Wcrtomb 97529->97540 97531 daaf6f 97534 d8d73d __Wcrtomb 14 API calls 97531->97534 97533 daafaf 97536 d8d73d __Wcrtomb 14 API calls 97533->97536 97537 daaf77 97534->97537 97535->97516 97536->97537 97537->97516 97538->97520 97539->97531 97540->97533 97541->97478 97542 d922d9 97543 d922e9 97542->97543 97544 d922fc 97542->97544 97545 d8d73d __Wcrtomb 14 API calls 97543->97545 97546 d9230e 97544->97546 97550 d92321 97544->97550 97566 d922ee __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z __allrem 97545->97566 97547 d8d73d __Wcrtomb 14 API calls 97546->97547 97547->97566 97548 d92341 97551 d8d73d __Wcrtomb 14 API calls 97548->97551 97549 d92352 97567 da3473 14 API calls __Wcrtomb 97549->97567 97550->97548 97550->97549 97551->97566 97553 d92369 97554 d9255d 97553->97554 97568 da349f 14 API calls __Wcrtomb 97553->97568 97572 d8d62c 11 API calls std::locale::_Setgloballocale 97554->97572 97557 d9237b 97557->97554 97569 da34cb 14 API calls __Wcrtomb 97557->97569 97558 d92567 97560 d9238d 97560->97554 97561 d92396 97560->97561 97562 d9241b 97561->97562 97563 d923b7 97561->97563 97562->97566 97571 da3f0a 25 API calls 2 library calls 97562->97571 97563->97566 97570 da3f0a 25 API calls 2 library calls 97563->97570 97567->97553 97568->97557 97569->97560 97570->97566 97571->97566 97572->97558 97573 d3ecd0 97574 d3ece7 lstrlenW 97573->97574 97575 d3ecde 97573->97575 97578 d3ed10 97574->97578 97576 d3ed07 97579 d3ed1a 97578->97579 97580 d3ed39 97578->97580 97579->97580 97581 d3ed22 RegSetValueExW 97579->97581 97580->97576 97581->97576 97588 d3e590 97589 d3e5a5 97588->97589 97590 d3e59a 97588->97590 97593 d3e8c0 RegQueryValueExW 97589->97593 97591 d3e5bf 97593->97591 97594 d3ea50 97596 d3ed10 RegSetValueExW 97594->97596 97595 d3ea63 97596->97595 97597 d3df10 RegCreateKeyExW 97598 d3df52 97597->97598 97599 d27156 97786 d88713 97599->97786 97601 d2715c _LStrxfrm 97602 d271bf 97601->97602 97611 d2722a 97601->97611 97916 d19bb0 InitOnceBeginInitialize 97602->97916 97606 d27df1 97989 d134d0 21 API calls collate 97606->97989 97611->97606 97614 d272b4 97611->97614 97615 d272db 97611->97615 97627 d2725f _LStrxfrm 97611->97627 97618 d27dfc Concurrency::cancel_current_task 97614->97618 97621 d88713 messages 27 API calls 97614->97621 97622 d88713 messages 27 API calls 97615->97622 97615->97627 97617 d27200 97950 d11c50 97617->97950 97623 d27e01 97618->97623 97620 d27348 97626 d19bb0 125 API calls 97620->97626 97621->97627 97622->97627 97990 d8d60f 97623->97990 97630 d2734d 97626->97630 97627->97620 97627->97623 97640 d273b3 97627->97640 97628 d27e06 97633 d19bb0 125 API calls 97628->97633 97632 d19940 169 API calls 97630->97632 97631 d27219 97955 d1b8a0 97631->97955 97635 d2735d 97632->97635 97636 d27e5c 97633->97636 97637 d11b84 84 API calls 97635->97637 97638 d19940 169 API calls 97636->97638 97639 d27379 97637->97639 97641 d27e6c 97638->97641 97971 d11be0 97639->97971 97640->97606 97643 d27443 97640->97643 97644 d2746a 97640->97644 97653 d273ee _LStrxfrm 97640->97653 97645 d11b84 84 API calls 97641->97645 97643->97618 97647 d88713 messages 27 API calls 97643->97647 97648 d88713 messages 27 API calls 97644->97648 97644->97653 97649 d27e88 97645->97649 97647->97653 97648->97653 97654 d11be0 81 API calls 97649->97654 97650 d11c50 81 API calls 97655 d27397 97650->97655 97651 d274d7 97652 d19bb0 125 API calls 97651->97652 97657 d274dc 97652->97657 97653->97623 97653->97651 97670 d27542 97653->97670 97659 d27e98 97654->97659 97975 d28f20 81 API calls 97655->97975 97661 d19940 169 API calls 97657->97661 97658 d27221 std::ios_base::_Ios_base_dtor Concurrency::cancel_current_task __Mtx_unlock 97982 d88367 97658->97982 97663 d1b8a0 168 API calls 97659->97663 97660 d273a2 97664 d1b8a0 168 API calls 97660->97664 97665 d274ec 97661->97665 97677 d27ea3 std::ios_base::_Ios_base_dtor 97663->97677 97664->97658 97667 d11b84 84 API calls 97665->97667 97666 d27dea 97669 d27508 97667->97669 97668 d27d49 97802 d34b40 97668->97802 97674 d11be0 81 API calls 97669->97674 97670->97606 97672 d276d8 97670->97672 97679 d275d6 97670->97679 97680 d275ff 97670->97680 97688 d2757f _LStrxfrm 97670->97688 97672->97606 97681 d27715 _LStrxfrm 97672->97681 97683 d2786e 97672->97683 97686 d2776c 97672->97686 97693 d27795 97672->97693 97673 d27a44 _LStrxfrm 97673->97623 97676 d27b9d 97673->97676 97719 d27b32 97673->97719 97682 d27518 97674->97682 97676->97606 97676->97668 97700 d27c00 97676->97700 97732 d27bde _LStrxfrm 97676->97732 97678 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 97677->97678 97684 d285c6 97678->97684 97679->97618 97689 d88713 messages 27 API calls 97679->97689 97680->97688 97690 d88713 messages 27 API calls 97680->97690 97681->97623 97681->97683 97695 d27803 97681->97695 97687 d11c50 81 API calls 97682->97687 97683->97606 97685 d27a07 97683->97685 97694 d27905 97683->97694 97696 d2792e 97683->97696 97699 d278ae _LStrxfrm 97683->97699 97685->97606 97685->97673 97685->97676 97697 d27ac2 97685->97697 97698 d27a9b 97685->97698 97686->97618 97701 d88713 messages 27 API calls 97686->97701 97691 d27526 97687->97691 97688->97623 97688->97672 97692 d2766d 97688->97692 97689->97688 97690->97688 97976 d28f20 81 API calls 97691->97976 97703 d19bb0 125 API calls 97692->97703 97693->97681 97704 d88713 messages 27 API calls 97693->97704 97694->97618 97706 d88713 messages 27 API calls 97694->97706 97707 d19bb0 125 API calls 97695->97707 97696->97699 97708 d88713 messages 27 API calls 97696->97708 97697->97673 97717 d88713 messages 27 API calls 97697->97717 97698->97618 97715 d88713 messages 27 API calls 97698->97715 97699->97623 97699->97685 97709 d2799c 97699->97709 97710 d27c35 97700->97710 97711 d27c5c 97700->97711 97701->97681 97713 d27672 97703->97713 97704->97681 97706->97699 97714 d27808 97707->97714 97708->97699 97716 d19bb0 125 API calls 97709->97716 97710->97618 97718 d27c40 97710->97718 97727 d88713 messages 27 API calls 97711->97727 97711->97732 97712 d27531 97720 d1b8a0 168 API calls 97712->97720 97721 d19940 169 API calls 97713->97721 97723 d19940 169 API calls 97714->97723 97715->97673 97724 d279a1 97716->97724 97717->97673 97725 d88713 messages 27 API calls 97718->97725 97726 d19bb0 125 API calls 97719->97726 97720->97658 97728 d27682 97721->97728 97722 d27ccc 97729 d19bb0 125 API calls 97722->97729 97730 d27818 97723->97730 97731 d19940 169 API calls 97724->97731 97725->97732 97733 d27b37 97726->97733 97727->97732 97734 d11b84 84 API calls 97728->97734 97736 d27cd1 97729->97736 97737 d11b84 84 API calls 97730->97737 97738 d279b1 97731->97738 97732->97623 97732->97668 97732->97722 97739 d19940 169 API calls 97733->97739 97735 d2769e 97734->97735 97740 d11be0 81 API calls 97735->97740 97741 d19940 169 API calls 97736->97741 97742 d27834 97737->97742 97743 d11b84 84 API calls 97738->97743 97744 d27b47 97739->97744 97746 d276ae 97740->97746 97747 d27ce1 97741->97747 97748 d11be0 81 API calls 97742->97748 97749 d279cd 97743->97749 97745 d11b84 84 API calls 97744->97745 97750 d27b63 97745->97750 97751 d11c50 81 API calls 97746->97751 97752 d11b84 84 API calls 97747->97752 97753 d27844 97748->97753 97754 d11be0 81 API calls 97749->97754 97755 d11be0 81 API calls 97750->97755 97756 d276bc 97751->97756 97757 d27cfd 97752->97757 97758 d11c50 81 API calls 97753->97758 97759 d279dd 97754->97759 97760 d27b73 97755->97760 97977 d28f20 81 API calls 97756->97977 97762 d11be0 81 API calls 97757->97762 97763 d27852 97758->97763 97764 d11c50 81 API calls 97759->97764 97765 d11c50 81 API calls 97760->97765 97767 d27d0d 97762->97767 97978 d28f20 81 API calls 97763->97978 97769 d279eb 97764->97769 97770 d27b81 97765->97770 97766 d276c7 97771 d1b8a0 168 API calls 97766->97771 97772 d11c50 81 API calls 97767->97772 97979 d28f20 81 API calls 97769->97979 97980 d28f20 81 API calls 97770->97980 97771->97658 97776 d27d1b 97772->97776 97773 d2785d 97777 d1b8a0 168 API calls 97773->97777 97981 d28f20 81 API calls 97776->97981 97777->97658 97778 d279f6 97781 d1b8a0 168 API calls 97778->97781 97779 d27b8c 97782 d1b8a0 168 API calls 97779->97782 97781->97658 97782->97658 97783 d27d26 97784 d1b8a0 168 API calls 97783->97784 97784->97658 97788 d88718 97786->97788 97789 d88732 97788->97789 97792 d13599 messages 97788->97792 97996 d9594f 97788->97996 98006 d9f60f EnterCriticalSection LeaveCriticalSection messages 97788->98006 97789->97601 97791 d8873e 97791->97791 97792->97791 97794 d135c5 97792->97794 98003 d8a332 97792->98003 97795 d88713 messages 27 API calls 97794->97795 97796 d135cb 97795->97796 97797 d135d2 97796->97797 97800 d135dc 97796->97800 97797->97601 97801 dc8100 Concurrency::cancel_current_task 97800->97801 98007 d8d59b 25 API calls 2 library calls 97800->98007 98008 d8d62c 11 API calls std::locale::_Setgloballocale 97800->98008 97801->97601 98010 d352d0 97802->98010 97804 d34b83 97805 d88713 messages 27 API calls 97804->97805 97806 d34c08 97805->97806 98086 d36340 97806->98086 97808 d34eba 98089 d31b40 97808->98089 97811 d34d1a 97811->97808 97813 d36360 27 API calls 97811->97813 97831 d88713 messages 27 API calls 97811->97831 97833 d9594f _Yarn 15 API calls 97811->97833 98117 d36640 27 API calls 3 library calls 97811->98117 97813->97811 97814 d34c8a 97814->97811 98116 d36c80 29 API calls messages 97814->98116 97816 d34ec9 Concurrency::cancel_current_task 97819 d35187 97816->97819 97825 d34f98 97816->97825 98118 d177a9 5 API calls collate 97816->98118 97817 d34fc2 97818 d3517d 97817->97818 97823 d3500e _LStrxfrm 97817->97823 97827 d3502e 97817->97827 98120 d134d0 21 API calls collate 97818->98120 97822 d8d60f 25 API calls 97819->97822 97826 d3518c 97822->97826 98113 d8e960 97823->98113 97824 d35182 Concurrency::cancel_current_task 97824->97819 97825->97817 98119 d32f20 29 API calls 3 library calls 97825->98119 97834 d19bb0 125 API calls 97826->97834 97829 d35062 97827->97829 97830 d3508b 97827->97830 97829->97824 97832 d3506d 97829->97832 97830->97823 97836 d88713 messages 27 API calls 97830->97836 97831->97811 97835 d88713 messages 27 API calls 97832->97835 97833->97811 97837 d351cb 97834->97837 97838 d35073 97835->97838 97836->97823 97839 d19940 169 API calls 97837->97839 97838->97819 97838->97823 97840 d351db 97839->97840 97842 d11b84 84 API calls 97840->97842 97841 d8e960 _Yarn 14 API calls 97843 d3513b Concurrency::cancel_current_task 97841->97843 97845 d351f7 97842->97845 97850 d8e960 _Yarn 14 API calls 97843->97850 97844 d350d8 Concurrency::cancel_current_task 97846 d8e960 _Yarn 14 API calls 97844->97846 97848 d3510c Concurrency::cancel_current_task 97844->97848 97847 d11be0 81 API calls 97845->97847 97846->97844 97849 d35207 97847->97849 97848->97841 97851 d1b8a0 168 API calls 97849->97851 97852 d3514d Concurrency::cancel_current_task 97850->97852 97856 d3520f std::ios_base::_Ios_base_dtor Concurrency::cancel_current_task 97851->97856 97855 d352a8 Concurrency::cancel_current_task 97856->97855 97857 d8d60f 25 API calls 97856->97857 97917 d19c45 97916->97917 97918 d19bef 97916->97918 98319 d941c9 48 API calls std::locale::_Setgloballocale 97917->98319 97920 d19c27 97918->97920 98289 d19c50 97918->98289 97923 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 97920->97923 97924 d19c41 97923->97924 97926 d19940 97924->97926 97927 d19985 97926->97927 97928 d19a1c 97926->97928 97927->97928 97929 d1998e __cftof 97927->97929 98585 d1b420 168 API calls 2 library calls 97928->98585 98582 d1b420 168 API calls 2 library calls 97929->98582 97931 d19a00 std::ios_base::_Ios_base_dtor 97932 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 97931->97932 97933 d19a51 97932->97933 97941 d11b84 97933->97941 97935 d199d5 98583 d19820 81 API calls 97935->98583 97937 d199e9 98584 d1b690 84 API calls Concurrency::cancel_current_task 97937->98584 97939 d199f8 97940 d1b8a0 168 API calls 97939->97940 97940->97931 97942 d11bb6 97941->97942 97943 d11bbf 97941->97943 98586 d180b0 97942->98586 97945 d19ab0 97943->97945 97946 d19b1a 97945->97946 97947 d19aec 97945->97947 97946->97617 98650 d120a0 81 API calls 3 library calls 97947->98650 97949 d19afa 97949->97617 97951 d11c98 97950->97951 97952 d11c8c 97950->97952 97954 d28f20 81 API calls 97951->97954 98651 d120a0 81 API calls 3 library calls 97952->98651 97954->97631 97956 d1b8ff 97955->97956 97962 d1b96c Concurrency::cancel_current_task 97955->97962 97957 d19ab0 81 API calls 97956->97957 97958 d1b910 97957->97958 98652 d1ba20 97958->98652 97961 d1b9e0 97961->97658 98810 d1cd20 97962->98810 97963 d1b927 98666 d207c0 97963->98666 98738 d220f0 97963->98738 98742 d20890 97963->98742 97964 d1b93c 97964->97962 97965 d1ba0d 97964->97965 97966 d8d60f 25 API calls 97965->97966 97967 d1ba12 97966->97967 97972 d11c27 97971->97972 97973 d11c1c 97971->97973 97972->97650 99258 d120a0 81 API calls 3 library calls 97973->99258 97975->97660 97976->97712 97977->97766 97978->97773 97979->97778 97980->97779 97981->97783 97983 d8836f 97982->97983 97984 d88370 IsProcessorFeaturePresent 97982->97984 97983->97666 97986 d89055 97984->97986 99259 d89018 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 97986->99259 97988 d89138 97988->97666 99260 d8d59b 25 API calls 2 library calls 97990->99260 97992 d8d61e 99261 d8d62c 11 API calls std::locale::_Setgloballocale 97992->99261 97994 d8d62b 97994->97990 97995 dc8100 Concurrency::cancel_current_task 97994->97995 97995->97628 98001 da2174 std::_Locinfo::_W_Getmonths 97996->98001 97997 da21b2 97998 d8d73d __Wcrtomb 14 API calls 97997->97998 98000 da21b0 97998->98000 97999 da219d RtlAllocateHeap 97999->98000 97999->98001 98000->97788 98001->97997 98001->97999 98009 d9f60f EnterCriticalSection LeaveCriticalSection messages 98001->98009 98004 d8a379 RaiseException 98003->98004 98005 d8a34c 98003->98005 98004->97792 98005->98004 98006->97788 98007->97800 98008->97800 98009->98001 98011 d3571d 98010->98011 98121 d36440 98011->98121 98013 d3575a GetModuleHandleW 98015 d35816 98013->98015 98016 d36440 27 API calls 98015->98016 98017 d35885 98016->98017 98131 d365c0 98017->98131 98019 d3588c 98020 d36440 27 API calls 98019->98020 98021 d3595c 98020->98021 98022 d36440 27 API calls 98021->98022 98023 d35ae8 98022->98023 98044 d35b83 std::ios_base::_Ios_base_dtor Concurrency::cancel_current_task 98023->98044 98136 d111f3 29 API calls 2 library calls 98023->98136 98025 d36440 27 API calls 98033 d35cc5 98025->98033 98026 d35bdb 98027 d35be6 98026->98027 98034 d35cfc Concurrency::cancel_current_task 98026->98034 98028 d19bb0 125 API calls 98027->98028 98030 d35beb 98028->98030 98029 d36440 27 API calls 98031 d35d62 98029->98031 98032 d19940 169 API calls 98030->98032 98031->98044 98137 d2aad0 28 API calls 4 library calls 98031->98137 98035 d35bfb 98032->98035 98036 d35e30 98033->98036 98037 d35de7 98033->98037 98049 d35cd3 _LStrxfrm 98033->98049 98034->98029 98039 d11b84 84 API calls 98035->98039 98042 d88713 messages 27 API calls 98036->98042 98036->98049 98040 d35df2 98037->98040 98041 d36085 Concurrency::cancel_current_task 98037->98041 98043 d35c17 98039->98043 98046 d88713 messages 27 API calls 98040->98046 98045 d3608a 98041->98045 98042->98049 98047 d11be0 81 API calls 98043->98047 98044->98025 98048 d8d60f 25 API calls 98045->98048 98046->98049 98050 d35c27 98047->98050 98051 d3608f 98048->98051 98049->98045 98052 d35ebc Concurrency::cancel_current_task 98049->98052 98053 d1b8a0 168 API calls 98050->98053 98054 d8d60f 25 API calls 98051->98054 98055 d36440 27 API calls 98052->98055 98067 d35f73 Concurrency::cancel_current_task 98052->98067 98053->98044 98063 d36094 Concurrency::cancel_current_task 98054->98063 98057 d35f2f 98055->98057 98056 d35f82 GetModuleHandleW 98058 d35fc1 98056->98058 98059 d35f95 GetProcAddress 98056->98059 98060 d35f45 98057->98060 98138 d2aad0 28 API calls 4 library calls 98057->98138 98065 d36440 27 API calls 98058->98065 98059->98058 98062 d35fa7 GetCurrentProcess 98059->98062 98060->98051 98060->98056 98060->98067 98062->98058 98078 d36166 Concurrency::cancel_current_task 98063->98078 98143 d367b0 26 API calls Concurrency::cancel_current_task 98063->98143 98068 d36022 98065->98068 98066 d360f4 98074 d3610e SysFreeString 98066->98074 98077 d3611b Concurrency::cancel_current_task 98066->98077 98067->98056 98139 d136db 27 API calls collate 98068->98139 98069 d8d60f 25 API calls 98071 d361d9 98069->98071 98072 d361b4 Concurrency::cancel_current_task 98072->97804 98073 d3602a 98140 d1372a 5 API calls collate 98073->98140 98074->98077 98075 d36159 SysFreeString 98075->98078 98077->98075 98077->98078 98078->98069 98078->98072 98079 d36032 98141 d1372a 5 API calls collate 98079->98141 98081 d3603a 98142 d1372a 5 API calls collate 98081->98142 98083 d36042 98084 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98083->98084 98085 d36059 98084->98085 98085->97804 98087 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98086->98087 98088 d36355 98087->98088 98088->97814 98090 d31db3 98089->98090 98091 d31de3 98090->98091 98092 d31dff 98090->98092 98146 d32580 29 API calls 98091->98146 98094 d31e24 98092->98094 98095 d31e08 98092->98095 98098 d31e33 98094->98098 98099 d31e4b 98094->98099 98147 d324c0 29 API calls 98095->98147 98096 d31dec 98101 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98096->98101 98148 d323e0 29 API calls 98098->98148 98149 d32320 29 API calls 98099->98149 98106 d31df9 98101->98106 98102 d31e11 98107 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98102->98107 98104 d31e38 98108 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98104->98108 98105 d31e50 98109 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98105->98109 98106->97816 98110 d31e1e 98107->98110 98111 d31e45 98108->98111 98112 d31e5e 98109->98112 98110->97816 98111->97816 98112->97816 98150 da2098 98113->98150 98115 d8e978 98115->97844 98116->97814 98117->97811 98118->97816 98119->97817 98122 d36496 98121->98122 98123 d365af 98122->98123 98124 d364fd 98122->98124 98130 d364e8 98122->98130 98145 d19b40 27 API calls 2 library calls 98123->98145 98126 d88713 messages 27 API calls 98124->98126 98127 d36515 98126->98127 98144 d36bb0 25 API calls Concurrency::cancel_current_task 98127->98144 98128 d365b4 98130->98013 98132 d365ef Concurrency::cancel_current_task 98131->98132 98133 d365cc 98131->98133 98132->98019 98133->98132 98134 d8d60f 25 API calls 98133->98134 98135 d36639 98134->98135 98136->98026 98137->98044 98138->98060 98139->98073 98140->98079 98141->98081 98142->98083 98143->98066 98144->98130 98145->98128 98146->98096 98147->98102 98148->98104 98149->98105 98151 da20a3 RtlFreeHeap 98150->98151 98155 da20cc __dosmaperr 98150->98155 98152 da20b8 98151->98152 98151->98155 98153 d8d73d __Wcrtomb 12 API calls 98152->98153 98154 da20be GetLastError 98153->98154 98154->98155 98155->98115 98320 d1e310 ConvertStringSecurityDescriptorToSecurityDescriptorW 98289->98320 98292 d1a048 Concurrency::cancel_current_task 98294 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98292->98294 98297 d19c11 InitOnceComplete 98294->98297 98296 d1a072 98298 d8d60f 25 API calls 98296->98298 98297->97917 98297->97920 98301 d1a077 98298->98301 98300 d88713 messages 27 API calls 98304 d19eec Concurrency::cancel_current_task 98300->98304 98302 d19cec 98305 d3d900 27 API calls 98302->98305 98303 d3d900 27 API calls 98306 d19f7e 98303->98306 98304->98296 98304->98303 98307 d19d4c 98305->98307 98306->98292 98306->98296 98347 d73b8a 98307->98347 98311 d19def 98312 d1a06d Concurrency::cancel_current_task 98311->98312 98313 d19e74 98311->98313 98314 d19e9b 98311->98314 98318 d19e24 _LStrxfrm 98311->98318 98312->98296 98313->98312 98315 d19e7f 98313->98315 98317 d88713 messages 27 API calls 98314->98317 98314->98318 98316 d88713 messages 27 API calls 98315->98316 98316->98318 98317->98318 98318->98296 98318->98300 98321 d1e37d 98320->98321 98328 d1e376 Concurrency::cancel_current_task 98320->98328 98371 d1deb0 98321->98371 98323 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98325 d19ca2 98323->98325 98324 d1e3d9 98326 d1e3e8 __cftof 98324->98326 98329 d1e3dd 98324->98329 98325->98306 98341 d88760 98325->98341 98327 d1e425 GetModuleFileNameW 98326->98327 98330 d1e443 98327->98330 98338 d1e54f Concurrency::cancel_current_task 98327->98338 98328->98323 98329->98328 98331 d1e62e 98329->98331 98423 d1daa0 29 API calls 4 library calls 98330->98423 98333 d8d60f 25 API calls 98331->98333 98335 d1e633 98333->98335 98334 d1e454 98334->98338 98424 d1dc20 98334->98424 98337 d1e49d Concurrency::cancel_current_task 98337->98338 98339 d1e629 98337->98339 98338->98329 98338->98331 98340 d8d60f 25 API calls 98339->98340 98340->98331 98342 d88713 messages 27 API calls 98341->98342 98343 d19cc1 98342->98343 98343->98318 98344 d3d900 98343->98344 98533 d3dc50 98344->98533 98346 d3d95d 98346->98302 98539 d738db 98347->98539 98349 d19dd9 98350 d21130 98349->98350 98545 d23d80 98350->98545 98354 d21183 98355 d213d8 98354->98355 98356 d2119d 98354->98356 98577 d134d0 21 API calls collate 98355->98577 98569 d140e8 98356->98569 98359 d211bc 98573 d23640 28 API calls _LStrxfrm 98359->98573 98360 d8d60f 25 API calls 98362 d213e2 98360->98362 98363 d211cc 98574 d23590 28 API calls _LStrxfrm 98363->98574 98365 d211df 98575 d1f310 28 API calls 3 library calls 98365->98575 98367 d211f5 98576 d23590 28 API calls _LStrxfrm 98367->98576 98369 d213b9 Concurrency::cancel_current_task 98369->98311 98370 d21208 Concurrency::cancel_current_task 98370->98360 98370->98369 98495 d8a920 98371->98495 98374 d1df16 98377 d1dc20 93 API calls 98374->98377 98375 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98376 d1e2ee 98375->98376 98376->98324 98378 d1df5d Concurrency::cancel_current_task 98377->98378 98379 d1e2f2 98378->98379 98380 d1e00f Concurrency::cancel_current_task 98378->98380 98381 d8d60f 25 API calls 98379->98381 98497 d1f520 98380->98497 98383 d1e2f7 98381->98383 98385 d8d60f 25 API calls 98383->98385 98384 d1e084 98512 d1e640 98384->98512 98387 d1e2fc 98385->98387 98389 d8d60f 25 API calls 98387->98389 98390 d1e301 98389->98390 98391 d8d60f 25 API calls 98390->98391 98392 d1e306 ConvertStringSecurityDescriptorToSecurityDescriptorW 98391->98392 98395 d1e37d 98392->98395 98404 d1e376 Concurrency::cancel_current_task 98392->98404 98394 d1e0e8 Concurrency::cancel_current_task 98394->98394 98396 d1dc20 93 API calls 98394->98396 98418 d1e2bd Concurrency::cancel_current_task 98394->98418 98397 d1deb0 93 API calls 98395->98397 98402 d1e143 Concurrency::cancel_current_task 98396->98402 98399 d1e3d9 98397->98399 98398 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98400 d1e625 98398->98400 98401 d1e3e8 __cftof 98399->98401 98405 d1e3dd 98399->98405 98400->98324 98403 d1e425 GetModuleFileNameW 98401->98403 98402->98387 98407 d1e1f5 Concurrency::cancel_current_task 98402->98407 98406 d1e443 98403->98406 98420 d1e54f Concurrency::cancel_current_task 98403->98420 98404->98398 98405->98404 98408 d1e62e 98405->98408 98527 d1daa0 29 API calls 4 library calls 98406->98527 98411 d1f520 28 API calls 98407->98411 98410 d8d60f 25 API calls 98408->98410 98413 d1e633 98410->98413 98414 d1e264 98411->98414 98412 d1e454 98416 d1dc20 93 API calls 98412->98416 98412->98420 98415 d1e640 87 API calls 98414->98415 98417 d1e27d 98415->98417 98419 d1e49d Concurrency::cancel_current_task 98416->98419 98417->98390 98417->98418 98418->98375 98419->98420 98421 d1e629 98419->98421 98420->98405 98420->98408 98422 d8d60f 25 API calls 98421->98422 98422->98408 98423->98334 98425 d1dc83 98424->98425 98426 d1dc55 98424->98426 98428 d1dd83 98425->98428 98429 d1dcaa 98425->98429 98427 d1f520 28 API calls 98426->98427 98431 d1dc71 98427->98431 98430 d1f520 28 API calls 98428->98430 98432 d1f520 28 API calls 98429->98432 98434 d1dd92 98430->98434 98431->98337 98433 d1dcb9 98432->98433 98435 d1f520 28 API calls 98433->98435 98436 d1f520 28 API calls 98434->98436 98437 d1dce7 98435->98437 98438 d1ddc0 98436->98438 98530 d1f310 28 API calls 3 library calls 98437->98530 98531 d1f310 28 API calls 3 library calls 98438->98531 98441 d1dd67 Concurrency::cancel_current_task 98441->98337 98442 d1dcfd Concurrency::cancel_current_task 98442->98441 98443 d8d60f 25 API calls 98442->98443 98444 d1dea8 __cftof 98443->98444 98445 d1def8 SHGetSpecialFolderPathW 98444->98445 98446 d1df16 98445->98446 98490 d1e2bd Concurrency::cancel_current_task 98445->98490 98449 d1dc20 93 API calls 98446->98449 98447 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98448 d1e2ee 98447->98448 98448->98337 98450 d1df5d Concurrency::cancel_current_task 98449->98450 98451 d1e2f2 98450->98451 98452 d1e00f Concurrency::cancel_current_task 98450->98452 98453 d8d60f 25 API calls 98451->98453 98454 d1f520 28 API calls 98452->98454 98455 d1e2f7 98453->98455 98456 d1e084 98454->98456 98457 d8d60f 25 API calls 98455->98457 98458 d1e640 87 API calls 98456->98458 98459 d1e2fc 98457->98459 98460 d1e09d 98458->98460 98461 d8d60f 25 API calls 98459->98461 98460->98455 98466 d1e0e8 Concurrency::cancel_current_task 98460->98466 98462 d1e301 98461->98462 98463 d8d60f 25 API calls 98462->98463 98464 d1e306 ConvertStringSecurityDescriptorToSecurityDescriptorW 98463->98464 98467 d1e37d 98464->98467 98476 d1e376 Concurrency::cancel_current_task 98464->98476 98466->98466 98468 d1dc20 93 API calls 98466->98468 98466->98490 98469 d1deb0 93 API calls 98467->98469 98474 d1e143 Concurrency::cancel_current_task 98468->98474 98471 d1e3d9 98469->98471 98470 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98472 d1e625 98470->98472 98473 d1e3e8 __cftof 98471->98473 98477 d1e3dd 98471->98477 98472->98337 98475 d1e425 GetModuleFileNameW 98473->98475 98474->98459 98479 d1e1f5 Concurrency::cancel_current_task 98474->98479 98478 d1e443 98475->98478 98492 d1e54f Concurrency::cancel_current_task 98475->98492 98476->98470 98477->98476 98480 d1e62e 98477->98480 98532 d1daa0 29 API calls 4 library calls 98478->98532 98483 d1f520 28 API calls 98479->98483 98482 d8d60f 25 API calls 98480->98482 98485 d1e633 98482->98485 98486 d1e264 98483->98486 98484 d1e454 98488 d1dc20 93 API calls 98484->98488 98484->98492 98487 d1e640 87 API calls 98486->98487 98489 d1e27d 98487->98489 98491 d1e49d Concurrency::cancel_current_task 98488->98491 98489->98462 98489->98490 98490->98447 98491->98492 98493 d1e629 98491->98493 98492->98477 98492->98480 98494 d8d60f 25 API calls 98493->98494 98494->98480 98496 d1def8 SHGetSpecialFolderPathW 98495->98496 98496->98374 98496->98418 98498 d1f541 _LStrxfrm 98497->98498 98503 d1f571 98497->98503 98498->98384 98499 d1f677 98528 d134d0 21 API calls collate 98499->98528 98501 d8d60f 25 API calls 98504 d1f681 98501->98504 98502 d1f672 Concurrency::cancel_current_task 98502->98499 98503->98499 98503->98502 98505 d1f5d3 98503->98505 98506 d1f5fa 98503->98506 98505->98502 98507 d1f5de 98505->98507 98508 d88713 messages 27 API calls 98506->98508 98510 d1f5e4 _LStrxfrm 98506->98510 98509 d88713 messages 27 API calls 98507->98509 98508->98510 98509->98510 98510->98501 98511 d1f658 Concurrency::cancel_current_task 98510->98511 98511->98384 98513 d1e680 GetFileAttributesW 98512->98513 98514 d1e67e 98512->98514 98518 d1e690 98513->98518 98523 d1e724 Concurrency::cancel_current_task 98513->98523 98514->98513 98515 d1e736 CreateDirectoryW 98516 d1e742 GetLastError 98515->98516 98517 d1e09d 98515->98517 98516->98517 98517->98383 98517->98394 98518->98518 98519 d1f520 28 API calls 98518->98519 98518->98523 98520 d1e6ec 98519->98520 98529 d1d6d0 83 API calls 98520->98529 98522 d1e6f8 98522->98523 98524 d1e77d 98522->98524 98523->98515 98525 d8d60f 25 API calls 98524->98525 98526 d1e782 98525->98526 98527->98412 98529->98522 98530->98442 98531->98442 98532->98484 98534 d3dc90 98533->98534 98538 d3dcc5 98533->98538 98535 d88760 27 API calls 98534->98535 98536 d3dc9c 98535->98536 98537 d88713 messages 27 API calls 98536->98537 98537->98538 98538->98346 98544 d738e8 98539->98544 98540 d738c4 InitializeSRWLock 98540->98349 98541 d738a6 InitializeCriticalSectionEx 98541->98349 98544->98540 98544->98541 98578 d8a3a0 98545->98578 98548 d23e15 98549 d23e0b OutputDebugStringW 98548->98549 98553 d23e3e 98548->98553 98567 d23e57 Concurrency::cancel_current_task _LStrxfrm 98549->98567 98551 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98552 d21172 98551->98552 98568 d23fd0 70 API calls 2 library calls 98552->98568 98554 d23f81 OutputDebugStringW 98553->98554 98555 d23e4a 98553->98555 98554->98567 98556 d23fc0 98555->98556 98560 d23e90 98555->98560 98555->98567 98580 d134d0 21 API calls collate 98556->98580 98558 d23fc5 98561 d8d60f 25 API calls 98558->98561 98559 d23fca Concurrency::cancel_current_task 98560->98559 98562 d23ee7 98560->98562 98563 d23f0e 98560->98563 98561->98559 98562->98559 98565 d88713 messages 27 API calls 98562->98565 98564 d88713 messages 27 API calls 98563->98564 98566 d23ef8 _LStrxfrm 98563->98566 98564->98566 98565->98566 98566->98558 98566->98567 98567->98551 98568->98354 98570 d14122 98569->98570 98572 d14147 _LStrxfrm 98569->98572 98581 d133c3 28 API calls collate 98570->98581 98572->98359 98573->98363 98574->98365 98575->98367 98576->98370 98579 d23de7 WTSGetActiveConsoleSessionId 98578->98579 98579->98548 98579->98549 98581->98572 98582->97935 98583->97937 98584->97939 98585->97931 98587 d180f9 98586->98587 98601 d18185 Concurrency::cancel_current_task 98586->98601 98605 d17f60 98587->98605 98591 d18109 98621 d181d0 28 API calls 5 library calls 98591->98621 98593 d18119 98622 d189b0 98593->98622 98595 d18130 98596 d14300 5 API calls 98595->98596 98597 d1813e 98596->98597 98633 d18730 80 API calls Concurrency::cancel_current_task 98597->98633 98599 d1814b 98600 d14300 5 API calls 98599->98600 98602 d18156 98600->98602 98601->97943 98602->98601 98603 d8d60f 25 API calls 98602->98603 98604 d181c5 98603->98604 98606 d17faa 98605->98606 98616 d18076 98605->98616 98634 d73cd6 98606->98634 98608 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98609 d1809e 98608->98609 98617 d14300 98609->98617 98610 d17faf std::_Stodx_v2 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z 98637 d19620 81 API calls Concurrency::cancel_current_task 98610->98637 98612 d18036 98638 d18530 80 API calls Concurrency::cancel_current_task 98612->98638 98614 d1806b 98615 d14300 5 API calls 98614->98615 98615->98616 98616->98608 98619 d1430c __EH_prolog3_catch 98617->98619 98644 d12c9c 98619->98644 98620 d1436d messages 98620->98591 98621->98593 98623 d189ff 98622->98623 98624 d12c9c 5 API calls 98623->98624 98625 d18a1b 98624->98625 98626 d18bce 98625->98626 98649 d128d1 27 API calls 3 library calls 98625->98649 98626->98595 98628 d18c51 98629 d8a332 Concurrency::cancel_current_task RaiseException 98628->98629 98630 d18c5f 98629->98630 98631 d8e960 _Yarn 14 API calls 98630->98631 98632 d18c71 Concurrency::cancel_current_task 98631->98632 98632->98595 98633->98599 98639 d76d6a 98634->98639 98637->98612 98638->98614 98640 d76d87 GetSystemTimeAsFileTime 98639->98640 98641 d76d7b GetSystemTimePreciseAsFileTime 98639->98641 98642 d73ce4 98640->98642 98641->98642 98642->98610 98646 d12ca8 __EH_prolog3 98644->98646 98645 d12cf7 messages 98645->98620 98646->98645 98648 d12c33 5 API calls 2 library calls 98646->98648 98648->98645 98649->98628 98650->97949 98651->97951 98654 d1ba83 98652->98654 98653 d1bba2 98813 d134d0 21 API calls collate 98653->98813 98654->98653 98657 d1bb9d Concurrency::cancel_current_task 98654->98657 98659 d1bb43 98654->98659 98660 d1bb64 98654->98660 98663 d1baca _LStrxfrm 98654->98663 98656 d1bb50 98658 d8d60f 25 API calls 98656->98658 98656->98663 98657->98653 98661 d1bbac 98658->98661 98659->98657 98662 d1bb4a 98659->98662 98660->98663 98665 d88713 messages 27 API calls 98660->98665 98664 d88713 messages 27 API calls 98662->98664 98663->97963 98664->98656 98665->98663 98667 d207cb Concurrency::cancel_current_task 98666->98667 98668 d8d60f 25 API calls 98667->98668 98670 d2083b Concurrency::cancel_current_task __Mtx_destroy_in_situ 98667->98670 98669 d20884 98668->98669 98671 d73bab 13 API calls 98669->98671 98670->97964 98672 d208dd 98671->98672 98673 d21045 98672->98673 98674 d208e8 98672->98674 98675 d73faf 79 API calls 98673->98675 98676 d208f4 ConvertStringSecurityDescriptorToSecurityDescriptorW 98674->98676 98679 d20a51 __cftof 98674->98679 98677 d2104b 98675->98677 98680 d20911 98676->98680 98693 d20fdb std::ios_base::_Ios_base_dtor __Mtx_unlock 98676->98693 98678 d8d60f 25 API calls 98677->98678 98688 d20f65 98678->98688 98814 d23110 98679->98814 98684 d1f520 28 API calls 98680->98684 98681 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98685 d2103f 98681->98685 98687 d20991 98684->98687 98685->97964 98689 d1e640 87 API calls 98687->98689 98877 d128d1 27 API calls 3 library calls 98688->98877 98692 d209a4 98689->98692 98692->98677 98696 d209ec Concurrency::cancel_current_task 98692->98696 98693->98681 98700 d20a31 98696->98700 98701 d20a1d 98696->98701 98698 d21087 98699 d8a332 Concurrency::cancel_current_task RaiseException 98698->98699 98703 d21098 98699->98703 98700->98679 98704 d20a42 LocalFree 98700->98704 98701->98693 98705 d20a25 LocalFree 98701->98705 98704->98679 98705->98693 98739 d220f9 98738->98739 98741 d22123 98738->98741 98739->98741 99212 d94ef7 98739->99212 98741->97964 98743 d73bab 13 API calls 98742->98743 98744 d208dd 98743->98744 98745 d21045 98744->98745 98746 d208e8 98744->98746 98747 d73faf 79 API calls 98745->98747 98748 d208f4 ConvertStringSecurityDescriptorToSecurityDescriptorW 98746->98748 98751 d20a51 __cftof 98746->98751 98749 d2104b 98747->98749 98752 d20911 98748->98752 98765 d20fdb std::ios_base::_Ios_base_dtor __Mtx_unlock 98748->98765 98750 d8d60f 25 API calls 98749->98750 98760 d20f65 98750->98760 98754 d23110 107 API calls 98751->98754 98756 d1f520 28 API calls 98752->98756 98753 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 98757 d2103f 98753->98757 98755 d20a84 98754->98755 98758 d20fa9 98755->98758 98763 d88713 messages 27 API calls 98755->98763 98808 d20c43 _LStrxfrm 98755->98808 98759 d20991 98756->98759 98757->97964 99249 d22b90 73 API calls Concurrency::cancel_current_task 98758->99249 98761 d1e640 87 API calls 98759->98761 99250 d128d1 27 API calls 3 library calls 98760->99250 98764 d209a4 98761->98764 98767 d20ae1 __cftof 98763->98767 98764->98749 98768 d209ec Concurrency::cancel_current_task 98764->98768 98765->98753 98778 d73367 std::_Lockit::_Lockit 7 API calls 98767->98778 98772 d20a31 98768->98772 98773 d20a1d 98768->98773 98769 d189b0 27 API calls 98774 d20d38 98769->98774 98770 d21087 98771 d8a332 Concurrency::cancel_current_task RaiseException 98770->98771 98775 d21098 98771->98775 98772->98751 98776 d20a42 LocalFree 98772->98776 98773->98765 98777 d20a25 LocalFree 98773->98777 98779 d12c9c 5 API calls 98774->98779 98785 d20d68 98774->98785 98776->98751 98777->98765 98781 d20b0d 98778->98781 98779->98785 98780 d12c9c 5 API calls 98782 d20e1f 98780->98782 99243 d73184 77 API calls 2 library calls 98781->99243 98791 d20e6e 98782->98791 98809 d22310 70 API calls 98782->98809 98784 d20b55 99244 d733f6 48 API calls 4 library calls 98784->99244 98785->98758 98785->98760 98785->98780 98787 d20b61 99245 d13128 77 API calls 3 library calls 98787->99245 98789 d20b8b 98790 d73084 std::locale::_Init 57 API calls 98789->98790 98795 d20b9c 98790->98795 98791->98758 98792 d23030 73 API calls 98791->98792 98793 d20f29 98792->98793 98793->98760 98796 d20f78 98793->98796 98794 d20be6 99246 d75688 82 API calls 8 library calls 98794->99246 98795->98794 98797 d73367 std::_Lockit::_Lockit 7 API calls 98795->98797 99247 d1e790 34 API calls 2 library calls 98796->99247 98799 d20bc5 98797->98799 98802 d733bf std::_Lockit::~_Lockit 2 API calls 98799->98802 98800 d20bf7 98804 d20c1e 98800->98804 98806 d8e960 _Yarn 14 API calls 98800->98806 98800->98808 98802->98794 98803 d20f9f 99248 d21740 28 API calls 98803->99248 98807 d9594f _Yarn 15 API calls 98804->98807 98806->98804 98807->98808 98808->98769 98809->98791 99251 d1cc80 98810->99251 98812 d1cd2f Concurrency::cancel_current_task 98812->97961 98878 d1be30 98814->98878 98822 d23388 98828 d23333 98822->98828 98903 d128d1 27 API calls 3 library calls 98822->98903 98824 d233e3 98877->98698 98904 d1c0c0 98878->98904 98883 d1be6f 98884 d1be7c 98883->98884 98913 d72bab 9 API calls 2 library calls 98883->98913 98891 d1bbb0 98884->98891 98886 d1be86 98914 d128d1 27 API calls 3 library calls 98886->98914 98888 d1bebc 98889 d8a332 Concurrency::cancel_current_task RaiseException 98888->98889 98890 d1becb 98889->98890 98892 d88713 messages 27 API calls 98891->98892 98893 d1bbea 98892->98893 98894 d73084 std::locale::_Init 57 API calls 98893->98894 98895 d1bc01 98894->98895 98895->98822 98896 d740b7 98895->98896 98898 d74011 98896->98898 98897 d23281 98897->98822 98898->98897 98901 d74079 98898->98901 98952 d95408 70 API calls 98898->98952 98901->98897 98903->98824 98905 d88713 messages 27 API calls 98904->98905 98906 d1c13a 98905->98906 98907 d73084 std::locale::_Init 57 API calls 98906->98907 98908 d1be3b 98907->98908 98909 d1bff0 98908->98909 98910 d1c02e 98909->98910 98915 d132de 98910->98915 98913->98884 98914->98888 98916 d132ea __EH_prolog3_GS 98915->98916 98917 d73367 std::_Lockit::_Lockit 7 API calls 98916->98917 98918 d132f7 98917->98918 98935 d12d14 14 API calls 3 library calls 98918->98935 98920 d13320 98922 d733bf std::_Lockit::~_Lockit 2 API calls 98920->98922 98921 d1330e std::locale::_Locimp::_Makeushloc 98921->98920 98936 d131d9 80 API calls 4 library calls 98921->98936 98924 d13365 98922->98924 98938 d88def 5 API calls __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 98924->98938 98925 d1332e 98927 d13335 98925->98927 98928 d1336d 98925->98928 98937 d73052 27 API calls messages 98927->98937 98939 d13268 RaiseException Concurrency::cancel_current_task 98928->98939 98932 d13372 98940 d732da LCMapStringEx ___crtLCMapStringW 98932->98940 98934 d1338d 98934->98883 98934->98886 98935->98921 98936->98925 98937->98920 98939->98932 98940->98934 98952->98901 99213 d94f09 99212->99213 99217 d94f12 ___scrt_uninitialize_crt 99212->99217 99228 d94d9c 72 API calls ___scrt_uninitialize_crt 99213->99228 99215 d94f0f 99215->98741 99216 d94f23 99216->98741 99217->99216 99220 d94d3c 99217->99220 99221 d94d48 ___scrt_is_nonwritable_in_current_image 99220->99221 99229 d9582c EnterCriticalSection 99221->99229 99223 d94d56 99230 d94ea6 99223->99230 99227 d94d79 99227->98741 99228->99215 99229->99223 99231 d94ebc 99230->99231 99232 d94eb3 99230->99232 99234 d94e41 ___scrt_uninitialize_crt 68 API calls 99231->99234 99241 d94d9c 72 API calls ___scrt_uninitialize_crt 99232->99241 99235 d94ec2 99234->99235 99236 d94d67 99235->99236 99237 da2e1c std::locale::_Setgloballocale 14 API calls 99235->99237 99240 d94d90 LeaveCriticalSection ___scrt_uninitialize_crt 99236->99240 99238 d94ed8 99237->99238 99242 da56f0 18 API calls 2 library calls 99238->99242 99240->99227 99241->99236 99242->99236 99243->98784 99244->98787 99245->98789 99246->98800 99247->98803 99249->98765 99250->98770 99252 d1cc89 99251->99252 99253 d1cccb Concurrency::cancel_current_task 99251->99253 99252->99253 99254 d8d60f 25 API calls 99252->99254 99253->98812 99255 d1cd1f 99254->99255 99256 d1cc80 25 API calls 99255->99256 99257 d1cd2f Concurrency::cancel_current_task 99256->99257 99257->98812 99258->97972 99259->97988 99260->97992 99261->97994 99262 d64d93 99263 d64d14 99262->99263 99263->99262 99265 d7293c 99263->99265 99291 d7269d 99265->99291 99268 d729a9 99269 d728da DloadReleaseSectionWriteAccess 8 API calls 99268->99269 99270 d729b4 RaiseException 99269->99270 99286 d72ba2 99270->99286 99271 d72a45 LoadLibraryExA 99273 d72aa6 99271->99273 99274 d72a58 GetLastError 99271->99274 99272 d729cd 99272->99271 99272->99273 99275 d72b74 99272->99275 99277 d72ab8 99272->99277 99276 d72ab1 FreeLibrary 99273->99276 99273->99277 99278 d72a81 99274->99278 99285 d72a6b 99274->99285 99297 d728da 99275->99297 99276->99277 99277->99275 99279 d72b16 GetProcAddress 99277->99279 99280 d728da DloadReleaseSectionWriteAccess 8 API calls 99278->99280 99279->99275 99281 d72b26 GetLastError 99279->99281 99282 d72a8c RaiseException 99280->99282 99283 d72b39 99281->99283 99282->99286 99283->99275 99287 d728da DloadReleaseSectionWriteAccess 8 API calls 99283->99287 99285->99273 99285->99278 99286->99263 99288 d72b5a RaiseException 99287->99288 99289 d7269d ___delayLoadHelper2@8 7 API calls 99288->99289 99290 d72b71 99289->99290 99290->99275 99292 d726ca 99291->99292 99293 d726a9 99291->99293 99292->99268 99292->99272 99305 d72743 99293->99305 99295 d726ae 99295->99292 99310 d7286c 99295->99310 99298 d7290e 99297->99298 99299 d728ec 99297->99299 99298->99286 99300 d72743 DloadReleaseSectionWriteAccess 4 API calls 99299->99300 99301 d728f1 99300->99301 99302 d72909 99301->99302 99303 d7286c DloadProtectSection 3 API calls 99301->99303 99317 d72910 GetModuleHandleW GetProcAddress GetProcAddress ReleaseSRWLockExclusive DloadGetSRWLockFunctionPointers 99302->99317 99303->99302 99315 d726d0 GetModuleHandleW GetProcAddress GetProcAddress 99305->99315 99307 d72748 99308 d72760 AcquireSRWLockExclusive 99307->99308 99309 d72764 99307->99309 99308->99295 99309->99295 99311 d72881 DloadObtainSection 99310->99311 99312 d728bc VirtualProtect 99311->99312 99313 d72887 99311->99313 99316 d72782 VirtualQuery GetSystemInfo 99311->99316 99312->99313 99313->99292 99315->99307 99316->99312 99317->99298 99318 da5192 99319 da2e1c std::locale::_Setgloballocale 14 API calls 99318->99319 99320 da51a0 99319->99320 99321 da51ce 99320->99321 99322 da51af 99320->99322 99324 da51e9 99321->99324 99325 da51dc 99321->99325 99323 d8d73d __Wcrtomb 14 API calls 99322->99323 99326 da51b4 99323->99326 99330 da51fc 99324->99330 99346 da555a 16 API calls __wsopen_s 99324->99346 99327 d8d73d __Wcrtomb 14 API calls 99325->99327 99327->99326 99330->99326 99331 daec2a __wsopen_s 14 API calls 99330->99331 99332 da526e 99330->99332 99333 da527b 99330->99333 99331->99332 99332->99333 99347 da55f5 15 API calls 2 library calls 99332->99347 99335 da53c0 99333->99335 99336 da2e1c std::locale::_Setgloballocale 14 API calls 99335->99336 99337 da53cf 99336->99337 99338 da5472 99337->99338 99339 da53e2 99337->99339 99340 da5ee6 __wsopen_s 68 API calls 99338->99340 99341 da53ff 99339->99341 99342 da5423 99339->99342 99344 da540c 99340->99344 99343 da5ee6 __wsopen_s 68 API calls 99341->99343 99342->99344 99345 da6972 18 API calls 99342->99345 99343->99344 99344->99326 99345->99344 99346->99330 99347->99333 99348 d9ed30 99349 d9ed4f 99348->99349 99350 d9ed39 99348->99350 99350->99349 99354 d9ed5c 99350->99354 99352 d9ed46 99352->99349 99367 d9f009 15 API calls 3 library calls 99352->99367 99355 d9ed68 99354->99355 99356 d9ed65 99354->99356 99368 daa3f0 99355->99368 99356->99352 99361 d9ed7a 99363 da2098 _free 14 API calls 99361->99363 99365 d9eda9 99363->99365 99364 d9ed85 99366 da2098 _free 14 API calls 99364->99366 99365->99352 99366->99361 99367->99349 99369 daa3f9 99368->99369 99373 d9ed6f 99368->99373 99387 da1d66 48 API calls 3 library calls 99369->99387 99371 daa41c 99388 daa234 56 API calls 3 library calls 99371->99388 99374 daa690 GetEnvironmentStringsW 99373->99374 99375 daa6a7 99374->99375 99385 daa6fd 99374->99385 99389 da98ff 99375->99389 99376 d9ed74 99376->99361 99386 d9edfd 25 API calls 4 library calls 99376->99386 99377 daa706 FreeEnvironmentStringsW 99377->99376 99379 daa6c0 99380 da2174 std::_Locinfo::_W_Getmonths 15 API calls 99379->99380 99379->99385 99381 daa6d0 99380->99381 99382 daa6e8 99381->99382 99383 da98ff __cftof WideCharToMultiByte 99381->99383 99384 da2098 _free 14 API calls 99382->99384 99383->99382 99384->99385 99385->99376 99385->99377 99386->99364 99387->99371 99388->99373 99391 da9918 WideCharToMultiByte 99389->99391 99391->99379 99392 d35318 99509 d888fa EnterCriticalSection 99392->99509 99394 d35322 99396 d88713 messages 27 API calls 99394->99396 99492 d3571a 99394->99492 99395 d36440 27 API calls 99397 d3575a GetModuleHandleW 99395->99397 99398 d3535e 99396->99398 99402 d35816 99397->99402 99514 d34a40 99398->99514 99401 d353a7 99403 d34a40 33 API calls 99401->99403 99405 d36440 27 API calls 99402->99405 99404 d353ba 99403->99404 99406 d34a40 33 API calls 99404->99406 99407 d35885 99405->99407 99408 d353cb 99406->99408 99410 d365c0 25 API calls 99407->99410 99521 d361f0 29 API calls 3 library calls 99408->99521 99412 d3588c 99410->99412 99411 d353e9 99414 d34a40 33 API calls 99411->99414 99413 d36440 27 API calls 99412->99413 99421 d3595c 99413->99421 99415 d35486 99414->99415 99416 d34a40 33 API calls 99415->99416 99417 d35499 99416->99417 99418 d34a40 33 API calls 99417->99418 99419 d354aa 99418->99419 99522 d361f0 29 API calls 3 library calls 99419->99522 99423 d36440 27 API calls 99421->99423 99422 d354c8 99424 d34a40 33 API calls 99422->99424 99432 d35ae8 99423->99432 99425 d35565 99424->99425 99426 d34a40 33 API calls 99425->99426 99427 d35578 99426->99427 99428 d34a40 33 API calls 99427->99428 99429 d35589 99428->99429 99523 d361f0 29 API calls 3 library calls 99429->99523 99431 d355a7 99436 d34a40 33 API calls 99431->99436 99459 d35b83 std::ios_base::_Ios_base_dtor Concurrency::cancel_current_task 99432->99459 99527 d111f3 29 API calls 2 library calls 99432->99527 99434 d36440 27 API calls 99445 d35cc5 99434->99445 99435 d35bdb 99437 d35be6 99435->99437 99447 d35cfc Concurrency::cancel_current_task 99435->99447 99439 d3564e 99436->99439 99438 d19bb0 125 API calls 99437->99438 99441 d35beb 99438->99441 99442 d34a40 33 API calls 99439->99442 99440 d36440 27 API calls 99443 d35d62 99440->99443 99444 d19940 169 API calls 99441->99444 99446 d35661 99442->99446 99443->99459 99528 d2aad0 28 API calls 4 library calls 99443->99528 99448 d35bfb 99444->99448 99449 d35e30 99445->99449 99450 d35de7 99445->99450 99465 d35cd3 _LStrxfrm 99445->99465 99451 d34a40 33 API calls 99446->99451 99447->99440 99453 d11b84 84 API calls 99448->99453 99457 d88713 messages 27 API calls 99449->99457 99449->99465 99454 d35df2 99450->99454 99455 d36085 Concurrency::cancel_current_task 99450->99455 99456 d35672 99451->99456 99458 d35c17 99453->99458 99461 d88713 messages 27 API calls 99454->99461 99460 d3608a 99455->99460 99524 d361f0 29 API calls 3 library calls 99456->99524 99457->99465 99463 d11be0 81 API calls 99458->99463 99459->99434 99464 d8d60f 25 API calls 99460->99464 99461->99465 99467 d35c27 99463->99467 99468 d3608f 99464->99468 99465->99460 99469 d35ebc Concurrency::cancel_current_task 99465->99469 99466 d35690 99474 d88713 messages 27 API calls 99466->99474 99471 d1b8a0 168 API calls 99467->99471 99472 d8d60f 25 API calls 99468->99472 99470 d35f73 Concurrency::cancel_current_task 99469->99470 99473 d36440 27 API calls 99469->99473 99475 d35f82 GetModuleHandleW 99470->99475 99471->99459 99488 d36094 Concurrency::cancel_current_task 99472->99488 99476 d35f2f 99473->99476 99477 d356d2 99474->99477 99478 d35f95 GetProcAddress 99475->99478 99487 d35fc1 99475->99487 99484 d35f45 99476->99484 99529 d2aad0 28 API calls 4 library calls 99476->99529 99525 d885bf 17 API calls 99477->99525 99481 d35fa7 GetCurrentProcess 99478->99481 99478->99487 99481->99487 99483 d35710 99526 d888b0 EnterCriticalSection LeaveCriticalSection RtlWakeAllConditionVariable SetEvent ResetEvent 99483->99526 99484->99468 99484->99470 99484->99475 99485 d36440 27 API calls 99490 d36022 99485->99490 99486 d360f4 99497 d3610e SysFreeString 99486->99497 99500 d3611b Concurrency::cancel_current_task 99486->99500 99487->99485 99501 d36166 Concurrency::cancel_current_task 99488->99501 99534 d367b0 26 API calls Concurrency::cancel_current_task 99488->99534 99530 d136db 27 API calls collate 99490->99530 99491 d8d60f 25 API calls 99494 d361d9 99491->99494 99492->99395 99495 d361b4 Concurrency::cancel_current_task 99496 d3602a 99531 d1372a 5 API calls collate 99496->99531 99497->99500 99498 d36159 SysFreeString 99498->99501 99500->99498 99500->99501 99501->99491 99501->99495 99502 d36032 99532 d1372a 5 API calls collate 99502->99532 99504 d3603a 99533 d1372a 5 API calls collate 99504->99533 99506 d36042 99507 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99506->99507 99508 d36059 99507->99508 99510 d8890e 99509->99510 99511 d88913 LeaveCriticalSection 99510->99511 99535 d88982 SleepConditionVariableCS LeaveCriticalSection WaitForSingleObjectEx EnterCriticalSection 99510->99535 99511->99394 99515 d88713 messages 27 API calls 99514->99515 99516 d34a6e 99515->99516 99518 d34aa5 _com_issue_error 99516->99518 99536 d89900 99516->99536 99519 d34ab8 Concurrency::cancel_current_task 99518->99519 99520 d34afc SysFreeString 99518->99520 99519->99401 99520->99519 99521->99411 99522->99422 99523->99431 99524->99466 99525->99483 99526->99492 99527->99435 99528->99459 99529->99484 99530->99496 99531->99502 99532->99504 99533->99506 99534->99486 99535->99510 99537 d8993d 99536->99537 99538 d89960 99536->99538 99539 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99537->99539 99540 d89a33 _com_issue_error 99538->99540 99541 d8997f MultiByteToWideChar 99538->99541 99542 d8995a 99539->99542 99544 d89a47 GetLastError 99540->99544 99543 d8999c 99541->99543 99541->99544 99542->99518 99545 d9594f _Yarn 15 API calls 99543->99545 99546 d899ae __Strxfrm 99543->99546 99548 d89a51 _com_issue_error 99544->99548 99545->99546 99546->99540 99549 d899fa MultiByteToWideChar 99546->99549 99547 d89a70 GetLastError 99553 d89a7a _com_issue_error 99547->99553 99548->99547 99550 d8e960 _Yarn 14 API calls 99548->99550 99549->99548 99551 d89a0e SysAllocString 99549->99551 99552 d89a6d 99550->99552 99554 d89a25 99551->99554 99555 d89a1f 99551->99555 99552->99547 99553->99518 99554->99537 99554->99540 99556 d8e960 _Yarn 14 API calls 99555->99556 99556->99554 99557 d64cfa 99558 d64c79 99557->99558 99559 d7293c ___delayLoadHelper2@8 16 API calls 99558->99559 99559->99558 99563 d64db8 99564 d64da7 99563->99564 99565 d7293c ___delayLoadHelper2@8 16 API calls 99564->99565 99566 d64db4 99565->99566 99567 da732a 99572 da70bf 99567->99572 99569 da7340 99570 da7369 99569->99570 99582 db0408 99569->99582 99575 da70ed ___vcrt_InitializeCriticalSectionEx 99572->99575 99573 d8d73d __Wcrtomb 14 API calls 99574 da7248 99573->99574 99574->99569 99580 da723d 99575->99580 99585 d92041 99575->99585 99577 da72a5 99578 d92041 49 API calls 99577->99578 99577->99580 99579 da72c3 99578->99579 99579->99580 99581 d92041 49 API calls 99579->99581 99580->99573 99580->99574 99581->99580 99594 dafb11 99582->99594 99584 db0423 99584->99570 99586 d92072 99585->99586 99587 d9204f 99585->99587 99593 d9208d 49 API calls 3 library calls 99586->99593 99587->99586 99588 d92055 99587->99588 99590 d8d73d __Wcrtomb 14 API calls 99588->99590 99592 d9205a 99590->99592 99591 d92088 99591->99577 99592->99577 99593->99591 99595 dafb1d ___scrt_is_nonwritable_in_current_image 99594->99595 99596 dafb24 99595->99596 99598 dafb4f 99595->99598 99597 d8d73d __Wcrtomb 14 API calls 99596->99597 99601 dafb29 99597->99601 99603 db00de 99598->99603 99601->99584 99651 dafeba 99603->99651 99606 db0129 99665 daadb9 99606->99665 99607 db0110 99679 d8d72a 14 API calls __Wcrtomb 99607->99679 99610 db0115 99615 d8d73d __Wcrtomb 14 API calls 99610->99615 99612 db014e 99678 dafe25 CreateFileW 99612->99678 99613 db0137 99680 d8d72a 14 API calls __Wcrtomb 99613->99680 99617 dafb73 99615->99617 99650 dafba6 LeaveCriticalSection __wsopen_s 99617->99650 99618 db013c 99620 d8d73d __Wcrtomb 14 API calls 99618->99620 99619 db0204 GetFileType 99622 db020f GetLastError 99619->99622 99623 db0256 99619->99623 99620->99610 99621 db01d9 GetLastError 99682 d8d707 14 API calls 2 library calls 99621->99682 99683 d8d707 14 API calls 2 library calls 99622->99683 99684 daad04 15 API calls 3 library calls 99623->99684 99624 db0187 99624->99619 99624->99621 99681 dafe25 CreateFileW 99624->99681 99628 db021d CloseHandle 99628->99610 99631 db0246 99628->99631 99630 db01cc 99630->99619 99630->99621 99632 d8d73d __Wcrtomb 14 API calls 99631->99632 99634 db024b 99632->99634 99633 db0277 99635 db02c3 99633->99635 99685 db0034 70 API calls 3 library calls 99633->99685 99634->99610 99639 db02ca 99635->99639 99686 dafbd2 71 API calls 3 library calls 99635->99686 99638 db02f8 99638->99639 99640 db0306 99638->99640 99641 da6b6c __wsopen_s 17 API calls 99639->99641 99640->99617 99642 db0382 CloseHandle 99640->99642 99641->99617 99687 dafe25 CreateFileW 99642->99687 99644 db03ad 99645 db03b7 GetLastError 99644->99645 99649 db03e3 99644->99649 99688 d8d707 14 API calls 2 library calls 99645->99688 99647 db03c3 99689 daaecc 15 API calls 3 library calls 99647->99689 99649->99617 99650->99601 99652 dafedb 99651->99652 99655 dafeea 99651->99655 99654 d8d73d __Wcrtomb 14 API calls 99652->99654 99652->99655 99654->99655 99690 dafe4a 99655->99690 99656 daff2d 99657 daff51 99656->99657 99658 d8d73d __Wcrtomb 14 API calls 99656->99658 99662 daffaf 99657->99662 99695 d9f7e4 14 API calls __Wcrtomb 99657->99695 99658->99657 99660 daffaa 99661 db0027 99660->99661 99660->99662 99696 d8d62c 11 API calls std::locale::_Setgloballocale 99661->99696 99662->99606 99662->99607 99664 db0033 99666 daadc5 ___scrt_is_nonwritable_in_current_image 99665->99666 99697 d9cd41 EnterCriticalSection 99666->99697 99669 daadf1 99701 daab93 15 API calls 3 library calls 99669->99701 99672 daadcc 99672->99669 99673 daae60 EnterCriticalSection 99672->99673 99675 daae13 99672->99675 99673->99675 99676 daae6d LeaveCriticalSection 99673->99676 99674 daadf6 99674->99675 99702 daace1 EnterCriticalSection 99674->99702 99698 daaec3 99675->99698 99676->99672 99678->99624 99679->99610 99680->99618 99681->99630 99682->99610 99683->99628 99684->99633 99685->99635 99686->99638 99687->99644 99688->99647 99689->99649 99692 dafe62 99690->99692 99691 dafe7d 99691->99656 99692->99691 99693 d8d73d __Wcrtomb 14 API calls 99692->99693 99694 dafea1 99693->99694 99694->99656 99695->99660 99696->99664 99697->99672 99703 d9cd91 LeaveCriticalSection 99698->99703 99700 daae33 99700->99612 99700->99613 99701->99674 99702->99675 99703->99700 99708 d229e0 99709 d22a00 99708->99709 99710 d22a15 99708->99710 99711 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99709->99711 99712 d22a2b 99710->99712 99720 d22a54 99710->99720 99713 d22a0f 99711->99713 99714 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99712->99714 99717 d22a4e 99714->99717 99715 d22b4c 99716 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99715->99716 99718 d22b60 99716->99718 99720->99715 99724 d22b07 99720->99724 99727 d22a86 99720->99727 99721 d22ae0 99721->99715 99722 d22af0 99721->99722 99723 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99722->99723 99725 d22b01 99723->99725 99726 d22b1f 99724->99726 99728 d9569d 70 API calls 99724->99728 99726->99715 99729 d22b34 99726->99729 99727->99715 99732 d94762 52 API calls 3 library calls 99727->99732 99728->99726 99730 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99729->99730 99731 d22b46 99730->99731 99732->99721 99737 da3e2f 99738 da2174 std::_Locinfo::_W_Getmonths 15 API calls 99737->99738 99739 da3e3a 99738->99739 99740 da3e41 99739->99740 99742 da3e67 99739->99742 99741 da2098 _free 14 API calls 99740->99741 99744 da3e47 99741->99744 99743 da2098 _free 14 API calls 99742->99743 99743->99744 99745 da2098 _free 14 API calls 99744->99745 99746 da3e9d 99745->99746 99747 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99746->99747 99748 da3eab 99747->99748 99749 daeced 99750 daecf9 ___scrt_is_nonwritable_in_current_image 99749->99750 99757 d9cd41 EnterCriticalSection 99750->99757 99752 daed04 99758 daed4c 99752->99758 99754 daed1a 99773 daed43 LeaveCriticalSection std::_Lockit::~_Lockit 99754->99773 99756 daed2e 99757->99752 99759 daed5b 99758->99759 99760 daed6e 99758->99760 99761 d8d73d __Wcrtomb 14 API calls 99759->99761 99762 daedbc 99760->99762 99763 daed80 99760->99763 99766 daed60 99761->99766 99764 d8d73d __Wcrtomb 14 API calls 99762->99764 99774 daec80 99763->99774 99764->99766 99766->99754 99769 daedd7 99769->99766 99770 daede5 99769->99770 99779 d8d62c 11 API calls std::locale::_Setgloballocale 99770->99779 99772 daedf1 99773->99756 99776 daec8d 99774->99776 99775 daece0 99775->99766 99778 da18d3 14 API calls __Wcrtomb 99775->99778 99776->99775 99780 db129f 50 API calls 99776->99780 99778->99769 99779->99772 99780->99776 99781 d88aa2 99782 d88aae ___scrt_is_nonwritable_in_current_image 99781->99782 99809 d883f9 99782->99809 99784 d88ab5 99785 d88c08 99784->99785 99788 d88adf ___scrt_is_nonwritable_in_current_image ___scrt_release_startup_lock std::locale::_Setgloballocale 99784->99788 99828 d893f2 4 API calls 2 library calls 99785->99828 99787 d88c0f 99821 d9e9fc 99787->99821 99793 d88afe 99788->99793 99794 d88b80 99788->99794 99797 d88b78 99788->99797 99792 d88c1d 99817 d8950d GetStartupInfoW __cftof 99794->99817 99796 d88b85 99818 d159aa 99796->99818 99824 d9c768 54 API calls 4 library calls 99797->99824 99799 d88b7f 99799->99794 99803 d88ba1 99803->99787 99804 d88ba5 99803->99804 99805 d88bae 99804->99805 99826 d9e9b1 23 API calls std::locale::_Setgloballocale 99804->99826 99827 d8856a 79 API calls ___scrt_uninitialize_crt 99805->99827 99808 d88bb6 99808->99793 99810 d88402 99809->99810 99830 d89215 IsProcessorFeaturePresent 99810->99830 99812 d8840e 99831 d8bd89 10 API calls 2 library calls 99812->99831 99814 d88417 99814->99784 99815 d88413 99815->99814 99832 d8bda8 7 API calls 2 library calls 99815->99832 99817->99796 99833 d14e1f 99818->99833 103078 d9e89a 99821->103078 99824->99799 99825 d89543 GetModuleHandleW 99825->99803 99826->99805 99827->99808 99828->99787 99829 d9e9c0 23 API calls std::locale::_Setgloballocale 99829->99792 99830->99812 99831->99815 99832->99814 100076 d3d6d0 GetModuleHandleW 99833->100076 99835 d14e6c 99836 d14ec6 99835->99836 99838 d19bb0 125 API calls 99835->99838 100080 d14d63 99836->100080 99840 d14e7a 99838->99840 99843 d19940 169 API calls 99840->99843 99841 d14ee0 99845 d19bb0 125 API calls 99841->99845 99842 d14f39 CoInitializeEx 99844 d14f48 99842->99844 99846 d14e8a 99843->99846 99848 d14f56 99844->99848 100100 d15a4f 99844->100100 99850 d14ee5 99845->99850 99847 d11b84 84 API calls 99846->99847 99851 d14eab 99847->99851 99852 d88760 27 API calls 99848->99852 99853 d19940 169 API calls 99850->99853 99854 d11be0 81 API calls 99851->99854 99855 d14f78 99852->99855 99856 d14ef5 99853->99856 99857 d14ebb 99854->99857 100137 d15d57 99855->100137 99858 d11b84 84 API calls 99856->99858 100327 d1136c 99857->100327 99860 d14f16 99858->99860 99862 d11be0 81 API calls 99860->99862 99863 d14f26 99862->99863 99865 d1136c 168 API calls 99863->99865 99864 d14f91 99866 d14ff1 99864->99866 99867 d14f9b 99864->99867 99869 d14f31 99865->99869 99870 d88760 27 API calls 99866->99870 99868 d19bb0 125 API calls 99867->99868 99871 d14fa0 99868->99871 99874 d158e3 CloseHandle 99869->99874 99875 d158ef 99869->99875 99872 d15004 99870->99872 99873 d19940 169 API calls 99871->99873 100141 d15db6 99872->100141 99876 d14fb0 99873->99876 99874->99875 99877 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 99875->99877 99879 d11b84 84 API calls 99876->99879 99880 d1590c 99877->99880 99882 d14fd1 99879->99882 99880->99825 99881 d15020 99883 d1507b __cftof 99881->99883 99884 d1502e 99881->99884 99885 d11be0 81 API calls 99882->99885 99890 d88760 27 API calls 99883->99890 99886 d19bb0 125 API calls 99884->99886 99887 d14fe1 99885->99887 99888 d15033 99886->99888 99889 d1136c 168 API calls 99887->99889 99891 d19940 169 API calls 99888->99891 99899 d14fec 99889->99899 99892 d150c0 99890->99892 99893 d15043 99891->99893 99894 d150d6 99892->99894 100330 d26bd0 29 API calls 3 library calls 99892->100330 99895 d11b84 84 API calls 99893->99895 100145 d15e16 99894->100145 99898 d1505b 99895->99898 99902 d11be0 81 API calls 99898->99902 100326 d159c2 ReleaseMutex 99899->100326 99900 d158ce 99900->99869 99903 d158d4 CoUninitialize 99900->99903 99905 d1506b 99902->99905 99903->99869 99904 d150e7 99906 d150f2 99904->99906 99910 d15143 99904->99910 99907 d1136c 168 API calls 99905->99907 99908 d19bb0 125 API calls 99906->99908 99907->99899 99909 d150f7 99908->99909 99911 d19940 169 API calls 99909->99911 100151 d43670 99910->100151 99913 d15107 99911->99913 99915 d11b84 84 API calls 99913->99915 99918 d15123 99915->99918 99916 d151f7 CommandLineToArgvW 99928 d15235 99916->99928 99929 d15284 __cftof 99916->99929 99917 d151ab 99920 d19bb0 125 API calls 99917->99920 99919 d11be0 81 API calls 99918->99919 99921 d15133 99919->99921 99922 d151b0 99920->99922 99924 d1136c 168 API calls 99921->99924 99923 d19940 169 API calls 99922->99923 99925 d151c0 99923->99925 99934 d1513e 99924->99934 99927 d11b84 84 API calls 99925->99927 99930 d151dc 99927->99930 99931 d19bb0 125 API calls 99928->99931 99933 d15296 GetModuleFileNameW 99929->99933 99932 d11be0 81 API calls 99930->99932 99936 d1523a 99931->99936 99938 d152b2 99933->99938 99939 d1531d 99933->99939 100347 d15946 IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 99934->100347 99940 d19940 169 API calls 99936->99940 99942 d19bb0 125 API calls 99938->99942 100185 d1d730 99939->100185 99943 d1524a 99940->99943 99947 d152b7 99942->99947 99944 d11b84 84 API calls 99943->99944 99948 d15266 99944->99948 99946 d1532c __cftof 99951 d15344 GetLongPathNameW 99946->99951 99949 d19940 169 API calls 99947->99949 99952 d152c7 99949->99952 100077 d3d6df GetProcAddress 100076->100077 100078 d3d6fd 100076->100078 100077->100078 100079 d3d6ef 100077->100079 100078->99835 100079->99835 100348 d14c8e GetCurrentProcessId 100080->100348 100083 d14df0 100083->99841 100083->99842 100084 d14d7f CreateMutexW 100085 d14d92 100084->100085 100086 d14df4 WaitForSingleObject 100084->100086 100088 d19bb0 125 API calls 100085->100088 100086->100083 100087 d14e06 100086->100087 100087->100083 100089 d14e0b CloseHandle 100087->100089 100090 d14d97 100088->100090 100089->100083 100091 d19940 169 API calls 100090->100091 100092 d14da5 100091->100092 100093 d11b84 84 API calls 100092->100093 100094 d14dc2 100093->100094 100095 d11be0 81 API calls 100094->100095 100096 d14dd0 GetLastError 100095->100096 100097 d16140 80 API calls 100096->100097 100098 d14de7 100097->100098 100099 d1136c 168 API calls 100098->100099 100099->100083 100101 d15a5e __EH_prolog3_GS 100100->100101 100468 d15c1e 100101->100468 100104 d15a78 100105 d19bb0 125 API calls 100104->100105 100107 d15a7d 100105->100107 100106 d15b92 _com_issue_error 100108 d19940 169 API calls 100107->100108 100109 d15a8d 100108->100109 100111 d11b84 84 API calls 100109->100111 100110 d15acc 100110->100106 100112 d15af5 100110->100112 100113 d15b38 100110->100113 100114 d15aa9 100111->100114 100115 d19bb0 125 API calls 100112->100115 100117 d19bb0 125 API calls 100113->100117 100116 d11be0 81 API calls 100114->100116 100118 d15afa 100115->100118 100134 d15ab9 100116->100134 100119 d15b3d 100117->100119 100121 d19940 169 API calls 100118->100121 100120 d19940 169 API calls 100119->100120 100123 d15b4d 100120->100123 100124 d15b0a 100121->100124 100126 d11b84 84 API calls 100123->100126 100127 d11b84 84 API calls 100124->100127 100125 d15ac7 100129 d1136c 168 API calls 100125->100129 100128 d15b69 100126->100128 100130 d15b26 100127->100130 100131 d11be0 81 API calls 100128->100131 100132 d15b84 100129->100132 100133 d11be0 81 API calls 100130->100133 100131->100125 100476 d88def 5 API calls __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 100132->100476 100133->100134 100475 d16300 80 API calls 100134->100475 100138 d15d63 __EH_prolog3 100137->100138 100139 d88713 messages 27 API calls 100138->100139 100140 d15d7c Concurrency::cancel_current_task messages 100139->100140 100140->99864 100142 d15dc2 __EH_prolog3 100141->100142 100143 d88713 messages 27 API calls 100142->100143 100144 d15ddb messages 100143->100144 100144->99881 100146 d15e22 __EH_prolog3 100145->100146 100147 d88713 messages 27 API calls 100146->100147 100148 d15e3b 100147->100148 100477 d15eee 100148->100477 100150 d15e6c messages 100150->99904 100152 d436ae 100151->100152 100183 d43977 100152->100183 100482 d26d24 100152->100482 100154 d43750 100155 d88713 messages 27 API calls 100154->100155 100154->100183 100156 d4375f 100155->100156 100158 d43799 100156->100158 100649 d48ba0 27 API calls messages 100156->100649 100528 d49400 GetModuleHandleW 100158->100528 100159 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 100162 d151a7 100159->100162 100161 d439df 100161->100159 100162->99916 100162->99917 100183->100161 100656 d48650 100183->100656 100186 d1d796 100185->100186 100187 d1d76f 100185->100187 100188 d1d7ab 100186->100188 100195 d1d8bc 100186->100195 100187->99946 100189 d1da86 100188->100189 100194 d1d80b 100188->100194 100200 d1d7de Concurrency::cancel_current_task _LStrxfrm 100188->100200 100191 d1da8b Concurrency::cancel_current_task 100192 d1da90 100191->100192 100194->100191 100195->100191 100195->100192 100195->100200 100202 d1d953 100195->100202 100203 d1d97a 100195->100203 100202->100191 100203->100200 100326->99900 100328 d1b8a0 168 API calls 100327->100328 100329 d1139a std::ios_base::_Ios_base_dtor 100328->100329 100329->99836 100330->99894 100347->99899 100349 d14cb0 CreateToolhelp32Snapshot 100348->100349 100350 d14cc5 Process32FirstW 100349->100350 100359 d14cdd 100349->100359 100350->100359 100351 d14d44 100355 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 100351->100355 100353 d14ce3 Process32NextW 100353->100359 100354 d14cf9 CloseHandle 100354->100359 100356 d14d58 100355->100356 100356->100083 100356->100084 100357 d92041 49 API calls 100357->100359 100358 d13899 5 API calls 100358->100359 100359->100349 100359->100351 100359->100353 100359->100354 100359->100357 100359->100358 100360 d24590 100359->100360 100371 d24760 100360->100371 100362 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 100364 d2468c 100362->100364 100364->100359 100365 d24693 100367 d8d60f 25 API calls 100365->100367 100366 d24650 Concurrency::cancel_current_task 100366->100362 100368 d24698 100367->100368 100369 d246b3 100368->100369 100370 d246ac CloseHandle 100368->100370 100369->100359 100370->100369 100382 d24200 OpenProcess 100371->100382 100373 d247a8 100376 d247b2 100373->100376 100454 d1daa0 29 API calls 4 library calls 100373->100454 100374 d247e2 Concurrency::cancel_current_task 100377 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 100374->100377 100376->100374 100378 d24935 100376->100378 100379 d24604 100377->100379 100380 d8d60f 25 API calls 100378->100380 100379->100365 100379->100366 100381 d2493a 100380->100381 100383 d24267 100382->100383 100389 d24310 100382->100389 100384 d19bb0 125 API calls 100383->100384 100385 d2426c 100384->100385 100388 d19940 169 API calls 100385->100388 100386 d246c0 28 API calls 100387 d24351 QueryFullProcessImageNameW 100386->100387 100387->100389 100390 d24375 GetLastError 100387->100390 100391 d2427c 100388->100391 100389->100386 100393 d2447f 100389->100393 100390->100389 100392 d24387 100390->100392 100394 d11b84 84 API calls 100391->100394 100396 d19bb0 125 API calls 100392->100396 100397 d19bb0 125 API calls 100393->100397 100395 d24298 100394->100395 100464 d11cc0 81 API calls 100395->100464 100399 d2438c 100396->100399 100400 d24484 100397->100400 100403 d19940 169 API calls 100399->100403 100401 d19940 169 API calls 100400->100401 100404 d24494 100401->100404 100402 d242a3 100405 d16140 80 API calls 100402->100405 100406 d2439c 100403->100406 100407 d11b84 84 API calls 100404->100407 100408 d242b1 100405->100408 100409 d11b84 84 API calls 100406->100409 100410 d244b0 100407->100410 100411 d24940 81 API calls 100408->100411 100412 d243b8 100409->100412 100413 d11be0 81 API calls 100410->100413 100414 d242bc GetLastError 100411->100414 100455 d249d0 100412->100455 100416 d244c0 100413->100416 100417 d16140 80 API calls 100414->100417 100419 d16140 80 API calls 100416->100419 100420 d242d3 100417->100420 100418 d243c3 100421 d16140 80 API calls 100418->100421 100422 d244ce 100419->100422 100423 d1b8a0 168 API calls 100420->100423 100424 d243d1 100421->100424 100465 d24a60 81 API calls 100422->100465 100433 d242de std::ios_base::_Ios_base_dtor 100423->100433 100460 d24940 100424->100460 100427 d244d9 100429 d14190 5 API calls 100427->100429 100432 d244f5 100429->100432 100430 d16140 80 API calls 100431 d243ea 100430->100431 100434 d1b8a0 168 API calls 100431->100434 100436 d1b8a0 168 API calls 100432->100436 100435 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 100433->100435 100438 d243f5 std::ios_base::_Ios_base_dtor 100434->100438 100437 d2457a 100435->100437 100440 d24462 std::ios_base::_Ios_base_dtor Concurrency::cancel_current_task 100436->100440 100437->100373 100438->100440 100441 d24581 100438->100441 100439 d2455a CloseHandle 100439->100433 100440->100433 100440->100439 100442 d8d60f 25 API calls 100441->100442 100443 d24586 100442->100443 100444 d24760 208 API calls 100443->100444 100446 d24604 100444->100446 100445 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 100447 d2468c 100445->100447 100448 d24693 100446->100448 100449 d24650 Concurrency::cancel_current_task 100446->100449 100447->100373 100450 d8d60f 25 API calls 100448->100450 100449->100445 100451 d24698 100450->100451 100452 d246b3 100451->100452 100453 d246ac CloseHandle 100451->100453 100452->100373 100453->100452 100454->100376 100456 d24a3e 100455->100456 100457 d24a0c 100455->100457 100456->100418 100466 d120a0 81 API calls 3 library calls 100457->100466 100459 d24a1e 100459->100418 100461 d2497c 100460->100461 100463 d243dc 100460->100463 100467 d120a0 81 API calls 3 library calls 100461->100467 100463->100430 100464->100402 100465->100427 100466->100459 100467->100463 100469 d15c64 CoCreateInstance 100468->100469 100470 d15c54 100468->100470 100471 d15c86 OleRun 100469->100471 100474 d15c95 100469->100474 100470->100469 100471->100474 100472 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 100473 d15a71 100472->100473 100473->100104 100473->100110 100474->100472 100475->100125 100478 d15ef5 100477->100478 100480 d15efc Concurrency::cancel_current_task 100477->100480 100481 d15f8a 5 API calls 2 library calls 100478->100481 100480->100150 100483 d26d30 100482->100483 100489 d26ec8 std::ios_base::_Ios_base_dtor __Mtx_unlock 100482->100489 100484 d26d3e 100483->100484 100485 d26dff 100483->100485 100487 d88760 27 API calls 100484->100487 100486 d88760 27 API calls 100485->100486 100488 d26e09 100486->100488 100490 d26d48 100487->100490 100493 d26db6 100488->100493 100689 d2ce00 100488->100689 100489->100154 100492 d2ce00 209 API calls 100490->100492 100490->100493 100494 d26d63 100492->100494 100495 d26e52 100493->100495 100496 d26ed1 100493->100496 100497 d73b8a __Mtx_init_in_situ 2 API calls 100494->100497 100499 d19bb0 125 API calls 100495->100499 100527 d2e380 229 API calls 100496->100527 100498 d26d80 100497->100498 100500 d88713 messages 27 API calls 100498->100500 100501 d26e57 100499->100501 100500->100493 100502 d19940 169 API calls 100501->100502 100504 d26e67 100502->100504 100503 d26ee3 100503->100489 100506 d19bb0 125 API calls 100503->100506 100505 d11b84 84 API calls 100504->100505 100508 d26ef0 100506->100508 100510 d19940 169 API calls 100508->100510 100527->100503 100529 d49485 GetProcAddress 100528->100529 100532 d494c2 100528->100532 100530 d49497 GetCurrentProcess 100529->100530 100529->100532 100531 d494b1 100530->100531 100531->100532 100803 d1347e 100532->100803 100534 d494fc 100535 d1347e 28 API calls 100534->100535 100649->100158 100657 d48b75 100656->100657 100670 d486ab swprintf 100656->100670 100954 d48400 91 API calls 3 library calls 100657->100954 100659 d48b89 100677 d488f1 Concurrency::cancel_current_task 100659->100677 100661 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 100662 d48b71 100661->100662 100662->100161 100663 d4870d __cftof 100948 d31820 100663->100948 100664 d91faa swprintf 54 API calls 100664->100670 100667 d88713 messages 27 API calls 100668 d48815 100667->100668 100671 d48834 100668->100671 100672 d73084 std::locale::_Init 57 API calls 100668->100672 100669 d48895 100934 d14880 100669->100934 100670->100663 100670->100664 100670->100669 100947 d19050 28 API calls 100670->100947 100673 d14300 5 API calls 100671->100673 100672->100671 100677->100661 100690 d88713 messages 27 API calls 100689->100690 100691 d2ce81 100690->100691 100692 d88713 messages 27 API calls 100691->100692 100693 d2cf42 100692->100693 100694 d88713 messages 27 API calls 100693->100694 100695 d2cfa0 100694->100695 100804 d134b8 100803->100804 100806 d1348d _LStrxfrm 100803->100806 100804->100806 100902 d133ed 28 API calls 2 library calls 100804->100902 100806->100534 100902->100806 100935 d19bb0 125 API calls 100934->100935 100936 d148ad 100935->100936 100937 d19940 169 API calls 100936->100937 100938 d148ba 100937->100938 100939 d11b84 84 API calls 100938->100939 100940 d148d5 100939->100940 100941 d14190 5 API calls 100940->100941 100947->100670 100949 d31858 100948->100949 100950 d1be30 83 API calls 100949->100950 100951 d318c7 100950->100951 100951->100667 100954->100659 103079 d9e8a8 103078->103079 103080 d9e8ba 103078->103080 103106 d89543 GetModuleHandleW 103079->103106 103090 d9e741 103080->103090 103083 d9e8ad 103083->103080 103107 d9e940 GetModuleHandleExW 103083->103107 103085 d88c15 103085->99829 103091 d9e74d ___scrt_is_nonwritable_in_current_image 103090->103091 103113 d9cd41 EnterCriticalSection 103091->103113 103093 d9e757 103114 d9e7ad 103093->103114 103095 d9e764 103118 d9e782 103095->103118 103098 d9e8fe 103123 da7cf2 GetPEB 103098->103123 103101 d9e92d 103104 d9e940 std::locale::_Setgloballocale 3 API calls 103101->103104 103102 d9e90d GetPEB 103102->103101 103103 d9e91d GetCurrentProcess TerminateProcess 103102->103103 103103->103101 103105 d9e935 ExitProcess 103104->103105 103106->103083 103108 d9e95f GetProcAddress 103107->103108 103109 d9e982 103107->103109 103112 d9e974 103108->103112 103110 d9e988 FreeLibrary 103109->103110 103111 d9e8b9 103109->103111 103110->103111 103111->103080 103112->103109 103113->103093 103115 d9e7b9 ___scrt_is_nonwritable_in_current_image 103114->103115 103116 d9e81a std::locale::_Setgloballocale 103115->103116 103121 d9f40b 14 API calls std::locale::_Setgloballocale 103115->103121 103116->103095 103122 d9cd91 LeaveCriticalSection 103118->103122 103120 d9e770 103120->103085 103120->103098 103121->103116 103122->103120 103124 d9e908 103123->103124 103125 da7d0c 103123->103125 103124->103101 103124->103102 103127 da42b4 5 API calls _unexpected 103125->103127 103127->103124 103128 d2928d 103167 d28fb0 CoCreateGuid 103128->103167 103130 d29293 103131 d29297 103130->103131 103134 d292e9 103130->103134 103132 d19bb0 125 API calls 103131->103132 103133 d2929c 103132->103133 103135 d19940 169 API calls 103133->103135 103136 d29307 103134->103136 103142 d29366 103134->103142 103137 d292ac 103135->103137 103138 d19bb0 125 API calls 103136->103138 103139 d11b84 84 API calls 103137->103139 103140 d2930c 103138->103140 103141 d292c8 103139->103141 103143 d19940 169 API calls 103140->103143 103144 d11be0 81 API calls 103141->103144 103145 d19bb0 125 API calls 103142->103145 103159 d292e0 std::ios_base::_Ios_base_dtor _LStrxfrm 103142->103159 103146 d2931c 103143->103146 103147 d292d8 103144->103147 103148 d2937e 103145->103148 103149 d11b84 84 API calls 103146->103149 103150 d1b8a0 168 API calls 103147->103150 103151 d19940 169 API calls 103148->103151 103152 d29338 103149->103152 103150->103159 103153 d2938e 103151->103153 103154 d11be0 81 API calls 103152->103154 103156 d11b84 84 API calls 103153->103156 103157 d29348 103154->103157 103155 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 103158 d2944c 103155->103158 103160 d293aa 103156->103160 103161 d14190 5 API calls 103157->103161 103159->103155 103162 d19ab0 81 API calls 103160->103162 103163 d29358 103161->103163 103164 d293ba 103162->103164 103165 d1b8a0 168 API calls 103163->103165 103166 d1b8a0 168 API calls 103164->103166 103165->103159 103166->103159 103168 d28fd6 StringFromCLSID 103167->103168 103169 d29155 103167->103169 103168->103169 103170 d28fee 103168->103170 103171 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 103169->103171 103170->103169 103173 d28ffe 103170->103173 103172 d29163 103171->103172 103172->103130 103174 d29169 103173->103174 103179 d29050 103173->103179 103191 d29020 Concurrency::cancel_current_task _LStrxfrm 103173->103191 103206 d134d0 21 API calls collate 103174->103206 103176 d2916e 103177 d8d60f 25 API calls 103176->103177 103178 d29173 Concurrency::cancel_current_task 103177->103178 103181 d29180 103178->103181 103179->103178 103182 d290a6 103179->103182 103183 d290cd 103179->103183 103180 d29134 CoTaskMemFree 103184 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 103180->103184 103185 d3d900 27 API calls 103181->103185 103182->103178 103187 d88713 messages 27 API calls 103182->103187 103188 d88713 messages 27 API calls 103183->103188 103189 d290b7 _LStrxfrm 103183->103189 103186 d2914f 103184->103186 103190 d291cd __cftof 103185->103190 103186->103130 103187->103189 103188->103189 103189->103176 103189->103191 103192 d19bb0 125 API calls 103190->103192 103191->103180 103193 d29213 103192->103193 103194 d19940 169 API calls 103193->103194 103195 d29223 103194->103195 103196 d11b84 84 API calls 103195->103196 103197 d2923f 103196->103197 103198 d19ab0 81 API calls 103197->103198 103199 d2924f 103198->103199 103200 d14190 5 API calls 103199->103200 103201 d2925f 103200->103201 103202 d1b8a0 168 API calls 103201->103202 103203 d29267 std::ios_base::_Ios_base_dtor 103202->103203 103204 d88367 __ehhandler$?_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@23@@Z 5 API calls 103203->103204 103205 d2944c 103204->103205 103205->103130

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 0 d35318-d3532c call d888fa 3 d35332-d353a2 call d88713 call d34a40 0->3 4 d3571d-d35b7a call d36440 GetModuleHandleW call d36440 call d365c0 call d36440 * 2 call d29180 0->4 12 d353a7-d3571a call d34a40 * 2 call d361f0 call d885d4 call d34a40 * 3 call d361f0 call d885d4 call d34a40 * 3 call d361f0 call d885d4 call d34a40 * 3 call d361f0 call d885d4 call d88713 call d885bf call d888b0 3->12 62 d35b7f-d35b81 4->62 63 d35b7a call d29180 4->63 12->4 65 d35b83-d35b8d 62->65 66 d35bc4-d35be0 call d111f3 62->66 63->62 68 d35b93-d35ba5 65->68 69 d35c8d-d35ccd call d36440 65->69 80 d35be6-d35c59 call d19bb0 call d19940 call d11b84 call d11be0 call d1b8a0 call d72bfd 66->80 81 d35cfc-d35d06 66->81 73 d35c83-d35c8a call d88375 68->73 74 d35bab-d35bbf 68->74 84 d35db3-d35dc0 69->84 85 d35cd3-d35cd8 69->85 73->69 74->73 80->69 180 d35c5b-d35c6d 80->180 87 d35d3a-d35d67 call d36440 81->87 88 d35d08-d35d1a 81->88 93 d35dc2-d35dc7 84->93 94 d35dc9-d35dce 84->94 91 d35cda 85->91 92 d35cdc-d35cf7 call d8a3a0 85->92 104 d35d69-d35d73 call d2aad0 87->104 105 d35d78-d35d82 87->105 96 d35d30-d35d37 call d88375 88->96 97 d35d1c-d35d2a 88->97 91->92 117 d35e8e-d35e98 92->117 101 d35dd1-d35de5 93->101 94->101 96->87 97->96 108 d35e30-d35e32 101->108 109 d35de7-d35dec 101->109 104->105 105->69 116 d35d88-d35d94 105->116 112 d35e64-d35e86 108->112 113 d35e34-d35e62 call d88713 108->113 118 d35df2-d35dfd call d88713 109->118 119 d36085 Concurrency::cancel_current_task 109->119 123 d35e8c 112->123 113->123 116->73 124 d35d9a-d35dae 116->124 125 d35ec6-d35ee7 call d29980 117->125 126 d35e9a-d35ea6 117->126 127 d3608a call d8d60f 118->127 139 d35e03-d35e2e 118->139 119->127 123->117 124->73 144 d35eec-d35eee 125->144 133 d35ea8-d35eb6 126->133 134 d35ebc-d35ec3 call d88375 126->134 143 d3608f-d360aa call d8d60f 127->143 133->127 133->134 134->125 139->123 156 d360d8-d360fc call d367b0 143->156 157 d360ac-d360b6 143->157 145 d35ef4-d35f34 call d36440 144->145 146 d35f7f 144->146 165 d35f36-d35f40 call d2aad0 145->165 166 d35f45-d35f4f 145->166 154 d35f82-d35f93 GetModuleHandleW 146->154 161 d35fd1 154->161 162 d35f95-d35fa5 GetProcAddress 154->162 188 d36144-d36149 156->188 189 d360fe-d36106 156->189 163 d360b8-d360c6 157->163 164 d360ce-d360d5 call d88375 157->164 168 d35fd3-d3605c call d36440 call d136db call d1372a * 3 call d88367 161->168 162->161 171 d35fa7-d35fc5 GetCurrentProcess 162->171 172 d361d4-d361d9 call d8d60f 163->172 173 d360cc 163->173 164->156 165->166 166->154 177 d35f51-d35f5d 166->177 171->161 210 d35fc7-d35fcb 171->210 173->164 184 d35f73-d35f7d call d88375 177->184 185 d35f5f-d35f6d 177->185 180->73 190 d35c6f-d35c7d 180->190 184->154 185->143 185->184 191 d3614b-d36151 188->191 192 d3618f-d36197 188->192 197 d36108-d3610c 189->197 198 d3613d 189->198 190->73 202 d36153-d36157 191->202 203 d36188 191->203 199 d361c0-d361d3 192->199 200 d36199-d361a2 192->200 206 d3611b-d36120 197->206 207 d3610e-d36115 SysFreeString 197->207 198->188 208 d361b6-d361bd call d88375 200->208 209 d361a4-d361b2 200->209 211 d36166-d3616b 202->211 212 d36159-d36160 SysFreeString 202->212 203->192 214 d36132-d3613a call d88375 206->214 215 d36122-d3612b call d8874c 206->215 207->206 208->199 209->172 217 d361b4 209->217 210->161 218 d35fcd-d35fcf 210->218 220 d3617d-d36185 call d88375 211->220 221 d3616d-d36176 call d8874c 211->221 212->211 214->198 215->214 217->208 218->168 220->203 221->220
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D888FA: EnterCriticalSection.KERNEL32(00E0742C,?,?,?,00D2402B,00E0827C,6EB998C3,?,00D21171,?), ref: 00D88905
                                                                                                                                                                                • Part of subcall function 00D888FA: LeaveCriticalSection.KERNEL32(00E0742C,?,?,?,00D2402B,00E0827C,6EB998C3,?,00D21171,?), ref: 00D88942
                                                                                                                                                                                • Part of subcall function 00D34A40: _com_issue_error.COMSUPP ref: 00D34AD2
                                                                                                                                                                                • Part of subcall function 00D34A40: SysFreeString.OLEAUT32(-00000001), ref: 00D34AFD
                                                                                                                                                                                • Part of subcall function 00D361F0: Concurrency::cancel_current_task.LIBCPMT ref: 00D362BF
                                                                                                                                                                                • Part of subcall function 00D888B0: EnterCriticalSection.KERNEL32(00E0742C,?,?,00D24086,00E0827C,00DC68E0,?), ref: 00D888BA
                                                                                                                                                                                • Part of subcall function 00D888B0: LeaveCriticalSection.KERNEL32(00E0742C,?,?,00D24086,00E0827C,00DC68E0,?), ref: 00D888ED
                                                                                                                                                                                • Part of subcall function 00D888B0: RtlWakeAllConditionVariable.NTDLL ref: 00D88964
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6EB998C3,?,?), ref: 00D357B4
                                                                                                                                                                              • FindResourceW.KERNEL32(00000000,00000001,00000010), ref: 00D357C5
                                                                                                                                                                              • LoadResource.KERNEL32(00000000,00000000), ref: 00D357D1
                                                                                                                                                                              • LockResource.KERNEL32(00000000), ref: 00D357DC
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D36067
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D36085
                                                                                                                                                                              • SysFreeString.OLEAUT32 ref: 00D3610F
                                                                                                                                                                              • SysFreeString.OLEAUT32(00000000), ref: 00D3615A
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CriticalSection$Concurrency::cancel_current_taskFreeResourceString$EnterLeave$ConditionFindHandleLoadLockModuleVariableWake_com_issue_error
                                                                                                                                                                              • String ID: (error)$)$0.0.0.0$4.1.1.865$EstimatedRunTime$Failed to convert wuuid to string$IsWow64Process$NO_REGKEY$PCSystemTypeEx$PowerState$PredictFailure$Root\CIMV2$Time$UUID$UUID$Version$ery)$kState$kernel32$kernel32.dll$orm$root\wmi$select EstimatedRunTime from Win32_Battery$select PCSystemTypeEx from Win32_ComputerSystem$select PowerState from Win32_ComputerSystem$select PredictFailure from MSStorageDriver_FailurePredictStatus$t
                                                                                                                                                                              • API String ID: 2830066208-329860846
                                                                                                                                                                              • Opcode ID: 18bbc42d26986b1090006cc6827e50a2a1dcd4a9531715b9884c8c445135d203
                                                                                                                                                                              • Instruction ID: a142df94fe08c4b11f3f3f1f38df78e06446772bc1fe294e3fa94bd276a5a0db
                                                                                                                                                                              • Opcode Fuzzy Hash: 18bbc42d26986b1090006cc6827e50a2a1dcd4a9531715b9884c8c445135d203
                                                                                                                                                                              • Instruction Fuzzy Hash: 9282F1709003889FEB14EFA4DD497ADBBB1EF45704F244258E445AB3D2DB789A88CB71
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2F268
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2F307
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2F37E
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2F8B0
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2FBBD
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2FDB6
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D300BA
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D3015F
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001,?,?,00000004), ref: 00D305D7
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D30614
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001,?,?,00000004), ref: 00D3086A
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D308A7
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001,0000018F,00000000,X-Api-Key: ,0000000B,00000000,00000000,?,?,00000004), ref: 00D30A90
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D30ACD
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$ErrorLast$InitOnce$BeginCompleteInitialize
                                                                                                                                                                              • String ID: 0Ywx4MUvRidmWf74nsIlBPIxJYIG9Nf0lSnge8SvgvY3RVy4E6gFLp3VDBcDO830QhXvfpgCb55sRtnVqKb2zUO3Vq7ko1b$AWS Adhoc Telemetry Payload = $AWS Response Code received $AdhocTelemetryAWS$Failed to convert the x_api_key string to wide$Failed to initialize buffer for AWS$HTTP add request header failed for AWS x_api_key: $HTTP connection failed for AWS: $HTTP open request failed for AWS: $HTTP receive response failed for AWS: $HTTP send request failed for AWS: $HTTP status error for AWS: $NO_REGVALUE$Querying AdhocTelemetryAWS value failed: $SOFTWARE\McAfee\WebAdvisor$X-Api-Key: $`aso
                                                                                                                                                                              • API String ID: 1658547907-2957302016
                                                                                                                                                                              • Opcode ID: a8fca10b2c184354c1162e7365203a9c0b0f8cddf52d82590227f88876a5c512
                                                                                                                                                                              • Instruction ID: d93b43951818f3b1a4766aeb21a91618cabc285e9250e4cab77383b07b132147
                                                                                                                                                                              • Opcode Fuzzy Hash: a8fca10b2c184354c1162e7365203a9c0b0f8cddf52d82590227f88876a5c512
                                                                                                                                                                              • Instruction Fuzzy Hash: 8EF2AF709002689BDB24EB24DD99BDEBBB5EF45304F0045E8E44DA7292DB759AC8CF70
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::locale::_Init.LIBCPMT ref: 00D43CE8
                                                                                                                                                                                • Part of subcall function 00D73084: __EH_prolog3.LIBCMT ref: 00D7308B
                                                                                                                                                                                • Part of subcall function 00D73084: std::_Lockit::_Lockit.LIBCPMT ref: 00D73096
                                                                                                                                                                                • Part of subcall function 00D73084: std::locale::_Setgloballocale.LIBCPMT ref: 00D730B1
                                                                                                                                                                                • Part of subcall function 00D73084: std::_Lockit::~_Lockit.LIBCPMT ref: 00D73107
                                                                                                                                                                              • std::locale::_Init.LIBCPMT ref: 00D44934
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D44CD5
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::locale::_$InitLockitstd::_$H_prolog3Ios_base_dtorLockit::_Lockit::~_Setgloballocalestd::ios_base::_
                                                                                                                                                                              • String ID: 2$Command "%s" failed$Couldn't find the ReturnCode attribute of EXIT command$EXIT$EXIT_UPDATE$EXIT_XML$Exit update command triggered. Exiting...$Malformed XML, no UPDATEARRAY element$NWebAdvisor::NXmlUpdater::CUpdater::Process$NWebAdvisor::NXmlUpdater::Hound::End$NWebAdvisor::NXmlUpdater::Hound::ExitResult$NWebAdvisor::NXmlUpdater::Hound::Start$PRECONDITION$PRECONDITIONARRAY$Precondition "%s" evaluated to false$Precondition "%s" evaluated to true$ReturnCode$TAG$UPDATE$UPDATEARRAY$UPDATECOMMANDS$Unable to convert ReturnCode into int$Unable to substitute the return code$XML precondition array returned false due to sniffer actions$XML precondition array returned true due to sniffer actions$XML precondition array with tag %s returned false$XML precondition array with tag %s returned false due to sniffer actions$XML precondition array with tag %s returned true due to sniffer actions$XML precondition failed - no Type specified$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\Hound.h$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\xmlUpdater.cpp$false$true$unknown
                                                                                                                                                                              • API String ID: 3544396713-2181764886
                                                                                                                                                                              • Opcode ID: a315cd8b01eb73b6a249ec85ca46089613e0351ada2ce3198c5a103e9df9e7b3
                                                                                                                                                                              • Instruction ID: 140aca796f61fd59ace777cd9fb996e4a6c3c6f93d4a236352033087e0cbad9b
                                                                                                                                                                              • Opcode Fuzzy Hash: a315cd8b01eb73b6a249ec85ca46089613e0351ada2ce3198c5a103e9df9e7b3
                                                                                                                                                                              • Instruction Fuzzy Hash: D2136975D012299FDB20DF64DC89BEDBBB4AF14304F1442D9E449A7291DB74AE84CFA0

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 1938 d25870-d258d0 GetCurrentProcessId GetCurrentThreadId call d9594f 1941 d26170-d26185 call d1c900 1938->1941 1942 d258d6-d25943 CreateFileW 1938->1942 1950 d26187-d26189 1941->1950 1951 d261a5-d261ab 1941->1951 1944 d25945-d25965 CreateFileW 1942->1944 1945 d2596f-d25973 1942->1945 1944->1945 1947 d25967-d2596d 1944->1947 1948 d25975 1945->1948 1949 d2597a-d2599c CreateFileW 1945->1949 1947->1948 1948->1949 1952 d25a05-d25a49 call d8a920 UuidCreate 1949->1952 1953 d2599e-d259c0 CreateFileW 1949->1953 1950->1951 1954 d2618b-d2618e 1950->1954 1957 d261be-d261c4 1951->1957 1958 d261ad-d261ba 1951->1958 1967 d2620b-d2621b call d1c900 1952->1967 1968 d25a4f-d25a5f UuidCreate 1952->1968 1953->1952 1955 d259c2-d259e4 CreateFileW 1953->1955 1954->1951 1959 d26190-d26194 1954->1959 1955->1952 1960 d259e6-d25a03 CreateFileW 1955->1960 1962 d261c6-d261d3 1957->1962 1963 d261d7-d261dd 1957->1963 1958->1957 1959->1951 1966 d26196-d2619a 1959->1966 1960->1952 1962->1963 1964 d261f0-d26206 call d88367 1963->1964 1965 d261df-d261ec 1963->1965 1965->1964 1966->1951 1971 d2619c-d261a3 call d269a0 1966->1971 1967->1954 1968->1967 1973 d25a65-d25a87 call d25790 1968->1973 1971->1951 1982 d25aea-d25af2 1973->1982 1983 d25a89 1973->1983 1982->1967 1985 d25af8-d25b30 1982->1985 1984 d25a90-d25a96 1983->1984 1986 d25a98-d25a9d 1984->1986 1987 d25a9f-d25aa5 1984->1987 2002 d25b36-d25b3e 1985->2002 2003 d26207 1985->2003 1989 d25ad9-d25ae1 call d25790 1986->1989 1990 d25aa7-d25aac 1987->1990 1991 d25aae-d25ab4 1987->1991 1998 d25ae6-d25ae8 1989->1998 1990->1989 1992 d25ab6-d25abb 1991->1992 1993 d25abd-d25ac3 1991->1993 1992->1989 1996 d25ac5-d25aca 1993->1996 1997 d25acc-d25ad2 1993->1997 1996->1989 1997->1982 1999 d25ad4 1997->1999 1998->1982 1998->1984 1999->1989 2002->2003 2004 d25b44-d25b5c 2002->2004 2003->1967 2004->2003 2007 d25b62-d25b66 2004->2007 2007->2003 2008 d25b6c-d25c01 call d24cc0 2007->2008 2008->2003 2021 d25c07-d25c4a 2008->2021 2026 d25c50-d25c54 2021->2026 2027 d2616c 2021->2027 2026->2027 2028 d25c5a-d25c74 2026->2028 2027->1941 2028->2027 2031 d25c7a-d25c7e 2028->2031 2031->2027 2032 d25c84-d25cd4 call d24cc0 2031->2032 2039 d25cd7-d25ce0 2032->2039 2039->2039 2040 d25ce2-d25d16 CryptAcquireContextW 2039->2040 2041 d25d65-d25d6b 2040->2041 2042 d25d18-d25d32 CryptCreateHash 2040->2042 2044 d25d74-d25d7a 2041->2044 2045 d25d6d-d25d6e CryptDestroyHash 2041->2045 2042->2041 2043 d25d34-d25d4b CryptHashData 2042->2043 2043->2041 2046 d25d4d-d25d5f CryptGetHashParam 2043->2046 2047 d25d85-d25ef5 2044->2047 2048 d25d7c-d25d7f CryptReleaseContext 2044->2048 2045->2044 2046->2041 2047->2027 2077 d25efb-d25f4e call d24cc0 2047->2077 2048->2047 2084 d25f50-d25f59 2077->2084 2084->2084 2085 d25f5b-d25f8f CryptAcquireContextW 2084->2085 2086 d25f91-d25fab CryptCreateHash 2085->2086 2087 d25fde-d25fe4 2085->2087 2086->2087 2088 d25fad-d25fc4 CryptHashData 2086->2088 2089 d25fe6-d25fe7 CryptDestroyHash 2087->2089 2090 d25fed-d25ff3 2087->2090 2088->2087 2091 d25fc6-d25fd8 CryptGetHashParam 2088->2091 2089->2090 2092 d25ff5-d25ff8 CryptReleaseContext 2090->2092 2093 d25ffe-d26166 2090->2093 2091->2087 2092->2093 2093->2027
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetCurrentProcessId.KERNEL32 ref: 00D258AA
                                                                                                                                                                              • GetCurrentThreadId.KERNEL32 ref: 00D258B4
                                                                                                                                                                              • CreateFileW.KERNEL32(\\.\WGUARDNT,C0000000,00000000,00000000,00000003,40000000,00000000), ref: 00D2593A
                                                                                                                                                                              • CreateFileW.KERNEL32(\\.\Global\WGUARDNT,C0000000,00000000,00000000,00000003,40000000,00000000), ref: 00D2595C
                                                                                                                                                                              • CreateFileW.KERNEL32(\\.\WGUARDNT,80000000,00000000,00000000,00000003,40000000,00000000), ref: 00D25991
                                                                                                                                                                              • CreateFileW.KERNEL32(\\.\Global\WGUARDNT,80000000,00000000,00000000,00000003,40000000,00000000), ref: 00D259B5
                                                                                                                                                                              • CreateFileW.KERNEL32(\\.\WGUARDNT,C0000000,00000000,00000000,00000003,40000000,00000000), ref: 00D259D9
                                                                                                                                                                              • CreateFileW.KERNEL32(\\.\Global\WGUARDNT,C0000000,00000000,00000000,00000003,40000000,00000000), ref: 00D259FD
                                                                                                                                                                              • UuidCreate.RPCRT4(00000000), ref: 00D25A41
                                                                                                                                                                              • UuidCreate.RPCRT4(00000000), ref: 00D25A57
                                                                                                                                                                              • CryptAcquireContextW.ADVAPI32(?), ref: 00D25D0E
                                                                                                                                                                              • CryptCreateHash.ADVAPI32(00000010,00008003,00000000,00000000,?), ref: 00D25D2A
                                                                                                                                                                              • CryptHashData.ADVAPI32(?,?,00000000,00000000), ref: 00D25D43
                                                                                                                                                                              • CryptGetHashParam.ADVAPI32(00000000,00000002,?,?,00000000), ref: 00D25D5F
                                                                                                                                                                              • CryptDestroyHash.ADVAPI32(?), ref: 00D25D6E
                                                                                                                                                                              • CryptReleaseContext.ADVAPI32(?,00000000), ref: 00D25D7F
                                                                                                                                                                              • CryptAcquireContextW.ADVAPI32(?), ref: 00D25F87
                                                                                                                                                                              • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,?), ref: 00D25FA3
                                                                                                                                                                              • CryptHashData.ADVAPI32(?,?,00000000,00000000), ref: 00D25FBC
                                                                                                                                                                              • CryptGetHashParam.ADVAPI32(00000000,00000002,?,?,00000000), ref: 00D25FD8
                                                                                                                                                                              • CryptDestroyHash.ADVAPI32(?), ref: 00D25FE7
                                                                                                                                                                              • CryptReleaseContext.ADVAPI32(?,00000000), ref: 00D25FF8
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Crypt$Create$Hash$File$Context$AcquireCurrentDataDestroyParamReleaseUuid$ProcessThread
                                                                                                                                                                              • String ID: AacControl$AacControl2$AacControl3$AacControl4$AacControl5$AacControl6$Created access handle %p$\\.\Global\WGUARDNT$\\.\WGUARDNT$accesslib policy %x:%x$al delete policy on terminate process 0x%x (%d) rule$al disable rules on terminate thread 0x%x (%d) rule
                                                                                                                                                                              • API String ID: 4128897270-3926088020
                                                                                                                                                                              • Opcode ID: 7c5002a880fae87566676f162678260aff18e19bce4059ff19ce7d956055d16a
                                                                                                                                                                              • Instruction ID: 1fd3b5accf59856b567b7504fff7fe297cdaab0585a9db35aeb3096bce68533d
                                                                                                                                                                              • Opcode Fuzzy Hash: 7c5002a880fae87566676f162678260aff18e19bce4059ff19ce7d956055d16a
                                                                                                                                                                              • Instruction Fuzzy Hash: 2C5257756043129FDB109F24D884F2EBBE5BF88714F190559FA46A73A1CB74ED028FA2
                                                                                                                                                                              APIs
                                                                                                                                                                              • RegCreateKeyExW.KERNEL32(80000002,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,-00000028,?,?,-00000028,00000000,?), ref: 00D61932
                                                                                                                                                                              • RegCloseKey.ADVAPI32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,-00000028,?), ref: 00D61DAD
                                                                                                                                                                              • RegCloseKey.ADVAPI32(00000000,?,?,?,-00000028,?,?,-00000028,00000000,?), ref: 00D61DD3
                                                                                                                                                                              • std::locale::_Init.LIBCPMT ref: 00D620C4
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Close$CreateInitstd::locale::_
                                                                                                                                                                              • String ID: to $(Default)$BIN$DWORD$Error (%d) creating registry key: %s$Error (%d) setting value (%s) under registry key: %s$Key$NUM$NWebAdvisor::NXmlUpdater::CSetVariableCommand::Execute$NWebAdvisor::NXmlUpdater::SetRegistryKey$QWORD$STR$Setting variable $Unable to convert %s to hex$Unable to read key or value attribute of SETVAR command$Unable to set the variable$Unable to substitute variables for the SETVAR command$Unknown registry key type: %s$Value$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\RegistryCommand.cpp$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\SetVariableCommand.cpp$invalid stoul argument$invalid stoull argument$invalid substitutor$memcpy_s failed in NWebAdvisor::NXmlUpdater::SetRegistryKey$stoul argument out of range$stoull argument out of range
                                                                                                                                                                              • API String ID: 3662814871-412574832
                                                                                                                                                                              • Opcode ID: 6d5cf827c63d865e5f01f579f1d6f9483bdf53411ede0f961d793b9e657d5387
                                                                                                                                                                              • Instruction ID: f79755f067d502ebf785f39f5b8bd7d085f510d090bcdd010755a02b2eddc7e9
                                                                                                                                                                              • Opcode Fuzzy Hash: 6d5cf827c63d865e5f01f579f1d6f9483bdf53411ede0f961d793b9e657d5387
                                                                                                                                                                              • Instruction Fuzzy Hash: 1A52AF74A003199FDB20DF58DC45BAEB7B5EF05704F1841AAE809A7381E775AA48CFB1

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 2779 d5ffe0-d6002d 2780 d60051-d60055 2779->2780 2781 d6002f-d6004c call d48650 2779->2781 2783 d60057-d6005d 2780->2783 2784 d600ae-d6010d 2780->2784 2790 d60557-d60571 call d88367 2781->2790 2788 d60061-d6006a 2783->2788 2789 d6005f 2783->2789 2786 d60122-d60135 2784->2786 2787 d6010f-d6011b 2784->2787 2791 d60574-d60579 call d134d0 2786->2791 2792 d6013b-d60145 2786->2792 2787->2786 2793 d60077-d6007c call d5eb20 2788->2793 2794 d6006c-d60073 call d721d0 2788->2794 2789->2788 2795 d60147-d60149 2792->2795 2796 d6014f-d60187 2792->2796 2806 d6007f-d60081 2793->2806 2801 d60075 2794->2801 2795->2796 2802 d601d3-d60283 call d8a3a0 call d1e9c0 2796->2802 2803 d60189-d60194 2796->2803 2801->2806 2821 d60287-d60318 call d1e9c0 call d138d0 * 2 call d8a920 2802->2821 2822 d60285 2802->2822 2807 d60196-d6019b 2803->2807 2808 d6019d-d601a4 2803->2808 2806->2784 2812 d60083-d60087 2806->2812 2811 d601a7-d601cd call d133c3 2807->2811 2808->2811 2811->2802 2815 d6008b-d600a9 call d48650 2812->2815 2816 d60089 2812->2816 2815->2790 2816->2815 2831 d60320-d60328 2821->2831 2822->2821 2832 d6033e-d60355 2831->2832 2833 d6032a-d60331 2831->2833 2834 d60357 2832->2834 2835 d60359-d60383 CreateProcessW 2832->2835 2833->2832 2836 d60333-d6033c 2833->2836 2834->2835 2837 d60385-d603b5 GetLastError call d48650 2835->2837 2838 d603ba-d603ca WaitForSingleObject 2835->2838 2836->2831 2836->2832 2849 d60526-d6053f call d138d0 2837->2849 2840 d603de-d603fd GetExitCodeProcess 2838->2840 2841 d603cc-d603d0 2838->2841 2845 d60430-d60434 2840->2845 2846 d603ff-d6040b GetLastError 2840->2846 2843 d603d4-d603dc 2841->2843 2844 d603d2 2841->2844 2850 d60410-d6042b call d48650 2843->2850 2844->2843 2847 d60436-d6043a 2845->2847 2848 d6046e-d60477 2845->2848 2846->2850 2851 d6043e-d60447 DeleteFileW 2847->2851 2852 d6043c 2847->2852 2854 d60480-d6049e 2848->2854 2861 d60544-d6054c 2849->2861 2862 d60541-d60542 CloseHandle 2849->2862 2850->2849 2851->2848 2856 d60449-d6046b GetLastError call d48650 2851->2856 2852->2851 2854->2854 2858 d604a0-d604c4 2854->2858 2856->2848 2863 d604c6-d604d2 call d1347e 2858->2863 2864 d604d7-d6051f call d114a1 call d4a350 call d138d0 * 2 2858->2864 2866 d60551 2861->2866 2867 d6054e-d6054f CloseHandle 2861->2867 2862->2861 2863->2864 2864->2849 2866->2790 2867->2866
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: D$Failed to delete executable (%d)$Failed to get process exit code (%d)$NWebAdvisor::NXmlUpdater::CExecuteLocalCommand::ExecuteLocalCommand$Signature check failed for command %s$Unable to run %s, error (%d)$Wait for process failed for command %s$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\ExecuteLocalCommand.cpp$invalid substitutor
                                                                                                                                                                              • API String ID: 0-284121414
                                                                                                                                                                              • Opcode ID: 4204cfee5daf3a91449cf22972ed74f6a89c90d3bb39ac0fe481ef4296e638c5
                                                                                                                                                                              • Instruction ID: 09591bb97ad51b6265472d0337b6c29eb8321d0c7b0b88a59db674b66941c8e3
                                                                                                                                                                              • Opcode Fuzzy Hash: 4204cfee5daf3a91449cf22972ed74f6a89c90d3bb39ac0fe481ef4296e638c5
                                                                                                                                                                              • Instruction Fuzzy Hash: 08E18D70A013599FDB24DF28CC59BEEBBB4EF55304F1442DAE409A7291EB709A84CF61

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 2878 d25110-d25175 2879 d25762 2878->2879 2880 d2517b-d25180 2878->2880 2882 d25767-d25784 call d88367 2879->2882 2880->2879 2881 d25186-d2518b 2880->2881 2881->2879 2883 d25191-d251c2 call d9594f 2881->2883 2888 d251c4-d251c7 2883->2888 2889 d251cc-d251e1 call d8a920 2883->2889 2888->2882 2892 d25313-d25326 2889->2892 2893 d251e7-d251f3 2889->2893 2895 d25384 2892->2895 2896 d25328-d2532d 2892->2896 2893->2892 2894 d251f9-d251fe 2893->2894 2894->2892 2897 d25204-d2523e RegOpenKeyExW 2894->2897 2900 d2538b-d253dc 2895->2900 2898 d25336-d25351 2896->2898 2899 d2532f-d25334 2896->2899 2901 d252e2-d25311 call d8e960 GetLastError 2897->2901 2902 d25244-d25273 RegQueryValueExW 2897->2902 2903 d25357-d2535c 2898->2903 2899->2895 2904 d253de-d253eb OutputDebugStringW call d24f50 2900->2904 2905 d253fd-d25401 2900->2905 2901->2900 2910 d25275-d2527d 2902->2910 2911 d252ca-d252dc RegCloseKey 2902->2911 2912 d25372-d25381 2903->2912 2913 d2535e-d25365 2903->2913 2914 d253f0-d253f8 2904->2914 2908 d25403-d25449 call d8a920 * 2 call d26ae0 2905->2908 2909 d2547e-d25481 2905->2909 2908->2909 2957 d2544b-d25471 2908->2957 2919 d25483-d25489 2909->2919 2920 d2548f-d25496 2909->2920 2910->2911 2917 d2527f-d25292 call d24c10 2910->2917 2911->2900 2911->2901 2912->2895 2913->2912 2918 d25367-d25370 2913->2918 2914->2909 2935 d252b4-d252c8 SetLastError RegCloseKey 2917->2935 2936 d25294-d2529c 2917->2936 2918->2903 2918->2912 2919->2920 2923 d255d1-d255d7 2919->2923 2920->2923 2924 d2549c-d254b8 OutputDebugStringW call d24e60 2920->2924 2928 d255f3 2923->2928 2929 d255d9 2923->2929 2938 d255cb 2924->2938 2939 d254be-d254d8 call d24e60 2924->2939 2933 d255f5 2928->2933 2930 d25703-d2570a 2929->2930 2931 d255df-d255e5 2929->2931 2943 d25739 2930->2943 2944 d2570c-d2571b LoadLibraryExW 2930->2944 2931->2930 2937 d255eb-d255f1 2931->2937 2933->2930 2940 d255fb-d25606 2933->2940 2935->2901 2936->2911 2942 d2529e-d252b2 call d24c10 2936->2942 2937->2933 2938->2923 2960 d254f2-d25516 call d9594f 2939->2960 2961 d254da-d254e0 2939->2961 2948 d25610-d2561c call d24dc0 2940->2948 2949 d25608-d2560a 2940->2949 2942->2911 2942->2935 2945 d2573e-d25743 2943->2945 2944->2945 2946 d2571d-d25737 GetLastError call d8e960 2944->2946 2954 d25745-d2574b call d8874c 2945->2954 2955 d2574e-d25753 2945->2955 2946->2945 2969 d25622-d2562a 2948->2969 2970 d256ea-d256ef 2948->2970 2949->2948 2954->2955 2964 d25755-d2575b call d8874c 2955->2964 2965 d2575e-d25760 2955->2965 2957->2909 2967 d25518-d2551f 2960->2967 2966 d254e2-d254eb call d8e960 2961->2966 2961->2967 2964->2965 2965->2882 2966->2960 2967->2940 2978 d25525-d2554b call d24e60 call d24cc0 2967->2978 2969->2970 2974 d25630 2969->2974 2970->2945 2975 d256f1-d25701 call d8e960 2970->2975 2980 d25635-d25639 2974->2980 2975->2945 2992 d255c4-d255c9 2978->2992 2993 d2554d-d2557f call d8a920 * 2 call d26ae0 2978->2993 2983 d25643-d2565a 2980->2983 2984 d2563b-d25641 2980->2984 2983->2970 2988 d25660-d256a2 call d24dc0 call d9594f 2983->2988 2984->2980 2984->2983 2988->2970 2998 d256a4-d256e2 call d24dc0 call d24cc0 OutputDebugStringW call d8e960 2988->2998 2992->2940 3005 d25584-d2558d 2993->3005 3009 d256e7 2998->3009 3005->2923 3007 d2558f-d255c2 3005->3007 3007->2923 3009->2970
                                                                                                                                                                              APIs
                                                                                                                                                                              • RegOpenKeyExW.KERNEL32(80000002,Software\McAfee\SystemCore,00000000,00020219,?), ref: 00D25225
                                                                                                                                                                              • RegQueryValueExW.ADVAPI32(?,szInstallDir32,00000000,?,?,?), ref: 00D25265
                                                                                                                                                                              • SetLastError.KERNEL32(0000006F,?,?,00DEA17C), ref: 00D252B6
                                                                                                                                                                              • RegCloseKey.ADVAPI32(?), ref: 00D252C2
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D252F6
                                                                                                                                                                              • OutputDebugStringW.KERNEL32(NCPrivateLoadAndValidateMPTDll: Looking in current directory), ref: 00D253E3
                                                                                                                                                                              Strings
                                                                                                                                                                              • szInstallDir32, xrefs: 00D2525F
                                                                                                                                                                              • NCPrivateLoadAndValidateMPTDll: Looking in current directory, xrefs: 00D253DE
                                                                                                                                                                              • NCPrivateLoadAndValidateMPTDll: Looking in EXE directory, xrefs: 00D2549C
                                                                                                                                                                              • Software\McAfee\SystemCore, xrefs: 00D2521B
                                                                                                                                                                              • %ls\%ls, xrefs: 00D25533
                                                                                                                                                                              • NotComDllGetInterface: %ls loading %ls, WinVerifyTrust failed with %08x, xrefs: 00D256B7
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast$CloseDebugOpenOutputQueryStringValue
                                                                                                                                                                              • String ID: %ls\%ls$NCPrivateLoadAndValidateMPTDll: Looking in EXE directory$NCPrivateLoadAndValidateMPTDll: Looking in current directory$NotComDllGetInterface: %ls loading %ls, WinVerifyTrust failed with %08x$Software\McAfee\SystemCore$szInstallDir32
                                                                                                                                                                              • API String ID: 1760606849-3767168787
                                                                                                                                                                              • Opcode ID: 3664b2136529ff9c32fa47166b972d3b1b60e02750dbc453295f6f28b1090280
                                                                                                                                                                              • Instruction ID: 78b0022c876a5ccd83c9f3cbd12e9eac846cc8ec778ad261d0dfdf69a5670bc5
                                                                                                                                                                              • Opcode Fuzzy Hash: 3664b2136529ff9c32fa47166b972d3b1b60e02750dbc453295f6f28b1090280
                                                                                                                                                                              • Instruction Fuzzy Hash: D9028EB1E006299FDB20DF64EC45F9AB7B5EF14318F1881A9E809A7285DB709D44CFB1

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 3185 d717a0-d717e9 3186 d7184f 3185->3186 3187 d717eb-d7181d CryptQueryObject 3185->3187 3190 d71851-d7186c call d88367 3186->3190 3188 d7181f-d71824 3187->3188 3189 d7186d-d718ae call d714f0 3187->3189 3193 d71826-d71827 CryptMsgClose 3188->3193 3194 d7182d-d71832 3188->3194 3199 d718e4-d718ea 3189->3199 3200 d718b0-d718bd call d5e680 3189->3200 3193->3194 3197 d71834-d7183f CertCloseStore 3194->3197 3198 d71842-d71848 3194->3198 3197->3198 3198->3186 3201 d7184a-d7184b 3198->3201 3203 d718f0-d718f6 3199->3203 3207 d718c6-d718cb 3200->3207 3208 d718bf-d718c0 CryptMsgClose 3200->3208 3201->3186 3205 d71b40-d71b4d call d5e680 3203->3205 3206 d718fc-d71944 3203->3206 3226 d71b52-d71b57 3205->3226 3227 d71b4f-d71b50 CryptMsgClose 3205->3227 3210 d71946-d71951 3206->3210 3211 d7198e-d719d5 CryptQueryObject 3206->3211 3216 d718cd-d718d8 CertCloseStore 3207->3216 3217 d718db-d718df 3207->3217 3208->3207 3212 d71953-d71961 3210->3212 3213 d71969-d7198b call d88375 3210->3213 3214 d719d7-d719dc 3211->3214 3215 d71a39-d71a5c call d714f0 3211->3215 3219 d71967 3212->3219 3220 d71b7c-d71b81 call d8d60f 3212->3220 3213->3211 3222 d719e1-d719ec 3214->3222 3223 d719de-d719df CryptMsgClose 3214->3223 3238 d71a5e-d71a60 3215->3238 3239 d71ac8-d71aca 3215->3239 3216->3217 3225 d71ab8-d71aba 3217->3225 3219->3213 3232 d719ee-d719f5 CertCloseStore 3222->3232 3233 d719f8-d719fe 3222->3233 3223->3222 3235 d71ac1-d71ac3 3225->3235 3236 d71abc-d71abd 3225->3236 3228 d71b67 3226->3228 3229 d71b59-d71b64 CertCloseStore 3226->3229 3227->3226 3228->3220 3229->3228 3232->3233 3240 d71a05-d71a1a call d5e630 call d5e680 3233->3240 3241 d71a00-d71a01 3233->3241 3235->3190 3236->3235 3242 d71a65-d71a70 3238->3242 3243 d71a62-d71a63 CryptMsgClose 3238->3243 3245 d71acf-d71ad4 3239->3245 3246 d71acc-d71acd CryptMsgClose 3239->3246 3260 d71a1f-d71a24 3240->3260 3261 d71a1c-d71a1d CryptMsgClose 3240->3261 3241->3240 3249 d71a72-d71a79 CertCloseStore 3242->3249 3250 d71a7c-d71a82 3242->3250 3243->3242 3247 d71ad6-d71ae1 CertCloseStore 3245->3247 3248 d71ae4-d71aea 3245->3248 3246->3245 3247->3248 3253 d71af1-d71af7 3248->3253 3254 d71aec-d71aed 3248->3254 3249->3250 3255 d71a84-d71a85 3250->3255 3256 d71a89-d71a9e call d5e630 call d5e680 3250->3256 3253->3203 3259 d71afd-d71b08 3253->3259 3254->3253 3255->3256 3272 d71aa3-d71aa8 3256->3272 3273 d71aa0-d71aa1 CryptMsgClose 3256->3273 3263 d71b1c-d71b3b call d88375 3259->3263 3264 d71b0a-d71b18 3259->3264 3265 d71a26-d71a2d CertCloseStore 3260->3265 3266 d71a30 3260->3266 3261->3260 3263->3203 3264->3220 3268 d71b1a 3264->3268 3265->3266 3266->3215 3268->3263 3274 d71ab4 3272->3274 3275 d71aaa-d71ab1 CertCloseStore 3272->3275 3273->3272 3274->3225 3275->3274
                                                                                                                                                                              APIs
                                                                                                                                                                              • CryptQueryObject.CRYPT32(00000001,00D72520,00000400,00000002,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D71815
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D71827
                                                                                                                                                                                • Part of subcall function 00D714F0: CryptMsgGetParam.CRYPT32(?,00000005,00000000,?,?), ref: 00D71581
                                                                                                                                                                                • Part of subcall function 00D714F0: CryptMsgGetParam.CRYPT32(?,00000006,00000000,00000000,?), ref: 00D715B2
                                                                                                                                                                                • Part of subcall function 00D714F0: CryptMsgGetParam.CRYPT32(?,00000006,?,00000000,?), ref: 00D715DD
                                                                                                                                                                                • Part of subcall function 00D714F0: CertGetSubjectCertificateFromStore.CRYPT32(?,00010001,?), ref: 00D71625
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D71837
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D718C0
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D718D0
                                                                                                                                                                              • CryptQueryObject.CRYPT32(00000002,?,00003FFE,00000002,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D719CD
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D719DF
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D719F1
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D71A1D
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D71A29
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D71A63
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D71A75
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D71AA1
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D71AAD
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D71ACD
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D71AD9
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D71B50
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D71B5C
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Close$Crypt$CertStore$Param$ObjectQuery$CertificateFromSubject
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2648890560-0
                                                                                                                                                                              • Opcode ID: 1d2f3c1c455f5624fb3bc01fcac5bbc5e9c37f057b63d0cbbf4338b4037110d9
                                                                                                                                                                              • Instruction ID: 6c3867bf05bb33514916fb6853872b914dd1c687b6ce0c664412e843c41ec192
                                                                                                                                                                              • Opcode Fuzzy Hash: 1d2f3c1c455f5624fb3bc01fcac5bbc5e9c37f057b63d0cbbf4338b4037110d9
                                                                                                                                                                              • Instruction Fuzzy Hash: BBC11D75E10209ABEF10DFA9CC85B9EBBF9AF04704F188519E504F7281EB759944CB70
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D34B40: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D3521E
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D27D3D
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D27DFC
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D27DC8
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D27EBB
                                                                                                                                                                              Strings
                                                                                                                                                                              • Failed to add event action (, xrefs: 00D27379
                                                                                                                                                                              • u, xrefs: 00D27B57
                                                                                                                                                                              • Failed to add reserved 5 dimension (, xrefs: 00D27CFD
                                                                                                                                                                              • z, xrefs: 00D27CF1
                                                                                                                                                                              • Failed to add reserved 1 dimension (, xrefs: 00D2769E
                                                                                                                                                                              • Failed to add event label (, xrefs: 00D27508
                                                                                                                                                                              • Failed to add reserved 2 dimension (, xrefs: 00D27834
                                                                                                                                                                              • Failed to add reserved 4 dimension (, xrefs: 00D27B63
                                                                                                                                                                              • Failed to add event category (, xrefs: 00D271F0
                                                                                                                                                                              • Failed to add reserved 3 dimension (, xrefs: 00D279CD
                                                                                                                                                                              • Service has not been initialized, xrefs: 00D27E88
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$InitOnce$BeginCompleteConcurrency::cancel_current_taskInitializeMtx_unlock
                                                                                                                                                                              • String ID: Failed to add event action ($Failed to add event category ($Failed to add event label ($Failed to add reserved 1 dimension ($Failed to add reserved 2 dimension ($Failed to add reserved 3 dimension ($Failed to add reserved 4 dimension ($Failed to add reserved 5 dimension ($Service has not been initialized$u$z
                                                                                                                                                                              • API String ID: 342047005-3525645681
                                                                                                                                                                              • Opcode ID: 0395b90ed16f409a3ff8ea0d5cfc335f883cda6c26ab04efe143ba94d2f0ac43
                                                                                                                                                                              • Instruction ID: 57e872d11d858628ba0f9fb85b17d80a78f0ad074e981a1d5ef58a84de6abe41
                                                                                                                                                                              • Opcode Fuzzy Hash: 0395b90ed16f409a3ff8ea0d5cfc335f883cda6c26ab04efe143ba94d2f0ac43
                                                                                                                                                                              • Instruction Fuzzy Hash: C2820570604244DFDB28EF24E891BEE7BA4EF55308F54419DE8168B382DB75DA44CBB2
                                                                                                                                                                              APIs
                                                                                                                                                                              • CoCreateGuid.OLE32(?), ref: 00D28FC8
                                                                                                                                                                              • StringFromCLSID.OLE32(?,?), ref: 00D28FE0
                                                                                                                                                                              • CoTaskMemFree.OLE32(?), ref: 00D29138
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D29173
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D293D1
                                                                                                                                                                              Strings
                                                                                                                                                                              • SOFTWARE\McAfee\WebAdvisor, xrefs: 00D291FB
                                                                                                                                                                              • Could not create registry key , xrefs: 00D2923F
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_taskCreateFreeFromGuidIos_base_dtorStringTaskstd::ios_base::_
                                                                                                                                                                              • String ID: Could not create registry key $SOFTWARE\McAfee\WebAdvisor
                                                                                                                                                                              • API String ID: 3741506170-3627174789
                                                                                                                                                                              • Opcode ID: 897c328fbe130cfbb492592ffd26edfb1dbe7beebe4df84754c3d9c5db84aa92
                                                                                                                                                                              • Instruction ID: ed5f0a9431858ecc102078a3584b3dd5f94b275065f5bc4f36d2b7a778390bc4
                                                                                                                                                                              • Opcode Fuzzy Hash: 897c328fbe130cfbb492592ffd26edfb1dbe7beebe4df84754c3d9c5db84aa92
                                                                                                                                                                              • Instruction Fuzzy Hash: 4D814871A003199FD714EF24EC95BAEB3A8EF54314F50462DF91683281EB30E954CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetCurrentProcessId.KERNEL32 ref: 00D14CA6
                                                                                                                                                                              • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 00D14CB8
                                                                                                                                                                              • Process32FirstW.KERNEL32(00000000,?), ref: 00D14CD3
                                                                                                                                                                              • Process32NextW.KERNEL32(00000000,0000022C), ref: 00D14CE9
                                                                                                                                                                              • CloseHandle.KERNEL32(00000000), ref: 00D14CFA
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Process32$CloseCreateCurrentFirstHandleNextProcessSnapshotToolhelp32
                                                                                                                                                                              • String ID: saBSI.exe
                                                                                                                                                                              • API String ID: 592884611-3955546181
                                                                                                                                                                              • Opcode ID: 6506e05ebea30dfbc5b4488d9fe52381c1a5fada8dfb74482e9423f417ec08e3
                                                                                                                                                                              • Instruction ID: a4d17f65ff76a3aee9077b34b04e310d5e7abc66e2a738e1d83fb66298b86261
                                                                                                                                                                              • Opcode Fuzzy Hash: 6506e05ebea30dfbc5b4488d9fe52381c1a5fada8dfb74482e9423f417ec08e3
                                                                                                                                                                              • Instruction Fuzzy Hash: 322105B1105301BFC620AB64FC89AAF77D5EF85324F190628F915C72D1EB3499858AF2
                                                                                                                                                                              APIs
                                                                                                                                                                              • CryptMsgGetParam.CRYPT32(?,00000005,00000000,?,?), ref: 00D71581
                                                                                                                                                                              • CryptMsgGetParam.CRYPT32(?,00000006,00000000,00000000,?), ref: 00D715B2
                                                                                                                                                                              • CryptMsgGetParam.CRYPT32(?,00000006,?,00000000,?), ref: 00D715DD
                                                                                                                                                                              • CertGetSubjectCertificateFromStore.CRYPT32(?,00010001,?), ref: 00D71625
                                                                                                                                                                              • CertFreeCRLContext.CRYPT32(?), ref: 00D7175E
                                                                                                                                                                                • Part of subcall function 00D8E960: _free.LIBCMT ref: 00D8E973
                                                                                                                                                                              • CertFreeCRLContext.CRYPT32(?), ref: 00D71738
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CertCryptParam$ContextFree$CertificateFromStoreSubject_free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 4059466977-0
                                                                                                                                                                              • Opcode ID: d0139dab110701f84996b9eb8cce8979671e8cf4614f994c878f03763cbed6ba
                                                                                                                                                                              • Instruction ID: 38328ab4563eedf198e15f6971fe4168b6fc55a4320fbc0f363c3e97476ff46f
                                                                                                                                                                              • Opcode Fuzzy Hash: d0139dab110701f84996b9eb8cce8979671e8cf4614f994c878f03763cbed6ba
                                                                                                                                                                              • Instruction Fuzzy Hash: F6814C75900258DFDF20DF68D841BEEBBB4FF09344F148259E859A7252E771AA08CBB1
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: HeapProcess
                                                                                                                                                                              • String ID: &$&$CObfuscatedIniReader cannot load file: %s$Key was not found: %s$NWebAdvisor::CSubInfoDatReader::ReadString$No section found for %s$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\SubInfoDataReader.cpp
                                                                                                                                                                              • API String ID: 54951025-2132657581
                                                                                                                                                                              • Opcode ID: 2f1de6119c70da80f438c57bafa6705427af364efaf39f74d0bfd90d41f9bebf
                                                                                                                                                                              • Instruction ID: 710f00388625cf7a04e955ba233d0b35863c505c3bc92aca8a872867b3c65e6d
                                                                                                                                                                              • Opcode Fuzzy Hash: 2f1de6119c70da80f438c57bafa6705427af364efaf39f74d0bfd90d41f9bebf
                                                                                                                                                                              • Instruction Fuzzy Hash: B9F1DF70A04249DFEB10DF68C855B9AB7B5FF15304F188299E849AB391EB709A48CF71
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetCurrentDirectoryW.KERNEL32(00000000,00000000,6EB998C3), ref: 00D24FB5
                                                                                                                                                                              • GetCurrentDirectoryW.KERNEL32(00000000,00000000), ref: 00D24FDF
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D24FF2
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D2500B
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CurrentDirectoryErrorLast
                                                                                                                                                                              • String ID: %ls\%ls
                                                                                                                                                                              • API String ID: 152501406-2125769799
                                                                                                                                                                              • Opcode ID: d06b02b74d4e8b817b64ed7aec44c493a8a2d7733389f7c8247c0337fe06d7dc
                                                                                                                                                                              • Instruction ID: 776ee46ba33e6f6deb97d26df00233430f6a33ac5f5123003a611dc987c544ee
                                                                                                                                                                              • Opcode Fuzzy Hash: d06b02b74d4e8b817b64ed7aec44c493a8a2d7733389f7c8247c0337fe06d7dc
                                                                                                                                                                              • Instruction Fuzzy Hash: 8841A1B1E006159BDB14DFA5ED45B6FBAB8EF54704F24413AE806EB285EA35C9008BB1
                                                                                                                                                                              Strings
                                                                                                                                                                              • Unable to substitute the arguments, xrefs: 00D5E16E
                                                                                                                                                                              • NEQ, xrefs: 00D5D892
                                                                                                                                                                              • invalid substitutor, xrefs: 00D5DB5E
                                                                                                                                                                              • NWebAdvisor::NXmlUpdater::CVersionPrecondition::IsPreconditionSatisfied, xrefs: 00D5DB65, 00D5E175
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\VersionPrecondition.cpp, xrefs: 00D5DB6A, 00D5E17A
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: NEQ$NWebAdvisor::NXmlUpdater::CVersionPrecondition::IsPreconditionSatisfied$Unable to substitute the arguments$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\VersionPrecondition.cpp$invalid substitutor
                                                                                                                                                                              • API String ID: 0-4090108046
                                                                                                                                                                              • Opcode ID: 5df791fb9554ac475a04accbb02e77097455020071bc62215e843b6dba1cea4b
                                                                                                                                                                              • Instruction ID: b54dc2eb787461ec677c07783d7a83c1e06951e32cb3dd1817913bf1715ae062
                                                                                                                                                                              • Opcode Fuzzy Hash: 5df791fb9554ac475a04accbb02e77097455020071bc62215e843b6dba1cea4b
                                                                                                                                                                              • Instruction Fuzzy Hash: 8082B270D002589BDF24DFA8C845BEDBBB1FF45304F144259E819AB291EB75AA89CF70
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetCurrentProcess.KERNEL32(?,?,00D9E8FD,00000002,00000002,?,00000002), ref: 00D9E920
                                                                                                                                                                              • TerminateProcess.KERNEL32(00000000,?,00D9E8FD,00000002,00000002,?,00000002), ref: 00D9E927
                                                                                                                                                                              • ExitProcess.KERNEL32 ref: 00D9E939
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Process$CurrentExitTerminate
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1703294689-0
                                                                                                                                                                              • Opcode ID: 3e033c6c7297d86864ab68baeb7f798cca877ab9b579becf69857987d7431c59
                                                                                                                                                                              • Instruction ID: 451dedb83f5839a0da42b9d92c5971ff40ca7a9b59551981af8e824f70716ff2
                                                                                                                                                                              • Opcode Fuzzy Hash: 3e033c6c7297d86864ab68baeb7f798cca877ab9b579becf69857987d7431c59
                                                                                                                                                                              • Instruction Fuzzy Hash: 24E0BDB100024AAFCF52AF65DD49E583B6AEB44351B184814F909CA231DB75ED82DAB6
                                                                                                                                                                              APIs
                                                                                                                                                                              • CoCreateInstance.OLE32(00DDD808,00000000,00000017,00DEB024,00000000,6EB998C3,?,?,?,00000000,00000000,00000000,00DB8687,000000FF), ref: 00D15C7A
                                                                                                                                                                              • OleRun.OLE32(00000000), ref: 00D15C89
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CreateInstance
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 542301482-0
                                                                                                                                                                              • Opcode ID: 85ab357da50658c86c0148edaf15e40579d3b7a6d44d933833e253bb8aa6b78e
                                                                                                                                                                              • Instruction ID: 729dc2720f7305668b074abc025daea2461acc9c3f8301f32779dc881e5c7f6b
                                                                                                                                                                              • Opcode Fuzzy Hash: 85ab357da50658c86c0148edaf15e40579d3b7a6d44d933833e253bb8aa6b78e
                                                                                                                                                                              • Instruction Fuzzy Hash: 9E218C75600B16EFCB05CB58DC45F6EB7BAEF88B21F104129E516E73A0DB34AD00CA60

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 1406 d14e1f-d14e73 call d3d6d0 1409 d14e75-d14ec1 call d19bb0 call d19940 call d11b84 call d11be0 call d1136c 1406->1409 1410 d14ec6-d14ede call d14d63 1406->1410 1409->1410 1415 d14ee0-d14f34 call d19bb0 call d19940 call d11b84 call d11be0 call d1136c 1410->1415 1416 d14f39-d14f46 CoInitializeEx 1410->1416 1450 d158da-d158e1 1415->1450 1418 d14f48-d14f4b 1416->1418 1419 d14f4d-d14f51 call d15a4f 1416->1419 1418->1419 1423 d14f56-d14f7c call d88760 1418->1423 1419->1423 1433 d14f86 1423->1433 1434 d14f7e-d14f84 1423->1434 1437 d14f88-d14f99 call d15d57 1433->1437 1434->1437 1444 d14ff1-d15008 call d88760 1437->1444 1445 d14f9b-d14fec call d19bb0 call d19940 call d11b84 call d11be0 call d1136c 1437->1445 1455 d15012 1444->1455 1456 d1500a-d15010 1444->1456 1479 d158ba-d158bf 1445->1479 1453 d158e3-d158e9 CloseHandle 1450->1453 1454 d158ef-d15913 call d88367 1450->1454 1453->1454 1459 d15014-d1502c call d15db6 1455->1459 1456->1459 1465 d1507b-d150cc call d8a920 call d88760 1459->1465 1466 d1502e-d15076 call d19bb0 call d19940 call d11b84 call d11be0 call d1136c 1459->1466 1480 d150d8 1465->1480 1481 d150ce-d150d6 call d26bd0 1465->1481 1507 d158ab-d158b3 1466->1507 1483 d158c1 call d17d21 1479->1483 1484 d158c6-d158d2 call d159c2 1479->1484 1487 d150da-d150f0 call d15e16 1480->1487 1481->1487 1483->1484 1484->1450 1494 d158d4 CoUninitialize 1484->1494 1497 d15143-d15154 1487->1497 1498 d150f2-d1513e call d19bb0 call d19940 call d11b84 call d11be0 call d1136c 1487->1498 1494->1450 1500 d15156 1497->1500 1501 d1515a-d15176 1497->1501 1531 d15897-d1589c 1498->1531 1500->1501 1504 d15178 1501->1504 1505 d1517c-d15194 1501->1505 1504->1505 1508 d15196 1505->1508 1509 d1519a-d151a9 call d43670 1505->1509 1507->1479 1510 d158b5 call d17d21 1507->1510 1508->1509 1517 d151f7-d15233 CommandLineToArgvW 1509->1517 1518 d151ab-d151f2 call d19bb0 call d19940 call d11b84 call d11be0 1509->1518 1510->1479 1532 d15235-d15282 call d19bb0 call d19940 call d11b84 call d11be0 GetLastError 1517->1532 1533 d15284-d152b0 call d8a920 GetModuleFileNameW 1517->1533 1548 d15310-d15318 call d1136c 1518->1548 1536 d158a3-d158a6 call d15946 1531->1536 1537 d1589e call d17d21 1531->1537 1567 d152ff-d1530a call d16140 1532->1567 1545 d152b2-d152fc call d19bb0 call d19940 call d11b84 call d11be0 GetLastError 1533->1545 1546 d1531d-d15367 call d1d730 call d8a920 GetLongPathNameW 1533->1546 1536->1507 1537->1536 1545->1567 1564 d15419-d15520 call d1171d * 2 call d45b70 call d13899 * 2 call d149d2 call d1171d * 2 call d45b70 call d13899 * 2 call d149d2 1546->1564 1565 d1536d-d15416 call d19bb0 call d19940 call d11b84 call d11be0 GetLastError call d16140 call d161b0 call d14190 call d1136c call d8ea46 1546->1565 1548->1531 1615 d15522-d15591 call d14a04 call d1171d call d45b70 call d13899 * 2 1564->1615 1616 d15596-d155a8 call d149d2 1564->1616 1565->1564 1567->1548 1615->1616 1621 d15611-d1564f call d14a4a 1616->1621 1622 d155aa-d1560c call d1171d * 2 call d45b70 call d13899 * 2 1616->1622 1640 d15651-d15693 call d19bb0 call d19940 call d11b84 call d16220 call d1136c 1621->1640 1641 d15698-d156a9 call d14b92 1621->1641 1622->1621 1640->1641 1649 d1571b-d15729 call d13a88 1641->1649 1650 d156ab-d15716 call d19bb0 call d19940 call d11b84 call d11be0 1641->1650 1654 d1572e-d15733 1649->1654 1691 d15887-d1588c call d1136c 1650->1691 1657 d15739-d1573b 1654->1657 1658 d157ed-d15802 call d17d7c 1654->1658 1660 d15746-d1575b call d17d7c 1657->1660 1661 d1573d-d15740 1657->1661 1671 d15804 1658->1671 1672 d15806-d15881 call d1372a call d19bb0 call d19940 call d11b84 call d11be0 call d16290 1658->1672 1674 d1575d 1660->1674 1675 d1575f-d157e8 call d1372a call d19bb0 call d19940 call d11b84 call d11be0 call d16290 call d1136c 1660->1675 1661->1658 1661->1660 1671->1672 1672->1691 1674->1675 1699 d1588f-d15892 call d13899 1675->1699 1691->1699 1699->1531
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D3D6D0: GetModuleHandleW.KERNEL32(kernel32.dll,00D14E6C,6EB998C3), ref: 00D3D6D5
                                                                                                                                                                                • Part of subcall function 00D3D6D0: GetProcAddress.KERNEL32(00000000,SetDefaultDllDirectories), ref: 00D3D6E5
                                                                                                                                                                              • CoInitializeEx.COMBASE(00000000,00000000,6EB998C3), ref: 00D14F3E
                                                                                                                                                                              • CommandLineToArgvW.SHELL32(?,?), ref: 00D15226
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001), ref: 00D15276
                                                                                                                                                                              • GetModuleFileNameW.KERNEL32(?,?,00000104), ref: 00D152A8
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001), ref: 00D152F3
                                                                                                                                                                              • GetLongPathNameW.KERNEL32(?,?,00000104), ref: 00D1535F
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000002), ref: 00D153AE
                                                                                                                                                                              • CloseHandle.KERNEL32(?,?,00000001), ref: 00D158E9
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                                • Part of subcall function 00D1136C: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D113A5
                                                                                                                                                                              • CoUninitialize.OLE32(?,00000001), ref: 00D158D4
                                                                                                                                                                                • Part of subcall function 00D26BD0: __Mtx_init_in_situ.LIBCPMT ref: 00D26CC0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast$HandleInitInitializeIos_base_dtorModuleNameOncestd::ios_base::_$AddressArgvBeginCloseCommandCompleteFileLineLongMtx_init_in_situPathProcUninitialize
                                                                                                                                                                              • String ID: /no_self_update$/store_xml_on_disk$/xml$BSI installation success. Exit code: $BootStrapInstaller$CommandLineToArgvW failed: $Ended$FALSE$Failed$Failed to allocate memory for event sender service$Failed to create xml updater logger$Failed to create xml updater signature verifier$GetLongPathName failed ($GetModuleFileName failed: $InitSecureDllLoading failed.$Install$InvalidArguments$MAIN_XML$Process$SA/WA installation failed with exit code: $SELF_UPDATE_ALLOWED$STORE_XML_ON_DISK$SaBsi.cpp$Some command line BSI variables are invalid.$Started$TRUE$WaitForOtherBSIToExit failed$failed to initialize updater
                                                                                                                                                                              • API String ID: 126520999-360321973
                                                                                                                                                                              • Opcode ID: 5028c5b9e18223e52f24f8cce74b7f4b218f70edd404fd4ebb0c1895800b796f
                                                                                                                                                                              • Instruction ID: 7383ddfa14cd1fc9697390f15362a81397b8438c34fb1bc30aa3d66aa78085a7
                                                                                                                                                                              • Opcode Fuzzy Hash: 5028c5b9e18223e52f24f8cce74b7f4b218f70edd404fd4ebb0c1895800b796f
                                                                                                                                                                              • Instruction Fuzzy Hash: D1626EB4904249EFDF14EFA4E991AED7BB4EF54304F504059F809A7281DF74AA88CBB1

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 1717 d4efc0-d4f053 call d641f0 call d64430 1722 d4f055-d4f06b call d48650 1717->1722 1723 d4f07f-d4f13b call d4ea50 call d8a920 * 2 1717->1723 1726 d4f070-d4f07a 1722->1726 1738 d4f13d-d4f163 GetLastError call d4e9b0 1723->1738 1739 d4f168-d4f170 1723->1739 1728 d4fa58-d4fa83 call d64210 call d88367 1726->1728 1746 d4f3cb-d4f3e6 call d48650 1738->1746 1740 d4f172-d4f186 1739->1740 1741 d4f18d-d4f1ab call d64280 1739->1741 1740->1741 1748 d4f1ad-d4f1d3 GetLastError call d4e9b0 1741->1748 1749 d4f1d8-d4f209 call d64480 1741->1749 1746->1728 1748->1746 1755 d4f236-d4f255 call d64250 1749->1755 1756 d4f20b-d4f231 GetLastError call d4e9b0 1749->1756 1761 d4f257-d4f286 call d48650 1755->1761 1762 d4f289-d4f29a call d64640 1755->1762 1756->1746 1761->1762 1767 d4f2f3-d4f300 call d64620 1762->1767 1768 d4f29c-d4f2ee GetLastError call d4e9b0 call d48650 1762->1768 1774 d4f302-d4f324 GetLastError call d4e9b0 1767->1774 1775 d4f329-d4f33f call d64560 1767->1775 1768->1728 1774->1746 1782 d4f341-d4f384 GetLastError call d4e9b0 call d48650 1775->1782 1783 d4f389-d4f3a7 call d644c0 1775->1783 1782->1728 1789 d4f3a9-d4f3c6 GetLastError call d4e9b0 1783->1789 1790 d4f3eb-d4f41a call d9594f 1783->1790 1789->1746 1796 d4f41c-d4f455 call d4e9b0 call d48650 1790->1796 1797 d4f45a-d4f461 1790->1797 1812 d4fa4f-d4fa50 call d8e960 1796->1812 1799 d4f4c2-d4f4db call d508c0 1797->1799 1800 d4f463-d4f48f 1797->1800 1808 d4f4e0-d4f501 call d144b2 1799->1808 1803 d4f495-d4f49e 1800->1803 1803->1803 1806 d4f4a0-d4f4c0 call d1347e 1803->1806 1806->1808 1816 d4f503-d4f517 call d138d0 1808->1816 1817 d4f51d-d4f523 1808->1817 1815 d4fa55 1812->1815 1815->1728 1816->1817 1819 d4f525-d4f52b call d138d0 1817->1819 1820 d4f530-d4f537 1817->1820 1819->1820 1823 d4f5a0-d4f5de call d50230 1820->1823 1824 d4f539-d4f53f 1820->1824 1833 d4f657-d4f669 call d138d0 1823->1833 1834 d4f5e0-d4f5e6 1823->1834 1825 d4f561-d4f582 call d48650 1824->1825 1826 d4f541-d4f55f call d48650 1824->1826 1835 d4f585-d4f59b call d4e9b0 1825->1835 1826->1835 1844 d4f66d-d4f676 PathFileExistsW 1833->1844 1845 d4f66b 1833->1845 1837 d4f625-d4f654 1834->1837 1838 d4f5e8-d4f5f7 1834->1838 1853 d4fa44-d4fa4a call d138d0 1835->1853 1837->1833 1841 d4f60f-d4f61f call d88375 1838->1841 1842 d4f5f9-d4f607 1838->1842 1841->1837 1847 d4f60d 1842->1847 1848 d4fadf-d4fb00 call d8d60f 1842->1848 1851 d4f67c-d4f68b 1844->1851 1852 d4f83d-d4f844 1844->1852 1845->1844 1847->1841 1862 d4fb02-d4fb0a call d88375 1848->1862 1863 d4fb0d-d4fb11 1848->1863 1858 d4f691-d4f6a4 1851->1858 1859 d4f8b8-d4f8bc 1851->1859 1856 d4f846 1852->1856 1857 d4f848-d4f86a CreateFileW 1852->1857 1853->1812 1856->1857 1864 d4f870-d4f8b3 call d4e9b0 call d48650 1857->1864 1865 d4f8fa-d4f942 call d635a0 call d645f0 1857->1865 1866 d4fada call d134d0 1858->1866 1867 d4f6aa-d4f6ae 1858->1867 1860 d4f8c0-d4f8f5 call d48650 call d4e9b0 1859->1860 1861 d4f8be 1859->1861 1860->1853 1861->1860 1862->1863 1864->1853 1895 d4f9d6-d4fa1a CloseHandle call d635f0 call d1149c 1865->1895 1896 d4f948 1865->1896 1866->1848 1872 d4f6b0-d4f6b2 1867->1872 1873 d4f6b8-d4f6f2 1867->1873 1872->1873 1878 d4f6f4-d4f6ff 1873->1878 1879 d4f739-d4f7ba call d8a3a0 DeleteFileW 1873->1879 1884 d4f701-d4f706 1878->1884 1885 d4f708-d4f70f 1878->1885 1893 d4f7bc 1879->1893 1894 d4f7be-d4f7ca call d965f0 1879->1894 1886 d4f712-d4f733 call d133c3 1884->1886 1885->1886 1886->1879 1893->1894 1907 d4f7cc-d4f7ee call d8d73d call d4e9b0 1894->1907 1908 d4f82e-d4f838 call d138d0 1894->1908 1916 d4fa24-d4fa33 call d4e9b0 1895->1916 1917 d4fa1c-d4fa1f 1895->1917 1901 d4f950-d4f958 1896->1901 1901->1895 1902 d4f95a-d4f973 WriteFile 1901->1902 1905 d4fa86-d4fad5 call d4e9b0 call d48650 CloseHandle 1902->1905 1906 d4f979-d4f9c9 call d4e990 call d64140 call d645f0 1902->1906 1929 d4fa3a 1905->1929 1934 d4f9ce-d4f9d0 1906->1934 1927 d4f7f0 1907->1927 1928 d4f7f2-d4f829 call d48650 call d138d0 1907->1928 1908->1852 1916->1929 1917->1916 1927->1928 1928->1853 1929->1853 1934->1895 1934->1901
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D4F13D
                                                                                                                                                                                • Part of subcall function 00D48650: std::locale::_Init.LIBCPMT ref: 00D4882F
                                                                                                                                                                              • CloseHandle.KERNEL32(?,?,?,?,?,00000006,00000000,?,?,?,00000000,?,?,?,00000000,00000000), ref: 00D4FAC8
                                                                                                                                                                                • Part of subcall function 00D8E960: _free.LIBCMT ref: 00D8E973
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CloseErrorHandleInitLast_freestd::locale::_
                                                                                                                                                                              • String ID: <$Cache-Control: no-cache$CreateFile failed (%d)$File already exists: %s$GET$HTTP GET request failed (%d), url: %s$HTTP add request headers failed (%d), url: %s$HTTP connection failed (%d), url: %s$HTTP query content length (%d), url: %s$HTTP receive response failed (%d), url: %s$HTTP send request failed (%d), url: %s, ignore proxy flag %s$HTTP status (%d) error (%d), url: %s$NWebAdvisor::NHttp::NDownloadFile::StoreOnDisk::<lambda_2af623cb1b195cc2505e5df23daadde2>::operator ()$Unable to allocate %d bytes$Unable to extract the filename from url (%s)$Unable to open HTTP transaction$Unable to rename the old file (%d): %s$WinHttpCrackUrl failed (%d), url: %s$WriteFile failed (%d)$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\HttpsDownloadFile.cpp$empty filename$false$true
                                                                                                                                                                              • API String ID: 2292809486-983596374
                                                                                                                                                                              • Opcode ID: 8dfecfd3018582a2c08f9661fb802e44e349e1d51dfbd07b7fbc0d38f70f18dd
                                                                                                                                                                              • Instruction ID: 1fc1bffc91850666c7f0ca8d76a58041dbdab405bf44f97dd4efc2dfadb5b0b6
                                                                                                                                                                              • Opcode Fuzzy Hash: 8dfecfd3018582a2c08f9661fb802e44e349e1d51dfbd07b7fbc0d38f70f18dd
                                                                                                                                                                              • Instruction Fuzzy Hash: 73627CB0A40619AFDB24DB14DC45FA9B7B5FF54304F0401E9F619A72A1DBB0AA84CFB4

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 2370 d565f0-d56642 2371 d56644 2370->2371 2372 d56646-d5664a 2370->2372 2371->2372 2373 d568c4-d568de 2372->2373 2374 d56650-d56662 call d11b0c 2372->2374 2375 d568e4-d56900 call d41ac0 2373->2375 2376 d56a8f-d56aa3 call d888fa 2373->2376 2374->2373 2382 d56668-d56690 2374->2382 2384 d56902-d56912 2375->2384 2385 d5695a-d56960 2375->2385 2376->2375 2388 d56aa9-d56cc3 call d560c0 * 3 call d1347e call d560c0 * 2 call d1347e * 4 call d56400 call d885d4 call d885bf call d888b0 2376->2388 2386 d56696-d566be 2382->2386 2387 d56712 2382->2387 2389 d56914 2384->2389 2390 d56916-d56923 2384->2390 2394 d56964-d569a1 call d48650 2385->2394 2395 d56962 2385->2395 2391 d566c4-d566cd 2386->2391 2392 d56719-d56727 2387->2392 2388->2375 2389->2390 2397 d56925-d56927 2390->2397 2398 d5692d-d5694e call d11b0c 2390->2398 2391->2391 2396 d566cf-d56710 call d1347e call d493a0 2391->2396 2399 d56734-d5673b 2392->2399 2400 d56729-d5672f call d138d0 2392->2400 2415 d569a4-d569ad 2394->2415 2395->2394 2396->2387 2396->2392 2397->2398 2417 d56954 2398->2417 2418 d569db-d569e4 2398->2418 2407 d5673d-d5677c call d48650 2399->2407 2408 d567a8-d567df call d8a920 2399->2408 2400->2399 2423 d56780-d56789 2407->2423 2427 d567e1-d567f5 2408->2427 2428 d5681d 2408->2428 2415->2415 2422 d569af-d569b7 call d1347e 2415->2422 2417->2385 2425 d569ea-d569f6 2417->2425 2418->2385 2418->2425 2431 d569bc-d569d8 call d88367 2422->2431 2423->2423 2430 d5678b-d567a3 call d1347e call d138d0 2423->2430 2425->2385 2432 d569fc-d56a1c SHGetKnownFolderPath 2425->2432 2427->2428 2433 d567f7-d567fd 2427->2433 2434 d5681f-d56843 GetEnvironmentVariableW 2428->2434 2430->2431 2441 d56a54-d56a8a call d114a1 CoTaskMemFree call d144b2 call d138d0 2432->2441 2442 d56a1e-d56a22 2432->2442 2443 d56800 2433->2443 2436 d56845-d5684a 2434->2436 2437 d5686e-d568b1 GetLastError call d48650 2434->2437 2436->2437 2444 d5684c-d56865 call d114a1 call d138d0 2436->2444 2465 d568b4-d568bd 2437->2465 2441->2431 2449 d56a24 2442->2449 2450 d56a26-d56a4f call d48650 call d114a1 2442->2450 2443->2428 2451 d56802-d56805 2443->2451 2444->2431 2449->2450 2450->2431 2459 d56807-d5681b 2451->2459 2460 d5686a-d5686c 2451->2460 2459->2428 2459->2443 2460->2434 2465->2465 2470 d568bf 2465->2470 2470->2373
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetEnvironmentVariableW.KERNEL32(ProgramW6432,?,00000104), ref: 00D5683B
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D5686E
                                                                                                                                                                              • SHGetKnownFolderPath.SHELL32(?,00000000,00000000,?,?,?,?), ref: 00D56A15
                                                                                                                                                                              • CoTaskMemFree.OLE32(00000000,00000000,?,00000000,00000000,?,?,?,?), ref: 00D56A6B
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: EnvironmentErrorFolderFreeKnownLastPathTaskVariable
                                                                                                                                                                              • String ID: CSIDL_COMMON_APPDATA$CSIDL_COMMON_DOCUMENTS$CSIDL_COMMON_STARTUP$CSIDL_PROGRAM_FILES$CSIDL_PROGRAM_FILESX64$CSIDL_PROGRAM_FILESX86$CSIDL_PROGRAM_FILES_COMMON$CSIDL_SYSTEM$CSIDL_SYSTEMX86$CSIDL_WINDOWS$Error retrieving directory %s$GetEnvironmentVariable failed (%d)$NWebAdvisor::NXmlUpdater::CDirSubstitution::Substitute$ProgramFiles$ProgramW6432$Unable to get the platform$Unknown folder identifier: %s$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\DirSubstitution.cpp
                                                                                                                                                                              • API String ID: 3946049928-1874136459
                                                                                                                                                                              • Opcode ID: 4d54770b46b6d1cc4d0db067e7f4470e3b6c4d8d16a01b4d53269ec256ffb7b3
                                                                                                                                                                              • Instruction ID: 99e2984c42cafc5bd0de8fe713668739f9334594cdda5b30a1cbafda157178ed
                                                                                                                                                                              • Opcode Fuzzy Hash: 4d54770b46b6d1cc4d0db067e7f4470e3b6c4d8d16a01b4d53269ec256ffb7b3
                                                                                                                                                                              • Instruction Fuzzy Hash: C4029C70A00358AADF20DF64CC49BE9B7B0EF14705F5441D9E809A7291EBB5AAC9CF71

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 2492 d4eaa0-d4eb46 call d641f0 call d64430 2497 d4eb4c-d4ebf6 call d8a920 * 2 2492->2497 2498 d4ec1b-d4ec28 2492->2498 2509 d4ec2d-d4ec35 2497->2509 2510 d4ebf8-d4ec18 GetLastError call d48650 2497->2510 2499 d4ef5b-d4ef83 call d64210 call d88367 2498->2499 2512 d4ec37-d4ec4b 2509->2512 2513 d4ec52-d4ec6d call d64280 2509->2513 2510->2498 2512->2513 2517 d4eca4-d4ecd5 call d64480 2513->2517 2518 d4ec6f-d4ec9f GetLastError call d48650 2513->2518 2523 d4ecd7-d4ed07 GetLastError call d48650 2517->2523 2524 d4ed0c-d4ed2b call d64250 2517->2524 2518->2499 2523->2499 2529 d4ed4c-d4ed5d call d64640 2524->2529 2530 d4ed2d-d4ed49 GetLastError call d48650 2524->2530 2535 d4eda5-d4edb2 call d64620 2529->2535 2536 d4ed5f-d4eda0 GetLastError call d48650 2529->2536 2530->2529 2541 d4edb4-d4ede0 GetLastError call d48650 2535->2541 2542 d4ede5-d4edfb call d64560 2535->2542 2536->2499 2541->2499 2547 d4ee34-d4ee52 call d644c0 2542->2547 2548 d4edfd-d4ee2f GetLastError call d48650 2542->2548 2553 d4ee54-d4ee83 GetLastError call d48650 2547->2553 2554 d4ee88-d4eea4 call d9594f 2547->2554 2548->2499 2553->2499 2559 d4eea6-d4eed5 call d48650 call d8e960 2554->2559 2560 d4eeda-d4ef01 call d645f0 2554->2560 2559->2499 2564 d4ef06-d4ef08 2560->2564 2566 d4ef46-d4ef58 call d8e960 2564->2566 2567 d4ef0a 2564->2567 2566->2499 2570 d4ef10-d4ef18 2567->2570 2570->2566 2572 d4ef1a-d4ef22 2570->2572 2573 d4ef24-d4ef44 call d645f0 2572->2573 2574 d4ef86-d4efb9 call d48650 call d8e960 2572->2574 2573->2566 2573->2570 2574->2499
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetLastError.KERNEL32(6EB998C3), ref: 00D4EBF9
                                                                                                                                                                              • GetLastError.KERNEL32(6EB998C3,?,00000000,00D45D40), ref: 00D4EC70
                                                                                                                                                                              • GetLastError.KERNEL32(6EB998C3,GET,?,00000000,00000000,00000000,00000000,?,00000000,00D45D40), ref: 00D4ECD8
                                                                                                                                                                                • Part of subcall function 00D48650: std::locale::_Init.LIBCPMT ref: 00D4882F
                                                                                                                                                                              • GetLastError.KERNEL32(6EB998C3,Cache-Control: no-cache,000000FF,40000000,GET,?,00000000,00000000,00000000,00000000,?,00000000,00D45D40), ref: 00D4ED2E
                                                                                                                                                                              • GetLastError.KERNEL32(6EB998C3,true,00000000,00000000,Cache-Control: no-cache,000000FF,40000000,GET,?,00000000,00000000,00000000,00000000,?,00000000,00D45D40), ref: 00D4ED75
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast$Initstd::locale::_
                                                                                                                                                                              • String ID: <$Cache-Control: no-cache$GET$HTTP GET request failed (%d), url: %s$HTTP add request headers failed (%d), url: %s$HTTP connection failed (%d), url: %s$HTTP query content length (%d), url: %s$HTTP receive response failed (%d), url: %s$HTTP send request failed (%d), url: %s, proxy ignore flag %s$HTTP status (%d) error (%d), url: %s$NWebAdvisor::NHttp::NDownloadFile::From::<lambda_1effc98e56da47b46c9f3c737083b6c0>::operator ()$Not enough space in buffer: bufferLength(%d) Read(%d)$Unable to allocate %d bytes$WinHttpCrackUrl failed (%d), url: %s$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\HttpsDownloadFile.cpp$false$true
                                                                                                                                                                              • API String ID: 1579124236-1699437461
                                                                                                                                                                              • Opcode ID: 234879c3339340fb94eb806bf71c149712e2d987d06be42b0ab48025444ccff8
                                                                                                                                                                              • Instruction ID: 8958c39facfb6e8c411f2f3885b47797852102d030fe03c620ffe064a81aea8f
                                                                                                                                                                              • Opcode Fuzzy Hash: 234879c3339340fb94eb806bf71c149712e2d987d06be42b0ab48025444ccff8
                                                                                                                                                                              • Instruction Fuzzy Hash: 95C183B0940729AFEB209F10DC42BE9B764FF15704F54419AF609772C2D7B16A888FB9

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 2581 d4bc60-d4bd0a call d1347e 2584 d4bd0c 2581->2584 2585 d4bd0e-d4bd14 2581->2585 2584->2585 2586 d4bd16 2585->2586 2587 d4bd18-d4bd39 call d4fbe0 2585->2587 2586->2587 2590 d4bd6e-d4bd94 PathFindExtensionW call d92041 2587->2590 2591 d4bd3b-d4bd3f 2587->2591 2598 d4bd96-d4bda8 call d92041 2590->2598 2599 d4bdaa-d4bdbe 2590->2599 2592 d4bd41 2591->2592 2593 d4bd43-d4bd63 call d48650 2591->2593 2592->2593 2600 d4be5d-d4be5f 2593->2600 2601 d4bd69 2593->2601 2598->2599 2612 d4bdea-d4bdfa call d4bbf0 2598->2612 2603 d4bdc0-d4bdc5 call d721d0 2599->2603 2604 d4bdc9-d4bdce call d5eb20 2599->2604 2606 d4be63-d4be69 2600->2606 2607 d4be4b-d4be57 DeleteFileW 2601->2607 2613 d4bdc7 2603->2613 2614 d4bdd1-d4bdd3 2604->2614 2610 d4be99-d4beb3 2606->2610 2611 d4be6b-d4be7d 2606->2611 2607->2600 2618 d4beb5-d4bec7 2610->2618 2619 d4bee3-d4bf00 call d88367 2610->2619 2615 d4be8f-d4be96 call d88375 2611->2615 2616 d4be7f-d4be8d 2611->2616 2630 d4be61 2612->2630 2631 d4bdfc-d4be0e 2612->2631 2613->2614 2614->2612 2621 d4bdd5-d4bde8 2614->2621 2615->2610 2616->2615 2623 d4bf03-d4bf63 call d8d60f 2616->2623 2625 d4bed9-d4bee0 call d88375 2618->2625 2626 d4bec9-d4bed7 2618->2626 2629 d4be37-d4be48 call d48650 2621->2629 2639 d4bf74-d4c0e0 call d1347e call d467e0 call d138d0 call d1347e call d467e0 call d138d0 call d1347e call d467e0 call d138d0 call d1347e call d467e0 call d138d0 call d1347e call d467e0 call d138d0 2623->2639 2640 d4bf65-d4bf6f 2623->2640 2625->2619 2626->2623 2626->2625 2629->2607 2630->2606 2635 d4be10 2631->2635 2636 d4be12-d4be1f call d92041 2631->2636 2635->2636 2636->2630 2648 d4be21-d4be32 2636->2648 2686 d4c0e6-d4c0ee 2639->2686 2687 d4c37d-d4c382 2639->2687 2644 d4c387-d4c39d call d48650 2640->2644 2651 d4c39f-d4c3a4 2644->2651 2648->2629 2653 d4c3a6-d4c3b0 2651->2653 2654 d4c3c7-d4c3e4 call d88367 2651->2654 2653->2654 2656 d4c3b2-d4c3be 2653->2656 2656->2654 2663 d4c3c0-d4c3c2 2656->2663 2663->2654 2686->2687 2688 d4c0f4-d4c0fc 2686->2688 2687->2644 2689 d4c115-d4c121 call d114c1 2688->2689 2690 d4c0fe-d4c113 call d114a1 2688->2690 2695 d4c126-d4c13c call d144b2 2689->2695 2690->2695 2698 d4c14c-d4c153 2695->2698 2699 d4c13e-d4c147 call d138d0 2695->2699 2701 d4c155-d4c161 call d138d0 2698->2701 2702 d4c166-d4c171 2698->2702 2699->2698 2701->2702 2704 d4c173-d4c186 call d114a1 2702->2704 2705 d4c188-d4c197 call d114c1 2702->2705 2710 d4c19a-d4c1b0 call d144b2 2704->2710 2705->2710 2713 d4c1b2-d4c1be call d138d0 2710->2713 2714 d4c1c3-d4c1ca 2710->2714 2713->2714 2716 d4c1cc-d4c1d8 call d138d0 2714->2716 2717 d4c1dd-d4c1e5 2714->2717 2716->2717 2719 d4c1e7-d4c1fa call d114a1 2717->2719 2720 d4c1fc-d4c20b call d114c1 2717->2720 2725 d4c20e-d4c221 call d144b2 2719->2725 2720->2725 2728 d4c231-d4c238 2725->2728 2729 d4c223-d4c22c call d138d0 2725->2729 2730 d4c245-d4c25e call d4a380 2728->2730 2731 d4c23a-d4c240 call d138d0 2728->2731 2729->2728 2736 d4c264-d4c271 call d4a380 2730->2736 2737 d4c346-d4c34b 2730->2737 2731->2730 2736->2737 2743 d4c277-d4c284 call d4a380 2736->2743 2738 d4c34d-d4c35e call d48650 2737->2738 2744 d4c361 2738->2744 2743->2737 2749 d4c28a-d4c297 2743->2749 2746 d4c363-d4c37b call d138d0 * 3 2744->2746 2746->2651 2751 d4c299 2749->2751 2752 d4c29b-d4c2aa call db4db0 2749->2752 2751->2752 2757 d4c2ac-d4c2ca call d48650 2752->2757 2758 d4c2cf-d4c301 call d114a1 call d467e0 call d138d0 2752->2758 2757->2744 2769 d4c323-d4c33d call d4bc60 2758->2769 2770 d4c303-d4c310 call d4a380 2758->2770 2773 d4c342-d4c344 2769->2773 2775 d4c312-d4c319 2770->2775 2776 d4c31b-d4c31f 2770->2776 2773->2746 2775->2738 2776->2769 2777 d4c321 2776->2777 2777->2769
                                                                                                                                                                              APIs
                                                                                                                                                                              • PathFindExtensionW.SHLWAPI(00000000,?,?,?,?,00DEBFD0,00000000,6EB998C3), ref: 00D4BD7A
                                                                                                                                                                              • DeleteFileW.KERNEL32(00000000), ref: 00D4BE57
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: DeleteExtensionFileFindPath
                                                                                                                                                                              • String ID: .cab$.exe$DestDir$DestFile$Location$MD5$NWebAdvisor::NXmlUpdater::CDownloadCommand::DownloadCommand$NWebAdvisor::NXmlUpdater::CDownloadCommand::Execute$Unable to create destination directory (%d)$Unable to download %s$Unable to get substitute download variables$Unable to read Location and/or DestDir attribute of DOWNLOAD command$Unable to verify MD5, deleting file: %s$Unable to verify signature, deleting file: %s$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\DownloadCommand.cpp$extra$invalid substitutor
                                                                                                                                                                              • API String ID: 3618814920-733304951
                                                                                                                                                                              • Opcode ID: 587781cc28d154dc7e3b70f70c9fef64b0b07f7796730d453804aa9ef76e76eb
                                                                                                                                                                              • Instruction ID: ee1f395dd660bce1d04fce17f2950c8398d708aed9cd14a5dbc98fb42f576afc
                                                                                                                                                                              • Opcode Fuzzy Hash: 587781cc28d154dc7e3b70f70c9fef64b0b07f7796730d453804aa9ef76e76eb
                                                                                                                                                                              • Instruction Fuzzy Hash: 00228E71E00208AFDB20DFA4DC95BEEB7B4EF14314F14416AE915A7282DB74AA48CF71

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 3011 d20890-d208e2 call d73bab 3014 d21045-d21046 call d73faf 3011->3014 3015 d208e8-d208ee 3011->3015 3019 d2104b call d8d60f 3014->3019 3017 d20a53-d20a70 call d8a920 3015->3017 3018 d208f4-d2090b ConvertStringSecurityDescriptorToSecurityDescriptorW 3015->3018 3029 d20a72 3017->3029 3030 d20a75-d20ab6 call d23110 3017->3030 3021 d20911-d20939 3018->3021 3022 d2101f-d21042 call d73bbc call d88367 3018->3022 3028 d21050-d21053 3019->3028 3025 d2093b 3021->3025 3026 d2093d-d20942 3021->3026 3025->3026 3031 d20945-d2094e 3026->3031 3035 d21055-d2105a 3028->3035 3036 d2105c-d21069 3028->3036 3029->3030 3042 d20fa9-d2101c call d22b90 call d72bfd 3030->3042 3043 d20abc-d20ac0 3030->3043 3031->3031 3033 d20950-d2099f call d1f520 call d1e640 3031->3033 3052 d209a4-d209bf 3033->3052 3041 d2106c-d21098 call d12a82 call d128d1 call d8a332 3035->3041 3036->3041 3042->3022 3046 d20ac6-d20bba call d88713 call d8a920 call d73367 call d73184 call d733f6 call d13128 call d73084 call d731e9 3043->3046 3047 d20d19-d20d26 3043->3047 3133 d20bef-d20c12 call d75688 3046->3133 3134 d20bbc-d20bcc call d73367 3046->3134 3053 d20d2a-d20d53 call d189b0 3047->3053 3054 d20d28 3047->3054 3058 d209c1-d209d6 3052->3058 3059 d209fc-d20a1b 3052->3059 3077 d20e00-d20e0a 3053->3077 3078 d20d59-d20d70 call d12c9c 3053->3078 3054->3053 3065 d209d8-d209e6 3058->3065 3066 d209ec-d209f9 call d88375 3058->3066 3067 d20a31-d20a40 3059->3067 3068 d20a1d-d20a1f 3059->3068 3065->3019 3065->3066 3066->3059 3074 d20a42-d20a4f LocalFree 3067->3074 3075 d20a51 3067->3075 3068->3022 3076 d20a25-d20a2c LocalFree 3068->3076 3074->3017 3075->3017 3076->3022 3077->3042 3079 d20e10-d20e3a call d12c9c 3077->3079 3086 d20d72-d20d8a 3078->3086 3087 d20db8-d20dc3 call d738a1 3078->3087 3090 d20e89-d20eb2 call d738a1 3079->3090 3091 d20e3c-d20e6c call d22310 3079->3091 3086->3087 3112 d20d8c-d20db2 3086->3112 3100 d20dc5-d20dc8 call d12510 3087->3100 3101 d20dcd-d20de5 3087->3101 3103 d20eb4-d20eb7 call d12510 3090->3103 3104 d20ebc 3090->3104 3113 d20e6e-d20e79 call d738a1 3091->3113 3100->3101 3107 d20de7-d20df4 3101->3107 3108 d20dfc 3101->3108 3103->3104 3111 d20ec0-d20ed4 3104->3111 3107->3108 3108->3077 3115 d20ed6-d20ee3 3111->3115 3116 d20eeb-d20f0d 3111->3116 3112->3028 3112->3087 3127 d20e83-d20e87 3113->3127 3128 d20e7b-d20e7e call d12510 3113->3128 3115->3116 3116->3042 3121 d20f13 3116->3121 3125 d20f15-d20f18 3121->3125 3126 d20f1e-d20f2b call d23030 3121->3126 3125->3042 3125->3126 3135 d20f78-d20f82 3126->3135 3136 d20f2d-d20f63 3126->3136 3127->3111 3128->3127 3148 d20c14-d20c16 3133->3148 3149 d20c5f-d20c7e call d22c50 3133->3149 3145 d20bde-d20bec call d733bf 3134->3145 3146 d20bce-d20bd9 3134->3146 3140 d20f86-d20fa4 call d1e790 call d21740 3135->3140 3141 d20f84 3135->3141 3136->3135 3139 d20f65-d20f68 3136->3139 3139->3036 3144 d20f6e-d20f73 3139->3144 3140->3042 3141->3140 3144->3041 3145->3133 3146->3145 3153 d20c21-d20c2d 3148->3153 3154 d20c18-d20c1e call d8e960 3148->3154 3162 d20c80-d20c9a 3149->3162 3163 d20caf-d20cb4 3149->3163 3155 d20c30-d20c34 3153->3155 3154->3153 3155->3155 3161 d20c36-d20c4e call d9594f 3155->3161 3161->3149 3170 d20c50-d20c5c call d8a3a0 3161->3170 3162->3163 3175 d20c9c-d20caa 3162->3175 3165 d20ce2-d20ceb 3163->3165 3166 d20cb6-d20ccd 3163->3166 3165->3047 3167 d20ced-d20d04 3165->3167 3166->3165 3179 d20ccf-d20cdd 3166->3179 3167->3047 3181 d20d06-d20d14 3167->3181 3170->3149 3175->3163 3179->3165 3181->3047
                                                                                                                                                                              APIs
                                                                                                                                                                              • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA),00000001,?,00000000), ref: 00D20903
                                                                                                                                                                              • LocalFree.KERNEL32(?,?), ref: 00D20A26
                                                                                                                                                                              • LocalFree.KERNEL32(?,?), ref: 00D20A43
                                                                                                                                                                                • Part of subcall function 00D12510: __EH_prolog3_catch.LIBCMT ref: 00D12517
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D20B08
                                                                                                                                                                              • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 00D20B50
                                                                                                                                                                              • std::_Locinfo::~_Locinfo.LIBCPMT ref: 00D20B86
                                                                                                                                                                              • std::locale::_Init.LIBCPMT ref: 00D20B97
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D20BC0
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D20BE1
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D20BF2
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D21017
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D21020
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$DescriptorFreeLocalLockit::_Securitystd::locale::_$AddfacConvertH_prolog3_catchInitIos_base_dtorLocimp::_Locimp_LocinfoLocinfo::_Locinfo::~_Locinfo_ctorLockit::~_Mtx_unlockStringstd::ios_base::_
                                                                                                                                                                              • String ID: D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA)$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                                                                                                                                                              • API String ID: 2168703646-3388121372
                                                                                                                                                                              • Opcode ID: 4c820c53b491138d1fca50f24c6843a867af327afda135b998951b8d4edb8023
                                                                                                                                                                              • Instruction ID: c1a40105288dd16c35c28254cb7c6f0307b60d1d15c78a7f4d77b6d8bccd9f4d
                                                                                                                                                                              • Opcode Fuzzy Hash: 4c820c53b491138d1fca50f24c6843a867af327afda135b998951b8d4edb8023
                                                                                                                                                                              • Instruction Fuzzy Hash: B1327D70D002698FDB14DFA8D945BDDBBB4AF14304F1440A9E949AB392DB74AE84CFB1

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 3640 d49400-d49483 GetModuleHandleW 3641 d49485-d49495 GetProcAddress 3640->3641 3642 d494c2 3640->3642 3641->3642 3643 d49497-d494b3 GetCurrentProcess 3641->3643 3644 d494c4-d494dc 3642->3644 3643->3642 3648 d494b5-d494bc 3643->3648 3645 d494e0-d494e9 3644->3645 3645->3645 3647 d494eb-d4952e call d1347e 3645->3647 3652 d49530-d49539 3647->3652 3648->3642 3650 d494be-d494c0 3648->3650 3650->3644 3652->3652 3653 d4953b-d49567 call d1347e call d48c60 3652->3653 3658 d49585-d49592 3653->3658 3659 d49569-d49580 call d1347e 3653->3659 3661 d49594-d495a9 3658->3661 3662 d495c9-d495f6 3658->3662 3659->3658 3663 d495bf-d495c6 call d88375 3661->3663 3664 d495ab-d495b9 3661->3664 3665 d4962d-d49674 call d491a0 3662->3665 3666 d495f8-d4960d 3662->3666 3663->3662 3664->3663 3668 d4a108-d4a121 call d8d60f 3664->3668 3676 d49677-d49680 3665->3676 3670 d49623-d4962a call d88375 3666->3670 3671 d4960f-d4961d 3666->3671 3670->3665 3671->3668 3671->3670 3676->3676 3679 d49682-d496a8 call d1347e call d48c60 3676->3679 3684 d496be-d496cb 3679->3684 3685 d496aa-d496b1 3679->3685 3688 d49702-d4972f 3684->3688 3689 d496cd-d496e2 3684->3689 3686 d496b5-d496b9 call d1347e 3685->3686 3687 d496b3 3685->3687 3686->3684 3687->3686 3690 d49766-d497c9 call d8a920 GetModuleFileNameW 3688->3690 3691 d49731-d49746 3688->3691 3693 d496e4-d496f2 3689->3693 3694 d496f8-d496ff call d88375 3689->3694 3703 d49816-d49884 call d50750 call d13f22 call d138d0 call d8a920 GetLongPathNameW 3690->3703 3704 d497cb-d497fb GetLastError call d48650 3690->3704 3696 d4975c-d49763 call d88375 3691->3696 3697 d49748-d49756 3691->3697 3693->3694 3694->3688 3696->3690 3697->3696 3722 d49886-d498e8 GetLastError call d48650 call d8ea46 3703->3722 3723 d498eb-d498f1 3703->3723 3710 d49800-d49809 3704->3710 3710->3710 3712 d4980b-d49811 3710->3712 3713 d4990b-d49948 call d1347e 3712->3713 3719 d49950-d49959 3713->3719 3719->3719 3721 d4995b-d49987 call d1347e call d48c60 3719->3721 3734 d499a5-d499b2 3721->3734 3735 d49989-d499a0 call d1347e 3721->3735 3722->3723 3726 d498f4-d498fd 3723->3726 3726->3726 3727 d498ff-d4990a 3726->3727 3727->3713 3737 d499b4-d499c9 3734->3737 3738 d499e9-d49a16 3734->3738 3735->3734 3741 d499df-d499e6 call d88375 3737->3741 3742 d499cb-d499d9 3737->3742 3739 d49a4d-d49abf call d1347e 3738->3739 3740 d49a18-d49a2d 3738->3740 3751 d49ac0-d49ac9 3739->3751 3744 d49a43-d49a4a call d88375 3740->3744 3745 d49a2f-d49a3d 3740->3745 3741->3738 3742->3741 3744->3739 3745->3744 3751->3751 3752 d49acb-d49af7 call d1347e call d48c60 3751->3752 3757 d49b15-d49b22 3752->3757 3758 d49af9-d49b10 call d1347e 3752->3758 3760 d49b24-d49b39 3757->3760 3761 d49b59-d49b86 3757->3761 3758->3757 3762 d49b4f-d49b56 call d88375 3760->3762 3763 d49b3b-d49b49 3760->3763 3764 d49bbd-d49c2f call d1347e 3761->3764 3765 d49b88-d49b9d 3761->3765 3762->3761 3763->3762 3773 d49c30-d49c39 3764->3773 3768 d49bb3-d49bba call d88375 3765->3768 3769 d49b9f-d49bad 3765->3769 3768->3764 3769->3768 3773->3773 3775 d49c3b-d49c67 call d1347e call d48c60 3773->3775 3780 d49c85-d49c92 3775->3780 3781 d49c69-d49c80 call d1347e 3775->3781 3783 d49c94-d49ca9 3780->3783 3784 d49cc9-d49cf6 3780->3784 3781->3780 3787 d49cbf-d49cc6 call d88375 3783->3787 3788 d49cab-d49cb9 3783->3788 3785 d49d2d-d49d69 call d48f20 call d4a130 3784->3785 3786 d49cf8-d49d0d 3784->3786 3799 d49d72-d49dae call d48f60 call d4a130 3785->3799 3800 d49d6b-d49d6d 3785->3800 3789 d49d23-d49d2a call d88375 3786->3789 3790 d49d0f-d49d1d 3786->3790 3787->3784 3788->3787 3789->3785 3790->3789 3805 d49db7-d49df3 call d48ee0 call d4a130 3799->3805 3806 d49db0-d49db2 3799->3806 3800->3799 3811 d49df5-d49df7 3805->3811 3812 d49dfc-d49e38 call d49120 call d4a130 3805->3812 3806->3805 3811->3812 3817 d49e41-d49e7d call d49120 call d4a130 3812->3817 3818 d49e3a-d49e3c 3812->3818 3823 d49e86-d49ec2 call d490e0 call d4a130 3817->3823 3824 d49e7f-d49e81 3817->3824 3818->3817 3829 d49ec4-d49ec6 3823->3829 3830 d49ecb-d49f07 call d49160 call d4a130 3823->3830 3824->3823 3829->3830 3835 d49f10-d49f4c call d49060 call d4a130 3830->3835 3836 d49f09-d49f0b 3830->3836 3841 d49f55-d49f91 call d49060 call d4a130 3835->3841 3842 d49f4e-d49f50 3835->3842 3836->3835 3847 d49f93-d49f95 3841->3847 3848 d49f9a-d49fd6 call d49020 call d4a130 3841->3848 3842->3841 3847->3848 3853 d49fdf-d4a01b call d490a0 call d4a130 3848->3853 3854 d49fd8-d49fda 3848->3854 3859 d4a024-d4a060 call d48fa0 call d4a130 3853->3859 3860 d4a01d-d4a01f 3853->3860 3854->3853 3865 d4a062-d4a064 3859->3865 3866 d4a069-d4a091 call d48fe0 call d4a130 3859->3866 3860->3859 3865->3866 3870 d4a096-d4a0a5 3866->3870 3871 d4a0a7-d4a0a9 3870->3871 3872 d4a0ae-d4a0e3 call d48ea0 call d4a130 3870->3872 3871->3872 3877 d4a0e5-d4a0e7 3872->3877 3878 d4a0ec-d4a107 call d88367 3872->3878 3877->3878
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(kernel32,6EB998C3,?), ref: 00D4947B
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,IsWow64Process), ref: 00D4948B
                                                                                                                                                                              • GetCurrentProcess.KERNEL32(?), ref: 00D494A8
                                                                                                                                                                              • GetModuleFileNameW.KERNEL32(00000000,?,00000104,00000000,00DEA52C,00DEA52A), ref: 00D497C1
                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,00DEA52C,00DEA52A), ref: 00D497CB
                                                                                                                                                                              • GetLongPathNameW.KERNEL32(00000000,?,00000104), ref: 00D4987C
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D4989A
                                                                                                                                                                              Strings
                                                                                                                                                                              • kernel32, xrefs: 00D49472
                                                                                                                                                                              • IsWow64Process, xrefs: 00D49485
                                                                                                                                                                              • GetModuleFileName failed (%d), xrefs: 00D497D2
                                                                                                                                                                              • GetLongPathName failed (%d) for %s, xrefs: 00D498A2
                                                                                                                                                                              • NWebAdvisor::NXmlUpdater::CSubstitutionManager::GetExtractDir, xrefs: 00D497DC, 00D498AC
                                                                                                                                                                              • 1.1, xrefs: 00D49BCB
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\SubstitutionManager.cpp, xrefs: 00D497E1, 00D498B1
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLastModuleName$AddressCurrentFileHandleLongPathProcProcess
                                                                                                                                                                              • String ID: 1.1$GetLongPathName failed (%d) for %s$GetModuleFileName failed (%d)$IsWow64Process$NWebAdvisor::NXmlUpdater::CSubstitutionManager::GetExtractDir$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\SubstitutionManager.cpp$kernel32
                                                                                                                                                                              • API String ID: 891933594-2307011595
                                                                                                                                                                              • Opcode ID: 1913b1b9335a39ada88f7109550a863425fbea2f355f8a92a122d3e1e6e33f07
                                                                                                                                                                              • Instruction ID: 60d28dbbd59ff68c25393818500df5ec693706b3c40c1faa863351d828f9d2c9
                                                                                                                                                                              • Opcode Fuzzy Hash: 1913b1b9335a39ada88f7109550a863425fbea2f355f8a92a122d3e1e6e33f07
                                                                                                                                                                              • Instruction Fuzzy Hash: 88729AB0A002189FDB24DF68CC95B9EB7B5AF48314F1441DCE609AB291DB74AE84CF75

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 3881 d359aa-d35b7a call d36440 call d29180 3894 d35b7f-d35b81 3881->3894 3895 d35b7a call d29180 3881->3895 3896 d35b83-d35b8d 3894->3896 3897 d35bc4-d35be0 call d111f3 3894->3897 3895->3894 3898 d35b93-d35ba5 3896->3898 3899 d35c8d-d35ccd call d36440 3896->3899 3908 d35be6-d35c59 call d19bb0 call d19940 call d11b84 call d11be0 call d1b8a0 call d72bfd 3897->3908 3909 d35cfc-d35d06 3897->3909 3902 d35c83-d35c8a call d88375 3898->3902 3903 d35bab-d35bbf 3898->3903 3912 d35db3-d35dc0 3899->3912 3913 d35cd3-d35cd8 3899->3913 3902->3899 3903->3902 3908->3899 3995 d35c5b-d35c6d 3908->3995 3914 d35d3a-d35d67 call d36440 3909->3914 3915 d35d08-d35d1a 3909->3915 3920 d35dc2-d35dc7 3912->3920 3921 d35dc9-d35dce 3912->3921 3918 d35cda 3913->3918 3919 d35cdc-d35cf7 call d8a3a0 3913->3919 3929 d35d69-d35d73 call d2aad0 3914->3929 3930 d35d78-d35d82 3914->3930 3922 d35d30-d35d37 call d88375 3915->3922 3923 d35d1c-d35d2a 3915->3923 3918->3919 3941 d35e8e-d35e98 3919->3941 3927 d35dd1-d35de5 3920->3927 3921->3927 3922->3914 3923->3922 3933 d35e30-d35e32 3927->3933 3934 d35de7-d35dec 3927->3934 3929->3930 3930->3899 3940 d35d88-d35d94 3930->3940 3936 d35e64-d35e86 3933->3936 3937 d35e34-d35e62 call d88713 3933->3937 3942 d35df2-d35dfd call d88713 3934->3942 3943 d36085 Concurrency::cancel_current_task 3934->3943 3946 d35e8c 3936->3946 3937->3946 3940->3902 3947 d35d9a-d35dae 3940->3947 3948 d35ec6-d35eee call d29980 3941->3948 3949 d35e9a-d35ea6 3941->3949 3950 d3608a call d8d60f 3942->3950 3960 d35e03-d35e2e 3942->3960 3943->3950 3946->3941 3947->3902 3965 d35ef4-d35f34 call d36440 3948->3965 3966 d35f7f 3948->3966 3955 d35ea8-d35eb6 3949->3955 3956 d35ebc-d35ec3 call d88375 3949->3956 3963 d3608f-d360aa call d8d60f 3950->3963 3955->3950 3955->3956 3956->3948 3960->3946 3974 d360d8-d360fc call d367b0 3963->3974 3975 d360ac-d360b6 3963->3975 3982 d35f36-d35f40 call d2aad0 3965->3982 3983 d35f45-d35f4f 3965->3983 3972 d35f82-d35f93 GetModuleHandleW 3966->3972 3978 d35fd1 3972->3978 3979 d35f95-d35fa5 GetProcAddress 3972->3979 4002 d36144-d36149 3974->4002 4003 d360fe-d36106 3974->4003 3980 d360b8-d360c6 3975->3980 3981 d360ce-d360d5 call d88375 3975->3981 3984 d35fd3-d3605c call d36440 call d136db call d1372a * 3 call d88367 3978->3984 3979->3978 3987 d35fa7-d35fc5 GetCurrentProcess 3979->3987 3988 d361d4-d361d9 call d8d60f 3980->3988 3989 d360cc 3980->3989 3981->3974 3982->3983 3983->3972 3992 d35f51-d35f5d 3983->3992 3987->3978 4023 d35fc7-d35fcb 3987->4023 3989->3981 3998 d35f73-d35f7d call d88375 3992->3998 3999 d35f5f-d35f6d 3992->3999 3995->3902 4004 d35c6f-d35c7d 3995->4004 3998->3972 3999->3963 3999->3998 4005 d3614b-d36151 4002->4005 4006 d3618f-d36197 4002->4006 4010 d36108-d3610c 4003->4010 4011 d3613d 4003->4011 4004->3902 4015 d36153-d36157 4005->4015 4016 d36188 4005->4016 4012 d361c0-d361d3 4006->4012 4013 d36199-d361a2 4006->4013 4019 d3611b-d36120 4010->4019 4020 d3610e-d36115 SysFreeString 4010->4020 4011->4002 4021 d361b6-d361bd call d88375 4013->4021 4022 d361a4-d361b2 4013->4022 4024 d36166-d3616b 4015->4024 4025 d36159-d36160 SysFreeString 4015->4025 4016->4006 4027 d36132-d3613a call d88375 4019->4027 4028 d36122-d3612b call d8874c 4019->4028 4020->4019 4021->4012 4022->3988 4030 d361b4 4022->4030 4023->3978 4031 d35fcd-d35fcf 4023->4031 4033 d3617d-d36185 call d88375 4024->4033 4034 d3616d-d36176 call d8874c 4024->4034 4025->4024 4027->4011 4028->4027 4030->4021 4031->3984 4033->4016 4034->4033
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D36067
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D36085
                                                                                                                                                                              • SysFreeString.OLEAUT32 ref: 00D3610F
                                                                                                                                                                              • SysFreeString.OLEAUT32(00000000), ref: 00D3615A
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_taskFreeString
                                                                                                                                                                              • String ID: )$IsWow64Process$NO_REGKEY$UUID$UUID$kernel32$orm
                                                                                                                                                                              • API String ID: 3597043392-3766208032
                                                                                                                                                                              • Opcode ID: c233fac03831a64d0ae126c8197b3ed7b571a7364ee3c9962efb8e030b4935f0
                                                                                                                                                                              • Instruction ID: 0d596ed87477f5058f36988b9d28f2e2113a9ddebab6d8cac0721983521cf621
                                                                                                                                                                              • Opcode Fuzzy Hash: c233fac03831a64d0ae126c8197b3ed7b571a7364ee3c9962efb8e030b4935f0
                                                                                                                                                                              • Instruction Fuzzy Hash: 8EE1F4B0900744ABEB28EF68D84979DBBB5EF41304F24821CE445AB3D6DB74D984CB71

                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                              • Executed
                                                                                                                                                                              • Not Executed
                                                                                                                                                                              control_flow_graph 4050 d46560-d4658d 4051 d4658f-d46592 GlobalFree 4050->4051 4052 d46599-d4659e 4050->4052 4051->4052 4053 d465a0-d465a3 GlobalFree 4052->4053 4054 d465aa-d465af 4052->4054 4053->4054 4055 d465b1-d465b4 GlobalFree 4054->4055 4056 d465bb-d465c8 4054->4056 4055->4056 4058 d4668c 4056->4058 4059 d465ce-d465d3 4056->4059 4062 d4668e-d46693 4058->4062 4060 d466cd-d466d1 4059->4060 4061 d465d9-d465de 4059->4061 4067 d466d3-d466d7 4060->4067 4068 d466dd-d466ef 4060->4068 4063 d465e0-d465e3 GlobalFree 4061->4063 4064 d465ea-d465ec 4061->4064 4065 d46695-d46698 GlobalFree 4062->4065 4066 d4669f-d466a4 4062->4066 4063->4064 4069 d465ee-d465f0 4064->4069 4070 d4662b-d46633 4064->4070 4065->4066 4071 d466a6-d466a9 GlobalFree 4066->4071 4072 d466b0-d466b6 4066->4072 4067->4068 4073 d467d0-d467d2 4067->4073 4074 d466f1-d466fb 4068->4074 4075 d466fd-d46704 4068->4075 4077 d465f3-d465fc 4069->4077 4080 d46635-d46638 GlobalFree 4070->4080 4081 d4663f-d46641 4070->4081 4071->4072 4078 d466b8-d466b9 GlobalFree 4072->4078 4079 d466bb-d466cc call d88367 4072->4079 4073->4062 4076 d4670b-d4672a 4074->4076 4075->4076 4076->4058 4089 d46730-d4676b 4076->4089 4077->4077 4082 d465fe-d46618 GlobalAlloc 4077->4082 4078->4079 4080->4081 4081->4073 4084 d46647-d4664c 4081->4084 4082->4058 4086 d4661a-d46629 call d8d660 4082->4086 4088 d46650-d46659 4084->4088 4086->4058 4086->4070 4088->4088 4091 d4665b-d46675 GlobalAlloc 4088->4091 4098 d46794-d46798 4089->4098 4099 d4676d-d46779 4089->4099 4091->4058 4093 d46677-d46686 call d8d660 4091->4093 4093->4058 4093->4073 4102 d467ae-d467ba 4098->4102 4103 d4679a-d467a9 call d46a70 call d46af0 4098->4103 4100 d46781-d46786 4099->4100 4101 d4677b-d4677e GlobalFree 4099->4101 4100->4058 4106 d4678c-d4678f GlobalFree 4100->4106 4101->4100 4104 d467c6-d467cb 4102->4104 4105 d467bc-d467bf GlobalFree 4102->4105 4103->4102 4104->4073 4109 d467cd-d467ce GlobalFree 4104->4109 4105->4104 4106->4058 4109->4073
                                                                                                                                                                              APIs
                                                                                                                                                                              • GlobalFree.KERNEL32(00000000), ref: 00D46590
                                                                                                                                                                              • GlobalFree.KERNEL32(?), ref: 00D465A1
                                                                                                                                                                              • GlobalFree.KERNEL32(00000000), ref: 00D465B2
                                                                                                                                                                              • GlobalFree.KERNEL32(?), ref: 00D465E1
                                                                                                                                                                              • GlobalAlloc.KERNEL32(00000000,?), ref: 00D4660D
                                                                                                                                                                              • GlobalFree.KERNEL32(00000000), ref: 00D46636
                                                                                                                                                                              • GlobalAlloc.KERNEL32(00000000,?), ref: 00D4666A
                                                                                                                                                                              • GlobalFree.KERNEL32(?), ref: 00D46696
                                                                                                                                                                              • GlobalFree.KERNEL32(?), ref: 00D466A7
                                                                                                                                                                              • GlobalFree.KERNEL32(?), ref: 00D466B9
                                                                                                                                                                              • GlobalFree.KERNEL32(00000000), ref: 00D4677C
                                                                                                                                                                              • GlobalFree.KERNEL32(00000000), ref: 00D4678D
                                                                                                                                                                              • GlobalFree.KERNEL32(00000000), ref: 00D467BD
                                                                                                                                                                              • GlobalFree.KERNEL32(00000000), ref: 00D467CE
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Global$Free$Alloc
                                                                                                                                                                              • String ID: Temp$`aso
                                                                                                                                                                              • API String ID: 1780285237-798098371
                                                                                                                                                                              • Opcode ID: 4d1635fc6e33d6a4903154cd798875e792de9ce04a4e85d9bfc83bef0c8f0a23
                                                                                                                                                                              • Instruction ID: 0167c8c9909d368da8deebab2831d7b3192761e6ca981b173fb2c46cfd63848e
                                                                                                                                                                              • Opcode Fuzzy Hash: 4d1635fc6e33d6a4903154cd798875e792de9ce04a4e85d9bfc83bef0c8f0a23
                                                                                                                                                                              • Instruction Fuzzy Hash: 5B713BB0E002199BDF109FA5CC84BAEFBB8AF15704F198159EC06EB245EB75D944CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • OpenProcess.KERNEL32(00000400,00000000,?,6EB998C3,?,?), ref: 00D24257
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001,?,?), ref: 00D242BC
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D242F2
                                                                                                                                                                              • QueryFullProcessImageNameW.KERNEL32(00000000,00000000,00000000,?,00000104,00000000,?,?), ref: 00D24367
                                                                                                                                                                              • GetLastError.KERNEL32(?,?), ref: 00D24375
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2440A
                                                                                                                                                                              • CloseHandle.KERNEL32(00000000,?), ref: 00D2455B
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              Strings
                                                                                                                                                                              • Filename for process with id , xrefs: 00D244B0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$ErrorInitLastOnceProcess$BeginCloseCompleteFullHandleImageInitializeNameOpenQuery
                                                                                                                                                                              • String ID: Filename for process with id
                                                                                                                                                                              • API String ID: 563014942-4200337779
                                                                                                                                                                              • Opcode ID: cadf40db16a7ec742ac24a0037c007d897facd7fff32f19a82b7eac48af3e2f3
                                                                                                                                                                              • Instruction ID: fdca37ab88834b61fb6d884947d4b45a4c569232cb4e3f64bf463d82dc64f4fb
                                                                                                                                                                              • Opcode Fuzzy Hash: cadf40db16a7ec742ac24a0037c007d897facd7fff32f19a82b7eac48af3e2f3
                                                                                                                                                                              • Instruction Fuzzy Hash: 4DD190B0D103199BCB20DF64EC55BEDB7B4FF54314F104659E809A7281EB746A89CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DAFE25: CreateFileW.KERNEL32(00000000,00000000,?,00DB0187,?,?,00000000,?,00DB0187,00000000,0000000C), ref: 00DAFE42
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00DB01F2
                                                                                                                                                                              • __dosmaperr.LIBCMT ref: 00DB01F9
                                                                                                                                                                              • GetFileType.KERNEL32(00000000), ref: 00DB0205
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00DB020F
                                                                                                                                                                              • __dosmaperr.LIBCMT ref: 00DB0218
                                                                                                                                                                              • CloseHandle.KERNEL32(00000000), ref: 00DB0238
                                                                                                                                                                              • CloseHandle.KERNEL32(00000000), ref: 00DB0385
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00DB03B7
                                                                                                                                                                              • __dosmaperr.LIBCMT ref: 00DB03BE
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast__dosmaperr$CloseFileHandle$CreateType
                                                                                                                                                                              • String ID: H
                                                                                                                                                                              • API String ID: 4237864984-2852464175
                                                                                                                                                                              • Opcode ID: 9c737cb0e872b756fa2831bc009564179dc2744e1a4ef78e5d3e258a48842efb
                                                                                                                                                                              • Instruction ID: ad33edbe09fbe3fc674d16014194aae58790b84710fb5027f3dfe65fa0471f35
                                                                                                                                                                              • Opcode Fuzzy Hash: 9c737cb0e872b756fa2831bc009564179dc2744e1a4ef78e5d3e258a48842efb
                                                                                                                                                                              • Instruction Fuzzy Hash: 8FA12532A042458FCF199F68DC95BAE3FA1EB0A320F180159E812EB3D1DB359956CB71
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E4A1
                                                                                                                                                                                • Part of subcall function 00D2DE80: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2DF0C
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D2E3DE
                                                                                                                                                                                • Part of subcall function 00D2E0D0: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E161
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D2E4FB
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E665
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E6F8
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$InitMtx_unlockOnce$BeginCompleteInitialize
                                                                                                                                                                              • String ID: AdhocTelemetryAzure$Event string is empty$Querying AdhocTelemetryAzure value failed: $SOFTWARE\McAfee\WebAdvisor$]
                                                                                                                                                                              • API String ID: 1670716954-2879113573
                                                                                                                                                                              • Opcode ID: e65b910582a298b32499f5ca4f9d0b616271995974cda0c15ef8e649f3136a76
                                                                                                                                                                              • Instruction ID: e2a025c00a77a32ac6e41d08d5e21d58b39c4f0661ab75f6bace171d91290840
                                                                                                                                                                              • Opcode Fuzzy Hash: e65b910582a298b32499f5ca4f9d0b616271995974cda0c15ef8e649f3136a76
                                                                                                                                                                              • Instruction Fuzzy Hash: 0391E5719002689BDB10EF54ED51BEEF3B8EF65314F0041A9E809A7381EB706B48CEB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D36085
                                                                                                                                                                              • SysFreeString.OLEAUT32 ref: 00D3610F
                                                                                                                                                                              • SysFreeString.OLEAUT32(00000000), ref: 00D3615A
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FreeString$Concurrency::cancel_current_task
                                                                                                                                                                              • String ID: )$IsWow64Process$NO_REGKEY$UUID$UUID$kernel32$orm
                                                                                                                                                                              • API String ID: 2663709405-3766208032
                                                                                                                                                                              • Opcode ID: 09e48197a0aec57b15cd9a9cfa1b155b7eb7c57b882a7971ff453e48b0b547eb
                                                                                                                                                                              • Instruction ID: 876f5313cf1cf07c8b1dd79bcd96fb9acecb9fd40fdf51af0046a6c8c84bb878
                                                                                                                                                                              • Opcode Fuzzy Hash: 09e48197a0aec57b15cd9a9cfa1b155b7eb7c57b882a7971ff453e48b0b547eb
                                                                                                                                                                              • Instruction Fuzzy Hash: 05B1C1709047889BEF14EFA8D94879DBBB2EF45304F24425CE444AB3D6DBB49A84CB71
                                                                                                                                                                              APIs
                                                                                                                                                                              • __Mtx_init_in_situ.LIBCPMT ref: 00D2D1E6
                                                                                                                                                                                • Part of subcall function 00D1BBB0: std::locale::_Init.LIBCPMT ref: 00D1BBFC
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2D6C4
                                                                                                                                                                              Strings
                                                                                                                                                                              • AWS m_url_aws = , xrefs: 00D2D675
                                                                                                                                                                              • /messages?timeout=60&api-version=2014-01, xrefs: 00D2D368
                                                                                                                                                                              • u, xrefs: 00D2D666
                                                                                                                                                                              • .servicebus.windows.net/, xrefs: 00D2D348
                                                                                                                                                                              • Content-Type: application/atom+xml;type=entry;charset=utf-8, xrefs: 00D2CF5D
                                                                                                                                                                              • https://, xrefs: 00D2D334
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitIos_base_dtorMtx_init_in_situstd::ios_base::_std::locale::_
                                                                                                                                                                              • String ID: .servicebus.windows.net/$/messages?timeout=60&api-version=2014-01$AWS m_url_aws = $Content-Type: application/atom+xml;type=entry;charset=utf-8$https://$u
                                                                                                                                                                              • API String ID: 655687434-3999228595
                                                                                                                                                                              • Opcode ID: 3fa9f3226a6ea7cb6af7872ad0f23e4fca586ce788859a74fee4b22c6cc2ca44
                                                                                                                                                                              • Instruction ID: 25d1dbd471c92556e30a85e7f991a7ccaa15da6e052c6e5b530816ce15be2d2e
                                                                                                                                                                              • Opcode Fuzzy Hash: 3fa9f3226a6ea7cb6af7872ad0f23e4fca586ce788859a74fee4b22c6cc2ca44
                                                                                                                                                                              • Instruction Fuzzy Hash: C142BE709007958FDB14DF28DD45BA9B7B1FF54308F1086A9E448AB692EB70AAC4CF60
                                                                                                                                                                              APIs
                                                                                                                                                                              • WTSGetActiveConsoleSessionId.KERNEL32(0000003C,?), ref: 00D23E00
                                                                                                                                                                              • OutputDebugStringW.KERNEL32(WTSQuerySessionInformation failed to retrieve current user name for the log name.), ref: 00D23F9C
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D23FCA
                                                                                                                                                                              Strings
                                                                                                                                                                              • WTSQuerySessionInformation failed to retrieve current user name for the log name., xrefs: 00D23F97
                                                                                                                                                                              • Error retrieving session id for generating log name., xrefs: 00D23E0B
                                                                                                                                                                              • WTSQuerySessionInformation failed to retrieve the size of the current user name for the log name., xrefs: 00D23F81
                                                                                                                                                                              • UNKNOWN, xrefs: 00D23DD2
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ActiveConcurrency::cancel_current_taskConsoleDebugOutputSessionString
                                                                                                                                                                              • String ID: Error retrieving session id for generating log name.$UNKNOWN$WTSQuerySessionInformation failed to retrieve current user name for the log name.$WTSQuerySessionInformation failed to retrieve the size of the current user name for the log name.
                                                                                                                                                                              • API String ID: 1186403813-1860316991
                                                                                                                                                                              • Opcode ID: 62411fa6d0c581de41c1a4c50c3b830a579c974241afc71ad08576da60f6f6fe
                                                                                                                                                                              • Instruction ID: a6c1e0f3b7c9c8b401593d1cf580449a83c09bd94017acb80a8060486d6f600d
                                                                                                                                                                              • Opcode Fuzzy Hash: 62411fa6d0c581de41c1a4c50c3b830a579c974241afc71ad08576da60f6f6fe
                                                                                                                                                                              • Instruction Fuzzy Hash: 7C51D370E003259FDB149F78EC85AAEBBB4FF54314F240629F426D6291D7789A44CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(00000000,00000000,00D34AA5,00D34AA7,00000000,00000000,6EB998C3,?,00000000,?,00D8BE00,00DFBF08,000000FE,?,00D34AA5,?), ref: 00D89989
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(00000000,00000000,00D34AA5,?,00000000,00000000,?,00D8BE00,00DFBF08,000000FE,?,00D34AA5), ref: 00D89A04
                                                                                                                                                                              • SysAllocString.OLEAUT32(00000000), ref: 00D89A0F
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D89A38
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D89A42
                                                                                                                                                                              • GetLastError.KERNEL32(80070057,6EB998C3,?,00000000,?,00D8BE00,00DFBF08,000000FE,?,00D34AA5,?), ref: 00D89A47
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D89A5A
                                                                                                                                                                              • GetLastError.KERNEL32(00000000,?,00000000,?,00D8BE00,00DFBF08,000000FE,?,00D34AA5,?), ref: 00D89A70
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D89A83
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _com_issue_error$ByteCharErrorLastMultiWide$AllocString
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1353541977-0
                                                                                                                                                                              • Opcode ID: 3a231ee3dbf10713476f285b19f03c0d931c0a27fe8f82622351a3142220d93a
                                                                                                                                                                              • Instruction ID: 8b7af6fd8659787e9db9fa08999cfdc24dc3b74b170407dd23e046798702bd74
                                                                                                                                                                              • Opcode Fuzzy Hash: 3a231ee3dbf10713476f285b19f03c0d931c0a27fe8f82622351a3142220d93a
                                                                                                                                                                              • Instruction Fuzzy Hash: 1441B3B1A00206AFD714AF65DC55BBEFBA8EF45710F18422AF546E7291DB349800CBB4
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D1E310: ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA),00000001,00000000,00000000), ref: 00D1E36C
                                                                                                                                                                              • __Mtx_init_in_situ.LIBCPMT ref: 00D19DD4
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D1A06D
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: DescriptorSecurity$Concurrency::cancel_current_taskConvertMtx_init_in_situString
                                                                                                                                                                              • String ID: LogLevel$LogRotationCount$LogRotationFileSize$SOFTWARE\McAfee\WebAdvisor$log
                                                                                                                                                                              • API String ID: 239504998-2017128786
                                                                                                                                                                              • Opcode ID: e73114961653aa857584f1fc9e4b27d65610717cc301a1bdd90e5f4e246daf04
                                                                                                                                                                              • Instruction ID: 84aac568b7f35244ca805b990909b7b9d607eff1b3cc414d2239266d3d0e9681
                                                                                                                                                                              • Opcode Fuzzy Hash: e73114961653aa857584f1fc9e4b27d65610717cc301a1bdd90e5f4e246daf04
                                                                                                                                                                              • Instruction Fuzzy Hash: 83C1BC71D01249AFDB04DFA8D951BEEFBF0EF48304F244119E405A7291EB75AA88CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • __Mtx_init_in_situ.LIBCPMT ref: 00D26D7B
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D26F75
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D26F88
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorMtx_init_in_situMtx_unlockstd::ios_base::_
                                                                                                                                                                              • String ID: event sender$=$Failed to initialize $async
                                                                                                                                                                              • API String ID: 3676452600-816272291
                                                                                                                                                                              • Opcode ID: 2f83e24cd5ee2922fee3dccad664924b4563f3de6fd7b8436434588e8150da81
                                                                                                                                                                              • Instruction ID: f2d0aa0fd4b4f8471862e8048e775a91821557d6764932c68403cd5db764051d
                                                                                                                                                                              • Opcode Fuzzy Hash: 2f83e24cd5ee2922fee3dccad664924b4563f3de6fd7b8436434588e8150da81
                                                                                                                                                                              • Instruction Fuzzy Hash: C161C1B0A003559FDB00EF60E865BEEBBB5EF54304F544099E805AB382DB749A48CFB1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D28FB0: CoCreateGuid.OLE32(?), ref: 00D28FC8
                                                                                                                                                                                • Part of subcall function 00D28FB0: StringFromCLSID.OLE32(?,?), ref: 00D28FE0
                                                                                                                                                                                • Part of subcall function 00D28FB0: CoTaskMemFree.OLE32(?), ref: 00D29138
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D293D1
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitIos_base_dtorOncestd::ios_base::_$BeginCompleteCreateFreeFromGuidInitializeStringTask
                                                                                                                                                                              • String ID: Could not set registry value $Could not set registry value InstallerFlags$Failed to create new UUID$InstallerFlags$UUID$]
                                                                                                                                                                              • API String ID: 598746661-2174109026
                                                                                                                                                                              • Opcode ID: 8d6ae10652c6ddb168ab83e2613990738630a3186ef9a25ec7871a92447cf07d
                                                                                                                                                                              • Instruction ID: 44974f86baf69e54e0ae8ad5930cfece36b00b1e2019a358db3e0d9448924e39
                                                                                                                                                                              • Opcode Fuzzy Hash: 8d6ae10652c6ddb168ab83e2613990738630a3186ef9a25ec7871a92447cf07d
                                                                                                                                                                              • Instruction Fuzzy Hash: 7B51C270A10258EEDF14EF60E9A1BEDB374EF65304F508059E80957281EF74AA89CFB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,NotComDllGetInterface), ref: 00D25808
                                                                                                                                                                              • FreeLibrary.KERNEL32(?), ref: 00D25828
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D25830
                                                                                                                                                                              • FreeLibrary.KERNEL32(?), ref: 00D25839
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FreeLibrary$AddressErrorLastProc
                                                                                                                                                                              • String ID: NotComDllGetInterface$mfeaaca.dll
                                                                                                                                                                              • API String ID: 1092183831-2777911605
                                                                                                                                                                              • Opcode ID: 0c826dc3ae46cf3b2e7a14dfa2dae70ebe9322f8ba8504bd5c213258abcd8850
                                                                                                                                                                              • Instruction ID: 3c74e8c256ff0848d2638ef13c99eeca0922cee1b776516583210b3916d03adc
                                                                                                                                                                              • Opcode Fuzzy Hash: 0c826dc3ae46cf3b2e7a14dfa2dae70ebe9322f8ba8504bd5c213258abcd8850
                                                                                                                                                                              • Instruction Fuzzy Hash: D421C772D0072A9BDB116B69F844A7EB7B4FB65355F450165EC01E3354DB708D009BF1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D14C8E: GetCurrentProcessId.KERNEL32 ref: 00D14CA6
                                                                                                                                                                                • Part of subcall function 00D14C8E: CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 00D14CB8
                                                                                                                                                                                • Part of subcall function 00D14C8E: Process32FirstW.KERNEL32(00000000,?), ref: 00D14CD3
                                                                                                                                                                                • Part of subcall function 00D14C8E: Process32NextW.KERNEL32(00000000,0000022C), ref: 00D14CE9
                                                                                                                                                                                • Part of subcall function 00D14C8E: CloseHandle.KERNEL32(00000000), ref: 00D14CFA
                                                                                                                                                                              • CreateMutexW.KERNEL32(00000000,00000000,Global\{48ca68e-e4ff-43ac-a993-6d162f33de7c}), ref: 00D14D88
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D14DD0
                                                                                                                                                                                • Part of subcall function 00D1136C: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D113A5
                                                                                                                                                                              • WaitForSingleObject.KERNEL32(00000000,0000EA60), ref: 00D14DFC
                                                                                                                                                                              • CloseHandle.KERNEL32 ref: 00D14E0D
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              Strings
                                                                                                                                                                              • Global\{48ca68e-e4ff-43ac-a993-6d162f33de7c}, xrefs: 00D14D7F
                                                                                                                                                                              • SaBsi.cpp, xrefs: 00D14DA9
                                                                                                                                                                              • CreateMutex failed: , xrefs: 00D14DC2
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CloseCreateHandleInitIos_base_dtorOnceProcess32std::ios_base::_$BeginCompleteCurrentErrorFirstInitializeLastMutexNextObjectProcessSingleSnapshotToolhelp32Wait
                                                                                                                                                                              • String ID: CreateMutex failed: $Global\{48ca68e-e4ff-43ac-a993-6d162f33de7c}$SaBsi.cpp
                                                                                                                                                                              • API String ID: 2598072538-1117126455
                                                                                                                                                                              • Opcode ID: 7d53b757f5b54c9a1e2b66128cb417c3bee6c3be15f0ab84d27b37e28fdcd9d0
                                                                                                                                                                              • Instruction ID: fdda144427c494b87e62d6f5bb37c7f032fef5de38b831a0e6cc57fb8cedb481
                                                                                                                                                                              • Opcode Fuzzy Hash: 7d53b757f5b54c9a1e2b66128cb417c3bee6c3be15f0ab84d27b37e28fdcd9d0
                                                                                                                                                                              • Instruction Fuzzy Hash: 29118F70258343BBD720EF24E855BEA77A4FF50710F14491CB49187291EF74A498CA72
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D2CCB0: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2CDBB
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D2F0FC
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2F268
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2F307
                                                                                                                                                                              Strings
                                                                                                                                                                              • SOFTWARE\McAfee\WebAdvisor, xrefs: 00D2F181
                                                                                                                                                                              • AdhocTelemetryAWS, xrefs: 00D2F1B6
                                                                                                                                                                              • Querying AdhocTelemetryAWS value failed: , xrefs: 00D2F217
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$Concurrency::cancel_current_task
                                                                                                                                                                              • String ID: AdhocTelemetryAWS$Querying AdhocTelemetryAWS value failed: $SOFTWARE\McAfee\WebAdvisor
                                                                                                                                                                              • API String ID: 1722207485-3297656441
                                                                                                                                                                              • Opcode ID: 3c39f1b7a1077187e13f023e99b09e9d6e46a823fc23f4e9aadc58149aad436c
                                                                                                                                                                              • Instruction ID: 63fff426c1057d3d0637034a8114ec4461f7cfb5b766954689e2f6cc2304cefd
                                                                                                                                                                              • Opcode Fuzzy Hash: 3c39f1b7a1077187e13f023e99b09e9d6e46a823fc23f4e9aadc58149aad436c
                                                                                                                                                                              • Instruction Fuzzy Hash: DFC1D170D002689FCB14EF68DD45BEEB7B4EF14314F1042A9E415A7281EF70AA85CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E161
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001), ref: 00D2E278
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E351
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              Strings
                                                                                                                                                                              • Event Sender already initialized for AWS, xrefs: 00D2E137
                                                                                                                                                                              • WinHttpCrackUrl failed for AWS: , xrefs: 00D2E268
                                                                                                                                                                              • Unable to open HTTP session for AWS, xrefs: 00D2E327
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$InitOnce$BeginCompleteErrorInitializeLast
                                                                                                                                                                              • String ID: Event Sender already initialized for AWS$Unable to open HTTP session for AWS$WinHttpCrackUrl failed for AWS:
                                                                                                                                                                              • API String ID: 2211357200-794796586
                                                                                                                                                                              • Opcode ID: 6f0eac3c02cfca3f19a47156b44570e16c75863cb436f30e1cb8d88fb7c74b97
                                                                                                                                                                              • Instruction ID: d182edd1978aed8e8e447e1cc55f44d9bc0b39603037481f2ccce133f5291aa9
                                                                                                                                                                              • Opcode Fuzzy Hash: 6f0eac3c02cfca3f19a47156b44570e16c75863cb436f30e1cb8d88fb7c74b97
                                                                                                                                                                              • Instruction Fuzzy Hash: 5F618D709007199ADB20DF60ED55BEAB7B8FF54305F00056DE51AA7380EB706A88CFB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2DF0C
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001), ref: 00D2DFD7
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E0A2
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              Strings
                                                                                                                                                                              • Event Sender already initialized for Azure, xrefs: 00D2DEE2
                                                                                                                                                                              • Unable to open HTTP session for Azure, xrefs: 00D2E078
                                                                                                                                                                              • WinHttpCrackUrl failed for Azure: , xrefs: 00D2DFC7
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$InitOnce$BeginCompleteErrorInitializeLast
                                                                                                                                                                              • String ID: Event Sender already initialized for Azure$Unable to open HTTP session for Azure$WinHttpCrackUrl failed for Azure:
                                                                                                                                                                              • API String ID: 2211357200-3864554942
                                                                                                                                                                              • Opcode ID: 2e1a928b82454703d75e21c2fa97d504364b20a968960a6dbf5416b6b2b20974
                                                                                                                                                                              • Instruction ID: da6fc6159fc8476c3d96fceda067bfa6fe32d2aec0654a051871daa81ca10471
                                                                                                                                                                              • Opcode Fuzzy Hash: 2e1a928b82454703d75e21c2fa97d504364b20a968960a6dbf5416b6b2b20974
                                                                                                                                                                              • Instruction Fuzzy Hash: 9B517C709043599FDB20EF60D955BEEB3B8FB14304F00459DE44AA7380EBB4AA88CB71
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3_GS.LIBCMT ref: 00D15A59
                                                                                                                                                                                • Part of subcall function 00D15C1E: CoCreateInstance.OLE32(00DDD808,00000000,00000017,00DEB024,00000000,6EB998C3,?,?,?,00000000,00000000,00000000,00DB8687,000000FF), ref: 00D15C7A
                                                                                                                                                                                • Part of subcall function 00D15C1E: OleRun.OLE32(00000000), ref: 00D15C89
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D15B97
                                                                                                                                                                              Strings
                                                                                                                                                                              • Activation option is set successfuly, xrefs: 00D15B69
                                                                                                                                                                              • i, xrefs: 00D15B5D
                                                                                                                                                                              • Failed to set new option. Error , xrefs: 00D15B26
                                                                                                                                                                              • Failed to create Global Options object. Error , xrefs: 00D15AA9
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitOnce$BeginCompleteCreateH_prolog3_InitializeInstanceIos_base_dtor_com_issue_errorstd::ios_base::_
                                                                                                                                                                              • String ID: Activation option is set successfuly$Failed to create Global Options object. Error $Failed to set new option. Error $i
                                                                                                                                                                              • API String ID: 1362393928-3233122435
                                                                                                                                                                              • Opcode ID: 889489cf83ac1fa7fad88946a9ebc0c1b5a2674f7b408cd09f0d2b839398316b
                                                                                                                                                                              • Instruction ID: d67ac6f1971a5be67a16f019971d3b448d4df8754ec1c32fae3d1f26c692a787
                                                                                                                                                                              • Opcode Fuzzy Hash: 889489cf83ac1fa7fad88946a9ebc0c1b5a2674f7b408cd09f0d2b839398316b
                                                                                                                                                                              • Instruction Fuzzy Hash: E8315C70A1521AEADF04FBA4ED62BEDB374FF50300F404598A505A7285EF746A85CFB2
                                                                                                                                                                              APIs
                                                                                                                                                                              • __allrem.LIBCMT ref: 00D92461
                                                                                                                                                                              • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00D9247D
                                                                                                                                                                              • __allrem.LIBCMT ref: 00D92494
                                                                                                                                                                              • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00D924B2
                                                                                                                                                                              • __allrem.LIBCMT ref: 00D924C9
                                                                                                                                                                              • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00D924E7
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1992179935-0
                                                                                                                                                                              • Opcode ID: f87d5442f0ebf9ebcbd6879315b9098c2ef1ccdfcdcf202bff3e40a4258d3857
                                                                                                                                                                              • Instruction ID: 8679319990967774ed149ca803739c77f6eb126f7a0444d8e0f4b101844372a9
                                                                                                                                                                              • Opcode Fuzzy Hash: f87d5442f0ebf9ebcbd6879315b9098c2ef1ccdfcdcf202bff3e40a4258d3857
                                                                                                                                                                              • Instruction Fuzzy Hash: 6B81F671600706BBEB24AF69CC82B7AB3EAEF55720F28452EF455D62C1E774DA018770
                                                                                                                                                                              APIs
                                                                                                                                                                              • __Mtx_destroy_in_situ.LIBCPMT ref: 00D2085F
                                                                                                                                                                              • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA),00000001,?,00000000), ref: 00D20903
                                                                                                                                                                              • LocalFree.KERNEL32(?,?), ref: 00D20A26
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D21020
                                                                                                                                                                              Strings
                                                                                                                                                                              • D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA), xrefs: 00D208FE
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: DescriptorSecurity$ConvertFreeLocalMtx_destroy_in_situMtx_unlockString
                                                                                                                                                                              • String ID: D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA)
                                                                                                                                                                              • API String ID: 4147401711-3078421892
                                                                                                                                                                              • Opcode ID: 2735024431ce095e81d450ea05da143dff3cbb5725dfe26e1a9fddf52a6c578a
                                                                                                                                                                              • Instruction ID: 05c783b20dc00fb5cc9529a2ddc191711c578ffe2ccb41ee1850ece44f1d810e
                                                                                                                                                                              • Opcode Fuzzy Hash: 2735024431ce095e81d450ea05da143dff3cbb5725dfe26e1a9fddf52a6c578a
                                                                                                                                                                              • Instruction Fuzzy Hash: 4D6103719002648FDB14DF68DC89BDEBBB5EF54308F04416DE44A97792DB74AA84CBA0
                                                                                                                                                                              APIs
                                                                                                                                                                              Strings
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\XMLParser.cpp, xrefs: 00D4E5AF, 00D4E6C8
                                                                                                                                                                              • NWebAdvisor::XMLParser::ParseBuffer, xrefs: 00D4E5AA, 00D4E6C3
                                                                                                                                                                              • Unable to convert XML buffer into wide characters, xrefs: 00D4E6BC
                                                                                                                                                                              • invalid input, xrefs: 00D4E5A3
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: __cftoe
                                                                                                                                                                              • String ID: NWebAdvisor::XMLParser::ParseBuffer$Unable to convert XML buffer into wide characters$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\XMLParser.cpp$invalid input
                                                                                                                                                                              • API String ID: 4189289331-3914853187
                                                                                                                                                                              • Opcode ID: 8f8aeaaef50ae05b5623699cbe739df7ea487ccc6ce533767e90f7041ff4f901
                                                                                                                                                                              • Instruction ID: 7a79b142f12c6df8fcff1d8e8afe94737c422bb2e4b03dba34b3767b0b9419d4
                                                                                                                                                                              • Opcode Fuzzy Hash: 8f8aeaaef50ae05b5623699cbe739df7ea487ccc6ce533767e90f7041ff4f901
                                                                                                                                                                              • Instruction Fuzzy Hash: AE4190B1A01304AFC724EF64D842BAEF7A4FF14700F45456EE84AA7381DBB4A904D7B4
                                                                                                                                                                              APIs
                                                                                                                                                                              • __Xtime_get_ticks.LIBCPMT ref: 00D17FAA
                                                                                                                                                                              • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00D17FBC
                                                                                                                                                                              • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00D17FD0
                                                                                                                                                                              • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00D17FE2
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Unothrow_t@std@@@__ehfuncinfo$??2@$Xtime_get_ticks
                                                                                                                                                                              • String ID: [%Y%m%d %H:%M:%S.
                                                                                                                                                                              • API String ID: 3638035285-2843400524
                                                                                                                                                                              • Opcode ID: f2f0a4116f02553a6bf6b2e8ea444972e7ae7d9bc14651e313b1ebde2dedb6b4
                                                                                                                                                                              • Instruction ID: 2824a51b2c5ab855617a03409f3739358c57510f89e9bde2688c059a17ed7468
                                                                                                                                                                              • Opcode Fuzzy Hash: f2f0a4116f02553a6bf6b2e8ea444972e7ae7d9bc14651e313b1ebde2dedb6b4
                                                                                                                                                                              • Instruction Fuzzy Hash: 71318171E00218AFDB11EBA49C82FAEB7B9EF45710F114129F505AB281EF74A905C7B4
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2CDBB
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitIos_base_dtorOncestd::ios_base::_$BeginCompleteInitialize
                                                                                                                                                                              • String ID: 5$AdhocAWSQAMode$Querying AdhocAWSQAMode value failed: $SOFTWARE\McAfee\WebAdvisor
                                                                                                                                                                              • API String ID: 539357862-4010608570
                                                                                                                                                                              • Opcode ID: 583974a162b718fbdf4fb3ac8f6d73f4ea621da1cc95a841664b80a3b1be3158
                                                                                                                                                                              • Instruction ID: ab9f8c1c97e5832d5d0f454f3d56ca8eb689b7655326a04bd48c35cc36b0a43f
                                                                                                                                                                              • Opcode Fuzzy Hash: 583974a162b718fbdf4fb3ac8f6d73f4ea621da1cc95a841664b80a3b1be3158
                                                                                                                                                                              • Instruction Fuzzy Hash: 3331AB719102599EDB10EFA4D892BEEB7B8FF18300F504569E406B3281EF746A48CF71
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D35182
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D3521E
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_taskIos_base_dtorstd::ios_base::_
                                                                                                                                                                              • String ID: Invalid arguements passed to AddDimension$N
                                                                                                                                                                              • API String ID: 4106036149-286115907
                                                                                                                                                                              • Opcode ID: 83f9e4bceecd9adf7e6e741f4ebaf3673e47b461f5fd0d9b5f7ff07c37a9e4c9
                                                                                                                                                                              • Instruction ID: 985d8dc4aae9dc7289937581ba449d3a45832f5d3cfa1762409dbfe9b2c2795b
                                                                                                                                                                              • Opcode Fuzzy Hash: 83f9e4bceecd9adf7e6e741f4ebaf3673e47b461f5fd0d9b5f7ff07c37a9e4c9
                                                                                                                                                                              • Instruction Fuzzy Hash: 7D32C171D003589FDB24DF64C844B9EBBF1FF45304F1882A9E459AB291DB75A984CFA0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: %s%s$%s\%s$\\?\
                                                                                                                                                                              • API String ID: 0-2843747179
                                                                                                                                                                              • Opcode ID: e7ecf9114e6f2dac05f62eb68d4ea9e0906a1b1db9f55e6ca7b95414b35af4de
                                                                                                                                                                              • Instruction ID: 38caf2e710709c6be555ed378817351968046dee5bb3989262733d68563b548e
                                                                                                                                                                              • Opcode Fuzzy Hash: e7ecf9114e6f2dac05f62eb68d4ea9e0906a1b1db9f55e6ca7b95414b35af4de
                                                                                                                                                                              • Instruction Fuzzy Hash: ABD18071D00218DFDF10EFE4D885AEEB7B8EF09310F540529E916A7295EB34AA45CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • RegOpenKeyExW.KERNEL32(80000002,SOFTWARE\WATesting,00000000,00000001,?,6EB998C3,00000000,00000001), ref: 00D539FC
                                                                                                                                                                                • Part of subcall function 00D52820: RegQueryInfoKeyW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,?,00000000,00000000,6EB998C3,00000000,00000001,?), ref: 00D528AC
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InfoOpenQuery
                                                                                                                                                                              • String ID: SOFTWARE\WATesting$path
                                                                                                                                                                              • API String ID: 165108877-1550987622
                                                                                                                                                                              • Opcode ID: 333786ffa1788153b650cf046b9c92cefcf1837bc72a06408187860876fa2262
                                                                                                                                                                              • Instruction ID: 1e4aa62fdf4d89621edf1acbe83d0e24ec58a83b0f377231f07c8599ab9a112d
                                                                                                                                                                              • Opcode Fuzzy Hash: 333786ffa1788153b650cf046b9c92cefcf1837bc72a06408187860876fa2262
                                                                                                                                                                              • Instruction Fuzzy Hash: 8A517071D00258ABDF20DBA4DD45BDEBBB8EF14705F540199E909B7281DB74AA88CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetFileAttributesW.KERNEL32(?,00DEBFD0,00000000,00DEBFD0,00000000,?,0000001C,00000001,00000000,0000001C,?,?,00000014,00DEBFD0,00000000,6EB998C3), ref: 00D4FC1D
                                                                                                                                                                              Strings
                                                                                                                                                                              • Destination directory does not exist, xrefs: 00D4FC8F
                                                                                                                                                                              • NWebAdvisor::NHttp::NDownloadFile::StoreOnDisk, xrefs: 00D4FC99
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\HttpsDownloadFile.cpp, xrefs: 00D4FC9E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AttributesFile
                                                                                                                                                                              • String ID: Destination directory does not exist$NWebAdvisor::NHttp::NDownloadFile::StoreOnDisk$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\HttpsDownloadFile.cpp
                                                                                                                                                                              • API String ID: 3188754299-3555079292
                                                                                                                                                                              • Opcode ID: c483bdf28afd119f87b49650eae3312b433a7f3c85d791c5e53e17d063ae2d8a
                                                                                                                                                                              • Instruction ID: de9a6dfefcbeb33912d9c484990042a0e23080a063fe68771981a9fa1cb228e6
                                                                                                                                                                              • Opcode Fuzzy Hash: c483bdf28afd119f87b49650eae3312b433a7f3c85d791c5e53e17d063ae2d8a
                                                                                                                                                                              • Instruction Fuzzy Hash: D5211E75E0021CAFCB00DFA8D881ADEB7F4EF48710F154666FC45A3281DB70AA45DBA0
                                                                                                                                                                              Strings
                                                                                                                                                                              • D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA), xrefs: 00D1E367
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA)
                                                                                                                                                                              • API String ID: 0-3078421892
                                                                                                                                                                              • Opcode ID: 877616b2d3b5b958911c3c7824393221f4f6d83062ca7994d6475d16ae097ac4
                                                                                                                                                                              • Instruction ID: edd2cbfa72cd25deabefaee01bc9c821ee2c5d2381304594fe7b211c09b1f3d3
                                                                                                                                                                              • Opcode Fuzzy Hash: 877616b2d3b5b958911c3c7824393221f4f6d83062ca7994d6475d16ae097ac4
                                                                                                                                                                              • Instruction Fuzzy Hash: 4222E571A00248ABDB14DF68EC89BDDB7B6FF48304F10465DE409A7691DB74AAC4CBA0
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::locale::_Init.LIBCPMT ref: 00D4882F
                                                                                                                                                                              Strings
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\XmlUpdaterLogger.cpp, xrefs: 00D48AF6
                                                                                                                                                                              • Failed to create log message string. Error 0x, xrefs: 00D489CF
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Initstd::locale::_
                                                                                                                                                                              • String ID: Failed to create log message string. Error 0x$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\XmlUpdaterLogger.cpp
                                                                                                                                                                              • API String ID: 1620887387-1553574442
                                                                                                                                                                              • Opcode ID: 36660456c04f561b5725082b8f75ca8e0721329672f1ff360c48b94dca31582e
                                                                                                                                                                              • Instruction ID: 42c21882431c53b507c3248e859e13eb352d4d54d88eaea22432751ac6baa270
                                                                                                                                                                              • Opcode Fuzzy Hash: 36660456c04f561b5725082b8f75ca8e0721329672f1ff360c48b94dca31582e
                                                                                                                                                                              • Instruction Fuzzy Hash: 8CE14C70E00259DFDB24CF58C885B9EB7B1FF48304F14819AE909AB381DB75AA84DF61
                                                                                                                                                                              APIs
                                                                                                                                                                              • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA),00000001,00000000,00000000), ref: 00D1E36C
                                                                                                                                                                              Strings
                                                                                                                                                                              • D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA), xrefs: 00D1E367
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: DescriptorSecurity$ConvertString
                                                                                                                                                                              • String ID: D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA)
                                                                                                                                                                              • API String ID: 3907675253-3078421892
                                                                                                                                                                              • Opcode ID: 035713b45bca58ed9303fa22ce5e6d7ab021164375a0c0801d17bea8c9ed8eb2
                                                                                                                                                                              • Instruction ID: 2a0c3ceee63d03ca51b92884423f6830b5ef3790d962fa5a32cd0c72385c9d12
                                                                                                                                                                              • Opcode Fuzzy Hash: 035713b45bca58ed9303fa22ce5e6d7ab021164375a0c0801d17bea8c9ed8eb2
                                                                                                                                                                              • Instruction Fuzzy Hash: 8481A270901259ABDB24DF24DC88BDDB7B2EF85304F1446D9E408A7291EB79ABC4CF64
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001), ref: 00D3CCBB
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D3CCEC
                                                                                                                                                                              Strings
                                                                                                                                                                              • Unable to set proxy option, error: , xrefs: 00D3CCAB
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitIos_base_dtorOncestd::ios_base::_$BeginCompleteErrorInitializeLast
                                                                                                                                                                              • String ID: Unable to set proxy option, error:
                                                                                                                                                                              • API String ID: 879576418-14943890
                                                                                                                                                                              • Opcode ID: 747a65cc9ed103d57f8bad1a7b71a64c7b162623f632f10d0190264ca858dc04
                                                                                                                                                                              • Instruction ID: 04b7b5cfb2bfc8bdc40ca5611212e5675786dfdb2aad81f54a5ed2680f90f4a7
                                                                                                                                                                              • Opcode Fuzzy Hash: 747a65cc9ed103d57f8bad1a7b71a64c7b162623f632f10d0190264ca858dc04
                                                                                                                                                                              • Instruction Fuzzy Hash: B3315C71A04319EFEB24DF60DC45BEEB7B9FB04710F00856AE805A7291EB756A48CB71
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA576D: GetConsoleCP.KERNEL32(?,00D4860A,00000000), ref: 00DA57B5
                                                                                                                                                                              • WriteFile.KERNEL32(?,00000000,00DFC218,6EB998C3,00000000,6EB998C3,00D4860A,00D4860A,00D4860A,6EB998C3,00000000,?,00D9591E,00000000,00DFC218,00000010), ref: 00DA6129
                                                                                                                                                                              • GetLastError.KERNEL32(?,00D9591E,00000000,00DFC218,00000010,00D4860A), ref: 00DA6133
                                                                                                                                                                              • __dosmaperr.LIBCMT ref: 00DA6178
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ConsoleErrorFileLastWrite__dosmaperr
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 251514795-0
                                                                                                                                                                              • Opcode ID: 767d6c6ac228b6f6fc91ccfc58a0841d6c6238c4ee2bff81bf7d8d37a72f0b3c
                                                                                                                                                                              • Instruction ID: be020a2a1f0b95dfe2357ab64abfba7c838341e1a4e4fa542f40fa48f7fdd8c1
                                                                                                                                                                              • Opcode Fuzzy Hash: 767d6c6ac228b6f6fc91ccfc58a0841d6c6238c4ee2bff81bf7d8d37a72f0b3c
                                                                                                                                                                              • Instruction Fuzzy Hash: 49518071A0020AEFEB11AFA4CC85BEEBBB9EF0A354F1C0451E501A7296D675DD818B71
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetFileAttributesW.KERNEL32(00000000,6EB998C3,0000005C,?,?,?,?,00000000,00DB952D,000000FF,?,00D1E09D), ref: 00D1E681
                                                                                                                                                                              • CreateDirectoryW.KERNEL32(00000000,?,?,?,?,?,00000000,00DB952D,000000FF,?,00D1E09D), ref: 00D1E738
                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,00000000,00DB952D,000000FF,?,00D1E09D), ref: 00D1E742
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AttributesCreateDirectoryErrorFileLast
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 674977465-0
                                                                                                                                                                              • Opcode ID: c72252eee5622d8bfbc7abeb166e219638aebf90bf399f64b1d6fd91e3eac2aa
                                                                                                                                                                              • Instruction ID: b48597adb2861b34f8af73efb0e9ffc16c34dc4418ef6797bdc0d776c397a0f2
                                                                                                                                                                              • Opcode Fuzzy Hash: c72252eee5622d8bfbc7abeb166e219638aebf90bf399f64b1d6fd91e3eac2aa
                                                                                                                                                                              • Instruction Fuzzy Hash: 0D31E371A00205ABEB24DF68E985BEEB7F5FF45714F144A2DE80593780DB35A944CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • CertGetCertificateChain.CRYPT32(00000000,?,?,?), ref: 00D7206C
                                                                                                                                                                              • CertVerifyCertificateChainPolicy.CRYPT32(00000003,?,?,?), ref: 00D720A4
                                                                                                                                                                              • CertFreeCertificateChain.CRYPT32(?), ref: 00D720D0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CertCertificateChain$FreePolicyVerify
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1741975133-0
                                                                                                                                                                              • Opcode ID: e56adea299742189612a5ccb5a39e1ccaee16436c23f8fb86bef8cc4f5571636
                                                                                                                                                                              • Instruction ID: 2f92d4f0f9afe624ac20e88796f6f1cfd9878e4677633ef4a2959b79383f2799
                                                                                                                                                                              • Opcode Fuzzy Hash: e56adea299742189612a5ccb5a39e1ccaee16436c23f8fb86bef8cc4f5571636
                                                                                                                                                                              • Instruction Fuzzy Hash: B6417BB56083859BD720CF54C894BABBBE8FF89704F04491DF58897290E776E588CB72
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetEnvironmentStringsW.KERNEL32 ref: 00DAA699
                                                                                                                                                                              • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00DAA707
                                                                                                                                                                                • Part of subcall function 00DA98FF: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,?,00000000,00000000,00000000,?,00DA7B21,?,00000000,00000000), ref: 00DA99A1
                                                                                                                                                                                • Part of subcall function 00DA2174: RtlAllocateHeap.NTDLL(00000000,?,?,?,00D8872D,?,?,00D1A1ED,0000002C,6EB998C3), ref: 00DA21A6
                                                                                                                                                                              • _free.LIBCMT ref: 00DAA6F8
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: EnvironmentStrings$AllocateByteCharFreeHeapMultiWide_free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2560199156-0
                                                                                                                                                                              • Opcode ID: 4e5fcb244af9cd50ffabc07337092497b6d4e76b401f930055094db07f642396
                                                                                                                                                                              • Instruction ID: 05d12fe585cd1cebf8a36f9c680fc1430d4a8a6fb575ff3337af1c81d0958b77
                                                                                                                                                                              • Opcode Fuzzy Hash: 4e5fcb244af9cd50ffabc07337092497b6d4e76b401f930055094db07f642396
                                                                                                                                                                              • Instruction Fuzzy Hash: 20018FB3A027667B272116BE1CC9D7F6A6DDAC7BA031C0229F901D6241EB61CD02C5B2
                                                                                                                                                                              APIs
                                                                                                                                                                              • CloseHandle.KERNEL32(00000000,00000000,00D4860A,?,00DA6A9A,00D4860A,00DFC5B8,0000000C,00DA6B4C,00DFC218), ref: 00DA6BC2
                                                                                                                                                                              • GetLastError.KERNEL32(?,00DA6A9A,00D4860A,00DFC5B8,0000000C,00DA6B4C,00DFC218), ref: 00DA6BCC
                                                                                                                                                                              • __dosmaperr.LIBCMT ref: 00DA6BF7
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CloseErrorHandleLast__dosmaperr
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2583163307-0
                                                                                                                                                                              • Opcode ID: 2b15baed93805cc0a4028b62fa9d5560e324219c28b0216064839b516f1e89fa
                                                                                                                                                                              • Instruction ID: d102a93df3d94a090a561b3e0d44def56d225a9ef9a25047df5dc1a3356e02b9
                                                                                                                                                                              • Opcode Fuzzy Hash: 2b15baed93805cc0a4028b62fa9d5560e324219c28b0216064839b516f1e89fa
                                                                                                                                                                              • Instruction Fuzzy Hash: 5F012633A0A2609ED6256738AC45B7E6B49DF93734F2D0249F819CB1C2DB31DC84C2B1
                                                                                                                                                                              APIs
                                                                                                                                                                              • SetFilePointerEx.KERNEL32(00000000,00000000,?,00000000,00DAF765,00000008,00000000,?,?,?,00DA69A3,00000000,00000000,?,00DAF765), ref: 00DA692F
                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,00DA69A3,00000000,00000000,?,00DAF765,?,00DAF765,?,00000000,00000000,00000001,?,00000008), ref: 00DA6939
                                                                                                                                                                              • __dosmaperr.LIBCMT ref: 00DA6940
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorFileLastPointer__dosmaperr
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2336955059-0
                                                                                                                                                                              • Opcode ID: eedc9d13f6f8fdf5d5b963dd2547893ed50451f07641f029c08c80b395c3d0da
                                                                                                                                                                              • Instruction ID: 3d580bbd3d8430f26c0f53e5a1cf67646984e1db554e4d646df5b905a59d843c
                                                                                                                                                                              • Opcode Fuzzy Hash: eedc9d13f6f8fdf5d5b963dd2547893ed50451f07641f029c08c80b395c3d0da
                                                                                                                                                                              • Instruction Fuzzy Hash: 6601D872614615EFCB059F69DC4596E7B2AEB86320B3C0205F452D72D0EB71DD518B70
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA2174: RtlAllocateHeap.NTDLL(00000000,?,?,?,00D8872D,?,?,00D1A1ED,0000002C,6EB998C3), ref: 00DA21A6
                                                                                                                                                                              • _free.LIBCMT ref: 00DA3E42
                                                                                                                                                                              • _free.LIBCMT ref: 00DA3E68
                                                                                                                                                                                • Part of subcall function 00DA2098: RtlFreeHeap.NTDLL(00000000,00000000,?,00DAB729,?,00000000,?,?,?,00DAB9CC,?,00000007,?,?,00DABDD6,?), ref: 00DA20AE
                                                                                                                                                                                • Part of subcall function 00DA2098: GetLastError.KERNEL32(?,?,00DAB729,?,00000000,?,?,?,00DAB9CC,?,00000007,?,?,00DABDD6,?,?), ref: 00DA20C0
                                                                                                                                                                              • _free.LIBCMT ref: 00DA3E98
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _free$Heap$AllocateErrorFreeLast
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 4150789928-0
                                                                                                                                                                              • Opcode ID: e6cf5ad7ee28672ace70fb70d539d815d7db59d91254a1e098047906647d6ff3
                                                                                                                                                                              • Instruction ID: d155a85afb58029b2857784b5d9a9f414e99c6e4685a7e542f96a8d82e9a43cf
                                                                                                                                                                              • Opcode Fuzzy Hash: e6cf5ad7ee28672ace70fb70d539d815d7db59d91254a1e098047906647d6ff3
                                                                                                                                                                              • Instruction Fuzzy Hash: 03F0A97790413556CF26A238AC45AFF6765CF43750F144399F48572141DF61CF8597B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: 7d73ad5ecf27e67bc426223a133bc9bfbed940a94f33e1cd66ef821072daa8e2
                                                                                                                                                                              • Instruction ID: 951ab154b3068446290c99501566e1976b7a4fd01a42af9d34f9e993fe1884f7
                                                                                                                                                                              • Opcode Fuzzy Hash: 7d73ad5ecf27e67bc426223a133bc9bfbed940a94f33e1cd66ef821072daa8e2
                                                                                                                                                                              • Instruction Fuzzy Hash: 10B012822983017D360455049C03D3B021EC2C0B10330C11AF908C1283E6404C88A431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: a673d630df764dfaae2afd09d19b23958d6efcaf873ba7ed8f4acf6aebd1f02e
                                                                                                                                                                              • Instruction ID: c6d0af2127a32c08464728435e48fad7799b7ab8993b8dbeb858834fdee37a96
                                                                                                                                                                              • Opcode Fuzzy Hash: a673d630df764dfaae2afd09d19b23958d6efcaf873ba7ed8f4acf6aebd1f02e
                                                                                                                                                                              • Instruction Fuzzy Hash: ECB012822983017D32045504AD03D3B121EC2C0B10330C01AF608C1293E6404C456431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: 0e69be4c82dccc07f55ebb9ad2dce9beec760f97c2410272b32383de25665cab
                                                                                                                                                                              • Instruction ID: de00f7cfbed3115b8dda83a7509bb49e876589c467d5084ff52304ecf1fab29a
                                                                                                                                                                              • Opcode Fuzzy Hash: 0e69be4c82dccc07f55ebb9ad2dce9beec760f97c2410272b32383de25665cab
                                                                                                                                                                              • Instruction Fuzzy Hash: A1B012826A81007D31045504DC03E3B022EC2C0B20330C21BF509C1283E5404C449431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: 45cc48f0ebb9b84928048391dfe13c68bb1ec9ea42ce967bdc14bef250a6e90e
                                                                                                                                                                              • Instruction ID: 8a38a9b8eddbab59d227c182f5f92c5263419e4f923a4de2aea1aa9156d32d59
                                                                                                                                                                              • Opcode Fuzzy Hash: 45cc48f0ebb9b84928048391dfe13c68bb1ec9ea42ce967bdc14bef250a6e90e
                                                                                                                                                                              • Instruction Fuzzy Hash: 45B012826981007D32045504DD03D3B121FC2C0B20370C21AF609C1293E5404C455431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: c541baacb89e18a36ce66e577e2f3b3a3a7f9196f1c48fae5daac17d482f8102
                                                                                                                                                                              • Instruction ID: a0aa15057f9de91fcae45e165078a2a8827bf8b1fd89cbb8dba64558261c0dec
                                                                                                                                                                              • Opcode Fuzzy Hash: c541baacb89e18a36ce66e577e2f3b3a3a7f9196f1c48fae5daac17d482f8102
                                                                                                                                                                              • Instruction Fuzzy Hash: B3B01282398100BD360455049C03D3B022EC2C0B10330C01AF988C2283E5844C485431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: ac60b67af15efe5639d90ac78d371389a22c929ed1ce37d5170bac35cc33e5c0
                                                                                                                                                                              • Instruction ID: ac72b6364bad137f1f55ae9ae390b88ac8cec89010f6bae0c7c990c90a35624b
                                                                                                                                                                              • Opcode Fuzzy Hash: ac60b67af15efe5639d90ac78d371389a22c929ed1ce37d5170bac35cc33e5c0
                                                                                                                                                                              • Instruction Fuzzy Hash: FCB01282298200BD350455049C03D3B021EC2C0B10330C01AFA48C1283E5404C485431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: 8a32aae8d434c16928ac0b9a3229ab83491bc8269ecf769eaf8f548312b25503
                                                                                                                                                                              • Instruction ID: f97b45caac864f5150ee0ffd0c83013b0d1b42ab54bd7810f84d4cded2344d57
                                                                                                                                                                              • Opcode Fuzzy Hash: 8a32aae8d434c16928ac0b9a3229ab83491bc8269ecf769eaf8f548312b25503
                                                                                                                                                                              • Instruction Fuzzy Hash: 16B012822D82057D310455059C03E3B022EC2C0B10330C01AF508C1283E6404C44A531
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: 970168bee525a417ad876afdd3c2874b8181d221b5b399f9eeefe99e96377bcb
                                                                                                                                                                              • Instruction ID: 02aea795f4dc373027c71233d081fe8ca70029e0c331ced8133bb69624f5806e
                                                                                                                                                                              • Opcode Fuzzy Hash: 970168bee525a417ad876afdd3c2874b8181d221b5b399f9eeefe99e96377bcb
                                                                                                                                                                              • Instruction Fuzzy Hash: 1EB01282298201BD350455049C03D3B021EC2C0B10330C01AFA88C1283E6404C446431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: 7dddb9ca1cbac2de552b6d391c3b395578292f2bb4f45a8f3cfc878c703e632a
                                                                                                                                                                              • Instruction ID: 437e1f2592cb346adf6dd2f20a604a77f6c02e0df88213d2196fda8174bba864
                                                                                                                                                                              • Opcode Fuzzy Hash: 7dddb9ca1cbac2de552b6d391c3b395578292f2bb4f45a8f3cfc878c703e632a
                                                                                                                                                                              • Instruction Fuzzy Hash: 0DB012823982007D320455049C03D3B021EC2C0B10370C11AF948C1283E5844C885431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: a54fd2af8b004336f8cbec05af3f69125ca9672c9a8c98a346859233f1fb4048
                                                                                                                                                                              • Instruction ID: 37c7b6bf66906380d88983f4a76b04513fa76638969b47f2ebb4fbdd630bb20a
                                                                                                                                                                              • Opcode Fuzzy Hash: a54fd2af8b004336f8cbec05af3f69125ca9672c9a8c98a346859233f1fb4048
                                                                                                                                                                              • Instruction Fuzzy Hash: 52B012823981427D320415009D03C3B121EC2C0B14330C01AF644D0193E5844C455431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: b829fe4a3ce015514b2e80732b5f43692e73680035502d307547e2f916ce6f93
                                                                                                                                                                              • Instruction ID: 9e36045af99bee5a1c98f96033eeb68374c46067aa2f1dc3d899492076ab4ed5
                                                                                                                                                                              • Opcode Fuzzy Hash: b829fe4a3ce015514b2e80732b5f43692e73680035502d307547e2f916ce6f93
                                                                                                                                                                              • Instruction Fuzzy Hash: BDB012826982007D32045504DC07D3B021EC2C0B20330C21AF909C1283E5404C885431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: 0f3fa38b67463814afb6d56dc31fa7fde44f1b56700f37dbc58d85f766c6fb0f
                                                                                                                                                                              • Instruction ID: 51051667d2add25d970ade1bfc922b1938fae5a81982be7d6382efe64ba2bb04
                                                                                                                                                                              • Opcode Fuzzy Hash: 0f3fa38b67463814afb6d56dc31fa7fde44f1b56700f37dbc58d85f766c6fb0f
                                                                                                                                                                              • Instruction Fuzzy Hash: E2B012823981007E310455049C03E3B022EC2C0B10330C01AF548C1283E5844C489431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64D1C
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID: `aso
                                                                                                                                                                              • API String ID: 1269201914-2322128884
                                                                                                                                                                              • Opcode ID: e1c988cef349388426cbc6a54420da81496736cc62c50cbb2bdd31c074c43074
                                                                                                                                                                              • Instruction ID: 573cabb824d4b9a043198a4b130ad1e441e8f74409cb3544d470a6cf1e204448
                                                                                                                                                                              • Opcode Fuzzy Hash: e1c988cef349388426cbc6a54420da81496736cc62c50cbb2bdd31c074c43074
                                                                                                                                                                              • Instruction Fuzzy Hash: 8DB01282698100BD35045504DC03D3B031EC3C4B20330C11AF949C1383E5404C445431
                                                                                                                                                                              APIs
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D34AD2
                                                                                                                                                                              • SysFreeString.OLEAUT32(-00000001), ref: 00D34AFD
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FreeString_com_issue_error
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 709734423-0
                                                                                                                                                                              • Opcode ID: 8aa13e328022893340621de94196f2263a6a473181f99d3d955373d59a05c078
                                                                                                                                                                              • Instruction ID: 4be8bc1124127e95bd8d38d53c57dda9d1bbd6971643a48ab6e5107c8258f614
                                                                                                                                                                              • Opcode Fuzzy Hash: 8aa13e328022893340621de94196f2263a6a473181f99d3d955373d59a05c078
                                                                                                                                                                              • Instruction Fuzzy Hash: 712177B19017159BD7209F55DC05B5AF7E8EF41B60F24472EF86597680D7B8E840CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • WriteFile.KERNEL32(?,?,?,?,00000000,?,00D4860A,00000000,?,00DA610D,00D4860A,00D4860A,00000000,00DFC218,6EB998C3,00D4860A), ref: 00DA5C8C
                                                                                                                                                                              • GetLastError.KERNEL32(?,00DA610D,00D4860A,00D4860A,00000000,00DFC218,6EB998C3,00D4860A,00D4860A,00D4860A,6EB998C3,00000000,?,00D9591E,00000000,00DFC218), ref: 00DA5CB2
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorFileLastWrite
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 442123175-0
                                                                                                                                                                              • Opcode ID: 97c4bac0694f3bc2a9b21c157e6ade723fb16f9673a6d9b5d7dd390820221a50
                                                                                                                                                                              • Instruction ID: c1aa931c4fddd9a49c19ce7189ee2c0d8ddbd15d0ffadd6396d41470653935a7
                                                                                                                                                                              • Opcode Fuzzy Hash: 97c4bac0694f3bc2a9b21c157e6ade723fb16f9673a6d9b5d7dd390820221a50
                                                                                                                                                                              • Instruction Fuzzy Hash: 42217C70A002199FCF19CF29DC809E9B7FAEB59311B2440A9E946D7319D630DE82CB70
                                                                                                                                                                              APIs
                                                                                                                                                                              • InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                              • InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitOnce$BeginCompleteInitialize
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 51270584-0
                                                                                                                                                                              • Opcode ID: df8ed65ffe9c6089a79f0eb35c74257d741b23bcf13ebac80899b381f6ac9b7f
                                                                                                                                                                              • Instruction ID: 2678cbf18ea8b8213095f38264ba61270111018fe283b4eb75ce6b27dba56692
                                                                                                                                                                              • Opcode Fuzzy Hash: df8ed65ffe9c6089a79f0eb35c74257d741b23bcf13ebac80899b381f6ac9b7f
                                                                                                                                                                              • Instruction Fuzzy Hash: 8D018070A40749AFEB10EF949D16BAAB7B8EB04B04F140629B511A76C0DF745544CAA5
                                                                                                                                                                              APIs
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(00000000,00000000,00D34AA5,?,00000000,00000000,?,00D8BE00,00DFBF08,000000FE,?,00D34AA5), ref: 00D89A04
                                                                                                                                                                              • SysAllocString.OLEAUT32(00000000), ref: 00D89A0F
                                                                                                                                                                                • Part of subcall function 00D8E960: _free.LIBCMT ref: 00D8E973
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D89A38
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D89A42
                                                                                                                                                                              • GetLastError.KERNEL32(80070057,6EB998C3,?,00000000,?,00D8BE00,00DFBF08,000000FE,?,00D34AA5,?), ref: 00D89A47
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D89A5A
                                                                                                                                                                              • GetLastError.KERNEL32(00000000,?,00000000,?,00D8BE00,00DFBF08,000000FE,?,00D34AA5,?), ref: 00D89A70
                                                                                                                                                                              • _com_issue_error.COMSUPP ref: 00D89A83
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _com_issue_error$ErrorLast$AllocByteCharMultiStringWide_free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 878839965-0
                                                                                                                                                                              • Opcode ID: c32bca75ae052097b49147bd2ad835c22256dbc69cf7c19488995aee6abcf4b9
                                                                                                                                                                              • Instruction ID: 81d82f783b0392f9ec4e2ee22694699ea5c87176b64eba0677e6ded86af5db52
                                                                                                                                                                              • Opcode Fuzzy Hash: c32bca75ae052097b49147bd2ad835c22256dbc69cf7c19488995aee6abcf4b9
                                                                                                                                                                              • Instruction Fuzzy Hash: 5E01A271F052159BDB24AF949841BAEF7B4EF48B20F080129E901A7240CB315810CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 269201875-0
                                                                                                                                                                              • Opcode ID: 79ca71214ccee149ac043e6ba62a39454f96bbbce5fdcd9bd07afe74724be422
                                                                                                                                                                              • Instruction ID: 6b825d399f25e41b63a40f850c71e0125deb81f04afa9312b1c565c7c6114c01
                                                                                                                                                                              • Opcode Fuzzy Hash: 79ca71214ccee149ac043e6ba62a39454f96bbbce5fdcd9bd07afe74724be422
                                                                                                                                                                              • Instruction Fuzzy Hash: B3E02B2294692159EB31A73FBC0577A1786DF82730F150316F420961D0DF3088C6C9B1
                                                                                                                                                                              APIs
                                                                                                                                                                              • SHDeleteKeyW.SHLWAPI(?,00DEBFD0,?,00D3DE7B), ref: 00D3DED6
                                                                                                                                                                              • RegCloseKey.KERNEL32(?,?,00D3DE7B), ref: 00D3DEE4
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CloseDelete
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 453069226-0
                                                                                                                                                                              • Opcode ID: af4b394268b491743bb486272a65f1761359c2b36a348fe55d1f8b2558ec9174
                                                                                                                                                                              • Instruction ID: 9210b3b4980c099fbe6a35224dd1e8f217cdfd06769d8bf4acc1b2d8dd7c089a
                                                                                                                                                                              • Opcode Fuzzy Hash: af4b394268b491743bb486272a65f1761359c2b36a348fe55d1f8b2558ec9174
                                                                                                                                                                              • Instruction Fuzzy Hash: 8FE0EDB05047528ED7309B29F808B43BBD86B04710F08C84DA49AD6A50C3B8E8448F64
                                                                                                                                                                              APIs
                                                                                                                                                                              • SHGetSpecialFolderPathW.SHELL32(00000000,?,00000023,00000001,6EB998C3,?,?), ref: 00D1DF08
                                                                                                                                                                              • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA),00000001,00000000,00000000), ref: 00D1E36C
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: DescriptorSecurity$ConvertFolderPathSpecialString
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 4077199523-0
                                                                                                                                                                              • Opcode ID: e98a2f6fd2b9c6175f5e80cc08189b6b130804412434c0f41b055bc9dc6209c3
                                                                                                                                                                              • Instruction ID: 31d76440a5ea7bdec1c9e81f23243a17b5e53a041e421a55b2cd3bd87ea0da58
                                                                                                                                                                              • Opcode Fuzzy Hash: e98a2f6fd2b9c6175f5e80cc08189b6b130804412434c0f41b055bc9dc6209c3
                                                                                                                                                                              • Instruction Fuzzy Hash: 4AC10371900244ABCB28DF28EC897DDB7B2FF85304F14869DD80997691DB75AAC4CBA0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: 936a548fb05dc6954880368ab7170469812f8da341fce087c998b9590afc5aef
                                                                                                                                                                              • Instruction ID: 73b878c155587ab36141bbe6faaa263b1ec712e031ac60bbdd4f0f53743475a7
                                                                                                                                                                              • Opcode Fuzzy Hash: 936a548fb05dc6954880368ab7170469812f8da341fce087c998b9590afc5aef
                                                                                                                                                                              • Instruction Fuzzy Hash: C741A471A00104EFDF14DF58C881AAE7BA2EB8A364F2D8168F5499B391D772DD82D770
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: __wsopen_s
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3347428461-0
                                                                                                                                                                              • Opcode ID: f42dcb6ac8901057dbd10d9c621c04fbd3a702af6594d32fa9d4d6be6121df42
                                                                                                                                                                              • Instruction ID: ef702c9f1081959fb625d3b669be16c99e8b26f5181821f66c0f25f2c08bae2f
                                                                                                                                                                              • Opcode Fuzzy Hash: f42dcb6ac8901057dbd10d9c621c04fbd3a702af6594d32fa9d4d6be6121df42
                                                                                                                                                                              • Instruction Fuzzy Hash: 32111571A0420AAFCF09DF58E94199B7BF5EF49304F054069F809EB251D631EA11DBA5
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: 738b2551a80a8a8d4bf8db57af4b31d13eda5225752eac16fda81814e4d2ac91
                                                                                                                                                                              • Instruction ID: 97df92c259bf29f3f9169dace83d60548c8e7f0859d16026f371e7ead2edcf2f
                                                                                                                                                                              • Opcode Fuzzy Hash: 738b2551a80a8a8d4bf8db57af4b31d13eda5225752eac16fda81814e4d2ac91
                                                                                                                                                                              • Instruction Fuzzy Hash: ABF0FF32501A149ADF22362AAC05B6B3799DF43335F180735F861A79D2CB74D80687B1
                                                                                                                                                                              APIs
                                                                                                                                                                              • RegCreateKeyExW.KERNEL32(00000000,?,00000000,?,?,?,?,?,?), ref: 00D3DF45
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Create
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2289755597-0
                                                                                                                                                                              • Opcode ID: 41f03e9cb2901ade6802ffe6167be7ce225ea5ff1cacc1b576b3690f8e0770d3
                                                                                                                                                                              • Instruction ID: 1c86923cff27885acfac21c81d9dd02ef78c488f3f5b84d638d56dfd9af8b6e1
                                                                                                                                                                              • Opcode Fuzzy Hash: 41f03e9cb2901ade6802ffe6167be7ce225ea5ff1cacc1b576b3690f8e0770d3
                                                                                                                                                                              • Instruction Fuzzy Hash: FD015A75500209ABCB11CF45D844F9EBBBAEF98310F108059F80597350C770AA14DBA0
                                                                                                                                                                              APIs
                                                                                                                                                                              • PathFileExistsW.SHLWAPI(?), ref: 00D56061
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ExistsFilePath
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1174141254-0
                                                                                                                                                                              • Opcode ID: 6d65618fdcaa978be08effe6e36319bc718ce7df990a7bdeb6f84e80f369c803
                                                                                                                                                                              • Instruction ID: 8411ab73aff618434c905ea1c287941c453e13226b17be0dcc92453138dcddde
                                                                                                                                                                              • Opcode Fuzzy Hash: 6d65618fdcaa978be08effe6e36319bc718ce7df990a7bdeb6f84e80f369c803
                                                                                                                                                                              • Instruction Fuzzy Hash: E5F049712003009BCB24DF6DD818B6BB7EAEF88711F40851DE849CB760D775E945CBA0
                                                                                                                                                                              APIs
                                                                                                                                                                              • RtlAllocateHeap.NTDLL(00000000,?,?,?,00D8872D,?,?,00D1A1ED,0000002C,6EB998C3), ref: 00DA21A6
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AllocateHeap
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1279760036-0
                                                                                                                                                                              • Opcode ID: dbe661bdf3cb29a21604276d638e559e1ad05b207b2c114808dfde8b49c9538e
                                                                                                                                                                              • Instruction ID: fa566dda76d9b2fc7b48d661e56ce9f4991628e7593136078dd90cb4b7b995d9
                                                                                                                                                                              • Opcode Fuzzy Hash: dbe661bdf3cb29a21604276d638e559e1ad05b207b2c114808dfde8b49c9538e
                                                                                                                                                                              • Instruction Fuzzy Hash: 69E06D352003256AEB313B6F9C00B7B3B59DB437A0F694221EE55D61D0DB24CC8482F4
                                                                                                                                                                              APIs
                                                                                                                                                                              • RegOpenKeyExW.KERNEL32(?,?,00000000,?,?), ref: 00D3E51F
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Open
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 71445658-0
                                                                                                                                                                              • Opcode ID: b32844f258af8655a42d6e7b0b03bdabda32bac48e8ddf41c17f8c21eeab0187
                                                                                                                                                                              • Instruction ID: 5328ab3d35eff46e77bfdd5562c3b890deabe8f5522307174197bd4c59332a8b
                                                                                                                                                                              • Opcode Fuzzy Hash: b32844f258af8655a42d6e7b0b03bdabda32bac48e8ddf41c17f8c21eeab0187
                                                                                                                                                                              • Instruction Fuzzy Hash: 66F05E31600209ABDB248F09DC04F5EBBA8EF94710F14845EF80597250D6B0AA109BA4
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D113A5
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 323602529-0
                                                                                                                                                                              • Opcode ID: 35f7ea466692a37f553989f0c4fad1afce5ad28c6c76d006e1f19fe3d73f5f2b
                                                                                                                                                                              • Instruction ID: dff3877676b8087c65ee644b8ae4e3c8a825cdb8e90333f4b28cf998ba74e85f
                                                                                                                                                                              • Opcode Fuzzy Hash: 35f7ea466692a37f553989f0c4fad1afce5ad28c6c76d006e1f19fe3d73f5f2b
                                                                                                                                                                              • Instruction Fuzzy Hash: 11F06572904654EFD7059F44DC41FAAB3ECEB09B20F10862FE41293780DF756905CAB4
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetFileAttributesW.KERNEL32(00000000,?,00DB4E6A,00000000,00000000,-00000002,6EB998C3,00000028,00000000,?,00000000,extra,00000005,00000000,00000000,00DD44E4), ref: 00DB4D92
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AttributesFile
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3188754299-0
                                                                                                                                                                              • Opcode ID: f452fb62f1c434ea73a7b2e8606118655db57486b8ab3262cae6250affdf6c60
                                                                                                                                                                              • Instruction ID: 94b354a84893ceeb8206da97f01718ff285c5e226896ce8138cffdb3a152d9b1
                                                                                                                                                                              • Opcode Fuzzy Hash: f452fb62f1c434ea73a7b2e8606118655db57486b8ab3262cae6250affdf6c60
                                                                                                                                                                              • Instruction Fuzzy Hash: 04D0A73111130999AF548E7C94696F6334C994176474C0650F51FC71D6E630EC829970
                                                                                                                                                                              APIs
                                                                                                                                                                              • RegSetValueExW.KERNEL32(?,?,00000000,?,?,?), ref: 00D3ED2F
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Value
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3702945584-0
                                                                                                                                                                              • Opcode ID: e93f4c0f3d5a6f374ed8a9269a2d1c320a6120ed604c4cf02ed9f75f979c30c0
                                                                                                                                                                              • Instruction ID: e9d734017d9e050ea58b1b4c4e8d5bf4f0c4f0c4bdf1f45fcefcfe8b7d336cd5
                                                                                                                                                                              • Opcode Fuzzy Hash: e93f4c0f3d5a6f374ed8a9269a2d1c320a6120ed604c4cf02ed9f75f979c30c0
                                                                                                                                                                              • Instruction Fuzzy Hash: EFE0123524020DEBDB008E84FC40FA77B6AEB94700F14C415F9098A2D6C373DC21ABB4
                                                                                                                                                                              APIs
                                                                                                                                                                              • CreateFileW.KERNEL32(00000000,00000000,?,00DB0187,?,?,00000000,?,00DB0187,00000000,0000000C), ref: 00DAFE42
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CreateFile
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 823142352-0
                                                                                                                                                                              • Opcode ID: fbee1885033017e39931da046ffccf15321f5fc357ad62c8957f655b7bf60936
                                                                                                                                                                              • Instruction ID: 28d2433bfd1ad6885dbfc3fce29c3eebe7d61962014f85a7c5a6730a66f4d891
                                                                                                                                                                              • Opcode Fuzzy Hash: fbee1885033017e39931da046ffccf15321f5fc357ad62c8957f655b7bf60936
                                                                                                                                                                              • Instruction Fuzzy Hash: E9D06C3200024EBBDF028F84DD06EDA3BAAFB48714F014000BA1896160C772E921AB91
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D72743: DloadGetSRWLockFunctionPointers.DELAYIMP ref: 00D72743
                                                                                                                                                                                • Part of subcall function 00D72743: AcquireSRWLockExclusive.KERNEL32(?,00D728F1), ref: 00D72760
                                                                                                                                                                              • DloadProtectSection.DELAYIMP ref: 00D726C5
                                                                                                                                                                                • Part of subcall function 00D7286C: DloadObtainSection.DELAYIMP ref: 00D7287C
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Dload$LockSection$AcquireExclusiveFunctionObtainPointersProtect
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1209458687-0
                                                                                                                                                                              • Opcode ID: 6a9f1784186857a06dc6f9dbf371c5814dec7614b628433e0b2de45a92cb0e6e
                                                                                                                                                                              • Instruction ID: a9622d0bf0ffc136082269c5e1816573f1e04efb896b6b4f72b58ee9378b9338
                                                                                                                                                                              • Opcode Fuzzy Hash: 6a9f1784186857a06dc6f9dbf371c5814dec7614b628433e0b2de45a92cb0e6e
                                                                                                                                                                              • Instruction Fuzzy Hash: 57D0C9306442D14EC255BF16A8867382250E304340F58C403A64EE11B5E7B2A8D48A35
                                                                                                                                                                              APIs
                                                                                                                                                                              • RegQueryValueExW.KERNEL32(?,?,00000000,?,?,?), ref: 00D3E8D4
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: QueryValue
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3660427363-0
                                                                                                                                                                              • Opcode ID: 5dfa6cfbe81bebb7fabd4917a6899a4dc585ba76b1b16a7d29ba0670ac15a31f
                                                                                                                                                                              • Instruction ID: 8708bd71058fb3bea5f543c8f3867b2ae4267ac1b33767e16fe0253233135411
                                                                                                                                                                              • Opcode Fuzzy Hash: 5dfa6cfbe81bebb7fabd4917a6899a4dc585ba76b1b16a7d29ba0670ac15a31f
                                                                                                                                                                              • Instruction Fuzzy Hash: 1FD0CA3200020EBBCF024F80ED01E8A3F2AFB08320F048400FA080806183B39430BBA0
                                                                                                                                                                              APIs
                                                                                                                                                                              • _free.LIBCMT ref: 00D8E973
                                                                                                                                                                                • Part of subcall function 00DA2098: RtlFreeHeap.NTDLL(00000000,00000000,?,00DAB729,?,00000000,?,?,?,00DAB9CC,?,00000007,?,?,00DABDD6,?), ref: 00DA20AE
                                                                                                                                                                                • Part of subcall function 00DA2098: GetLastError.KERNEL32(?,?,00DAB729,?,00000000,?,?,?,00DAB9CC,?,00000007,?,?,00DABDD6,?,?), ref: 00DA20C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorFreeHeapLast_free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1353095263-0
                                                                                                                                                                              • Opcode ID: fab4fa4e78e3bb56b6f0db2a41ca46f282b47d196b259d4a4af83b9d8bde8242
                                                                                                                                                                              • Instruction ID: aaa846bcb968f8e761cd1e730000e893f794e43687917058dbbd15e5adb4c1ff
                                                                                                                                                                              • Opcode Fuzzy Hash: fab4fa4e78e3bb56b6f0db2a41ca46f282b47d196b259d4a4af83b9d8bde8242
                                                                                                                                                                              • Instruction Fuzzy Hash: 9DC08C3100020CBBCB009B46C806A4E7BA8DB80364F200044F40117240CAB1EE0496A0
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: cc22b741d4595752a869af4ab17db982c250a9ac99970421a539839ce332f982
                                                                                                                                                                              • Instruction ID: bf8f6310fad1d27868c6e3f474ceb92a0a121d8181d6b751a34514e0fbfe2006
                                                                                                                                                                              • Opcode Fuzzy Hash: cc22b741d4595752a869af4ab17db982c250a9ac99970421a539839ce332f982
                                                                                                                                                                              • Instruction Fuzzy Hash: B1B01281299600FE720452045D03C3B010EC2C0B10F31C11AF544C0293E5404CC80032
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 47a07286d681b5e6e5cc37d93a5b9c22e28cd99fdc59e901f653ab91ce2f2fe8
                                                                                                                                                                              • Instruction ID: f8bc3cc99cef0a05ddf8434eed3ed3b73ae1d1892eb8760ea3c9d5dcc2775dcc
                                                                                                                                                                              • Opcode Fuzzy Hash: 47a07286d681b5e6e5cc37d93a5b9c22e28cd99fdc59e901f653ab91ce2f2fe8
                                                                                                                                                                              • Instruction Fuzzy Hash: A7B012C1299500FE710452085D03C3B010EC2C0B10B31C01EF584C0283E5804C840032
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 621e072132ba0f8eb20feed452ef236b1d524b532c8681d717f7360c1ff43d60
                                                                                                                                                                              • Instruction ID: 06e396a350c14718653c4d330e6bb104f6f350e8a8ada1d01a2ffbb60795730d
                                                                                                                                                                              • Opcode Fuzzy Hash: 621e072132ba0f8eb20feed452ef236b1d524b532c8681d717f7360c1ff43d60
                                                                                                                                                                              • Instruction Fuzzy Hash: 36B01281299500FE710452045D03D3B011EC2C0B10B31C01AF144C0283E5404C844032
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: fee4e5f6d417794efb67b5a4f1023dde3a05c3f700f5c43b6bfb8ef70a476c42
                                                                                                                                                                              • Instruction ID: 329fb688ce1662567d62cbdd9ada349d0294bda4b8036200b0ff7b66538b8a69
                                                                                                                                                                              • Opcode Fuzzy Hash: fee4e5f6d417794efb67b5a4f1023dde3a05c3f700f5c43b6bfb8ef70a476c42
                                                                                                                                                                              • Instruction Fuzzy Hash: 9BB01281299500FE720452045E03C3B110EC2C0B10B31C01AF244C0293E5414D850032
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: cf093badd089faccb8aa7906fb8330261e580b352c86d30a198c98126866a80a
                                                                                                                                                                              • Instruction ID: 23bb27cfe05a5387746d100564caa4051e6f1b016aaec1fbf0fc71272e7d1a0f
                                                                                                                                                                              • Opcode Fuzzy Hash: cf093badd089faccb8aa7906fb8330261e580b352c86d30a198c98126866a80a
                                                                                                                                                                              • Instruction Fuzzy Hash: 8FB012C1299600BE720453045C03C3B010EC2C0B10B31C11AF644C12C3E5404CC80031
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 9cd2ea963dc1368a16d5e576dff5414c7f1770d3921d6ae782d1d080e1bed081
                                                                                                                                                                              • Instruction ID: 4eea7f55bb00669d613aac0fcea38b45f4efba65cc805349296b4458b758427b
                                                                                                                                                                              • Opcode Fuzzy Hash: 9cd2ea963dc1368a16d5e576dff5414c7f1770d3921d6ae782d1d080e1bed081
                                                                                                                                                                              • Instruction Fuzzy Hash: 54B012C1299501FE710453049C03C3B010EC2C0B10B31C41AF688C12C3E5404C840031
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: b344ce7d76ea84a7a212b363c92b7a9d1bbba8e8dce1698b0c2b39c764e655ef
                                                                                                                                                                              • Instruction ID: 86d75cbb262164a78cc4a917a7a21f96f3f96639721a0f183f0333d78f0f125e
                                                                                                                                                                              • Opcode Fuzzy Hash: b344ce7d76ea84a7a212b363c92b7a9d1bbba8e8dce1698b0c2b39c764e655ef
                                                                                                                                                                              • Instruction Fuzzy Hash: E3B01281299500FE710452045C03C3B010EC6C0B10B32C01AF584C42C3E5514C840431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 74ccd76a81e21a54e971d5131ac77af1acb7e6d86e7a43715d700bc7a7163166
                                                                                                                                                                              • Instruction ID: c9bc11cd0cbef4009f955b6d3dd0a7b07fffb093f100938350350913ce7d01fe
                                                                                                                                                                              • Opcode Fuzzy Hash: 74ccd76a81e21a54e971d5131ac77af1acb7e6d86e7a43715d700bc7a7163166
                                                                                                                                                                              • Instruction Fuzzy Hash: 40B012C1299500BE720453045D03C3B110EC2C0B10B31C01AF344C12D3E5414C850031
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64C81
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: ddf29f2b99b319640fa5e5de9bd8702e0c3f718cb9df7c570366ab99492bc66a
                                                                                                                                                                              • Instruction ID: a1b4a796f61a68eccab3ab7292660a3757cba9b5fe0f8f8683c09a7a630aa9a9
                                                                                                                                                                              • Opcode Fuzzy Hash: ddf29f2b99b319640fa5e5de9bd8702e0c3f718cb9df7c570366ab99492bc66a
                                                                                                                                                                              • Instruction Fuzzy Hash: DFB01295299600FE720412105D07C3B110EC6C0B10B31C11AF540D41C3E5514CC80071
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64DAF
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 34fc70c382f6739938683f8763e3d7a9e8a9c214adc6f63abc0de3f187507601
                                                                                                                                                                              • Instruction ID: 0fa6779402ffbc0c2605cd8c52f562b45eeb0c8a0f134497273139ee20c3701d
                                                                                                                                                                              • Opcode Fuzzy Hash: 34fc70c382f6739938683f8763e3d7a9e8a9c214adc6f63abc0de3f187507601
                                                                                                                                                                              • Instruction Fuzzy Hash: 0EB012C12DA1047D33042100FC03C3B011EC6C1B107B0C01AF180D40D3E5508C844431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D64DAF
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: ea3c2d6749b2e53922b84d8fa6cc598345c16548877d2c021412229c173b46a1
                                                                                                                                                                              • Instruction ID: efb79225e04556baf908646fe69ec75561c9e4bf2504613a8aa7f581fc94b406
                                                                                                                                                                              • Opcode Fuzzy Hash: ea3c2d6749b2e53922b84d8fa6cc598345c16548877d2c021412229c173b46a1
                                                                                                                                                                              • Instruction Fuzzy Hash: 3CB012C16D9100BD73446114BC03C3B010EC3C4B10330C02AF588C1193E5408C880431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D714D8
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 8253007ecacef240e220b647e39297e7c57ea855d3013edcffc4f2353e741881
                                                                                                                                                                              • Instruction ID: 557fb2ec4518b50ebe3584439b5f87b8631a2affaf2308e3607892848a23060b
                                                                                                                                                                              • Opcode Fuzzy Hash: 8253007ecacef240e220b647e39297e7c57ea855d3013edcffc4f2353e741881
                                                                                                                                                                              • Instruction Fuzzy Hash: 24B012E52981007C320411155D07D3B210EC2C0B14730C11EF348D1093F5405D451031
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D897C4
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 267b1f1148f2f81d3071aa82ab15f7d57d5fb8cbfabf17e225139d368081877b
                                                                                                                                                                              • Instruction ID: 24a784c09cd3df2383e598b2a40519fbedad2966c550bd7e15c27b66c7bf74f5
                                                                                                                                                                              • Opcode Fuzzy Hash: 267b1f1148f2f81d3071aa82ab15f7d57d5fb8cbfabf17e225139d368081877b
                                                                                                                                                                              • Instruction Fuzzy Hash: 3CB012D12B81007C320435145D03C3B110EC3C0B10339C82EFA40E0093B5404C4B0431
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 1e55b2c9a2543cbb34ebd21689bc0122d4b72560e8f38a07042fb7e2551b4b66
                                                                                                                                                                              • Instruction ID: 15ad70646fb5a84a7c1dc9c3bb41406b9a8901d47a52c4439a2f95dfc5d248e4
                                                                                                                                                                              • Opcode Fuzzy Hash: 1e55b2c9a2543cbb34ebd21689bc0122d4b72560e8f38a07042fb7e2551b4b66
                                                                                                                                                                              • Instruction Fuzzy Hash: 50B012912AC140BC310461447C43C3B131FC2C0B10734C61AF584C0183E4405CC41131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: c8ddf850af07492fc0b83fbde64661425aeb1a95513858bd5c40acb981f73f0b
                                                                                                                                                                              • Instruction ID: 660cff5749c40255afbee8ea200af9f4a0b6e1c850d2efbf88845eca96e61daa
                                                                                                                                                                              • Opcode Fuzzy Hash: c8ddf850af07492fc0b83fbde64661425aeb1a95513858bd5c40acb981f73f0b
                                                                                                                                                                              • Instruction Fuzzy Hash: C9B012912AC1407C320461447D43C3B220FC2C0B10734C51AF344C0193F4405CC51131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 574e0cf93698a50e98aa261daff9c3f81d10add1cd5435a72b8f6ccdd9ecf456
                                                                                                                                                                              • Instruction ID: 0a26e3d33b0aa2f651eef6e0b183685d955e8ba6ba769964633dc3a5bf7af718
                                                                                                                                                                              • Opcode Fuzzy Hash: 574e0cf93698a50e98aa261daff9c3f81d10add1cd5435a72b8f6ccdd9ecf456
                                                                                                                                                                              • Instruction Fuzzy Hash: 70B012812AC1407C710461047C43E3B121EC2C0B10334C91AF184C01C3E4405CC46131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 301191465a8ad7031f9d1f9437dbde4154235090cff5a15fc07b743f247fc731
                                                                                                                                                                              • Instruction ID: 03bbca96cf072b35414c1666f48d22dbee5bca9b61d3cbc5781365e60d666278
                                                                                                                                                                              • Opcode Fuzzy Hash: 301191465a8ad7031f9d1f9437dbde4154235090cff5a15fc07b743f247fc731
                                                                                                                                                                              • Instruction Fuzzy Hash: 99B012812AC1407C72046104BD43D3B220EC2C0B10334C51AF244C01A3E4405C852131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 2f03719c209596fff358e489fa74ba14cc797e9c02763c96ab374b079696d517
                                                                                                                                                                              • Instruction ID: 9a983fcd537478fe86f4b2e10ff2d4fbd09fa2bac8722238e7a1f084af9f929b
                                                                                                                                                                              • Opcode Fuzzy Hash: 2f03719c209596fff358e489fa74ba14cc797e9c02763c96ab374b079696d517
                                                                                                                                                                              • Instruction Fuzzy Hash: E8B012812AC2407C720461047C43D3B120EC2C0B10334C61AF544C0183E4405DC82131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: e707342b4043fe66788d87d248dacf1d063c1c7c786ac4ce47a941ee047f7611
                                                                                                                                                                              • Instruction ID: 8f3c87be47c34b8df6fc86a46c57cf79e3e79464b61fe583fb299c877c0120df
                                                                                                                                                                              • Opcode Fuzzy Hash: e707342b4043fe66788d87d248dacf1d063c1c7c786ac4ce47a941ee047f7611
                                                                                                                                                                              • Instruction Fuzzy Hash: A2B012852AC2407C320461047C43C3B124EC2C0B10334C61AF544C0183E4405CC81131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 20f3746401fd0381180cc112c5be4036e293ae87190c410ff0c869a635a0a33a
                                                                                                                                                                              • Instruction ID: 734d5e7d118a52cc43dec023c316810594ef3912552734df01d3caae6a1157de
                                                                                                                                                                              • Opcode Fuzzy Hash: 20f3746401fd0381180cc112c5be4036e293ae87190c410ff0c869a635a0a33a
                                                                                                                                                                              • Instruction Fuzzy Hash: 3DB012812AC140BC310461147C43C3F124EC2C0B10334C51AF584C0183E5405C841131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 4e41b12aa30e9a8c41dbb53bae31e7df3a66b98f7c61e6d0eb49cb8c0b03adab
                                                                                                                                                                              • Instruction ID: f427eec23465c5aef5672c2a3b56ea30cdb5f49cf0f337dce97980203bdb6da1
                                                                                                                                                                              • Opcode Fuzzy Hash: 4e41b12aa30e9a8c41dbb53bae31e7df3a66b98f7c61e6d0eb49cb8c0b03adab
                                                                                                                                                                              • Instruction Fuzzy Hash: EBB012912AC1407C310461447C43E3B121FC3C0B10734C51AF144C0183E4405CC49131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: b01514949201cc976e41b4abdcae17c9cdd7bdcede5184cba6cfe548c1127d41
                                                                                                                                                                              • Instruction ID: 04e1e2f5aed53d59c69bb226df7ce305867c8d3acc3c32d68d1243aaad0cf7e5
                                                                                                                                                                              • Opcode Fuzzy Hash: b01514949201cc976e41b4abdcae17c9cdd7bdcede5184cba6cfe548c1127d41
                                                                                                                                                                              • Instruction Fuzzy Hash: 8CB012812EC140BC710461047C43D3B120EC2C0B10334C51AF584C0183E4409C842131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: 6ef8a19144a2ea66354f6192bf5adb29a376721573004f34f073064a0d94d856
                                                                                                                                                                              • Instruction ID: d41726d5e0f14c9fb96b3dfb55969ae406da03515655b831e4312d880a55f940
                                                                                                                                                                              • Opcode Fuzzy Hash: 6ef8a19144a2ea66354f6192bf5adb29a376721573004f34f073064a0d94d856
                                                                                                                                                                              • Instruction Fuzzy Hash: 3EB012822AC2447C310461047C43D3B125EC2C0B10334C51AF144C0183E4405C845131
                                                                                                                                                                              APIs
                                                                                                                                                                              • ___delayLoadHelper2@8.DELAYIMP ref: 00D89BE7
                                                                                                                                                                                • Part of subcall function 00D7293C: DloadReleaseSectionWriteAccess.DELAYIMP ref: 00D729AF
                                                                                                                                                                                • Part of subcall function 00D7293C: RaiseException.KERNEL32(C06D0057,00000000,00000001,?), ref: 00D729C0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AccessDloadExceptionHelper2@8LoadRaiseReleaseSectionWrite___delay
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1269201914-0
                                                                                                                                                                              • Opcode ID: bcde56d5f483de2e1d6203d118748a03f2086cfa1b0edf0411fba49347c642cf
                                                                                                                                                                              • Instruction ID: a2ac626fa3a1b850b95999515c326ffa9b362d782b917f0815daad17a334272f
                                                                                                                                                                              • Opcode Fuzzy Hash: bcde56d5f483de2e1d6203d118748a03f2086cfa1b0edf0411fba49347c642cf
                                                                                                                                                                              • Instruction Fuzzy Hash: 11B012912AC1407C320461047D43C3B228EC2C0B10734C51AF244C0193E4405C851131
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: lstrlen
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1659193697-0
                                                                                                                                                                              • Opcode ID: 481b1e0bd938dbfcd0fbeae18a316d74aa0400c3704e7e3e55f046e867537fca
                                                                                                                                                                              • Instruction ID: d32a45a4d38108f04200b94c1e172576d7b672d26d9892a128761d3e0c296fbc
                                                                                                                                                                              • Opcode Fuzzy Hash: 481b1e0bd938dbfcd0fbeae18a316d74aa0400c3704e7e3e55f046e867537fca
                                                                                                                                                                              • Instruction Fuzzy Hash: D3E0ED37200119ABDB018B89EC84D9AFB6DEBD5371B04403BFA04C7220D772AD25DBA0
                                                                                                                                                                              APIs
                                                                                                                                                                              • EnterCriticalSection.KERNEL32(?,6EB998C3), ref: 00D40571
                                                                                                                                                                              • FreeLibrary.KERNEL32(00000000), ref: 00D405B7
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,SetEntriesInAclW), ref: 00D405DD
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,GetFileSecurityW), ref: 00D405E9
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,SetFileSecurityW), ref: 00D405F5
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,LookupAccountSidW), ref: 00D40601
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,GetExplicitEntriesFromAclW), ref: 00D4060D
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,RegGetKeySecurity), ref: 00D4061C
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,RegSetKeySecurity), ref: 00D40628
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,InitializeSecurityDescriptor), ref: 00D40634
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,SetSecurityDescriptorDacl), ref: 00D40640
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,GetSecurityDescriptorDacl), ref: 00D4064C
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,AllocateAndInitializeSid), ref: 00D40658
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,FreeSid), ref: 00D40664
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,OpenThreadToken), ref: 00D40670
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,GetTokenInformation), ref: 00D4067C
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,InitializeAcl), ref: 00D40688
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,InitializeSid), ref: 00D40694
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,GetSidSubAuthority), ref: 00D406A0
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,AddAccessAllowedAce), ref: 00D406AC
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,GetSecurityInfo), ref: 00D406B8
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,SetSecurityInfo), ref: 00D406C4
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,QueryServiceStatusEx), ref: 00D406D0
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,GetAce), ref: 00D406DC
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,DeleteAce), ref: 00D406E8
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,EqualSid), ref: 00D406F4
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,GetAclInformation), ref: 00D40700
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,SetSecurityDescriptorControl), ref: 00D4070F
                                                                                                                                                                              • LeaveCriticalSection.KERNEL32(?), ref: 00D407DE
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AddressProc$CriticalSection$EnterFreeLeaveLibrary
                                                                                                                                                                              • String ID: AddAccessAllowedAce$AllocateAndInitializeSid$DeleteAce$EqualSid$FreeSid$GetAce$GetAclInformation$GetExplicitEntriesFromAclW$GetFileSecurityW$GetSecurityDescriptorDacl$GetSecurityInfo$GetSidSubAuthority$GetTokenInformation$InitializeAcl$InitializeSecurityDescriptor$InitializeSid$LookupAccountSidW$OpenThreadToken$QueryServiceStatusEx$RegGetKeySecurity$RegSetKeySecurity$SetEntriesInAclW$SetFileSecurityW$SetSecurityDescriptorControl$SetSecurityDescriptorDacl$SetSecurityInfo$advapi32.dll
                                                                                                                                                                              • API String ID: 2701342527-838666417
                                                                                                                                                                              • Opcode ID: 780890e4c283b2bb5a5cab012f56ff786ae12db0aa3bddeaf9998e9ac75d5450
                                                                                                                                                                              • Instruction ID: 3d4f24b11e5bb1595947c37c1f6e0a18baa7bb6d8db11011be29d1298beee01d
                                                                                                                                                                              • Opcode Fuzzy Hash: 780890e4c283b2bb5a5cab012f56ff786ae12db0aa3bddeaf9998e9ac75d5450
                                                                                                                                                                              • Instruction Fuzzy Hash: 4C812874940B66FFCF259B61C848B95BFA1FF05315F040126EA0462AA0D7B5A46CDFE2
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D1463F: GetProcessHeap.KERNEL32(?,?,?,00D1E97C,6EB998C3,?,?,?,?,00DB9590,000000FF), ref: 00D14676
                                                                                                                                                                              • VariantTimeToSystemTime.OLEAUT32 ref: 00D58539
                                                                                                                                                                              • GetLastError.KERNEL32(6EB998C3,?), ref: 00D5867A
                                                                                                                                                                                • Part of subcall function 00D38690: FindResourceExW.KERNEL32(00000000,00000006,?,00000000,00000000), ref: 00D386D6
                                                                                                                                                                                • Part of subcall function 00D38690: LoadResource.KERNEL32(00000000,00000000), ref: 00D386E4
                                                                                                                                                                                • Part of subcall function 00D38690: LockResource.KERNEL32(00000000), ref: 00D386EF
                                                                                                                                                                                • Part of subcall function 00D38690: SizeofResource.KERNEL32(00000000,00000000), ref: 00D386FD
                                                                                                                                                                                • Part of subcall function 00D38690: FindResourceW.KERNEL32(00000000,?,00000006), ref: 00D38764
                                                                                                                                                                                • Part of subcall function 00D38690: LoadResource.KERNEL32(00000000,00000000), ref: 00D38776
                                                                                                                                                                                • Part of subcall function 00D38690: LockResource.KERNEL32(00000000), ref: 00D38785
                                                                                                                                                                                • Part of subcall function 00D38690: SizeofResource.KERNEL32(00000000,00000000), ref: 00D38797
                                                                                                                                                                              • __floor_pentium4.LIBCMT ref: 00D58C83
                                                                                                                                                                              • __floor_pentium4.LIBCMT ref: 00D58CDF
                                                                                                                                                                              • __floor_pentium4.LIBCMT ref: 00D58D37
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Resource$__floor_pentium4$FindLoadLockSizeofTime$ErrorHeapLastProcessSystemVariant
                                                                                                                                                                              • String ID: $GetAsSystemTime failed: %d$Invalid DateTime$NWebAdvisor::NXmlUpdater::CDateSubstitution::FormatDateTime$NWebAdvisor::NXmlUpdater::CDateSubstitution::Substitute$TOMORROW$YESTERDAY$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\DateSubstitution.cpp$epoch$failed to convert date element(s) to int: year = %s, month = %s, day = %s$failed to convert epoch date: %s$failed to parse day: %s$failed to parse month: %s$failed to parse year: %s$string %s does not have %d symbols starting index %d$yyyy
                                                                                                                                                                              • API String ID: 3108935575-1381540002
                                                                                                                                                                              • Opcode ID: 9802155a83f76d0aec5bf3a5b73948f62aea7fdeb85436a9ecb7de9ea3058332
                                                                                                                                                                              • Instruction ID: 4545b21b97dc8c285abb92190dee5fcc43d6baf9ec4796d2bd906334b6c97874
                                                                                                                                                                              • Opcode Fuzzy Hash: 9802155a83f76d0aec5bf3a5b73948f62aea7fdeb85436a9ecb7de9ea3058332
                                                                                                                                                                              • Instruction Fuzzy Hash: 83E29C71A00219DBDF24DF68CC55BEDB7B5EF44305F144299E85AA7281EB30AA89CF70
                                                                                                                                                                              APIs
                                                                                                                                                                              • CryptQueryObject.CRYPT32(00000001,00D4BDCE,00000400,00000002,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D5EBD2
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D5EBE4
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D5EBF4
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D5ECEE
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D5ECFE
                                                                                                                                                                              • CryptQueryObject.CRYPT32(00000002,?,00003FFE,00000002,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D5EDEE
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D5EE0A
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D5EE1C
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D5EEB6
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D5EEC2
                                                                                                                                                                                • Part of subcall function 00D5F3C0: CryptMsgGetParam.CRYPT32(00000000,00000005,00000000,?,?), ref: 00D5F442
                                                                                                                                                                                • Part of subcall function 00D5F3C0: CryptMsgGetParam.CRYPT32(00000000,00000006,00000000,00000000,00000004), ref: 00D5F488
                                                                                                                                                                                • Part of subcall function 00D5F3C0: CryptMsgGetParam.CRYPT32(?,00000006,00000000,00000000,00000000), ref: 00D5F4C6
                                                                                                                                                                                • Part of subcall function 00D5F3C0: CertGetSubjectCertificateFromStore.CRYPT32(?,00010001,?), ref: 00D5F527
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D5EF02
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D5EF14
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D5EFAE
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D5EFBA
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D5EFDA
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D5EFEA
                                                                                                                                                                              • CryptMsgClose.CRYPT32(00000000), ref: 00D5F0CB
                                                                                                                                                                              • CertCloseStore.CRYPT32(00000000,00000001), ref: 00D5F0DB
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Close$Crypt$CertStore$Param$ObjectQuery$CertificateFromSubject
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2648890560-0
                                                                                                                                                                              • Opcode ID: 1ae661cdb34d3cae632287aa52c0e798d58e5ecc943374a11da3ff1e7ab94a3d
                                                                                                                                                                              • Instruction ID: 166387cc09532eb08d82da3752b7b10101be2ef5a2795798f28bacc354f911a4
                                                                                                                                                                              • Opcode Fuzzy Hash: 1ae661cdb34d3cae632287aa52c0e798d58e5ecc943374a11da3ff1e7ab94a3d
                                                                                                                                                                              • Instruction Fuzzy Hash: A9023171E002089BEF18DFA9CD49BAEBBB9AF48305F184519ED01F7281D7759A48CB74
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D0ABD1
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D0ABD6
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D0B256
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_task
                                                                                                                                                                              • String ID: (#$)$/$8"$@#$X#$YSTEM$p#$"
                                                                                                                                                                              • API String ID: 118556049-1208883006
                                                                                                                                                                              • Opcode ID: 08cfd4f8bfedb647972bdaeab040e122cedb07c1b89a4b2108e7f46a3d3e4620
                                                                                                                                                                              • Instruction ID: 112690ffdb588e98083481a252212119c2108d904c70419990af5ce680a38253
                                                                                                                                                                              • Opcode Fuzzy Hash: 08cfd4f8bfedb647972bdaeab040e122cedb07c1b89a4b2108e7f46a3d3e4620
                                                                                                                                                                              • Instruction Fuzzy Hash: 9C7210B1E00355CFDB14DF68CC557AE77B4EB48314F24422EE42AA72D1EB359A88CB61
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D030C1
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D030C6
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D03746
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_task
                                                                                                                                                                              • String ID: $)$/$0$8$H$YSTEM$`$x
                                                                                                                                                                              • API String ID: 118556049-3882720062
                                                                                                                                                                              • Opcode ID: 9c8054c738b2583950bbaab8123e6bab7416e175b19a74403311d899ead0a815
                                                                                                                                                                              • Instruction ID: 891e21e2d679d87e89796c74393ef702caeb0913d5939f26e1bbf80c7cf3ea7c
                                                                                                                                                                              • Opcode Fuzzy Hash: 9c8054c738b2583950bbaab8123e6bab7416e175b19a74403311d899ead0a815
                                                                                                                                                                              • Instruction Fuzzy Hash: ED7206B1D00254CFEB24DF28CC557AE77B8EB48314F24466DE45AA72D1EB35DA88CB60
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetCurrentProcessId.KERNEL32(?,?), ref: 00D26268
                                                                                                                                                                              • GetCurrentThreadId.KERNEL32 ref: 00D26274
                                                                                                                                                                              • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000,?,?,?,?,?,?,?,?), ref: 00D263BF
                                                                                                                                                                              • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000,?,?,?,?,?,?,?,?), ref: 00D263DF
                                                                                                                                                                              • CryptHashData.ADVAPI32(00000000,?,00000000,00000000,?,?,?,?,?,?,?,?), ref: 00D263FC
                                                                                                                                                                              Strings
                                                                                                                                                                              • al exception rule %x:%x res %s, xrefs: 00D2632E
                                                                                                                                                                              • 3c224a00-5d51-11cf-b3ca-000000000001, xrefs: 00D2671E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Crypt$CurrentHash$AcquireContextCreateDataProcessThread
                                                                                                                                                                              • String ID: 3c224a00-5d51-11cf-b3ca-000000000001$al exception rule %x:%x res %s
                                                                                                                                                                              • API String ID: 3004248768-911235813
                                                                                                                                                                              • Opcode ID: bf7e31e8e00f291b44fefdf415d88c737516b8fc367be61cac02612df5e3157b
                                                                                                                                                                              • Instruction ID: 8cde5b03aec16203152c1d42ea2e935f3cc8a0a48f48710810677ebb75b25da1
                                                                                                                                                                              • Opcode Fuzzy Hash: bf7e31e8e00f291b44fefdf415d88c737516b8fc367be61cac02612df5e3157b
                                                                                                                                                                              • Instruction Fuzzy Hash: 34F13975B013299BCB259B14DC95FADB7B5BF48710F1800D9E90AA7391CB74AE41CFA0
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetCurrentProcessId.KERNEL32 ref: 00D267F3
                                                                                                                                                                              • GetCurrentThreadId.KERNEL32 ref: 00D267FB
                                                                                                                                                                              • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000), ref: 00D2687F
                                                                                                                                                                              • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 00D2689F
                                                                                                                                                                              • CryptHashData.ADVAPI32(00000000,?,00000000,00000000), ref: 00D268BC
                                                                                                                                                                              • CryptGetHashParam.ADVAPI32(00000000,00000002,?,00000010,00000000), ref: 00D268DE
                                                                                                                                                                              • CryptDestroyHash.ADVAPI32(00000000), ref: 00D268EF
                                                                                                                                                                              • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 00D26902
                                                                                                                                                                              • DeviceIoControl.KERNEL32(00000000,9EDBA51C,00000000,00000000,00000000,00000000,?,00000000), ref: 00D26951
                                                                                                                                                                              • DeviceIoControl.KERNEL32(?,9EDB651C,00000000,00000000,00000000,00000000,?,00000000), ref: 00D26980
                                                                                                                                                                              Strings
                                                                                                                                                                              • Freeing access handle %p, xrefs: 00D267D0
                                                                                                                                                                              • al exception rule %x:%x res %s, xrefs: 00D26824
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Crypt$Hash$ContextControlCurrentDevice$AcquireCreateDataDestroyParamProcessReleaseThread
                                                                                                                                                                              • String ID: Freeing access handle %p$al exception rule %x:%x res %s
                                                                                                                                                                              • API String ID: 581428007-3582322424
                                                                                                                                                                              • Opcode ID: 7ba06933912b345801b066e5efb133552adca134bb4d9e8567970ddc3583410e
                                                                                                                                                                              • Instruction ID: f77fcfb60ee33bde79f00f94fcfbd796900d1c225361f2cf240a1a277554e1a9
                                                                                                                                                                              • Opcode Fuzzy Hash: 7ba06933912b345801b066e5efb133552adca134bb4d9e8567970ddc3583410e
                                                                                                                                                                              • Instruction Fuzzy Hash: 25518271A00319ABEB309B64DC45FDAB7B8AB14714F144295FA14E62C1DBB0EE84CFB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D0D501
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D0D506
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D0DB86
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_task
                                                                                                                                                                              • String ID: +$)$/$8+$P+$YSTEM$h+$+
                                                                                                                                                                              • API String ID: 118556049-3922242405
                                                                                                                                                                              • Opcode ID: 194b42c24962714316eb97942ddb8bf5ec086b6d4023feafba82234eaeca4a3a
                                                                                                                                                                              • Instruction ID: e4c1b256a906d36a1d0e35154b7742b4cfa707a6bbf70f3ba2a581e983579e8a
                                                                                                                                                                              • Opcode Fuzzy Hash: 194b42c24962714316eb97942ddb8bf5ec086b6d4023feafba82234eaeca4a3a
                                                                                                                                                                              • Instruction Fuzzy Hash: 497211B1D00254CFDB24DFA8CC557AE77F5EB18314F24062EE41AA72D1EB359A88CB61
                                                                                                                                                                              Strings
                                                                                                                                                                              • invalid stol argument, xrefs: 00D5A987
                                                                                                                                                                              • failed to parse date from value: %s, xrefs: 00D5A63C
                                                                                                                                                                              • Unable to substitute the arguments, xrefs: 00D5B077
                                                                                                                                                                              • failed to parse date from name: %s, xrefs: 00D5A5B2
                                                                                                                                                                              • NEQ, xrefs: 00D5A8CD
                                                                                                                                                                              • NWebAdvisor::NXmlUpdater::CDateDeltaPrecondition::IsPreconditionSatisfied, xrefs: 00D5A9FF, 00D5B07E
                                                                                                                                                                              • stol argument out of range, xrefs: 00D5A991
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\DateDeltaPrecondition.cpp, xrefs: 00D5A95B, 00D5AA04, 00D5B083
                                                                                                                                                                              • invalid substitutor, xrefs: 00D5A9F8
                                                                                                                                                                              • [DATE:TODAY], xrefs: 00D5AA28
                                                                                                                                                                              • Unknown comparison operator: %s, xrefs: 00D5A94F
                                                                                                                                                                              • NWebAdvisor::NXmlUpdater::CDateDeltaPrecondition::CheckDateDelatImpl, xrefs: 00D5A956
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Time$SystemVariant
                                                                                                                                                                              • String ID: NEQ$NWebAdvisor::NXmlUpdater::CDateDeltaPrecondition::CheckDateDelatImpl$NWebAdvisor::NXmlUpdater::CDateDeltaPrecondition::IsPreconditionSatisfied$Unable to substitute the arguments$Unknown comparison operator: %s$[DATE:TODAY]$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\DateDeltaPrecondition.cpp$failed to parse date from name: %s$failed to parse date from value: %s$invalid stol argument$invalid substitutor$stol argument out of range
                                                                                                                                                                              • API String ID: 352189841-3100175478
                                                                                                                                                                              • Opcode ID: 032ed55b95ca567f128d0fdc636f1723c85b69b4a090c96a585230178a49f5a3
                                                                                                                                                                              • Instruction ID: b735c7fd99f0741f5b84b553d8ff4706514e782ba4e699bb09a9e8e87f660703
                                                                                                                                                                              • Opcode Fuzzy Hash: 032ed55b95ca567f128d0fdc636f1723c85b69b4a090c96a585230178a49f5a3
                                                                                                                                                                              • Instruction Fuzzy Hash: CB729271D002189ACF25DFA8C851BEEB7B4FF15305F144259E80ABB291EB746A89CF71
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: Encountered SEND_EVENT, but no event reporter was defined$Invalid$Invalid arguments passed to SEND_EVENT command$NWebAdvisor::NXmlUpdater::CSendEventCommand::Execute$Name$Unable to substitute variables for the SEND_EVENT command$Unexpected call to legacy SEND_EVENT command$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\SendEventCommand.cpp$default$invalid substitutor
                                                                                                                                                                              • API String ID: 0-494503603
                                                                                                                                                                              • Opcode ID: f4a7e1ffe9ee896e2a10c835aac47d4cbdc059ba4b620e4f12c7dd9735099daa
                                                                                                                                                                              • Instruction ID: b754f20d484093d9ac528a5e2a7b1f30a9a69263ff2f59c3430ebc8cbdbb9bf1
                                                                                                                                                                              • Opcode Fuzzy Hash: f4a7e1ffe9ee896e2a10c835aac47d4cbdc059ba4b620e4f12c7dd9735099daa
                                                                                                                                                                              • Instruction Fuzzy Hash: EA024870A40208EFDB10DF94D996BEEB7B4EF19704F15405AF5417B281DBB6AE088BB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D059C1
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D059C6
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D06066
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_task
                                                                                                                                                                              • String ID: )$/$YSTEM
                                                                                                                                                                              • API String ID: 118556049-314724184
                                                                                                                                                                              • Opcode ID: d2da8bd67847f5527d915837fc990d4d90848a727f27dbd79c0d5c3762f054e9
                                                                                                                                                                              • Instruction ID: 0ea5ca3fca35565e35bf2c770c57548722dc22a3bb37d93c4e41444c08552a6b
                                                                                                                                                                              • Opcode Fuzzy Hash: d2da8bd67847f5527d915837fc990d4d90848a727f27dbd79c0d5c3762f054e9
                                                                                                                                                                              • Instruction Fuzzy Hash: 5372EFB1D00254CFDB149F28DC557AE77B4EB18310F24026EE85AEB2D1EB359A88CF61
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                              • GetACP.KERNEL32(?,?,?,?,?,?,00DA00E4,?,?,?,00000055,?,-00000050,?,?,00000004), ref: 00DAC720
                                                                                                                                                                              • IsValidCodePage.KERNEL32(00000000,?,?,?,?,?,?,00DA00E4,?,?,?,00000055,?,-00000050,?,?), ref: 00DAC74B
                                                                                                                                                                              • _wcschr.LIBVCRUNTIME ref: 00DAC7DF
                                                                                                                                                                              • _wcschr.LIBVCRUNTIME ref: 00DAC7ED
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078,-00000050,00000000,000000D0), ref: 00DAC8B4
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast_wcschr$CodeInfoLocalePageValid
                                                                                                                                                                              • String ID: utf8
                                                                                                                                                                              • API String ID: 4147378913-905460609
                                                                                                                                                                              • Opcode ID: 4d9bf47c3b79d8d49d399fd5703e4534ba512f27703296139d9b81f5187b7ade
                                                                                                                                                                              • Instruction ID: 420a8c55b481e11c121e0a6852120bc38a3dabf1d8d8db701bcf1835720a89df
                                                                                                                                                                              • Opcode Fuzzy Hash: 4d9bf47c3b79d8d49d399fd5703e4534ba512f27703296139d9b81f5187b7ade
                                                                                                                                                                              • Instruction Fuzzy Hash: B571C776A10302AADB25AB35CC86FB673A8FF4A720F18542AF905DB181EB74D9408775
                                                                                                                                                                              APIs
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: __floor_pentium4
                                                                                                                                                                              • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                                                                                                                                                              • API String ID: 4168288129-2761157908
                                                                                                                                                                              • Opcode ID: be001b6961f680f592be39088c4821011c142a5a61f92ee42e9918875b623935
                                                                                                                                                                              • Instruction ID: 850f9a3c934e725b2b702a6ce6b798351d563946f2dbab4a0462a404b80ddf88
                                                                                                                                                                              • Opcode Fuzzy Hash: be001b6961f680f592be39088c4821011c142a5a61f92ee42e9918875b623935
                                                                                                                                                                              • Instruction Fuzzy Hash: AAC23C71E046288FDB64CE28DD407EAB7B5EB89305F1441EAD44EE7240E778AE85CF61
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(?,2000000B,00DAD124,00000002,00000000,?,?,?,00DAD124,?,00000000), ref: 00DACE9F
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(?,20001004,00DAD124,00000002,00000000,?,?,?,00DAD124,?,00000000), ref: 00DACEC8
                                                                                                                                                                              • GetACP.KERNEL32(?,?,00DAD124,?,00000000), ref: 00DACEDD
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InfoLocale
                                                                                                                                                                              • String ID: ACP$OCP
                                                                                                                                                                              • API String ID: 2299586839-711371036
                                                                                                                                                                              • Opcode ID: 1c04ff18adaae4ce8f4636c8b61c317213a7a6da0df3ee68949443c890ebbe9f
                                                                                                                                                                              • Instruction ID: 0248a3b642a9e2eebedd8a2ca84e86920b708f9554c2fa261441e0ef2134d68e
                                                                                                                                                                              • Opcode Fuzzy Hash: 1c04ff18adaae4ce8f4636c8b61c317213a7a6da0df3ee68949443c890ebbe9f
                                                                                                                                                                              • Instruction Fuzzy Hash: 32218672620105EADB358F24C900AA773A6AB56B74B5E9464F946D7204E732DF41C3B0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: expected ' or "$expected =$expected >$expected element name$invalid numeric character entity$unexpected end of data
                                                                                                                                                                              • API String ID: 0-1758782166
                                                                                                                                                                              • Opcode ID: f655983861f0c8853d06f86e2423b9ec2ffc1e76cba0ed8e01f97d7773853613
                                                                                                                                                                              • Instruction ID: a885f915fe08f86290b46cdbec0f3b43fa5bc31e1a759a107ca0a40a15ec13b5
                                                                                                                                                                              • Opcode Fuzzy Hash: f655983861f0c8853d06f86e2423b9ec2ffc1e76cba0ed8e01f97d7773853613
                                                                                                                                                                              • Instruction Fuzzy Hash: 9502D0706042109FCB28CF28D495B76BBF2FF55304F28859EE4898B292E775D945CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                                • Part of subcall function 00DA1CA9: _free.LIBCMT ref: 00DA1D0B
                                                                                                                                                                                • Part of subcall function 00DA1CA9: _free.LIBCMT ref: 00DA1D41
                                                                                                                                                                              • GetUserDefaultLCID.KERNEL32(?,?,?,00000055,?), ref: 00DAD0E7
                                                                                                                                                                              • IsValidCodePage.KERNEL32(00000000), ref: 00DAD130
                                                                                                                                                                              • IsValidLocale.KERNEL32(?,00000001), ref: 00DAD13F
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(?,00001001,-00000050,00000040,?,000000D0,00000055,00000000,?,?,00000055,00000000), ref: 00DAD187
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(?,00001002,00000030,00000040), ref: 00DAD1A6
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Locale$ErrorInfoLastValid_free$CodeDefaultPageUser
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 949163717-0
                                                                                                                                                                              • Opcode ID: c59da80874939300303729cfe2b48187ba778c66029038db8da47159c26a0c10
                                                                                                                                                                              • Instruction ID: 637056dd27e1305943dc464fa46ca7d6b1cc695c28d3c1b4c84534f3314fa05c
                                                                                                                                                                              • Opcode Fuzzy Hash: c59da80874939300303729cfe2b48187ba778c66029038db8da47159c26a0c10
                                                                                                                                                                              • Instruction Fuzzy Hash: C8515F71A00206AFDB10DFA5CC45ABAB7BAFF0A700F184429F556EB190DB70DA05CB75
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: ERCP$PCRE$VUUU$VUUU$VUUU
                                                                                                                                                                              • API String ID: 0-663802839
                                                                                                                                                                              • Opcode ID: d77bca935420a169d9370bd7ddb76095784785a67ae919e00d8ae63995bbc5b2
                                                                                                                                                                              • Instruction ID: ab8d8a1477e37f8f730d09dd0a25910272ce73233c369be9f42fa7c3483e8c7c
                                                                                                                                                                              • Opcode Fuzzy Hash: d77bca935420a169d9370bd7ddb76095784785a67ae919e00d8ae63995bbc5b2
                                                                                                                                                                              • Instruction Fuzzy Hash: DB826D75A00259CBDB24CF1CC8817ADBBB1BF45314F5882EAD85DAB281E7719E85CF60
                                                                                                                                                                              APIs
                                                                                                                                                                              • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00D893FE
                                                                                                                                                                              • IsDebuggerPresent.KERNEL32 ref: 00D894CA
                                                                                                                                                                              • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00D894EA
                                                                                                                                                                              • UnhandledExceptionFilter.KERNEL32(?), ref: 00D894F4
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 254469556-0
                                                                                                                                                                              • Opcode ID: 1680311c7f7c90f3cfd56bacdfbd7f65ac9e3a02d00208909e3734067e91165c
                                                                                                                                                                              • Instruction ID: 584782af07b33f249f730fb6b9d6594345c32483cf4fa68564118c0855e17e5b
                                                                                                                                                                              • Opcode Fuzzy Hash: 1680311c7f7c90f3cfd56bacdfbd7f65ac9e3a02d00208909e3734067e91165c
                                                                                                                                                                              • Instruction Fuzzy Hash: F8313AB5D0531D9BDB21EF64D989BCDBBB8EF04300F1041DAE44CA7250EB715A858F15
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: )$)$:$\b(?=\w)
                                                                                                                                                                              • API String ID: 0-1096454370
                                                                                                                                                                              • Opcode ID: a855af3411d3cff91136866cfc841f463a15f19766891b9039c79c6663072964
                                                                                                                                                                              • Instruction ID: 0a43b6ee4c03c75d4104e71aac1d14402fd02adb3abc564c1bc2b2dbde847cf6
                                                                                                                                                                              • Opcode Fuzzy Hash: a855af3411d3cff91136866cfc841f463a15f19766891b9039c79c6663072964
                                                                                                                                                                              • Instruction Fuzzy Hash: CA324B70D042198FDB25CF68C8907ACFBB5BF09314F28819AD89AAB351C7749D86DF60
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                                • Part of subcall function 00DA1CA9: _free.LIBCMT ref: 00DA1D0B
                                                                                                                                                                                • Part of subcall function 00DA1CA9: _free.LIBCMT ref: 00DA1D41
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00DACAD4
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00DACB1E
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00DACBE4
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InfoLocale$ErrorLast_free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3140898709-0
                                                                                                                                                                              • Opcode ID: 72188304278fa87e48bcca1129fb5617a1f5a7bc26d1c5649613e556f84cb826
                                                                                                                                                                              • Instruction ID: 027694fe51ec54ca6edccaf5863af85347018022ace01935a4dac56ab1218bd1
                                                                                                                                                                              • Opcode Fuzzy Hash: 72188304278fa87e48bcca1129fb5617a1f5a7bc26d1c5649613e556f84cb826
                                                                                                                                                                              • Instruction Fuzzy Hash: 386192715202179FDB289F24CC82BBAB7A8EF15320F1850BAED09C7285E735D994DB70
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D391DE
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D3952E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_task
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 118556049-0
                                                                                                                                                                              • Opcode ID: c3560a314514efda40c6f086a8cd4e3d5d83ae3484a09588799ff44b693dd8b6
                                                                                                                                                                              • Instruction ID: 525ad596355274b3f46b90db3d6407f66e6b60a8b6a7aea12e3fb7f2e31c3bd6
                                                                                                                                                                              • Opcode Fuzzy Hash: c3560a314514efda40c6f086a8cd4e3d5d83ae3484a09588799ff44b693dd8b6
                                                                                                                                                                              • Instruction Fuzzy Hash: 4E22BE72E00219AFCF15DFA8DC51AAEF7B5FF48310F584229F815B7291DB74A9018BA1
                                                                                                                                                                              APIs
                                                                                                                                                                              • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,00DA14AA,?,?,00000008,?,?,00DB0D68,00000000), ref: 00DA16DC
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ExceptionRaise
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3997070919-0
                                                                                                                                                                              • Opcode ID: c7d48d48d5d0bcdfec232ad92f6212b77752650e053bf34e54da190f30814784
                                                                                                                                                                              • Instruction ID: 0ddf4d4eef83359c7eacebc01e91d76c3f25262585b6d20b707468f64b9d3fc9
                                                                                                                                                                              • Opcode Fuzzy Hash: c7d48d48d5d0bcdfec232ad92f6212b77752650e053bf34e54da190f30814784
                                                                                                                                                                              • Instruction Fuzzy Hash: 04B15A39610608CFD714CF28C486B647BE0FF46364F298658E8DACF2A1C335E992CB50
                                                                                                                                                                              APIs
                                                                                                                                                                              • IsProcessorFeaturePresent.KERNEL32(0000000A), ref: 00D8922B
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FeaturePresentProcessor
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2325560087-0
                                                                                                                                                                              • Opcode ID: 2c522e8cc8f1d94022035fd2107ade865551bda798282c42af51594b966f0336
                                                                                                                                                                              • Instruction ID: 062bda1468bf76dcea4d5f87acfa7c1f3f4e2530c1da97e52d7e5f9b15923805
                                                                                                                                                                              • Opcode Fuzzy Hash: 2c522e8cc8f1d94022035fd2107ade865551bda798282c42af51594b966f0336
                                                                                                                                                                              • Instruction Fuzzy Hash: E9517AB2D112059FEB14CFA5D8957AABBF0FB48311F2C856AD485EB390D375A940CB60
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: 505144d93ad4b4649c9590274202d1add9cd998eba489f8904529d10e812154c
                                                                                                                                                                              • Instruction ID: acf736b42cebd07547d15737ba9c7bfb71056ce1ad0a5c15a053d1639c178c91
                                                                                                                                                                              • Opcode Fuzzy Hash: 505144d93ad4b4649c9590274202d1add9cd998eba489f8904529d10e812154c
                                                                                                                                                                              • Instruction Fuzzy Hash: EE31D572900219AFCB24EFA9CC99DBBB7BDEB85310F144558F91597245EA30EE40CB70
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                                • Part of subcall function 00DA1CA9: _free.LIBCMT ref: 00DA1D0B
                                                                                                                                                                                • Part of subcall function 00DA1CA9: _free.LIBCMT ref: 00DA1D41
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078), ref: 00DACD34
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast_free$InfoLocale
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2003897158-0
                                                                                                                                                                              • Opcode ID: 8f76e50fdbb0e72775eecbecc16995d73c0809132fbd198353553e80f9c5d28c
                                                                                                                                                                              • Instruction ID: 6898dd0e8c2c41a584ffc8582d259e143ee4d86f5459016d3eb324ed93e3afcb
                                                                                                                                                                              • Opcode Fuzzy Hash: 8f76e50fdbb0e72775eecbecc16995d73c0809132fbd198353553e80f9c5d28c
                                                                                                                                                                              • Instruction Fuzzy Hash: 4F219576620206ABDF28AB29DC42BBA7BACEF45320F14107AFD06D6141EB34DD44DB70
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                              • EnumSystemLocalesW.KERNEL32(00DACA80,00000001,00000000,?,-00000050,?,00DAD0BB,00000000,?,?,?,00000055,?), ref: 00DAC9C4
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast$EnumLocalesSystem
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2417226690-0
                                                                                                                                                                              • Opcode ID: 6df1406159538f6185ee10646bdfe4e55a65c93d167b1b5c3a6c61f8ecc758db
                                                                                                                                                                              • Instruction ID: c448c1bad762dd67e911b10e108e64f8d7f6b7ae1611d6545f5caabaa60a8fe7
                                                                                                                                                                              • Opcode Fuzzy Hash: 6df1406159538f6185ee10646bdfe4e55a65c93d167b1b5c3a6c61f8ecc758db
                                                                                                                                                                              • Instruction Fuzzy Hash: 3911483B2103059FDB189F39C8915BBBB92FF85329B18442DE98787B40D371B902CB60
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(?,20000001,?,00000002,?,00000000,?,?,00DACC9C,00000000,00000000,?), ref: 00DACF38
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast$InfoLocale
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3736152602-0
                                                                                                                                                                              • Opcode ID: a1794b1d079a5271ebc5a622b3827d3bd86a12faf0b00bd50e978b702fabcf7e
                                                                                                                                                                              • Instruction ID: 992d32e6b0a0a263f415d8c0b96e7447c746cd06d75150a190c01fff5c923f13
                                                                                                                                                                              • Opcode Fuzzy Hash: a1794b1d079a5271ebc5a622b3827d3bd86a12faf0b00bd50e978b702fabcf7e
                                                                                                                                                                              • Instruction Fuzzy Hash: CBF0F936A20216AFDB245724CC05BBA7B59EF42774F094424ED15A3180DA34FE41C5B0
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                              • EnumSystemLocalesW.KERNEL32(00DACCE0,00000001,?,?,-00000050,?,00DAD07F,-00000050,?,?,?,00000055,?,-00000050,?,?), ref: 00DACA37
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast$EnumLocalesSystem
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2417226690-0
                                                                                                                                                                              • Opcode ID: b8482b7b793b734ed7e3cd1039701279861d9527c4af2e24e19833eb60dee854
                                                                                                                                                                              • Instruction ID: 8f2ac2b783f6bb05ac594ffee86abcd551b4a739e3b922bb7722fd648d60c1a0
                                                                                                                                                                              • Opcode Fuzzy Hash: b8482b7b793b734ed7e3cd1039701279861d9527c4af2e24e19833eb60dee854
                                                                                                                                                                              • Instruction Fuzzy Hash: 97F0F6362103085FDB149F39DC81A7ABB95EF82378F09442DF9458B690C6719C41C670
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                              • EnumSystemLocalesW.KERNEL32(00DAC860,00000001,?,?,?,00DAD0DD,-00000050,?,?,?,00000055,?,-00000050,?,?,00000004), ref: 00DAC93E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast$EnumLocalesSystem
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2417226690-0
                                                                                                                                                                              • Opcode ID: 3818c19f25408449d70b63941226646b6030ea10d81113f5648f1990d0467530
                                                                                                                                                                              • Instruction ID: 317ac5c72c8d055e35815561d61cbb3b78aeefc6e87b9f54fdcd6060f1115a4e
                                                                                                                                                                              • Opcode Fuzzy Hash: 3818c19f25408449d70b63941226646b6030ea10d81113f5648f1990d0467530
                                                                                                                                                                              • Instruction Fuzzy Hash: C8F0553A30020557CB059F7ADC06A6BBF94EFC2B30F0A4059FA098B280C2359942CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetLocaleInfoW.KERNEL32(00000000,?,00000000,?,-00000050,?,?,?,00DA0C61,?,20001004,00000000,00000002,?,?,00DA024C), ref: 00DA460E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InfoLocale
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2299586839-0
                                                                                                                                                                              • Opcode ID: e88caaf06992d89161a61592b68984cb77f4c820c957228c088e71a00f2245f9
                                                                                                                                                                              • Instruction ID: e1017c1e1ae6c203d5f471cdd18c4aebdbae582e05a15f782a5057730d8f9935
                                                                                                                                                                              • Opcode Fuzzy Hash: e88caaf06992d89161a61592b68984cb77f4c820c957228c088e71a00f2245f9
                                                                                                                                                                              • Instruction Fuzzy Hash: 87E04F3150022ABBCF122F60EC04EDE7F19EF86761F094010FD1566261CBB59921AAF8
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CloseCrypt
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1563465135-0
                                                                                                                                                                              • Opcode ID: 761988bb221e77653ace4cb3297db2c49a66e817fce2b2e784c2e796dc92d805
                                                                                                                                                                              • Instruction ID: 7b3f83b72bad152f9ae00be375d7422c3f21ec4e0f26adda025a29d1f4ecd042
                                                                                                                                                                              • Opcode Fuzzy Hash: 761988bb221e77653ace4cb3297db2c49a66e817fce2b2e784c2e796dc92d805
                                                                                                                                                                              • Instruction Fuzzy Hash: A1B012B06001004BDF049F73890C80133595B4034231804446900D1022D621C804C924
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: 0
                                                                                                                                                                              • API String ID: 0-4108050209
                                                                                                                                                                              • Opcode ID: 84466ffa83b5f578f869104dd61fd6ec5269090a1ed644bd650bd96268123642
                                                                                                                                                                              • Instruction ID: dc6ab687cf68bfacc474475ba1c48ba79c991c14217cb7324f7710d1687a1d9b
                                                                                                                                                                              • Opcode Fuzzy Hash: 84466ffa83b5f578f869104dd61fd6ec5269090a1ed644bd650bd96268123642
                                                                                                                                                                              • Instruction Fuzzy Hash: CB616A706007099EDF38AA68A491BBE7BA5EF41708F5C0A2DE582DB681D661ED81C371
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: 0
                                                                                                                                                                              • API String ID: 0-4108050209
                                                                                                                                                                              • Opcode ID: b85963471340551fc1d65e6da54e869a27c505fde31b74a5488fce3f4256d08d
                                                                                                                                                                              • Instruction ID: b88727b774696f67470993655bc73b9f131aea5b28989333df1eaa211a2c9a67
                                                                                                                                                                              • Opcode Fuzzy Hash: b85963471340551fc1d65e6da54e869a27c505fde31b74a5488fce3f4256d08d
                                                                                                                                                                              • Instruction Fuzzy Hash: DC517F70600749BEEF389A28A4957BE7F9ADF02704F1C451DD886EB283D611DE448BB2
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: :
                                                                                                                                                                              • API String ID: 0-336475711
                                                                                                                                                                              • Opcode ID: 85dc1fcb633cb364f40a4942cfd3be99533d8fdc13b5614b16b56131dfe25109
                                                                                                                                                                              • Instruction ID: 6f31cc8a9080695bb478bd58863f23738c2cd74928ca3724b13e3578e19e2e16
                                                                                                                                                                              • Opcode Fuzzy Hash: 85dc1fcb633cb364f40a4942cfd3be99533d8fdc13b5614b16b56131dfe25109
                                                                                                                                                                              • Instruction Fuzzy Hash: 2B41E7A6A41248AFEB019E5998A37DFBBA4DB77700F44409ED8001B383D565970BCBB2
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D888FA: EnterCriticalSection.KERNEL32(00E0742C,?,?,?,00D2402B,00E0827C,6EB998C3,?,00D21171,?), ref: 00D88905
                                                                                                                                                                                • Part of subcall function 00D888FA: LeaveCriticalSection.KERNEL32(00E0742C,?,?,?,00D2402B,00E0827C,6EB998C3,?,00D21171,?), ref: 00D88942
                                                                                                                                                                              • GetProcessHeap.KERNEL32(?,?,?,00D1E97C,6EB998C3,?,?,?,?,00DB9590,000000FF), ref: 00D14676
                                                                                                                                                                                • Part of subcall function 00D888B0: EnterCriticalSection.KERNEL32(00E0742C,?,?,00D24086,00E0827C,00DC68E0,?), ref: 00D888BA
                                                                                                                                                                                • Part of subcall function 00D888B0: LeaveCriticalSection.KERNEL32(00E0742C,?,?,00D24086,00E0827C,00DC68E0,?), ref: 00D888ED
                                                                                                                                                                                • Part of subcall function 00D888B0: RtlWakeAllConditionVariable.NTDLL ref: 00D88964
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CriticalSection$EnterLeave$ConditionHeapProcessVariableWake
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 325507722-0
                                                                                                                                                                              • Opcode ID: cadda88d558a831fe4ef14afbcdc78526f64b723ffb523d341628e9b79803907
                                                                                                                                                                              • Instruction ID: f5604931323e73437abf96fe69c540924e8be5e966ef047121175cf71c7ee5b4
                                                                                                                                                                              • Opcode Fuzzy Hash: cadda88d558a831fe4ef14afbcdc78526f64b723ffb523d341628e9b79803907
                                                                                                                                                                              • Instruction Fuzzy Hash: C7117C71504A01EEF350AB2AFE0674677A0E745324F59012AE6C8A72E1DF7668CCDB74
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: c93143074e084b5f39dec4510a6073ea415b1cfe3cb7f4e85a14ecd60ae03a41
                                                                                                                                                                              • Instruction ID: 376d7daca5838c92f07200c351ea84c3978355ed64f99302b4fe1e49387b4cd0
                                                                                                                                                                              • Opcode Fuzzy Hash: c93143074e084b5f39dec4510a6073ea415b1cfe3cb7f4e85a14ecd60ae03a41
                                                                                                                                                                              • Instruction Fuzzy Hash: 8B325FB3F515145BDB0CCE5DCC927ECB3E3AF98214B0E813DA81AD7345EA78D9158A84
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: 7b294939c58e553e76aee712086afaa6411dcbc10999fb7e3e07904b96a5ed17
                                                                                                                                                                              • Instruction ID: 92e8fcc6fbacdecb8e73f5f845e847538a9895ca051c57b444dca95c7f998be4
                                                                                                                                                                              • Opcode Fuzzy Hash: 7b294939c58e553e76aee712086afaa6411dcbc10999fb7e3e07904b96a5ed17
                                                                                                                                                                              • Instruction Fuzzy Hash: 47322422D29F454DD7236634CC62336A28CAFB73D5F14D727EC1AB9AA5EF29C4835120
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLastProcess_free$CurrentFeatureInfoLocalePresentProcessorTerminate
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 4283097504-0
                                                                                                                                                                              • Opcode ID: e3e8ee7636894217e7faab596445d5a44ffd32d54413ac1bb65d372df32f47ac
                                                                                                                                                                              • Instruction ID: 4e1d447a6b611625f00beeb588b735456c4217754157a5152fa5d7684e91244c
                                                                                                                                                                              • Opcode Fuzzy Hash: e3e8ee7636894217e7faab596445d5a44ffd32d54413ac1bb65d372df32f47ac
                                                                                                                                                                              • Instruction Fuzzy Hash: EEB119755107058BDB34AF64CC82BBBB3A8EF46318F58552DE943C6580EA75E985CB30
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: 36c5b734693225f8a58c84b4ae48c8a81fa5342cf49dbaae9d942c66902344f8
                                                                                                                                                                              • Instruction ID: a986b51702c61fa3d0690141b1bb17792bf63da1aada5542814062a09b05dc1a
                                                                                                                                                                              • Opcode Fuzzy Hash: 36c5b734693225f8a58c84b4ae48c8a81fa5342cf49dbaae9d942c66902344f8
                                                                                                                                                                              • Instruction Fuzzy Hash: C661467060020A6EDF38AE28A8917BEBBA5EF41704F5C4D2EF482DB281D761DE45D371
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: 3d4406a1fdde6bc6bac325aee5dd4238fab62e370ddbc8ac11956ba0301d4bd2
                                                                                                                                                                              • Instruction ID: afef0cbee880757c6d4127454cfdd10b5f92478724ee0fbc08ca3e5ca87bf97d
                                                                                                                                                                              • Opcode Fuzzy Hash: 3d4406a1fdde6bc6bac325aee5dd4238fab62e370ddbc8ac11956ba0301d4bd2
                                                                                                                                                                              • Instruction Fuzzy Hash: 36517071E00119EFDF05CFA9C991AEEBBB2EF88304F19805DE905AB241C7349E51DBA4
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: 5abbbaa323b7b018f2579ddb7873c9d6c888b9dd131c6c46dabfcdb4d4857cb8
                                                                                                                                                                              • Instruction ID: f26f6eda48933f107994e8ab6082f0fe444d3e7ab6ae2b1a9a229a69c856ae92
                                                                                                                                                                              • Opcode Fuzzy Hash: 5abbbaa323b7b018f2579ddb7873c9d6c888b9dd131c6c46dabfcdb4d4857cb8
                                                                                                                                                                              • Instruction Fuzzy Hash: D921B373F204394B7B0CC47E8C522BDB6E1C78C641745823AE8A6EA2C1D968D917E2E4
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: bfefb36dc9194c7b990f4e788c5088cccf07202c7b872c21e379b47797fdd8c8
                                                                                                                                                                              • Instruction ID: d567dfc95f3ea5ebf46a049e56c1087178621b3cde0d36de060b13bee40fa750
                                                                                                                                                                              • Opcode Fuzzy Hash: bfefb36dc9194c7b990f4e788c5088cccf07202c7b872c21e379b47797fdd8c8
                                                                                                                                                                              • Instruction Fuzzy Hash: 49117323F30C255A775C816D8C172BAA5D6EBD825070F533AD827E7284E9A4EE13D290
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(kernel32.dll), ref: 00D76AB6
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 00D76AC4
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 00D76AD5
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 00D76AE6
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00D76AF7
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00D76B08
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,InitOnceExecuteOnce), ref: 00D76B19
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00D76B2A
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CreateSemaphoreW), ref: 00D76B3B
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00D76B4C
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 00D76B5D
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 00D76B6E
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 00D76B7F
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 00D76B90
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 00D76BA1
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 00D76BB2
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 00D76BC3
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,FlushProcessWriteBuffers), ref: 00D76BD4
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,FreeLibraryWhenCallbackReturns), ref: 00D76BE5
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,GetCurrentProcessorNumber), ref: 00D76BF6
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CreateSymbolicLinkW), ref: 00D76C07
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,GetCurrentPackageId), ref: 00D76C18
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,GetTickCount64), ref: 00D76C29
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,GetFileInformationByHandleEx), ref: 00D76C3A
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,SetFileInformationByHandle), ref: 00D76C4B
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,GetSystemTimePreciseAsFileTime), ref: 00D76C5C
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,InitializeConditionVariable), ref: 00D76C6D
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,WakeConditionVariable), ref: 00D76C7E
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 00D76C8F
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 00D76CA0
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,InitializeSRWLock), ref: 00D76CB1
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,AcquireSRWLockExclusive), ref: 00D76CC2
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,TryAcquireSRWLockExclusive), ref: 00D76CD3
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,ReleaseSRWLockExclusive), ref: 00D76CE4
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,SleepConditionVariableSRW), ref: 00D76CF5
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CreateThreadpoolWork), ref: 00D76D06
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,SubmitThreadpoolWork), ref: 00D76D17
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CloseThreadpoolWork), ref: 00D76D28
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CompareStringEx), ref: 00D76D39
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,GetLocaleInfoEx), ref: 00D76D4A
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,LCMapStringEx), ref: 00D76D5B
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AddressProc$HandleModule
                                                                                                                                                                              • String ID: AcquireSRWLockExclusive$CloseThreadpoolTimer$CloseThreadpoolWait$CloseThreadpoolWork$CompareStringEx$CreateEventExW$CreateSemaphoreExW$CreateSemaphoreW$CreateSymbolicLinkW$CreateThreadpoolTimer$CreateThreadpoolWait$CreateThreadpoolWork$FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$FlushProcessWriteBuffers$FreeLibraryWhenCallbackReturns$GetCurrentPackageId$GetCurrentProcessorNumber$GetFileInformationByHandleEx$GetLocaleInfoEx$GetSystemTimePreciseAsFileTime$GetTickCount64$InitOnceExecuteOnce$InitializeConditionVariable$InitializeCriticalSectionEx$InitializeSRWLock$LCMapStringEx$ReleaseSRWLockExclusive$SetFileInformationByHandle$SetThreadpoolTimer$SetThreadpoolWait$SleepConditionVariableCS$SleepConditionVariableSRW$SubmitThreadpoolWork$TryAcquireSRWLockExclusive$WaitForThreadpoolTimerCallbacks$WakeAllConditionVariable$WakeConditionVariable$kernel32.dll
                                                                                                                                                                              • API String ID: 667068680-295688737
                                                                                                                                                                              • Opcode ID: fcc005ab27ab52b4fcd51f69464b22f6ee4c1aba904cf5e4c85529b17061115c
                                                                                                                                                                              • Instruction ID: d6984e24c7f77f0880980d2f116617c1b9ba13b4bb83132cb8b8ca82619d823f
                                                                                                                                                                              • Opcode Fuzzy Hash: fcc005ab27ab52b4fcd51f69464b22f6ee4c1aba904cf5e4c85529b17061115c
                                                                                                                                                                              • Instruction Fuzzy Hash: D961F0B1D96312AFDB406FB6AC4DD563BA8BB19702304092BB141E73B1D6F55088EBB1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • ctype.LIBCPMT ref: 00D7E830
                                                                                                                                                                                • Part of subcall function 00D13055: __Getctype.LIBCPMT ref: 00D13064
                                                                                                                                                                                • Part of subcall function 00D77D5B: __EH_prolog3.LIBCMT ref: 00D77D62
                                                                                                                                                                                • Part of subcall function 00D77D5B: std::_Lockit::_Lockit.LIBCPMT ref: 00D77D6C
                                                                                                                                                                                • Part of subcall function 00D77D5B: std::_Lockit::~_Lockit.LIBCPMT ref: 00D77DDD
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E83E
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E855
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E89C
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E8CF
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E921
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E936
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E955
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E974
                                                                                                                                                                              • collate.LIBCPMT ref: 00D7E97E
                                                                                                                                                                              • __Getcoll.LIBCPMT ref: 00D7E9C0
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E9D4
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EABD
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EB18
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EB74
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EB89
                                                                                                                                                                                • Part of subcall function 00D7816E: __EH_prolog3.LIBCMT ref: 00D78175
                                                                                                                                                                                • Part of subcall function 00D7816E: std::_Lockit::_Lockit.LIBCPMT ref: 00D7817F
                                                                                                                                                                                • Part of subcall function 00D7816E: std::_Lockit::~_Lockit.LIBCPMT ref: 00D781F0
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EBA8
                                                                                                                                                                                • Part of subcall function 00D783C2: __EH_prolog3.LIBCMT ref: 00D783C9
                                                                                                                                                                                • Part of subcall function 00D783C2: std::_Lockit::_Lockit.LIBCPMT ref: 00D783D3
                                                                                                                                                                                • Part of subcall function 00D783C2: std::_Lockit::~_Lockit.LIBCPMT ref: 00D78444
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EBC7
                                                                                                                                                                                • Part of subcall function 00D7832D: __EH_prolog3.LIBCMT ref: 00D78334
                                                                                                                                                                                • Part of subcall function 00D7832D: std::_Lockit::_Lockit.LIBCPMT ref: 00D7833E
                                                                                                                                                                                • Part of subcall function 00D7832D: std::_Lockit::~_Lockit.LIBCPMT ref: 00D783AF
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EBE6
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EC38
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EC7D
                                                                                                                                                                                • Part of subcall function 00D7DDD2: __EH_prolog3.LIBCMT ref: 00D7DDD9
                                                                                                                                                                                • Part of subcall function 00D7DDD2: _Getvals.LIBCPMT ref: 00D7DE2B
                                                                                                                                                                                • Part of subcall function 00D7DDD2: _Mpunct.LIBCPMT ref: 00D7DE66
                                                                                                                                                                                • Part of subcall function 00D7DDD2: _Mpunct.LIBCPMT ref: 00D7DE80
                                                                                                                                                                                • Part of subcall function 00D78044: __EH_prolog3.LIBCMT ref: 00D7804B
                                                                                                                                                                                • Part of subcall function 00D78044: std::_Lockit::_Lockit.LIBCPMT ref: 00D78055
                                                                                                                                                                                • Part of subcall function 00D78044: std::_Lockit::~_Lockit.LIBCPMT ref: 00D780C6
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EA41
                                                                                                                                                                                • Part of subcall function 00D75688: Concurrency::cancel_current_task.LIBCPMT ref: 00D75748
                                                                                                                                                                                • Part of subcall function 00D75688: __EH_prolog3.LIBCMT ref: 00D75755
                                                                                                                                                                                • Part of subcall function 00D75688: std::locale::_Locimp::_Makeloc.LIBCPMT ref: 00D75781
                                                                                                                                                                                • Part of subcall function 00D75688: std::_Locinfo::~_Locinfo.LIBCPMT ref: 00D7578C
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7E9EB
                                                                                                                                                                                • Part of subcall function 00D75688: __EH_prolog3.LIBCMT ref: 00D7568F
                                                                                                                                                                                • Part of subcall function 00D75688: std::_Lockit::_Lockit.LIBCPMT ref: 00D75699
                                                                                                                                                                                • Part of subcall function 00D75688: std::_Lockit::~_Lockit.LIBCPMT ref: 00D7573D
                                                                                                                                                                                • Part of subcall function 00D77F1A: __EH_prolog3.LIBCMT ref: 00D77F21
                                                                                                                                                                                • Part of subcall function 00D77F1A: std::_Lockit::_Lockit.LIBCPMT ref: 00D77F2B
                                                                                                                                                                                • Part of subcall function 00D77F1A: std::_Lockit::~_Lockit.LIBCPMT ref: 00D77F9C
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EA2C
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D7EA8A
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Locimp::_std::locale::_$AddfacLocimp_$std::_$Lockit$H_prolog3$Lockit::_Lockit::~_$Mpunct$Concurrency::cancel_current_taskGetcollGetctypeGetvalsLocinfoLocinfo::~_Makeloccollatectype
                                                                                                                                                                              • String ID: s$$s$(s$,s$0s$0s$4s$4s$8s$8s$<s$u{jD
                                                                                                                                                                              • API String ID: 207879573-273142262
                                                                                                                                                                              • Opcode ID: 06dfadb385ad5f7589ce49ca3e3df35703a80e111981669394eb6e4104bf7dc1
                                                                                                                                                                              • Instruction ID: 912191a4464da1ffd61e9887d28f235d3707a623ae3a2a1a15e774dcea5419ab
                                                                                                                                                                              • Opcode Fuzzy Hash: 06dfadb385ad5f7589ce49ca3e3df35703a80e111981669394eb6e4104bf7dc1
                                                                                                                                                                              • Instruction Fuzzy Hash: 08D1E3B0C01216AEEB206F64D806ABF7BA4EF45750F1484ADF8486B381FB758D5097F2
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D85D6D
                                                                                                                                                                              • collate.LIBCPMT ref: 00D85D76
                                                                                                                                                                                • Part of subcall function 00D84A42: __EH_prolog3_GS.LIBCMT ref: 00D84A49
                                                                                                                                                                                • Part of subcall function 00D84A42: __Getcoll.LIBCPMT ref: 00D84AAD
                                                                                                                                                                                • Part of subcall function 00D84A42: std::_Locinfo::~_Locinfo.LIBCPMT ref: 00D84AC9
                                                                                                                                                                              • __Getcoll.LIBCPMT ref: 00D85DBC
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85DD0
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85DE5
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85E23
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85E36
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85E7C
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85EB0
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85F6B
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85F7E
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85F9B
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85FB8
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85FD5
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D85F0D
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • numpunct.LIBCPMT ref: 00D86014
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D86024
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D86068
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D8607B
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D86098
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AddfacLocimp::_Locimp_std::locale::_$std::_$GetcollLockit$H_prolog3H_prolog3_LocinfoLocinfo::~_Lockit::_Lockit::~_collatenumpunct
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2009638416-0
                                                                                                                                                                              • Opcode ID: e0aba5c3bcbf27149643671afb25989fd2edcf73bb2b7ed9d85cb8dfb0622928
                                                                                                                                                                              • Instruction ID: 8d35448be6f3f5bb435c76dc42fe09c06fea85d03ff11f5a01b137760559e3ec
                                                                                                                                                                              • Opcode Fuzzy Hash: e0aba5c3bcbf27149643671afb25989fd2edcf73bb2b7ed9d85cb8dfb0622928
                                                                                                                                                                              • Instruction Fuzzy Hash: E39119B0C01612AFEB207B74AC06BBF7AA8DF41750F544469F849A7285EF748D0097F2
                                                                                                                                                                              Strings
                                                                                                                                                                              • Failed to parse DeleteFile as a boolean - default to false, xrefs: 00D608D9
                                                                                                                                                                              • Unable to substitute DeleteFile attribute, xrefs: 00D608BC
                                                                                                                                                                              • Unable to substitute variables for the EXTRACT_CAB_LOCAL command, xrefs: 00D60A31
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\ExtractCabLocalCommand.cpp, xrefs: 00D608E5, 00D60962, 00D609A7, 00D609DE, 00D60A19, 00D60A49
                                                                                                                                                                              • invalid substitutor, xrefs: 00D607C5
                                                                                                                                                                              • Unable to create destination directory (%d), xrefs: 00D6099B
                                                                                                                                                                              • Failed to extract cab (%s), xrefs: 00D609D2
                                                                                                                                                                              • Unable to read Source and/or DestDir attribute of EXTRACT_CAB_LOCAL command, xrefs: 00D60A3D, 00D60A42
                                                                                                                                                                              • DeleteFile, xrefs: 00D6086B
                                                                                                                                                                              • NWebAdvisor::NXmlUpdater::CExtractCabLocalCommand::Execute, xrefs: 00D608E0, 00D60A44
                                                                                                                                                                              • DestDir, xrefs: 00D60813
                                                                                                                                                                              • NWebAdvisor::NXmlUpdater::CExtractCabLocalCommand::ExecuteExtractCabLocalCommand, xrefs: 00D6095D, 00D609A2, 00D609D9, 00D60A14
                                                                                                                                                                              • Source, xrefs: 00D607D1
                                                                                                                                                                              • Unable to verify signature for file: %s, xrefs: 00D60956
                                                                                                                                                                              • Failed to delete src cab (%d), xrefs: 00D60A0D
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: DeleteFile$DestDir$Failed to delete src cab (%d)$Failed to extract cab (%s)$Failed to parse DeleteFile as a boolean - default to false$NWebAdvisor::NXmlUpdater::CExtractCabLocalCommand::Execute$NWebAdvisor::NXmlUpdater::CExtractCabLocalCommand::ExecuteExtractCabLocalCommand$Source$Unable to create destination directory (%d)$Unable to read Source and/or DestDir attribute of EXTRACT_CAB_LOCAL command$Unable to substitute DeleteFile attribute$Unable to substitute variables for the EXTRACT_CAB_LOCAL command$Unable to verify signature for file: %s$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\ExtractCabLocalCommand.cpp$invalid substitutor
                                                                                                                                                                              • API String ID: 0-2605792675
                                                                                                                                                                              • Opcode ID: b21308dd37e393c797a0aad1d88e22e9566b4dfcedb02bf15819c013b55b9003
                                                                                                                                                                              • Instruction ID: b102336207bcb822a9ad47a44718dc5560d17a34523f95c08992f37fe430ff2a
                                                                                                                                                                              • Opcode Fuzzy Hash: b21308dd37e393c797a0aad1d88e22e9566b4dfcedb02bf15819c013b55b9003
                                                                                                                                                                              • Instruction Fuzzy Hash: B191CF70A40304AFDB10EF94D856BAFBBB5EF15745F08041AF50567382EBB5A948CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D2DE80: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2DF0C
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D2A143
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2A1AA
                                                                                                                                                                                • Part of subcall function 00D2E0D0: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E161
                                                                                                                                                                              • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000), ref: 00D2A1C1
                                                                                                                                                                              • CloseHandle.KERNEL32(?), ref: 00D2A1DD
                                                                                                                                                                              • CreateSemaphoreW.KERNEL32(00000000,00000000,000003E8,00000000), ref: 00D2A24C
                                                                                                                                                                              • CloseHandle.KERNEL32(?), ref: 00D2A268
                                                                                                                                                                              • ReleaseSemaphore.KERNEL32(?,00000001,00000000,?,00000000), ref: 00D2A410
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001), ref: 00D2A46F
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$CloseCreateHandleSemaphore$ErrorEventLastMtx_unlockRelease
                                                                                                                                                                              • String ID: E$Failed to create event semaphore$Failed to create stop event$Failed to initialize event sender$Failed to release semaphore. Error: $V
                                                                                                                                                                              • API String ID: 1380281556-3274429967
                                                                                                                                                                              • Opcode ID: e523a4519ebacc05d46f7597e9f67df93c16fd62ebc12a6668bd0d3dbce23706
                                                                                                                                                                              • Instruction ID: abc9a18d4bdf777df5940fff5ac896d46a1b45ce7c8020aee0fb2706a41b960e
                                                                                                                                                                              • Opcode Fuzzy Hash: e523a4519ebacc05d46f7597e9f67df93c16fd62ebc12a6668bd0d3dbce23706
                                                                                                                                                                              • Instruction Fuzzy Hash: 53B1F2B0A00309ABDB04EF64DC52BEEB7B5FF14314F044169E41967281EB71AA55CFB2
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(kernel32.dll,6EB998C3,000000FF,00000000,00000000,00DBDF30,000000FF), ref: 00D60FE8
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CreateFileTransactedW), ref: 00D60FF8
                                                                                                                                                                              • CreateFileW.KERNEL32(000000FF,00000001,00000001,00000000,00000003,00000080,00000000,6EB998C3,000000FF,00000000,00000000,00DBDF30,000000FF), ref: 00D61037
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D61058
                                                                                                                                                                              • GetFileSize.KERNEL32(?,?), ref: 00D61088
                                                                                                                                                                              • CreateFileMappingW.KERNEL32(?,00000000,00000002,?,00000000,00000000), ref: 00D6109C
                                                                                                                                                                              • MapViewOfFileEx.KERNEL32(00000000,00000004,00000000,00000000,?,00000000), ref: 00D610D9
                                                                                                                                                                              • CloseHandle.KERNEL32(?), ref: 00D610F0
                                                                                                                                                                              Strings
                                                                                                                                                                              • NWebAdvisor::CFileMemMap::Init, xrefs: 00D61066, 00D61108
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\FileMemMap.h, xrefs: 00D6106B, 00D6110D
                                                                                                                                                                              • CreateFileTransactedW, xrefs: 00D60FF2
                                                                                                                                                                              • Failed to open the file: %d, xrefs: 00D6105F
                                                                                                                                                                              • kernel32.dll, xrefs: 00D60FE3
                                                                                                                                                                              • Failed to map file to memory, xrefs: 00D61101
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: File$CreateHandle$AddressCloseErrorLastMappingModuleProcSizeView
                                                                                                                                                                              • String ID: CreateFileTransactedW$Failed to map file to memory$Failed to open the file: %d$NWebAdvisor::CFileMemMap::Init$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\FileMemMap.h$kernel32.dll
                                                                                                                                                                              • API String ID: 2423579280-2843467768
                                                                                                                                                                              • Opcode ID: 91738e4e32c98b8da9a1778cc4e2ded36db653e7a99fb17500d1dbf796a8438a
                                                                                                                                                                              • Instruction ID: be9d04ae7fb2cf83162b0d7220ed734b68bdcab77b478a28036ec87a85a814a8
                                                                                                                                                                              • Opcode Fuzzy Hash: 91738e4e32c98b8da9a1778cc4e2ded36db653e7a99fb17500d1dbf796a8438a
                                                                                                                                                                              • Instruction Fuzzy Hash: 0A41B4B5640302BFEB209F60DC46F6ABBA8FB04B10F144615FA15E62C0D7B5A9448BB5
                                                                                                                                                                              APIs
                                                                                                                                                                              • SHGetSpecialFolderPathW.SHELL32(00000000,00DFF278,00000023,00000001,00000004,00000000,00000000), ref: 00D48462
                                                                                                                                                                              • CreateDirectoryW.KERNEL32(00DFF278,00000000,00DFF278,00000104,\McAfee\), ref: 00D48491
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D4849D
                                                                                                                                                                              • CreateDirectoryW.KERNEL32(00DFF278,00000000,00DFF278,00000104,00DFF070), ref: 00D484C5
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D484CB
                                                                                                                                                                              • GetModuleFileNameW.KERNEL32(?,00000104), ref: 00D484FC
                                                                                                                                                                              • StrRChrW.SHLWAPI(?,00000000,0000005C), ref: 00D48511
                                                                                                                                                                              • CreateDirectoryW.KERNEL32(00DFF278,00000000,00DFF278,00000104,00000000), ref: 00D4852E
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D48534
                                                                                                                                                                              • GetTickCount.KERNEL32 ref: 00D485B9
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CreateDirectoryErrorLast$CountFileFolderModuleNamePathSpecialTick
                                                                                                                                                                              • String ID: %uFile:%sFunction:%sLine:%d$\McAfee\$\log.txt
                                                                                                                                                                              • API String ID: 922589859-3713371193
                                                                                                                                                                              • Opcode ID: dd897b0c8660ffcdef32cfbad208e2d2b8b0e76ec466e23ea1e2cea15e07eabd
                                                                                                                                                                              • Instruction ID: 6545e937a1896f85bbd199a3a6f516dc8d643199e5c5cbaa6a16a4a9db06443f
                                                                                                                                                                              • Opcode Fuzzy Hash: dd897b0c8660ffcdef32cfbad208e2d2b8b0e76ec466e23ea1e2cea15e07eabd
                                                                                                                                                                              • Instruction Fuzzy Hash: 8D511A75A803096FDF10AB68EC46FED77A4AF14740F1445A1F908F3291CAB09984DFB9
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _free$Info
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2509303402-0
                                                                                                                                                                              • Opcode ID: b8813971caf06a68081d0d65fcd2ddb26d7867081ce90d040a7d55045226ad7c
                                                                                                                                                                              • Instruction ID: f71725fce00c06e938f2b13528e4b4502b6b7aaef83d0b4bf507ea2f281ffc0e
                                                                                                                                                                              • Opcode Fuzzy Hash: b8813971caf06a68081d0d65fcd2ddb26d7867081ce90d040a7d55045226ad7c
                                                                                                                                                                              • Instruction Fuzzy Hash: 8AD17D719003059FDF21DFB9C881BAEBBB6FF09300F184169E899A7292D771A945CB74
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleExW.KERNEL32(00000006,?,?,?,?,?,?,?,?,?,?,?,00000003,?,?), ref: 00D95B0F
                                                                                                                                                                              • GetModuleFileNameW.KERNEL32(?,?,00000105,?,?,?,?,?,?,?,?,?,00000003,?,?), ref: 00D95B33
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Module$FileHandleName
                                                                                                                                                                              • String ID: (Press Retry to debug the application - JIT must be enabled)$...$<program name unknown>$Assertion failed!$Expression: $File: $For information on how your program can cause an assertionfailure, see the Visual C++ documentation on asserts$Line: $Program: $\
                                                                                                                                                                              • API String ID: 4146042529-3261600717
                                                                                                                                                                              • Opcode ID: 040e5daa922a88dd0a735d97dd64438c040b7533dbfe27bd196f31f367e08236
                                                                                                                                                                              • Instruction ID: 0d788802fbd9f2ebe79721cdf3718c711a2cae591620b531243fc965f5605b56
                                                                                                                                                                              • Opcode Fuzzy Hash: 040e5daa922a88dd0a735d97dd64438c040b7533dbfe27bd196f31f367e08236
                                                                                                                                                                              • Instruction Fuzzy Hash: 36C14D71A0060A6AEF257F25AC46FAB3768EFA5750F0805B8FC09D114AF7309E56CB74
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2E8A8
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitIos_base_dtorOncestd::ios_base::_$BeginCompleteInitialize
                                                                                                                                                                              • String ID: Authorization: $Failed to create access token$HTTP receive response failed for Azure: $HTTP send request failed for Azure: $HTTP status error for Azure: $`aso
                                                                                                                                                                              • API String ID: 539357862-1443210642
                                                                                                                                                                              • Opcode ID: 06a97de0fb0005e82dfbe4e71b7c0a2e3a8795252609c8443b87aba8451da490
                                                                                                                                                                              • Instruction ID: f9e54d0d51dc133c832a912369701c0f8015605c0c60184765541a4b4a4a75c4
                                                                                                                                                                              • Opcode Fuzzy Hash: 06a97de0fb0005e82dfbe4e71b7c0a2e3a8795252609c8443b87aba8451da490
                                                                                                                                                                              • Instruction Fuzzy Hash: A2D17D70A002299FDB24EB60EE55BEDB3B4EF55308F5044D8E509A7281DB70AAC8DF71
                                                                                                                                                                              APIs
                                                                                                                                                                              • InitializeCriticalSectionAndSpinCount.KERNEL32(00E0742C,00000FA0,?,?,00D887C5), ref: 00D887F3
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(api-ms-win-core-synch-l1-2-0.dll,?,?,00D887C5), ref: 00D887FE
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(kernel32.dll,?,?,00D887C5), ref: 00D8880F
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,SleepConditionVariableCS), ref: 00D88821
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,WakeAllConditionVariable), ref: 00D8882F
                                                                                                                                                                              • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,?,00D887C5), ref: 00D88852
                                                                                                                                                                              • DeleteCriticalSection.KERNEL32(00E0742C,00000007,?,?,00D887C5), ref: 00D88875
                                                                                                                                                                              • CloseHandle.KERNEL32(00000000,?,?,00D887C5), ref: 00D88885
                                                                                                                                                                              Strings
                                                                                                                                                                              • api-ms-win-core-synch-l1-2-0.dll, xrefs: 00D887F9
                                                                                                                                                                              • WakeAllConditionVariable, xrefs: 00D88827
                                                                                                                                                                              • SleepConditionVariableCS, xrefs: 00D8881B
                                                                                                                                                                              • kernel32.dll, xrefs: 00D8880A
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Handle$AddressCriticalModuleProcSection$CloseCountCreateDeleteEventInitializeSpin
                                                                                                                                                                              • String ID: SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
                                                                                                                                                                              • API String ID: 2565136772-3242537097
                                                                                                                                                                              • Opcode ID: c4bd05746a685daa8defa70a982ab7b88963f2856c9f93cecf11026c3eb78be7
                                                                                                                                                                              • Instruction ID: b8547933b1d6228ccf1edac751695bfc38c786b289488cf1a3e02cec6e8909e1
                                                                                                                                                                              • Opcode Fuzzy Hash: c4bd05746a685daa8defa70a982ab7b88963f2856c9f93cecf11026c3eb78be7
                                                                                                                                                                              • Instruction Fuzzy Hash: 420171B1E457136FDB202B76BC49E2A3F68EB44B51B880421F955E33A0DEB09845A771
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D50490: CreateDirectoryW.KERNEL32(?,00000000,?), ref: 00D504AA
                                                                                                                                                                                • Part of subcall function 00D50490: GetLastError.KERNEL32 ref: 00D504B8
                                                                                                                                                                              • CreateFileW.KERNEL32(00000000,40000000,00000000,00000000,00000002,00000080,00000000,00000000,00000000,?,00000000,00000000,00000000,0000005C,00000001,00000000), ref: 00D50BB5
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D50BC2
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CreateErrorLast$DirectoryFile
                                                                                                                                                                              • String ID: CreateDir failed for %s$CreateFile failed for %s: %d$NWebAdvisor::NUtils::StoreBufferInFile$WriteFile failed: %d$\$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\FileUtils.cpp
                                                                                                                                                                              • API String ID: 1552088572-2321083101
                                                                                                                                                                              • Opcode ID: 07a443c25136dc43ad0b38ee7f10579ed5315bdd7136f8bd43fcddb3cd774852
                                                                                                                                                                              • Instruction ID: c946496aa48bc55376b9a987f21473fefa412003404353794ea033783960547e
                                                                                                                                                                              • Opcode Fuzzy Hash: 07a443c25136dc43ad0b38ee7f10579ed5315bdd7136f8bd43fcddb3cd774852
                                                                                                                                                                              • Instruction Fuzzy Hash: B5A15C71D00349AEDF10DFA4C855BEEBBB4EF58314F184219E905B7291DB706A89CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D1BA20: Concurrency::cancel_current_task.LIBCPMT ref: 00D1BB9D
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2DBE9
                                                                                                                                                                                • Part of subcall function 00D2D740: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2D7E7
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2DB35
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2DF0C
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$InitOnce$BeginCompleteConcurrency::cancel_current_taskInitialize
                                                                                                                                                                              • String ID: &se=$&sig=$&skn=$Event Sender already initialized for Azure$Failed to create HMACSha256 Hash$Failed to escape hash$SharedAccessSignature sr=
                                                                                                                                                                              • API String ID: 3638550806-2007429668
                                                                                                                                                                              • Opcode ID: a33a2f98cf461fcda75400bbbd94b12374e14ed698f806adc69bc13f681045f7
                                                                                                                                                                              • Instruction ID: cd5397dd7b187b180863e81cb96093f1fd50a878ef0203358f8faacfe8cfce4a
                                                                                                                                                                              • Opcode Fuzzy Hash: a33a2f98cf461fcda75400bbbd94b12374e14ed698f806adc69bc13f681045f7
                                                                                                                                                                              • Instruction Fuzzy Hash: EFE1F270D00258ABDF14EBA4EC95BDDB776EF55308F108198E409A7291EB74AB84CF71
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(kernel32.dll,00DEA536,00000003), ref: 00D491C9
                                                                                                                                                                              • FindResourceW.KERNEL32(00000000,00000001,00000010), ref: 00D491DE
                                                                                                                                                                              • LoadResource.KERNEL32(00000000,00000000), ref: 00D491EE
                                                                                                                                                                              • LockResource.KERNEL32(00000000), ref: 00D491FD
                                                                                                                                                                              Strings
                                                                                                                                                                              • NWebAdvisor::NXmlUpdater::CSubstitutionManager::GetOsVersion, xrefs: 00D4927F, 00D49336
                                                                                                                                                                              • Failed to format version, xrefs: 00D49275
                                                                                                                                                                              • %d.%d.%d.%d, xrefs: 00D4925E
                                                                                                                                                                              • Failed to retrieve kernel verison, xrefs: 00D4932C
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\SubstitutionManager.cpp, xrefs: 00D49284, 00D4933B
                                                                                                                                                                              • kernel32.dll, xrefs: 00D491B8
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Resource$FindHandleLoadLockModule
                                                                                                                                                                              • String ID: %d.%d.%d.%d$Failed to format version$Failed to retrieve kernel verison$NWebAdvisor::NXmlUpdater::CSubstitutionManager::GetOsVersion$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\SubstitutionManager.cpp$kernel32.dll
                                                                                                                                                                              • API String ID: 3968257194-3470154288
                                                                                                                                                                              • Opcode ID: 1383c8078c10ecf902a9b81ed9a543f1832f332f1dc967e474deefab06d100cc
                                                                                                                                                                              • Instruction ID: d709da5208215aaaaa2a2e2e81e9a6d02adb3211aaa896cb3752971d97ce4016
                                                                                                                                                                              • Opcode Fuzzy Hash: 1383c8078c10ecf902a9b81ed9a543f1832f332f1dc967e474deefab06d100cc
                                                                                                                                                                              • Instruction Fuzzy Hash: 4C512774600311AFCB24AF25CC59B6BB7B4EF04704F44469DF80AAB2C2D7719A45CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D75853
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D75866
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D758AB
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D758DF
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D75933
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D75946
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D75963
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D75980
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D759BD
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D759D0
                                                                                                                                                                              • std::locale::_Locimp::_Makeushloc.LIBCPMT ref: 00D759F8
                                                                                                                                                                                • Part of subcall function 00D3C930: __Getctype.LIBCPMT ref: 00D3C948
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Locimp::_std::locale::_$AddfacLocimp_$Lockitstd::_$GetctypeLockit::_Lockit::~_Makeushloc
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1462480416-0
                                                                                                                                                                              • Opcode ID: dd7fa1d171a085e9d80e4e9e21c9589ff6f772e0198785d77042fb825c3888cb
                                                                                                                                                                              • Instruction ID: 91cd33490e9b76ec3e1ca78cb7ebbcb268eabc9b26dfc2be4f1fb1115d46ce7c
                                                                                                                                                                              • Opcode Fuzzy Hash: dd7fa1d171a085e9d80e4e9e21c9589ff6f772e0198785d77042fb825c3888cb
                                                                                                                                                                              • Instruction Fuzzy Hash: 165105B1901612AFEB117B70AC46ABF6A68DF41320F548459F94CA7282FFB4D90097F3
                                                                                                                                                                              APIs
                                                                                                                                                                              • __Mtx_destroy_in_situ.LIBCPMT ref: 00D29C1A
                                                                                                                                                                              Strings
                                                                                                                                                                              • Wait timeout. Should not have gotten this..., xrefs: 00D2A86F
                                                                                                                                                                              • Wait failed: , xrefs: 00D2A93F
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Mtx_destroy_in_situ
                                                                                                                                                                              • String ID: Wait failed: $Wait timeout. Should not have gotten this...
                                                                                                                                                                              • API String ID: 3543493169-4232610396
                                                                                                                                                                              • Opcode ID: 2e7f8ae374462d4f1b76de2471a4e86d959e021d47a501aa195fcd2ced4ad59d
                                                                                                                                                                              • Instruction ID: 911807d1e65ec3b1f4778ff88d162396f12d4f3f3aa5cb1cb3f69d5d6096ec59
                                                                                                                                                                              • Opcode Fuzzy Hash: 2e7f8ae374462d4f1b76de2471a4e86d959e021d47a501aa195fcd2ced4ad59d
                                                                                                                                                                              • Instruction Fuzzy Hash: B7E1BDB0900A549FDB24DF68D894BEBB7E5FF14308F04051DE56A97280EB74A948CF76
                                                                                                                                                                              APIs
                                                                                                                                                                              • IsInExceptionSpec.LIBVCRUNTIME ref: 00D8C435
                                                                                                                                                                              • type_info::operator==.LIBVCRUNTIME ref: 00D8C457
                                                                                                                                                                              • ___TypeMatch.LIBVCRUNTIME ref: 00D8C566
                                                                                                                                                                              • IsInExceptionSpec.LIBVCRUNTIME ref: 00D8C638
                                                                                                                                                                              • _UnwindNestedFrames.LIBCMT ref: 00D8C6BC
                                                                                                                                                                              • CallUnexpected.LIBVCRUNTIME ref: 00D8C6D7
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ExceptionSpec$CallFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                                                                                                                                                              • String ID: csm$csm$csm
                                                                                                                                                                              • API String ID: 2123188842-393685449
                                                                                                                                                                              • Opcode ID: d43deaedd5ec20c3e1c9466564b03c0916df67e4f372bab2f04cabdc756eb077
                                                                                                                                                                              • Instruction ID: df83d427b29f403bc1153ab30cbf437f595ba517562b9f51eb5f4a25301a395e
                                                                                                                                                                              • Opcode Fuzzy Hash: d43deaedd5ec20c3e1c9466564b03c0916df67e4f372bab2f04cabdc756eb077
                                                                                                                                                                              • Instruction Fuzzy Hash: C1B18D71810209EFCF15FFA8C9819AEBBB5FF04310B18656AE9156B212D731EA51CFB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • DeviceIoControl.KERNEL32(6EB998C3,9EDBA51C,00000000,00000000,00000000,00000000,?,00000000), ref: 00D269E9
                                                                                                                                                                              • CloseHandle.KERNEL32(6EB998C3,?,?,00000000), ref: 00D269FB
                                                                                                                                                                              • DeviceIoControl.KERNEL32(00000000,9EDB651C,00000000,00000000,00000000,00000000,?,00000000), ref: 00D26A2A
                                                                                                                                                                              • CloseHandle.KERNEL32(00000000,?,?,00000000), ref: 00D26A3D
                                                                                                                                                                              • GetModuleHandleExW.KERNEL32(00000000,mfeaaca.dll,?), ref: 00D26A8B
                                                                                                                                                                              • GetProcAddress.KERNEL32(?,NotComDllUnload), ref: 00D26A9E
                                                                                                                                                                              • FreeLibrary.KERNEL32(00000000), ref: 00D26AB8
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Handle$CloseControlDevice$AddressFreeLibraryModuleProc
                                                                                                                                                                              • String ID: NotComDllUnload$mfeaaca.dll
                                                                                                                                                                              • API String ID: 2321898493-1077453148
                                                                                                                                                                              • Opcode ID: 285659801bd039286c080cfcee07fb572ff9a62814974f7181b98e35921845c0
                                                                                                                                                                              • Instruction ID: ee1fa0c947fa6848dc20bee24b398c927610165c5e134da593c085f128a37931
                                                                                                                                                                              • Opcode Fuzzy Hash: 285659801bd039286c080cfcee07fb572ff9a62814974f7181b98e35921845c0
                                                                                                                                                                              • Instruction Fuzzy Hash: E6318DB13003129BDB209F25EC89F2A77A8EF54B15F184619F915EB2D1DB70EC05CAB2
                                                                                                                                                                              APIs
                                                                                                                                                                              Strings
                                                                                                                                                                              • Unable to set proxy option, error: %d, xrefs: 00D643CE
                                                                                                                                                                              • NWebAdvisor::CHttpTransaction::SetAutoProxy, xrefs: 00D64325
                                                                                                                                                                              • # SetAutoProxyUrl: Can't get proxy. Err: %d, xrefs: 00D64381
                                                                                                                                                                              • NWebAdvisor::CHttpTransaction::SetAutoProxyUrl, xrefs: 00D64388
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\HttpTransaction_sacore.cpp, xrefs: 00D6432A, 00D6438D, 00D643DD
                                                                                                                                                                              • # SetAutoProxy: Can't get proxy. Err: %d, xrefs: 00D6431E
                                                                                                                                                                              • NWebAdvisor::CHttpTransaction::Connect, xrefs: 00D643D8
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast
                                                                                                                                                                              • String ID: # SetAutoProxy: Can't get proxy. Err: %d$# SetAutoProxyUrl: Can't get proxy. Err: %d$NWebAdvisor::CHttpTransaction::Connect$NWebAdvisor::CHttpTransaction::SetAutoProxy$NWebAdvisor::CHttpTransaction::SetAutoProxyUrl$Unable to set proxy option, error: %d$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\HttpTransaction_sacore.cpp
                                                                                                                                                                              • API String ID: 1452528299-2881327693
                                                                                                                                                                              • Opcode ID: 399bd0027db8956db69934c080f35a7c091f984a01097c42a51385d8badb4b6a
                                                                                                                                                                              • Instruction ID: 632c14809a7c8fec073b679c388d1f85a5d50edda47561643ff4fdec5ae9f977
                                                                                                                                                                              • Opcode Fuzzy Hash: 399bd0027db8956db69934c080f35a7c091f984a01097c42a51385d8badb4b6a
                                                                                                                                                                              • Instruction Fuzzy Hash: CB418D70A40309EFEB10DFA4CC45BAEBBF8EF18714F04801AE914B6280DBB19944CBB4
                                                                                                                                                                              APIs
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1BA7
                                                                                                                                                                                • Part of subcall function 00DA2098: RtlFreeHeap.NTDLL(00000000,00000000,?,00DAB729,?,00000000,?,?,?,00DAB9CC,?,00000007,?,?,00DABDD6,?), ref: 00DA20AE
                                                                                                                                                                                • Part of subcall function 00DA2098: GetLastError.KERNEL32(?,?,00DAB729,?,00000000,?,?,?,00DAB9CC,?,00000007,?,?,00DABDD6,?,?), ref: 00DA20C0
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1BB3
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1BBE
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1BC9
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1BD4
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1BDF
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1BEA
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1BF5
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1C00
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1C0E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _free$ErrorFreeHeapLast
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 776569668-0
                                                                                                                                                                              • Opcode ID: d7ad23a40b7546b1be6902dad06d0bf83bd7780782dfd48dcc91bcefd10a435e
                                                                                                                                                                              • Instruction ID: dd1a6ae3a8b65972ca87443bccff6cec70410c8a53ab8ff585b565d1af34e280
                                                                                                                                                                              • Opcode Fuzzy Hash: d7ad23a40b7546b1be6902dad06d0bf83bd7780782dfd48dcc91bcefd10a435e
                                                                                                                                                                              • Instruction Fuzzy Hash: A1217B76900108AFCB41EFA9C841DEE7BB9FF09340F4145A5F515AB221EB31EA58CBA4
                                                                                                                                                                              APIs
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: __aulldvrm
                                                                                                                                                                              • String ID: :$f$f$f$p$p$p
                                                                                                                                                                              • API String ID: 1302938615-1434680307
                                                                                                                                                                              • Opcode ID: cea7733dabf86bc5c6ea0c60d40b02c71f29b3b5f468f1def6264aa648266a2d
                                                                                                                                                                              • Instruction ID: 5ca404b8ebd9e2d190737b7c276b76d4966371a5d73ee207a8272fc081fcf9a4
                                                                                                                                                                              • Opcode Fuzzy Hash: cea7733dabf86bc5c6ea0c60d40b02c71f29b3b5f468f1def6264aa648266a2d
                                                                                                                                                                              • Instruction Fuzzy Hash: 5902C375A00218EADF30AFA9D4456EDB7F6FB44B18FA84655D414BB280E3709E88CF35
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D81617
                                                                                                                                                                                • Part of subcall function 00D77DF0: __EH_prolog3.LIBCMT ref: 00D77DF7
                                                                                                                                                                                • Part of subcall function 00D77DF0: std::_Lockit::_Lockit.LIBCPMT ref: 00D77E01
                                                                                                                                                                                • Part of subcall function 00D77DF0: std::_Lockit::~_Lockit.LIBCPMT ref: 00D77E72
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: H_prolog3Lockitstd::_$Lockit::_Lockit::~_
                                                                                                                                                                              • String ID: %H : %M$%H : %M : %S$%I : %M : %S %p$%b %d %H : %M : %S %Y$%d / %m / %y$%m / %d / %y$:AM:am:PM:pm
                                                                                                                                                                              • API String ID: 1538362411-2891247106
                                                                                                                                                                              • Opcode ID: 3114f75d4047128fba80f0961d424452d7a88a96d50b0dc222d2ec07346a8121
                                                                                                                                                                              • Instruction ID: 3b604e13d00db5eeb41552e17e6e92a16e0700f19a5fdbe72a5a87434e0005c9
                                                                                                                                                                              • Opcode Fuzzy Hash: 3114f75d4047128fba80f0961d424452d7a88a96d50b0dc222d2ec07346a8121
                                                                                                                                                                              • Instruction Fuzzy Hash: D4B18D7990020AAFDF19FF68CD66DBE7BBDEB05300F094119F952A2251D631CA1ADB31
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D819E7
                                                                                                                                                                                • Part of subcall function 00D132DE: __EH_prolog3_GS.LIBCMT ref: 00D132E5
                                                                                                                                                                                • Part of subcall function 00D132DE: std::_Lockit::_Lockit.LIBCPMT ref: 00D132F2
                                                                                                                                                                                • Part of subcall function 00D132DE: std::_Lockit::~_Lockit.LIBCPMT ref: 00D13360
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Lockitstd::_$H_prolog3H_prolog3_Lockit::_Lockit::~_
                                                                                                                                                                              • String ID: %H : %M$%H : %M : %S$%I : %M : %S %p$%b %d %H : %M : %S %Y$%d / %m / %y$%m / %d / %y$:AM:am:PM:pm
                                                                                                                                                                              • API String ID: 2728201062-2891247106
                                                                                                                                                                              • Opcode ID: 11db654c5b94d084fdc6f8c180436c5934feea3868634e53ec270508e1f0e96c
                                                                                                                                                                              • Instruction ID: 5bf6fa08354cc7fa63e7c75742edf709c236f59c1b9867cb556b6c53094378a2
                                                                                                                                                                              • Opcode Fuzzy Hash: 11db654c5b94d084fdc6f8c180436c5934feea3868634e53ec270508e1f0e96c
                                                                                                                                                                              • Instruction Fuzzy Hash: 61B19EB954010AAFCF19EF68C955EFE7BBDEF05300F084619F942A6251E631DA1ADB30
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D86947
                                                                                                                                                                                • Part of subcall function 00D3C960: std::_Lockit::_Lockit.LIBCPMT ref: 00D3C995
                                                                                                                                                                                • Part of subcall function 00D3C960: std::_Lockit::_Lockit.LIBCPMT ref: 00D3C9B7
                                                                                                                                                                                • Part of subcall function 00D3C960: std::_Lockit::~_Lockit.LIBCPMT ref: 00D3C9D7
                                                                                                                                                                                • Part of subcall function 00D3C960: std::_Lockit::~_Lockit.LIBCPMT ref: 00D3CAB1
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Lockitstd::_$Lockit::_Lockit::~_$H_prolog3
                                                                                                                                                                              • String ID: %H : %M$%H : %M : %S$%I : %M : %S %p$%b %d %H : %M : %S %Y$%d / %m / %y$%m / %d / %y$:AM:am:PM:pm
                                                                                                                                                                              • API String ID: 1383202999-2891247106
                                                                                                                                                                              • Opcode ID: bcc3b08df95a9be6ff3f8fcab4b62e7367c85e18519b0bba99d874d97ed1e3a5
                                                                                                                                                                              • Instruction ID: 4864bd3b198ce790628aad3c0ed700b5e2902e4dcb940568efb1cb505fcdde45
                                                                                                                                                                              • Opcode Fuzzy Hash: bcc3b08df95a9be6ff3f8fcab4b62e7367c85e18519b0bba99d874d97ed1e3a5
                                                                                                                                                                              • Instruction Fuzzy Hash: DFB18D7150020AAFCF19EF68C965DFE7BB9EF19724F084119FA82A6251D631DA10DB70
                                                                                                                                                                              APIs
                                                                                                                                                                              • CreateFileW.KERNEL32(?,40000000,00000000,00000000,00000002,00000080,00000000,00000000,00000000,00000000,?,?,6EB998C3,00000000), ref: 00D60E20
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D60E2E
                                                                                                                                                                                • Part of subcall function 00D60FA0: GetModuleHandleW.KERNEL32(kernel32.dll,6EB998C3,000000FF,00000000,00000000,00DBDF30,000000FF), ref: 00D60FE8
                                                                                                                                                                                • Part of subcall function 00D60FA0: GetProcAddress.KERNEL32(00000000,CreateFileTransactedW), ref: 00D60FF8
                                                                                                                                                                                • Part of subcall function 00D60FA0: GetLastError.KERNEL32 ref: 00D61058
                                                                                                                                                                                • Part of subcall function 00D48650: std::locale::_Init.LIBCPMT ref: 00D4882F
                                                                                                                                                                              Strings
                                                                                                                                                                              • CreateFile failed: %d, xrefs: 00D60E35
                                                                                                                                                                              • NWebAdvisor::CCabParser::GetContentFile, xrefs: 00D60D9B, 00D60E3C
                                                                                                                                                                              • NWebAdvisor::CCabParser::LoadCabFile, xrefs: 00D60F0C
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\CabParser.h, xrefs: 00D60DA0, 00D60E41, 00D60F11
                                                                                                                                                                              • Failed to load cab %s, xrefs: 00D60F05
                                                                                                                                                                              • Unable to create destination directory (%d), xrefs: 00D60D94
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast$AddressCreateFileHandleInitModuleProcstd::locale::_
                                                                                                                                                                              • String ID: CreateFile failed: %d$Failed to load cab %s$NWebAdvisor::CCabParser::GetContentFile$NWebAdvisor::CCabParser::LoadCabFile$Unable to create destination directory (%d)$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\CabParser.h
                                                                                                                                                                              • API String ID: 1808632809-3418505487
                                                                                                                                                                              • Opcode ID: 8f8ba71681d8fb73c03cc82ca75f9c21e5530a564aa45050fda11c9b4eee24d7
                                                                                                                                                                              • Instruction ID: 8d35a99e649fda1fe1d3122b87bd4190300996f13f6d2ece86f4dc93f8cdea70
                                                                                                                                                                              • Opcode Fuzzy Hash: 8f8ba71681d8fb73c03cc82ca75f9c21e5530a564aa45050fda11c9b4eee24d7
                                                                                                                                                                              • Instruction Fuzzy Hash: 1D918271A00208EFDB14DFA8D896FEEB7B4EF14704F608529F515A7281DB71AA49CB70
                                                                                                                                                                              APIs
                                                                                                                                                                              • CertGetCertificateContextProperty.CRYPT32(00000000,00000003,00000000,?), ref: 00D71CB1
                                                                                                                                                                              • CertGetCertificateContextProperty.CRYPT32(00000000,00000003,00000000,?), ref: 00D71CE5
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CertCertificateContextProperty
                                                                                                                                                                              • String ID: 1.2.840.10045.4.1$1.2.840.10045.4.3$1.2.840.10045.4.3.2$1.2.840.10045.4.3.3$1.2.840.10045.4.3.4$MUSARUBRA US LLC
                                                                                                                                                                              • API String ID: 665277682-2910604786
                                                                                                                                                                              • Opcode ID: ec7de0038774c9c00644ef68e3465512de8832c5e4272cb869a72da9f5ecfc28
                                                                                                                                                                              • Instruction ID: 58f9e7a0232f6b7045eb171d96d9482b0df755a0890cf6f6c153006cead0fa6f
                                                                                                                                                                              • Opcode Fuzzy Hash: ec7de0038774c9c00644ef68e3465512de8832c5e4272cb869a72da9f5ecfc28
                                                                                                                                                                              • Instruction Fuzzy Hash: FA51F2796003014FDB35EF2CD881A66F7A1EF51720F4CC769E85A8B252E721E809CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3_GS.LIBCMT ref: 00D7DEA4
                                                                                                                                                                              • _Maklocstr.LIBCPMT ref: 00D7DF0D
                                                                                                                                                                              • _Maklocstr.LIBCPMT ref: 00D7DF1F
                                                                                                                                                                              • _Maklocchr.LIBCPMT ref: 00D7DF37
                                                                                                                                                                              • _Maklocchr.LIBCPMT ref: 00D7DF47
                                                                                                                                                                              • _Getvals.LIBCPMT ref: 00D7DF69
                                                                                                                                                                                • Part of subcall function 00D7760B: _Maklocchr.LIBCPMT ref: 00D7763A
                                                                                                                                                                                • Part of subcall function 00D7760B: _Maklocchr.LIBCPMT ref: 00D77650
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Maklocchr$Maklocstr$GetvalsH_prolog3_
                                                                                                                                                                              • String ID: false$true
                                                                                                                                                                              • API String ID: 3549167292-2658103896
                                                                                                                                                                              • Opcode ID: a0161109442fee27038842feedfd91ef31795afbf1cea265d5d20d46c2f00a2a
                                                                                                                                                                              • Instruction ID: 523201247309a10846370528e6f8819abf61d9f8dd8df7252d4351052987450d
                                                                                                                                                                              • Opcode Fuzzy Hash: a0161109442fee27038842feedfd91ef31795afbf1cea265d5d20d46c2f00a2a
                                                                                                                                                                              • Instruction Fuzzy Hash: D0217F72D04308AADF15EFA5D846ADE7B78EF05710F04C41AF9099F242EB709544CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D7861D
                                                                                                                                                                              • numpunct.LIBCPMT ref: 00D78661
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D78678
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D78698
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D786A5
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D78627
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registernumpunct
                                                                                                                                                                              • String ID: <s$Hs
                                                                                                                                                                              • API String ID: 3064348918-108348412
                                                                                                                                                                              • Opcode ID: 8e1f547cdc70aed76d8335e63415c5dad55c68f70cb535a87eeeeb5051ced17b
                                                                                                                                                                              • Instruction ID: 97d83fcbe11f673f171cb16861fa2bd4c80d70fe417b9c84603429bae7ce8063
                                                                                                                                                                              • Opcode Fuzzy Hash: 8e1f547cdc70aed76d8335e63415c5dad55c68f70cb535a87eeeeb5051ced17b
                                                                                                                                                                              • Instruction Fuzzy Hash: 1901C471900215ABCB04EB64D80AAFD7771EF80714F244008E818AB3D1EF75AE45A7B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • CertGetCertificateContextProperty.CRYPT32(?,00000003,00000000,00000000), ref: 00D5E877
                                                                                                                                                                              • CertGetCertificateContextProperty.CRYPT32(?,00000003,00000000,00000014), ref: 00D5E8A9
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CertCertificateContextProperty
                                                                                                                                                                              • String ID: 1.2.840.10045.4.1$1.2.840.10045.4.3$1.2.840.10045.4.3.2$1.2.840.10045.4.3.3$1.2.840.10045.4.3.4
                                                                                                                                                                              • API String ID: 665277682-3196566809
                                                                                                                                                                              • Opcode ID: 1490459b6dbcbbeac0d5749ffbcd8d998066551d834fd0b0b0d0afd69980aaf0
                                                                                                                                                                              • Instruction ID: 30ba1325dab20b06d67c0b93d77ebfa492d70fbc9f5443c6c902dc818355a1f1
                                                                                                                                                                              • Opcode Fuzzy Hash: 1490459b6dbcbbeac0d5749ffbcd8d998066551d834fd0b0b0d0afd69980aaf0
                                                                                                                                                                              • Instruction Fuzzy Hash: EC511A75A002059BDF28BF29DC91A6ABBA1EF55322F0C4269DC559B352D731EE08CF70
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: z
                                                                                                                                                                              • API String ID: 0-1657960367
                                                                                                                                                                              • Opcode ID: f4b3e8dc6b0d62f7b4dd524a8c7914c674e2472dfdf77b5d855f005a5442820b
                                                                                                                                                                              • Instruction ID: d92f2cd6abf403b3a4c4193672ba7c96cb704254c0cf60d1ef37ab579b14da9d
                                                                                                                                                                              • Opcode Fuzzy Hash: f4b3e8dc6b0d62f7b4dd524a8c7914c674e2472dfdf77b5d855f005a5442820b
                                                                                                                                                                              • Instruction Fuzzy Hash: 0D5140B1A00319ABEB10DB95DC85FEEB7B8EB48324F144169EA05E72C1D7759D04CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D7829F
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D782A9
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • moneypunct.LIBCPMT ref: 00D782E3
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D782FA
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D7831A
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D78327
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registermoneypunct
                                                                                                                                                                              • String ID: \s
                                                                                                                                                                              • API String ID: 3376033448-913846398
                                                                                                                                                                              • Opcode ID: 20cf533dd17eb23d68621cab8003f14fd09206c90c18f60172313ace8d6672f2
                                                                                                                                                                              • Instruction ID: 3f05251bd31161a941c65d9db60eb57108522500bcdd004fc0b05d784b858f11
                                                                                                                                                                              • Opcode Fuzzy Hash: 20cf533dd17eb23d68621cab8003f14fd09206c90c18f60172313ace8d6672f2
                                                                                                                                                                              • Instruction Fuzzy Hash: 8601C471900119AFCB04EB64D846ABEB7B1FF40711F184009E814A7391EF749E45EBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D7820A
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D78214
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • moneypunct.LIBCPMT ref: 00D7824E
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D78265
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D78285
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D78292
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registermoneypunct
                                                                                                                                                                              • String ID: `s
                                                                                                                                                                              • API String ID: 3376033448-1386833401
                                                                                                                                                                              • Opcode ID: dacb9db5d8172567494482b27c4de99d0234a7d461551344fb6b1e442c8ea1bd
                                                                                                                                                                              • Instruction ID: d92ca413afbec306f41d57196ea1716261387ca96fa9c4134b2161d631641ed4
                                                                                                                                                                              • Opcode Fuzzy Hash: dacb9db5d8172567494482b27c4de99d0234a7d461551344fb6b1e442c8ea1bd
                                                                                                                                                                              • Instruction Fuzzy Hash: 5001C4719001199FCB04FB64D806ABE7771FF80311F188508F814A7392EF749E44A7B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D783C9
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D783D3
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • moneypunct.LIBCPMT ref: 00D7840D
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D78424
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D78444
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D78451
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registermoneypunct
                                                                                                                                                                              • String ID: 4s
                                                                                                                                                                              • API String ID: 3376033448-2671381746
                                                                                                                                                                              • Opcode ID: 91bb7108492ae6d692173d87ebb5478f1228672ad8f68c281b1739658da54bc7
                                                                                                                                                                              • Instruction ID: 28d005ebca4976f6850e23d16724e60fdc8e690e16d4aca9a65a8e402a12802b
                                                                                                                                                                              • Opcode Fuzzy Hash: 91bb7108492ae6d692173d87ebb5478f1228672ad8f68c281b1739658da54bc7
                                                                                                                                                                              • Instruction Fuzzy Hash: F201C07190022A9BCB14EB64D806ABE7776FF80714F244108F819AB391EF74AE45A7B1
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D78334
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D7833E
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • moneypunct.LIBCPMT ref: 00D78378
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D7838F
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D783AF
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D783BC
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registermoneypunct
                                                                                                                                                                              • String ID: 8s
                                                                                                                                                                              • API String ID: 3376033448-1523245555
                                                                                                                                                                              • Opcode ID: d7e2e73081345ce14f11133b058d5c1d30266f7bc34e15e1f1c747b1a0e2a0da
                                                                                                                                                                              • Instruction ID: 4dd4b0327ac54ae96ef3ac92f37cc9a3a886cc3e3174eea476228a7276c14848
                                                                                                                                                                              • Opcode Fuzzy Hash: d7e2e73081345ce14f11133b058d5c1d30266f7bc34e15e1f1c747b1a0e2a0da
                                                                                                                                                                              • Instruction Fuzzy Hash: DE01C4719002159FCB14FB68D806ABE77B1EF40710F244008F818A7391EF749E45A7B1
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::locale::_Init.LIBCPMT ref: 00D5C641
                                                                                                                                                                                • Part of subcall function 00D73084: __EH_prolog3.LIBCMT ref: 00D7308B
                                                                                                                                                                                • Part of subcall function 00D73084: std::_Lockit::_Lockit.LIBCPMT ref: 00D73096
                                                                                                                                                                                • Part of subcall function 00D73084: std::locale::_Setgloballocale.LIBCPMT ref: 00D730B1
                                                                                                                                                                                • Part of subcall function 00D73084: std::_Lockit::~_Lockit.LIBCPMT ref: 00D73107
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D5C6CB
                                                                                                                                                                              • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 00D5C713
                                                                                                                                                                              • std::_Locinfo::_Locinfo_dtor.LIBCPMT ref: 00D5C748
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D5C7DD
                                                                                                                                                                                • Part of subcall function 00D8E960: _free.LIBCMT ref: 00D8E973
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D5C82B
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D5C84C
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D5C85B
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_std::locale::_$Locinfo::_$AddfacH_prolog3InitLocimp::_Locimp_Locinfo_ctorLocinfo_dtorSetgloballocale_free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3887427400-0
                                                                                                                                                                              • Opcode ID: ae178f045f00e2710f3d872f90b0b17d512ecdf5f65d0296cf6f52c26152fead
                                                                                                                                                                              • Instruction ID: 80d628d332e63b177ba2734eeda7f6452bfdcb690194773ad999802d5a833628
                                                                                                                                                                              • Opcode Fuzzy Hash: ae178f045f00e2710f3d872f90b0b17d512ecdf5f65d0296cf6f52c26152fead
                                                                                                                                                                              • Instruction Fuzzy Hash: 50A18CB0D003459FEB10EFA9D845B9EBBF4EF04304F144529E805A7791EBB5AA48CFA1
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _free$___from_strstr_to_strchr
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3409252457-0
                                                                                                                                                                              • Opcode ID: ee4ad9101151a17fb0b79a7cf1d1c3be72f022bfa06f9fc4116a8e7ec3918dab
                                                                                                                                                                              • Instruction ID: d88b3c8bf30b89ac377ff532c9c0ae47dee3cb8e1981d30e352e27fdcfc107a3
                                                                                                                                                                              • Opcode Fuzzy Hash: ee4ad9101151a17fb0b79a7cf1d1c3be72f022bfa06f9fc4116a8e7ec3918dab
                                                                                                                                                                              • Instruction Fuzzy Hash: 3B51F771904305AFDB20AFBD8C41A6EBBA4EF07310F594269E551AB281EB36D944CF72
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D8987E: EnterCriticalSection.KERNEL32(00E077A0,?,00000001,?,00D386A7,00000000,?,00000001,?,00000000,?,?,00D3C338,-00000010), ref: 00D89889
                                                                                                                                                                                • Part of subcall function 00D8987E: LeaveCriticalSection.KERNEL32(00E077A0,?,00D386A7,00000000,?,00000001,?,00000000,?,?,00D3C338,-00000010,?,?,?,6EB998C3), ref: 00D898B5
                                                                                                                                                                              • FindResourceExW.KERNEL32(00000000,00000006,?,00000000,00000000), ref: 00D386D6
                                                                                                                                                                              • LoadResource.KERNEL32(00000000,00000000), ref: 00D386E4
                                                                                                                                                                              • LockResource.KERNEL32(00000000), ref: 00D386EF
                                                                                                                                                                              • SizeofResource.KERNEL32(00000000,00000000), ref: 00D386FD
                                                                                                                                                                              • FindResourceW.KERNEL32(00000000,?,00000006), ref: 00D38764
                                                                                                                                                                              • LoadResource.KERNEL32(00000000,00000000), ref: 00D38776
                                                                                                                                                                              • LockResource.KERNEL32(00000000), ref: 00D38785
                                                                                                                                                                              • SizeofResource.KERNEL32(00000000,00000000), ref: 00D38797
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Resource$CriticalFindLoadLockSectionSizeof$EnterLeave
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 506522749-0
                                                                                                                                                                              • Opcode ID: 14bf736cb755b5e870338693aa3c3b8558ff650ce304683ef64a95f28edced97
                                                                                                                                                                              • Instruction ID: 7a37823125e7838008e84ad764c2e5d89397f325966d48322b8190a7a3f82e9c
                                                                                                                                                                              • Opcode Fuzzy Hash: 14bf736cb755b5e870338693aa3c3b8558ff650ce304683ef64a95f28edced97
                                                                                                                                                                              • Instruction Fuzzy Hash: CA4107B19003129BC721AF18A884A7BF3E9EF94381F14052DFD95D7241EF35DC05A6B1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA1CA9: GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                                • Part of subcall function 00DA1CA9: SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0B8A
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0BA3
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0BE1
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0BEA
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0BF6
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _free$ErrorLast
                                                                                                                                                                              • String ID: C
                                                                                                                                                                              • API String ID: 3291180501-1037565863
                                                                                                                                                                              • Opcode ID: 2d2841937c0b9a3eb7510ed86161f6be071075813a76f2458a3e7821231ccf7a
                                                                                                                                                                              • Instruction ID: a201de04c40c8cf620b2676034665d83eedc6e5e66414c809382b854101da91b
                                                                                                                                                                              • Opcode Fuzzy Hash: 2d2841937c0b9a3eb7510ed86161f6be071075813a76f2458a3e7821231ccf7a
                                                                                                                                                                              • Instruction Fuzzy Hash: 30B15B75A01219DFDB24DF28C884AADB7B4FF19304F1445EAE84AA7390D731AE90CF60
                                                                                                                                                                              APIs
                                                                                                                                                                              • InitOnceBeginInitialize.KERNEL32(00E0823C,00000000,?,00000000,?,?,?,?,00000000,00000000,?,6EB998C3,?,?), ref: 00D3125A
                                                                                                                                                                              • InitOnceComplete.KERNEL32(00E0823C,00000000,00000000), ref: 00D31278
                                                                                                                                                                              Strings
                                                                                                                                                                              • C:\non_system\Code\McCryptoLib\src\windows\win_hmac.cpp, xrefs: 00D312F3, 00D313DE
                                                                                                                                                                              • McCryptoLib::CMcCryptoHMACWin::Initialize, xrefs: 00D312EC, 00D313D7
                                                                                                                                                                              • [%S:(%d)][%S] Error trying to BCryptOpenAlgorithmProvider: %ls, xrefs: 00D313E3
                                                                                                                                                                              • [%S:(%d)][%S] Failed to create HMAC traits., xrefs: 00D312F8
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitOnce$BeginCompleteInitialize
                                                                                                                                                                              • String ID: C:\non_system\Code\McCryptoLib\src\windows\win_hmac.cpp$McCryptoLib::CMcCryptoHMACWin::Initialize$[%S:(%d)][%S] Error trying to BCryptOpenAlgorithmProvider: %ls$[%S:(%d)][%S] Failed to create HMAC traits.
                                                                                                                                                                              • API String ID: 51270584-3897904871
                                                                                                                                                                              • Opcode ID: 9cce957d4cf15e8ccf18ff796167a73e7901111576cc19c664dddba25775312f
                                                                                                                                                                              • Instruction ID: 8199f9118616cf90ebf53302a82cb36e1d4a1ce45fa0bc8d376c394b336eea1a
                                                                                                                                                                              • Opcode Fuzzy Hash: 9cce957d4cf15e8ccf18ff796167a73e7901111576cc19c664dddba25775312f
                                                                                                                                                                              • Instruction Fuzzy Hash: 0D516A757043069FDB00EF29DC82B6EB7A4FF98B00F444529F949E7291DA31E9048BB6
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D51DBB
                                                                                                                                                                              • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 00D51E03
                                                                                                                                                                              • std::_Locinfo::_Locinfo_dtor.LIBCPMT ref: 00D51E38
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D51ECD
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D51F1B
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D51F3C
                                                                                                                                                                              • std::locale::_Locimp::_Locimp_Addfac.LIBCPMT ref: 00D51F4B
                                                                                                                                                                                • Part of subcall function 00D8E960: _free.LIBCMT ref: 00D8E973
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Locinfo::_Lockit::_Lockit::~_$AddfacLocimp::_Locimp_Locinfo_ctorLocinfo_dtor_freestd::locale::_
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2317827675-0
                                                                                                                                                                              • Opcode ID: 3e52052722f2bbdc16f62ba7494881ad67daa650b57734c2570ef24327338208
                                                                                                                                                                              • Instruction ID: 8f2f81b9dbd8bd369826fa59da55af62e5119a01f51e6d14b33574726ab8fa4b
                                                                                                                                                                              • Opcode Fuzzy Hash: 3e52052722f2bbdc16f62ba7494881ad67daa650b57734c2570ef24327338208
                                                                                                                                                                              • Instruction Fuzzy Hash: 6B716BB4E003459FEF10EFA9D845B9EBBB4AF54304F084169EC05A7252EB75EA48CB71
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: 0.0.0.0$UUID$UUID$Version$kernel32.dll
                                                                                                                                                                              • API String ID: 0-1483847951
                                                                                                                                                                              • Opcode ID: 8484886c472326e4992100d3bd5de1bcdadb2b12641b1cdecb0a9eb4f148607c
                                                                                                                                                                              • Instruction ID: d100c89228acf457a97b764eeeac98c96391273622b6a169f179e0047d693093
                                                                                                                                                                              • Opcode Fuzzy Hash: 8484886c472326e4992100d3bd5de1bcdadb2b12641b1cdecb0a9eb4f148607c
                                                                                                                                                                              • Instruction Fuzzy Hash: C8816774904388CFEB24DFA8D98879DBBF2AF45314F248229D414AB392D7B85A44DB61
                                                                                                                                                                              APIs
                                                                                                                                                                              • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,6EB998C3,?,?), ref: 00D2A531
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D2A73D
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2A7AC
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2A989
                                                                                                                                                                              Strings
                                                                                                                                                                              • Unexpected return value: , xrefs: 00D2A8CC
                                                                                                                                                                              • Event string is empty, xrefs: 00D2A77C
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$Mtx_unlockMultipleObjectsWait
                                                                                                                                                                              • String ID: Event string is empty$Unexpected return value:
                                                                                                                                                                              • API String ID: 1703231451-1331613497
                                                                                                                                                                              • Opcode ID: 2f17c74136fa52bdf35f4bc1f0ed88abd386f210ae565f6d069f49e2233c57b3
                                                                                                                                                                              • Instruction ID: 3fe3c2f279997e71a6ccdc52cbb2c78868b73586fe8438b67afb32dfcbcd6ed0
                                                                                                                                                                              • Opcode Fuzzy Hash: 2f17c74136fa52bdf35f4bc1f0ed88abd386f210ae565f6d069f49e2233c57b3
                                                                                                                                                                              • Instruction Fuzzy Hash: 4A512370904258ABDB18EFA8EC99BEDB775EF20314F104298E0155B2C2DB709AC5CF32
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D3C995
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D3C9B7
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D3C9D7
                                                                                                                                                                              • __Getctype.LIBCPMT ref: 00D3CA70
                                                                                                                                                                              • std::_Locinfo::~_Locinfo.LIBCPMT ref: 00D3CA82
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D3CA8F
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D3CAB1
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetctypeLocinfoLocinfo::~_Register
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3947131827-0
                                                                                                                                                                              • Opcode ID: d8fb6c9dc0d6f0e79c22a60e64658b9c9ddfb93245500f5f391f3d80e385d6fc
                                                                                                                                                                              • Instruction ID: 120e05e9a96cb0fc1165a31733aac2f980c77d99e7871279e3e52240cd71e619
                                                                                                                                                                              • Opcode Fuzzy Hash: d8fb6c9dc0d6f0e79c22a60e64658b9c9ddfb93245500f5f391f3d80e385d6fc
                                                                                                                                                                              • Instruction Fuzzy Hash: 4141AC71A00209DFCB11DF58D841BAEB7B4EF44310F148169E81ABB391EB31EA49CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,6EB998C3,?,?), ref: 00D2A531
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D2A58B
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2A989
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D2A99D
                                                                                                                                                                              Strings
                                                                                                                                                                              • Thread signalled when event queue is empty, xrefs: 00D2A614
                                                                                                                                                                              • Unexpected return value: , xrefs: 00D2A8CC
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: InitIos_base_dtorMtx_unlockOncestd::ios_base::_$BeginCompleteInitializeMultipleObjectsWait
                                                                                                                                                                              • String ID: Thread signalled when event queue is empty$Unexpected return value:
                                                                                                                                                                              • API String ID: 3324347728-3645029203
                                                                                                                                                                              • Opcode ID: 682597138d964ddc926bc5d755359852812a1e2ae0263349b658535dc4ca13de
                                                                                                                                                                              • Instruction ID: 0d1c383e1235b0af3c5f72854a9760c8b92fc241080da4c227437f615a6736a9
                                                                                                                                                                              • Opcode Fuzzy Hash: 682597138d964ddc926bc5d755359852812a1e2ae0263349b658535dc4ca13de
                                                                                                                                                                              • Instruction Fuzzy Hash: 4541E1B0D04269ABDF14EBA4EC59BDDB775EF20314F108198E405672C1EB706A89CF72
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: api-ms-$ext-ms-
                                                                                                                                                                              • API String ID: 0-537541572
                                                                                                                                                                              • Opcode ID: ba09d5146d4fdce641557578a1b88a8222915e6e8425efca3dd014b1ad7007cf
                                                                                                                                                                              • Instruction ID: 0d731a9daa7bb48a41872214f6b5ee50c49b8dc5a96730180a48f89236b51e9d
                                                                                                                                                                              • Opcode Fuzzy Hash: ba09d5146d4fdce641557578a1b88a8222915e6e8425efca3dd014b1ad7007cf
                                                                                                                                                                              • Instruction Fuzzy Hash: 9721E7B1A41312ABCB219B689C40B2A37989F93760F290111FD55E72D1D6F0EC01D5F5
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D780E0
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D780EA
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D7813B
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D7815B
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D78168
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID: Xs
                                                                                                                                                                              • API String ID: 55977855-3287848638
                                                                                                                                                                              • Opcode ID: bdb4e3a6a0070158532652562aaca9be581706ab1475c89712c8ab1d1a3f496a
                                                                                                                                                                              • Instruction ID: 76c0df75d9404b2503d0aca752654cdafcffb0abef6464e5be6922d5ecab35e4
                                                                                                                                                                              • Opcode Fuzzy Hash: bdb4e3a6a0070158532652562aaca9be581706ab1475c89712c8ab1d1a3f496a
                                                                                                                                                                              • Instruction Fuzzy Hash: 6301C071900219AFCB05EB64D846AFE7771EF80710F644408E818AB391EF74AE45ABB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D7804B
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D78055
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D780A6
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D780C6
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D780D3
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID: ,s
                                                                                                                                                                              • API String ID: 55977855-3484078257
                                                                                                                                                                              • Opcode ID: 88a3a85e388a802b67c63a3a067b14e885703e48dcadb1924dd090dce8d022b6
                                                                                                                                                                              • Instruction ID: f4bea8d442eb106efa6036598b461fa9813fb113c3b01ba116f680d8c2482c65
                                                                                                                                                                              • Opcode Fuzzy Hash: 88a3a85e388a802b67c63a3a067b14e885703e48dcadb1924dd090dce8d022b6
                                                                                                                                                                              • Instruction Fuzzy Hash: 8401C0719002199BCB15EB64D846AFEB771EF80710F284009E814AB3D1EF75AE49E7B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D78175
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D7817F
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D781D0
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D781F0
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D781FD
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID: 0s
                                                                                                                                                                              • API String ID: 55977855-1790618162
                                                                                                                                                                              • Opcode ID: 9e16e158223f7e2cc72f2a2b1aad1ec666d3d6ce2e85a69729ad8eec1771c10e
                                                                                                                                                                              • Instruction ID: fb08c64fb3d44d5535b5030b8f44d9011416e8ce21a038ad8f931166c1c0b982
                                                                                                                                                                              • Opcode Fuzzy Hash: 9e16e158223f7e2cc72f2a2b1aad1ec666d3d6ce2e85a69729ad8eec1771c10e
                                                                                                                                                                              • Instruction Fuzzy Hash: 2D01C4719002159FCB14EB64D805ABD77B5FF44710F644109E814A7391EF749E45EBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D784F3
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D784FD
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D7854E
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D7856E
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D7857B
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID: s
                                                                                                                                                                              • API String ID: 55977855-173686192
                                                                                                                                                                              • Opcode ID: 38ba12eaa84585ceab9b35e0774c1692952f376ac0a740f4d4e01c9313a28aa1
                                                                                                                                                                              • Instruction ID: 936c68b2109aba3c7b0b69affdec0a04b26a9870609e59460117a368a3277556
                                                                                                                                                                              • Opcode Fuzzy Hash: 38ba12eaa84585ceab9b35e0774c1692952f376ac0a740f4d4e01c9313a28aa1
                                                                                                                                                                              • Instruction Fuzzy Hash: D401C4719042159FCB04EB64D806ABE77B1FF40710F248409E815A7391EF74AA45ABB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D7845E
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D78468
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D784B9
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D784D9
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D784E6
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID: @s
                                                                                                                                                                              • API String ID: 55977855-2473085693
                                                                                                                                                                              • Opcode ID: e5992610ceb2277d1e531735c4f861ebbd44e19c3aff8a2a4547f3530b654f1d
                                                                                                                                                                              • Instruction ID: edeb52d293c59baf17c8ef405c848f94af991770bfc59e95336e6b245fbc494f
                                                                                                                                                                              • Opcode Fuzzy Hash: e5992610ceb2277d1e531735c4f861ebbd44e19c3aff8a2a4547f3530b654f1d
                                                                                                                                                                              • Instruction Fuzzy Hash: BA01A17190021AABCB15EB64D806AAE7762FF40714F144408F918A7291EF74AE45EBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D78588
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D78592
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D785E3
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D78603
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D78610
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID: Ds
                                                                                                                                                                              • API String ID: 55977855-1726540861
                                                                                                                                                                              • Opcode ID: 7f43c00ce5a46b2634a6a0d6bbcfcf93d9b84ccc721216bd0112c416a4a91ccf
                                                                                                                                                                              • Instruction ID: 68a8fc99bb4f94b0f79dc2caf351e564ea434fa650dc050a7499c202cf486416
                                                                                                                                                                              • Opcode Fuzzy Hash: 7f43c00ce5a46b2634a6a0d6bbcfcf93d9b84ccc721216bd0112c416a4a91ccf
                                                                                                                                                                              • Instruction Fuzzy Hash: 6701C071900159ABCB04FB64D806ABEB7B1FF80710F244409E818AB391EF74AE45ABB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D786B2
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D786BC
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D7870D
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D7872D
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D7873A
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID: ds
                                                                                                                                                                              • API String ID: 55977855-2804532025
                                                                                                                                                                              • Opcode ID: e1f488dc0d53a6de5f9cf316208679414422519e8e58c76248e677a8738332af
                                                                                                                                                                              • Instruction ID: 4b19e952e1252e3036919bb66fdcce60583aa0b18fa4e487a0d16988da32a2c9
                                                                                                                                                                              • Opcode Fuzzy Hash: e1f488dc0d53a6de5f9cf316208679414422519e8e58c76248e677a8738332af
                                                                                                                                                                              • Instruction Fuzzy Hash: 0E01C07190421A9BCB05FB64D806ABEB7B1FF80310F248008E815AB391EF74AA45A7B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D787DC
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D787E6
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D78837
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D78857
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D78864
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID: hs
                                                                                                                                                                              • API String ID: 55977855-1658400312
                                                                                                                                                                              • Opcode ID: 058b0e252d54f6775f76b47e798f59421fa60c67204d1cb68694bbce98bfafd6
                                                                                                                                                                              • Instruction ID: dd2f91e16615ab7e9b87aaf3e4437d20533b55066137ca0a4640f35f45ffaa4a
                                                                                                                                                                              • Opcode Fuzzy Hash: 058b0e252d54f6775f76b47e798f59421fa60c67204d1cb68694bbce98bfafd6
                                                                                                                                                                              • Instruction Fuzzy Hash: 9301C071900219DFCB04EB64E846AFE77B5FF84710F688409E814AB391EF75AA44E7B1
                                                                                                                                                                              APIs
                                                                                                                                                                              • EnterCriticalSection.KERNEL32(00E0742C,?,?,00D24086,00E0827C,00DC68E0,?), ref: 00D888BA
                                                                                                                                                                              • LeaveCriticalSection.KERNEL32(00E0742C,?,?,00D24086,00E0827C,00DC68E0,?), ref: 00D888ED
                                                                                                                                                                              • RtlWakeAllConditionVariable.NTDLL ref: 00D88964
                                                                                                                                                                              • SetEvent.KERNEL32(?,00D24086,00E0827C,00DC68E0,?), ref: 00D8896E
                                                                                                                                                                              • ResetEvent.KERNEL32(?,00D24086,00E0827C,00DC68E0,?), ref: 00D8897A
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CriticalEventSection$ConditionEnterLeaveResetVariableWake
                                                                                                                                                                              • String ID: ,t
                                                                                                                                                                              • API String ID: 3916383385-1383983112
                                                                                                                                                                              • Opcode ID: 03a6d73e603ab0545ef79da79fd51e9be40bf5f66a4503ef64687865269ac08b
                                                                                                                                                                              • Instruction ID: 2bd0ab7bbc072d1136309d68dba828a8dc3379ef86b629b16b98633c64349f6a
                                                                                                                                                                              • Opcode Fuzzy Hash: 03a6d73e603ab0545ef79da79fd51e9be40bf5f66a4503ef64687865269ac08b
                                                                                                                                                                              • Instruction Fuzzy Hash: E50146B2904261DFC701AF28FC48DA87BA9EB0D711705806AF852E3331CB316892DFB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetConsoleCP.KERNEL32(?,00D4860A,00000000), ref: 00DA57B5
                                                                                                                                                                              • __fassign.LIBCMT ref: 00DA5994
                                                                                                                                                                              • __fassign.LIBCMT ref: 00DA59B1
                                                                                                                                                                              • WriteFile.KERNEL32(?,00D4860A,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00DA59F9
                                                                                                                                                                              • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00DA5A39
                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00DA5AE5
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FileWrite__fassign$ConsoleErrorLast
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 4031098158-0
                                                                                                                                                                              • Opcode ID: c4befad2b82f471fdaeb26c6fb6b5acac4f353ef66654e7ca4e51826fb02e378
                                                                                                                                                                              • Instruction ID: ca626c4c4d21c57150f52fcc78b073a22303b1b69dc319e1596ecbfa9c3f7976
                                                                                                                                                                              • Opcode Fuzzy Hash: c4befad2b82f471fdaeb26c6fb6b5acac4f353ef66654e7ca4e51826fb02e378
                                                                                                                                                                              • Instruction Fuzzy Hash: 31D1AA71E006589FCF15CFA8D8809EDBBB5FF4A310F28416AE855FB345D631AA46CB60
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetCPInfo.KERNEL32(?,?,?,?,?), ref: 00D88128
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(?,00000009,?,?,00000000,00000000), ref: 00D881B6
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 00D88228
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(?,00000009,?,?,00000000,00000000), ref: 00D88242
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(?,00000001,?,?,00000000,?), ref: 00D882A5
                                                                                                                                                                              • CompareStringEx.KERNEL32(?,?,?,?,00000000,?,00000000,00000000,00000000), ref: 00D882C2
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ByteCharMultiWide$CompareInfoString
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2984826149-0
                                                                                                                                                                              • Opcode ID: fd8c26855b79d765c0ed8feb804e9a6beba7584136dc92db510023adb79fbad5
                                                                                                                                                                              • Instruction ID: 3df1517d1833ae89b99d9baf802ca38884044e26fc1285a4e4298bf67d72860c
                                                                                                                                                                              • Opcode Fuzzy Hash: fd8c26855b79d765c0ed8feb804e9a6beba7584136dc92db510023adb79fbad5
                                                                                                                                                                              • Instruction Fuzzy Hash: BD718F7190074AAEDF21AFA4CC45BAF7BB6EF45750FA80115E845E6250DF31C801EB78
                                                                                                                                                                              APIs
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(00000000,00000000,00000001,?,00000000,00000000,?,?,?,00000001), ref: 00D76901
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(00000001,00000001,00000000,?,00000000,00000000), ref: 00D7696C
                                                                                                                                                                              • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D76989
                                                                                                                                                                              • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 00D769C8
                                                                                                                                                                              • LCMapStringEx.KERNEL32(?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D76A27
                                                                                                                                                                              • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,00000000), ref: 00D76A4A
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ByteCharMultiStringWide
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2829165498-0
                                                                                                                                                                              • Opcode ID: 84ab85dd725b252edcfd9bf1dd944fe5b953f2cfbf6775014e5bd709be49387e
                                                                                                                                                                              • Instruction ID: e3db283126c249e468bb4a7c47ea5c44351648cba595f9f9f571971e26725662
                                                                                                                                                                              • Opcode Fuzzy Hash: 84ab85dd725b252edcfd9bf1dd944fe5b953f2cfbf6775014e5bd709be49387e
                                                                                                                                                                              • Instruction Fuzzy Hash: E0515B7290061AABEF209F64CC45FAA7BA9EF44750F19C529FA19E6190F730DD10DB70
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetLastError.KERNEL32(?,00000001,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,6EB998C3), ref: 00D3E00F
                                                                                                                                                                              • LocalAlloc.KERNEL32(00000040,00000014,00000001,?,?,?,?,00000001,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00D3E073
                                                                                                                                                                              • LocalFree.KERNEL32(00000000,00000000,00000001,?,00000000,00000000,00000001), ref: 00D3E104
                                                                                                                                                                              • LocalFree.KERNEL32(?,00000001,?,?,?,?,00000001,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?), ref: 00D3E112
                                                                                                                                                                              • FreeSid.ADVAPI32(00000000,00000001,?,?,?,?,00000001,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?), ref: 00D3E11D
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FreeLocal$AllocErrorLast
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3195132385-0
                                                                                                                                                                              • Opcode ID: 9f5b905cdb622c074bc23e50893f926029e0744137f4f11ff6dead297331fbcd
                                                                                                                                                                              • Instruction ID: 6cf67c970cb8753f3b3f16346b69eb6ac842a2bfb051eb6beeafd7858b4e4ad6
                                                                                                                                                                              • Opcode Fuzzy Hash: 9f5b905cdb622c074bc23e50893f926029e0744137f4f11ff6dead297331fbcd
                                                                                                                                                                              • Instruction Fuzzy Hash: 2751E5B5E00319AFDB10DF94D885BEEBBB9EF48714F14412AE905B7381D7B499058BB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(?,00000001,?,00000000), ref: 00D1E7D7
                                                                                                                                                                              • GetSecurityDescriptorDacl.ADVAPI32(00000000,00000000,00000000,?), ref: 00D1E811
                                                                                                                                                                              • SetNamedSecurityInfoW.ADVAPI32(00000000,00000001,00000004,00000000,00000000,00000000,00000000,?), ref: 00D1E86D
                                                                                                                                                                              • LocalFree.KERNEL32(00000000), ref: 00D1E8C7
                                                                                                                                                                              • LocalFree.KERNEL32(00000000), ref: 00D1E8DC
                                                                                                                                                                              • LocalFree.KERNEL32(00000000), ref: 00D1E917
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Security$DescriptorFreeLocal$ConvertDaclInfoNamedString
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2792426717-0
                                                                                                                                                                              • Opcode ID: 7adc6ade60f45ed8d59b632f8d11afe750f34c348add732b77c6d0d43d312f4b
                                                                                                                                                                              • Instruction ID: 7354d65a9b0e5ad2aed1a9a8d0278591ec165f93f9076b511aef4f0eb70964ad
                                                                                                                                                                              • Opcode Fuzzy Hash: 7adc6ade60f45ed8d59b632f8d11afe750f34c348add732b77c6d0d43d312f4b
                                                                                                                                                                              • Instruction Fuzzy Hash: 86416DB1901249ABEF10DFA4ED49BDEB7B9FF44714F240129F905E2290DB789A44CBB4
                                                                                                                                                                              APIs
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D18D46
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D18D66
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D18D86
                                                                                                                                                                              • std::_Locinfo::~_Locinfo.LIBCPMT ref: 00D18E57
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D18E64
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D18E86
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_LocinfoLocinfo::~_Register
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2966223926-0
                                                                                                                                                                              • Opcode ID: 274ee620b023edaca05b60112668ec1d32e271ee6c78857ca7fae3679381fd9e
                                                                                                                                                                              • Instruction ID: 04ad50689c3445e270d9b7a9bc0643fc241d4c86e3c4608e4aa3940c7e2a0d5a
                                                                                                                                                                              • Opcode Fuzzy Hash: 274ee620b023edaca05b60112668ec1d32e271ee6c78857ca7fae3679381fd9e
                                                                                                                                                                              • Instruction Fuzzy Hash: 0D41D071A00205EFCB11EF55E881BAEBBB4FF50310F184159E446AB291DF31AE89DBB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D74362
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D7436C
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • codecvt.LIBCPMT ref: 00D743A6
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D743BD
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D743DD
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D743EA
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registercodecvt
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2133458128-0
                                                                                                                                                                              • Opcode ID: a897eb9cec0052e9f1a6d3999df81861ac48d221a342ae92c06ef6e70f0ce782
                                                                                                                                                                              • Instruction ID: 78c6d824328f064a3b50c80cfda17c71a244d02fb1c9ea8594a1f2c96940fdf0
                                                                                                                                                                              • Opcode Fuzzy Hash: a897eb9cec0052e9f1a6d3999df81861ac48d221a342ae92c06ef6e70f0ce782
                                                                                                                                                                              • Instruction Fuzzy Hash: E301C07190021A9BCB05FB64D802ABE77B1FF80310F248108E428AB3D1EF759E45DBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D8447C
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D84486
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • collate.LIBCPMT ref: 00D844C0
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D844D7
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D844F7
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D84504
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registercollate
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1767075461-0
                                                                                                                                                                              • Opcode ID: f3b709dc0f84494c20509befa8063b87eb34f5bab838449eb24aff848c1f25d8
                                                                                                                                                                              • Instruction ID: 6a2cf2ced06606632aad027021a83ea79bb4780297b4b3c0ad507d2b5ac6cf5f
                                                                                                                                                                              • Opcode Fuzzy Hash: f3b709dc0f84494c20509befa8063b87eb34f5bab838449eb24aff848c1f25d8
                                                                                                                                                                              • Instruction Fuzzy Hash: 5101C4719001169FCB04FB64D842ABD7771FF90310F244409F810AB3D2DF749A4597B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D84511
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D8451B
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • messages.LIBCPMT ref: 00D84555
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D8456C
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D8458C
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D84599
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registermessages
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 958335874-0
                                                                                                                                                                              • Opcode ID: 56f54a5543c554d6deb3466f315a4aa578e977bd467e66fc28283a0c2ca7df6e
                                                                                                                                                                              • Instruction ID: 81e1353ae9cbd607e75cdb1b19d87eac005f11ade2f111978dbd98a3c3d1951c
                                                                                                                                                                              • Opcode Fuzzy Hash: 56f54a5543c554d6deb3466f315a4aa578e977bd467e66fc28283a0c2ca7df6e
                                                                                                                                                                              • Instruction Fuzzy Hash: E501C07590011A9BCB04FB64D842AFE77B5FF84714F280449F810AB3D1DF74AA4497B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D846D0
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D846DA
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • moneypunct.LIBCPMT ref: 00D84714
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D8472B
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D8474B
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D84758
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registermoneypunct
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3376033448-0
                                                                                                                                                                              • Opcode ID: fcdbecff5be258b828f6979d7349f0bae63854a0e4995fccdf974615cf6347d1
                                                                                                                                                                              • Instruction ID: b36c4c66c319599fde7c475f8fb0e883aa54dfc1e60079183df0deac667de7ca
                                                                                                                                                                              • Opcode Fuzzy Hash: fcdbecff5be258b828f6979d7349f0bae63854a0e4995fccdf974615cf6347d1
                                                                                                                                                                              • Instruction Fuzzy Hash: E801CC7590021A9FCB04FBA4D802ABE77B5EF80310F290008E824AB391DF74AE45DBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D84765
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D8476F
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • moneypunct.LIBCPMT ref: 00D847A9
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D847C0
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D847E0
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D847ED
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Registermoneypunct
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3376033448-0
                                                                                                                                                                              • Opcode ID: 5912c52c9741e3a78fc89e12f38bce7d51692552e52fd3fad08693d8386f39a8
                                                                                                                                                                              • Instruction ID: 9c746ed7b49a58cef921805032d071ef842aed1a564cf2d4e592997c5fffd935
                                                                                                                                                                              • Opcode Fuzzy Hash: 5912c52c9741e3a78fc89e12f38bce7d51692552e52fd3fad08693d8386f39a8
                                                                                                                                                                              • Instruction Fuzzy Hash: 1301AD7590021A9BCB04FB64D802AAE7765FF80714F240108E810AB391DF74AA44D7B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D3C546
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D3C54B
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D3C550
                                                                                                                                                                                • Part of subcall function 00D8E960: _free.LIBCMT ref: 00D8E973
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_task$_free
                                                                                                                                                                              • String ID: false$true
                                                                                                                                                                              • API String ID: 149343396-2658103896
                                                                                                                                                                              • Opcode ID: ad9c9cfa732a6eb2ab1e8e4a42afd6fc3dbe7d32027897049769652469d9750b
                                                                                                                                                                              • Instruction ID: 1ee4486e075f70a209c6d3ee10ae9c70647fd9f5f5cad034203368c9fdb79810
                                                                                                                                                                              • Opcode Fuzzy Hash: ad9c9cfa732a6eb2ab1e8e4a42afd6fc3dbe7d32027897049769652469d9750b
                                                                                                                                                                              • Instruction Fuzzy Hash: 4F41E2759007419FCB20EF64D841BAABBF4EF05300F08856DE846AB752D776A904CBB1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceBeginInitialize.KERNEL32(00E080C4,00000000,6EB998C3,00000000,6EB998C3,00D1A219,00E080CC,?,?,?,?,?,?,00D1A219,?,?), ref: 00D19BE5
                                                                                                                                                                                • Part of subcall function 00D19BB0: InitOnceComplete.KERNEL32(00E080C4,00000000,00000000), ref: 00D19C1D
                                                                                                                                                                                • Part of subcall function 00D19940: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D19A12
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2D8F5
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2DF0C
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$InitOnce$BeginCompleteInitialize
                                                                                                                                                                              • String ID: Event Sender already initialized for Azure$Failed to encode url$~
                                                                                                                                                                              • API String ID: 1656330964-1958975516
                                                                                                                                                                              • Opcode ID: 85b0ac28e035adcb0cbe99206d5626955bed928a2d50e129786b595d975f7372
                                                                                                                                                                              • Instruction ID: 44199d7ada1a863060766be4cc8241cf286eeee134ee9fc3ad0dae4b320255c3
                                                                                                                                                                              • Opcode Fuzzy Hash: 85b0ac28e035adcb0cbe99206d5626955bed928a2d50e129786b595d975f7372
                                                                                                                                                                              • Instruction Fuzzy Hash: 45412470A04258AFDB14EB64EC95BEDB3B9EF55314F00419DE40967381EF706A88CB71
                                                                                                                                                                              APIs
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Mpunct$GetvalsH_prolog3
                                                                                                                                                                              • String ID: $+xv
                                                                                                                                                                              • API String ID: 2204710431-1686923651
                                                                                                                                                                              • Opcode ID: 2470bbc54886c6ed85484d2cafe8fe1a65a4f8efac2f295ebda8c00c93581cb4
                                                                                                                                                                              • Instruction ID: 080ae52e3700c441d622c1ef1eefd0384c80fdbf483c303f1436562e7400de3a
                                                                                                                                                                              • Opcode Fuzzy Hash: 2470bbc54886c6ed85484d2cafe8fe1a65a4f8efac2f295ebda8c00c93581cb4
                                                                                                                                                                              • Instruction Fuzzy Hash: 05218EA1904A526FDB22DF74C88067BBEF8AF0C700B04495AF499CBA41E730E601CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetStdHandle.KERNEL32(000000F4,?,?), ref: 00D96016
                                                                                                                                                                              • GetFileType.KERNEL32(00000000), ref: 00D96028
                                                                                                                                                                              • swprintf.LIBCMT ref: 00D96049
                                                                                                                                                                              • WriteConsoleW.KERNEL32(00000000,?,?,?,00000000), ref: 00D96086
                                                                                                                                                                              Strings
                                                                                                                                                                              • Assertion failed: %Ts, file %Ts, line %d, xrefs: 00D9603E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ConsoleFileHandleTypeWriteswprintf
                                                                                                                                                                              • String ID: Assertion failed: %Ts, file %Ts, line %d
                                                                                                                                                                              • API String ID: 2943507729-1719349581
                                                                                                                                                                              • Opcode ID: 5acba6ae0d9cdd99d979607f886334727b330882c320d389aaf9154a0b8a3411
                                                                                                                                                                              • Instruction ID: 98120501c023f0e10d7c72110e5948afcd4d3b7e3d897bfcd398306c853e8612
                                                                                                                                                                              • Opcode Fuzzy Hash: 5acba6ae0d9cdd99d979607f886334727b330882c320d389aaf9154a0b8a3411
                                                                                                                                                                              • Instruction Fuzzy Hash: CB1104B15002196BCF20AB298C85FAEB7ADEF84310F44465CFA1AD3181EA30ED458B74
                                                                                                                                                                              APIs
                                                                                                                                                                              • FreeLibrary.KERNEL32(00000000,?,?,?,00D8D278,?,?,00E077FC,00000000,?,00D8D3A3,00000004,InitializeCriticalSectionEx,00DE013C,00DE0144,00000000), ref: 00D8D247
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FreeLibrary
                                                                                                                                                                              • String ID: api-ms-
                                                                                                                                                                              • API String ID: 3664257935-2084034818
                                                                                                                                                                              • Opcode ID: fc4387d1f814f20bd79102b7f00cfc8377b2d93235beed7e95d28f68ed11dd45
                                                                                                                                                                              • Instruction ID: 2bd03da514ff8f95d1ef192145ee1b4821253a493568791efb4905c51ca99431
                                                                                                                                                                              • Opcode Fuzzy Hash: fc4387d1f814f20bd79102b7f00cfc8377b2d93235beed7e95d28f68ed11dd45
                                                                                                                                                                              • Instruction Fuzzy Hash: 2A11C631A41322ABDF22AB699C44F5A77A5AF02B60F280250FD41EB2D4D770ED00DBF5
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(Advapi32.dll), ref: 00D3E172
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,RegDeleteKeyExW), ref: 00D3E182
                                                                                                                                                                              • RegDeleteKeyW.ADVAPI32(00000000,?), ref: 00D3E1C2
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AddressDeleteHandleModuleProc
                                                                                                                                                                              • String ID: Advapi32.dll$RegDeleteKeyExW
                                                                                                                                                                              • API String ID: 588496660-2191092095
                                                                                                                                                                              • Opcode ID: b328109c8fa5b889bac81f998f42c868947ae114ad368b6639c579577dbbfd4c
                                                                                                                                                                              • Instruction ID: bbd905600b6c17ed33d7f87001fa3fe9772c4f9cb2d4ddf583a266a61f8a9d7f
                                                                                                                                                                              • Opcode Fuzzy Hash: b328109c8fa5b889bac81f998f42c868947ae114ad368b6639c579577dbbfd4c
                                                                                                                                                                              • Instruction Fuzzy Hash: 90015E7A244305AED7214B9BFC04B627BA9E790B61F08802AF144D62E0C7B2D495EB71
                                                                                                                                                                              APIs
                                                                                                                                                                              • WriteFile.KERNEL32(?,?,00000000,?,00000000), ref: 00D61210
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00D6121A
                                                                                                                                                                              Strings
                                                                                                                                                                              • WriteFile failed: %d, xrefs: 00D61221
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\CabParser.h, xrefs: 00D6122D
                                                                                                                                                                              • NWebAdvisor::CCabParser::Write, xrefs: 00D61228
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorFileLastWrite
                                                                                                                                                                              • String ID: NWebAdvisor::CCabParser::Write$WriteFile failed: %d$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\CabParser.h
                                                                                                                                                                              • API String ID: 442123175-2264278858
                                                                                                                                                                              • Opcode ID: d3ac609e44b59231dc55c8e71e8648c89a1e8d9249cfd615a9dc4897ce370840
                                                                                                                                                                              • Instruction ID: 14bf601d35b9cb4a2d60641f1ade3af56555521c981811c9ce549ab5763fbfa3
                                                                                                                                                                              • Opcode Fuzzy Hash: d3ac609e44b59231dc55c8e71e8648c89a1e8d9249cfd615a9dc4897ce370840
                                                                                                                                                                              • Instruction Fuzzy Hash: E6F0AF71700208BFDB40EFA8DC52F6DB7B4EF18B04F804059B906DA281D9729A18E7B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(kernel32), ref: 00D408A9
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,IsWow64Process), ref: 00D408C0
                                                                                                                                                                              • GetCurrentProcess.KERNEL32(?), ref: 00D408D7
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AddressCurrentHandleModuleProcProcess
                                                                                                                                                                              • String ID: IsWow64Process$kernel32
                                                                                                                                                                              • API String ID: 4190356694-3789238822
                                                                                                                                                                              • Opcode ID: 63c5fd4abe873a909c5a52ee692612dd893045cf03514398ff30a9ece5245854
                                                                                                                                                                              • Instruction ID: 262cd938556e41c1952f6700add1859d0592a53939b72f3adbeaff5665deb8eb
                                                                                                                                                                              • Opcode Fuzzy Hash: 63c5fd4abe873a909c5a52ee692612dd893045cf03514398ff30a9ece5245854
                                                                                                                                                                              • Instruction Fuzzy Hash: 58F0A772D4131EAFDE10ABA16D09AEA7BACDB01755B0445D5FD08D3240E6718E14A6F1
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,00D9E935,?,?,00D9E8FD,00000002,00000002,?), ref: 00D9E955
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00D9E968
                                                                                                                                                                              • FreeLibrary.KERNEL32(00000000,?,?,00D9E935,?,?,00D9E8FD,00000002,00000002,?), ref: 00D9E98B
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                              • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                              • API String ID: 4061214504-1276376045
                                                                                                                                                                              • Opcode ID: a10579208cf200bcf83f2838c478ac3322e0b49f7e8b8fe8c1c58647af4fcf96
                                                                                                                                                                              • Instruction ID: a72c83e4943337d35be09500b0999acb7c56ce0a00342664717bf02e39f1a33d
                                                                                                                                                                              • Opcode Fuzzy Hash: a10579208cf200bcf83f2838c478ac3322e0b49f7e8b8fe8c1c58647af4fcf96
                                                                                                                                                                              • Instruction Fuzzy Hash: 7EF08C30A1031AFBDF11AB52DD09F9DBB78EB00B56F140060F404E22A0CBB48E01EAB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • SleepConditionVariableCS.KERNELBASE(?,00D8891F,00000064), ref: 00D889A5
                                                                                                                                                                              • LeaveCriticalSection.KERNEL32(00E0742C,00D21171,?,00D8891F,00000064,?,?,?,00D2402B,00E0827C,6EB998C3,?,00D21171,?), ref: 00D889AF
                                                                                                                                                                              • WaitForSingleObjectEx.KERNEL32(00D21171,00000000,?,00D8891F,00000064,?,?,?,00D2402B,00E0827C,6EB998C3,?,00D21171,?), ref: 00D889C0
                                                                                                                                                                              • EnterCriticalSection.KERNEL32(00E0742C,?,00D8891F,00000064,?,?,?,00D2402B,00E0827C,6EB998C3,?,00D21171,?), ref: 00D889C7
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CriticalSection$ConditionEnterLeaveObjectSingleSleepVariableWait
                                                                                                                                                                              • String ID: ,t
                                                                                                                                                                              • API String ID: 3269011525-1383983112
                                                                                                                                                                              • Opcode ID: 0b7a6e29f239a675f2502589c0a021e3193bc8be2855e063ce7e4f794bd9b18d
                                                                                                                                                                              • Instruction ID: 3ec185452870b47a8ca2e8f25170a77dd98528fbee97b3219edf0baef3bacce8
                                                                                                                                                                              • Opcode Fuzzy Hash: 0b7a6e29f239a675f2502589c0a021e3193bc8be2855e063ce7e4f794bd9b18d
                                                                                                                                                                              • Instruction Fuzzy Hash: 1CE09232904366BFC7113B50EC08E9D7F2DEB08B11B440010F595B22A1CB7128A19BF6
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DA2174: RtlAllocateHeap.NTDLL(00000000,?,?,?,00D8872D,?,?,00D1A1ED,0000002C,6EB998C3), ref: 00DA21A6
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0501
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0518
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0535
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0550
                                                                                                                                                                              • _free.LIBCMT ref: 00DA0567
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _free$AllocateHeap
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3033488037-0
                                                                                                                                                                              • Opcode ID: e362d9972595d979db21bbe1d3401fff428cd5b17f998210e30a6d97f2ca4c2d
                                                                                                                                                                              • Instruction ID: 5d6aabb0b80ee04b034a8f3f355da37848ba6918a7942f3e2d658bdacc268b93
                                                                                                                                                                              • Opcode Fuzzy Hash: e362d9972595d979db21bbe1d3401fff428cd5b17f998210e30a6d97f2ca4c2d
                                                                                                                                                                              • Instruction Fuzzy Hash: 6951A172A00704AFDB21EF69D841A6A7BF5EF5A720F180969E845D7250E731EA01CF60
                                                                                                                                                                              APIs
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(?,00000000,00DFCFC4,00DFCFC6,?,00DFCFC6,?,00DFCFC4,ios_base::failbit set,00000000), ref: 00D39DB0
                                                                                                                                                                              • GetLastError.KERNEL32(?,00DFCFC6,?,00DFCFC4,ios_base::failbit set,00000000), ref: 00D39DC1
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(?,00000000,00DFCFC4,00DFCFC6,00000000,00000000,?,00DFCFC6,?,00DFCFC4,ios_base::failbit set,00000000), ref: 00D39DD9
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(?,00000000,00DFCFC4,?,?,00000000,?,?,?,00DFCFC6,?,00DFCFC4,ios_base::failbit set,00000000), ref: 00D39DFF
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ByteCharMultiWide$ErrorLast
                                                                                                                                                                              • String ID: ios_base::failbit set
                                                                                                                                                                              • API String ID: 1717984340-3924258884
                                                                                                                                                                              • Opcode ID: 8ee7259231ba3945c0aa98a3fbc3f56d380bbed74d4cf2344c6e58b11cb00543
                                                                                                                                                                              • Instruction ID: 15b9bf14567d35ab25f6e97ac179dde338067e3159b386419d33f9da7daf5133
                                                                                                                                                                              • Opcode Fuzzy Hash: 8ee7259231ba3945c0aa98a3fbc3f56d380bbed74d4cf2344c6e58b11cb00543
                                                                                                                                                                              • Instruction Fuzzy Hash: D8214376101306BFE3205F61DC45F67FB1CEF06744F284519F64596192DB72A42487B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • SetEvent.KERNEL32 ref: 00D29B16
                                                                                                                                                                              • GetCurrentThreadId.KERNEL32 ref: 00D29B29
                                                                                                                                                                                • Part of subcall function 00D766B6: WaitForSingleObjectEx.KERNEL32(?,000000FF,00000000), ref: 00D766C1
                                                                                                                                                                                • Part of subcall function 00D766B6: GetExitCodeThread.KERNEL32(?,?), ref: 00D766D3
                                                                                                                                                                                • Part of subcall function 00D766B6: CloseHandle.KERNEL32(?), ref: 00D766EC
                                                                                                                                                                              • CloseHandle.KERNEL32(?), ref: 00D29B81
                                                                                                                                                                              • CloseHandle.KERNEL32(?), ref: 00D29B97
                                                                                                                                                                              • __Mtx_destroy_in_situ.LIBCPMT ref: 00D29BAF
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CloseHandle$Thread$CodeCurrentEventExitMtx_destroy_in_situObjectSingleWait
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2780651522-0
                                                                                                                                                                              • Opcode ID: 9243822d167126e81e47d80ac2ab538279b92971b8446568bb5d56e76b8ff0b4
                                                                                                                                                                              • Instruction ID: 7ab18cf6fcff51cc69e819d7ded5cd64c7ef1eedb41311f59f4d422685934e94
                                                                                                                                                                              • Opcode Fuzzy Hash: 9243822d167126e81e47d80ac2ab538279b92971b8446568bb5d56e76b8ff0b4
                                                                                                                                                                              • Instruction Fuzzy Hash: 1D21E771904B109BD720BF74FC99B9AF7D5EF60318F084929F56D911D1EB32A520CAB2
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D743F7
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D74401
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D74452
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D74472
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D7447F
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 55977855-0
                                                                                                                                                                              • Opcode ID: 5c75576451e283f487ed25d3c3ad51d6c355cbb7d19000cf7723fef776966493
                                                                                                                                                                              • Instruction ID: 58b2987cc1acc21eb868b7d0c075c2eb301a1f9c79cc6b7e3d63f780a70db958
                                                                                                                                                                              • Opcode Fuzzy Hash: 5c75576451e283f487ed25d3c3ad51d6c355cbb7d19000cf7723fef776966493
                                                                                                                                                                              • Instruction Fuzzy Hash: 3E01C4719001199BCB05FB64D801ABE77B1EF80714F148109E954A7391EFB09A459BB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D845A6
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D845B0
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D84601
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D84621
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D8462E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 55977855-0
                                                                                                                                                                              • Opcode ID: 4e3d60ef9e522bd121939e97f8f6c73da8232d774eb72081b47dd42aeb180826
                                                                                                                                                                              • Instruction ID: fb2f97a7fa1e03688bb86f948780aeb0da2e84b190006b236504a43a1b3793d8
                                                                                                                                                                              • Opcode Fuzzy Hash: 4e3d60ef9e522bd121939e97f8f6c73da8232d774eb72081b47dd42aeb180826
                                                                                                                                                                              • Instruction Fuzzy Hash: FD016D75D0022A9BCB15FB64D852AEE7775EF80710F240009E814AB2D1EF79AE45D7B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D8463B
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D84645
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D84696
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D846B6
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D846C3
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 55977855-0
                                                                                                                                                                              • Opcode ID: 165acde33c9a9ffbbaad86ae1c41b6993cd18e82b5d2de14683e012648946919
                                                                                                                                                                              • Instruction ID: c2406231de16f20757493baa4471e5d2a6f49302002aaa1ed8ab395f656b2819
                                                                                                                                                                              • Opcode Fuzzy Hash: 165acde33c9a9ffbbaad86ae1c41b6993cd18e82b5d2de14683e012648946919
                                                                                                                                                                              • Instruction Fuzzy Hash: 0101AD7190011AABCB04FB64D842AEE77A5FF80310F294109E814AB3D1EF74AA449BB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D847FA
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D84804
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D84855
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D84875
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D84882
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 55977855-0
                                                                                                                                                                              • Opcode ID: da60352d3daf65c91495b4ebdb6850ad52001e084e1b82d8152b63ee19f504e2
                                                                                                                                                                              • Instruction ID: fef046d874175d1ae70bf5e51c8b0d22727dccf5a13b98a4c65e20229efaf7f3
                                                                                                                                                                              • Opcode Fuzzy Hash: da60352d3daf65c91495b4ebdb6850ad52001e084e1b82d8152b63ee19f504e2
                                                                                                                                                                              • Instruction Fuzzy Hash: 9101CC7190025A9BCB04FB64D812AFEB7B5FF80720F244008E810AB391DF74AE45EBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D8488F
                                                                                                                                                                              • std::_Lockit::_Lockit.LIBCPMT ref: 00D84899
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::_Lockit.LIBCPMT ref: 00D12D30
                                                                                                                                                                                • Part of subcall function 00D12D14: std::_Lockit::~_Lockit.LIBCPMT ref: 00D12D4C
                                                                                                                                                                              • std::_Facet_Register.LIBCPMT ref: 00D848EA
                                                                                                                                                                              • std::_Lockit::~_Lockit.LIBCPMT ref: 00D8490A
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D84917
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_H_prolog3Register
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 55977855-0
                                                                                                                                                                              • Opcode ID: 020ed78bd7efe3f8882e1d408628063f148b87b6590cb73911c9f6ee350f0961
                                                                                                                                                                              • Instruction ID: c457bf3e1bc65548cbbbe9d15fde7e1a6e6f9f96516efd6abb8b833e94be6682
                                                                                                                                                                              • Opcode Fuzzy Hash: 020ed78bd7efe3f8882e1d408628063f148b87b6590cb73911c9f6ee350f0961
                                                                                                                                                                              • Instruction Fuzzy Hash: EB01C07590021AAFCB14FBA4D802ABE77B1EF84320F244009E850AB391DF74AE45DBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              Strings
                                                                                                                                                                              • CloseHandle failed: %d, xrefs: 00D60737
                                                                                                                                                                              • c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\CabParser.h, xrefs: 00D60743
                                                                                                                                                                              • NWebAdvisor::CCabParser::Close, xrefs: 00D6073E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CloseErrorHandleLast
                                                                                                                                                                              • String ID: CloseHandle failed: %d$NWebAdvisor::CCabParser::Close$c:\jenkins\workspace\mer_WebAdvisor_XMLUpdater_master\src\XmlUpdater\CabParser.h
                                                                                                                                                                              • API String ID: 918212764-1823807987
                                                                                                                                                                              • Opcode ID: 92873acd87ab3b1a1674942321e315d4be42eb028272805d68ed69f28763a235
                                                                                                                                                                              • Instruction ID: 9eecb88d0e852d65ba5c745ba6f4bba26b580314864df2f9ddc0a65b2e4e3686
                                                                                                                                                                              • Opcode Fuzzy Hash: 92873acd87ab3b1a1674942321e315d4be42eb028272805d68ed69f28763a235
                                                                                                                                                                              • Instruction Fuzzy Hash: 67D02B703403112FE7602F28BC1AF567A64DB01720F050A1AB600D12E1D5E3A8128771
                                                                                                                                                                              APIs
                                                                                                                                                                              • FreeLibrary.KERNEL32(?), ref: 00D52319
                                                                                                                                                                              • FreeLibrary.KERNEL32(00000000), ref: 00D52369
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FreeLibrary
                                                                                                                                                                              • String ID: XML hound handler failed.$_=nil}
                                                                                                                                                                              • API String ID: 3664257935-979112626
                                                                                                                                                                              • Opcode ID: 579dbbbdf2d6a48eac1e992f7ddff40317bcc1982d1d55ac3657da4ba32d398c
                                                                                                                                                                              • Instruction ID: 07c98a68ef668f47c4d83131fc2232008d6efff529d374927210a45e4df35f98
                                                                                                                                                                              • Opcode Fuzzy Hash: 579dbbbdf2d6a48eac1e992f7ddff40317bcc1982d1d55ac3657da4ba32d398c
                                                                                                                                                                              • Instruction Fuzzy Hash: 6FF1D471900209AFDF24DF68DC45BAEB7F5EF05314F088569E809A7291DB74E988CBB0
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: 1$Async event sender already initialized$`aso
                                                                                                                                                                              • API String ID: 0-109377809
                                                                                                                                                                              • Opcode ID: 93caa1f4734085485161d4ab8fdc3a24b8fdcb3e2de3b7994c79e20999986c8a
                                                                                                                                                                              • Instruction ID: f87096fc9e8ccc03a4114d27f169b19cc8361c8cc7b05ac3394a94bdb74c482d
                                                                                                                                                                              • Opcode Fuzzy Hash: 93caa1f4734085485161d4ab8fdc3a24b8fdcb3e2de3b7994c79e20999986c8a
                                                                                                                                                                              • Instruction Fuzzy Hash: 46C19FB1610A408FDB18DB38DCA8BABB7E5EF40319F544A1CE15AC7691DB39B584CB24
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: \\?\
                                                                                                                                                                              • API String ID: 0-4282027825
                                                                                                                                                                              • Opcode ID: 33fce7e6ab46eca8cef29c24389600a48892b9ade3559f0cdf87c2ff8c99d260
                                                                                                                                                                              • Instruction ID: a6e6778fb5cc343a2bccf440b6da9dd7cefe2a98167259c28ff009312a12041f
                                                                                                                                                                              • Opcode Fuzzy Hash: 33fce7e6ab46eca8cef29c24389600a48892b9ade3559f0cdf87c2ff8c99d260
                                                                                                                                                                              • Instruction Fuzzy Hash: B4713871D00619DBDB14DFA8E884BDEB7F9AF49310F18062AE41AE7294D730A941CBB5
                                                                                                                                                                              APIs
                                                                                                                                                                              • WritePrivateProfileStructW.KERNEL32(?,00000000,4752434D,00000024,00000000), ref: 00DB46E4
                                                                                                                                                                              • GetLastError.KERNEL32 ref: 00DB4728
                                                                                                                                                                              • WritePrivateProfileStructW.KERNEL32(?,00000000,?,00000004,00000000), ref: 00DB4768
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: PrivateProfileStructWrite$ErrorLast
                                                                                                                                                                              • String ID: MCRG
                                                                                                                                                                              • API String ID: 3778923442-1523812224
                                                                                                                                                                              • Opcode ID: 4966e952dc51f339145f61a94e3fc35e7d0788c9299806d8867b64f47d6408c6
                                                                                                                                                                              • Instruction ID: 9877b561018b0c65cf4dcdac2c24605ef106e5c3446e08d201677b8a6d9fe294
                                                                                                                                                                              • Opcode Fuzzy Hash: 4966e952dc51f339145f61a94e3fc35e7d0788c9299806d8867b64f47d6408c6
                                                                                                                                                                              • Instruction Fuzzy Hash: 55517E75900249EFDB10DFA8D845FDEBBB8EF45320F148259F815AB3A1DB709905CBA0
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D73D98: FormatMessageA.KERNEL32(00001300,00000000,?,00000000,?,00000000,00000000,?,?,00D204D5,?,?,6EB998C3), ref: 00D73DAE
                                                                                                                                                                              • LocalFree.KERNEL32(00000000), ref: 00D205CC
                                                                                                                                                                              • Concurrency::cancel_current_task.LIBCPMT ref: 00D205F6
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Concurrency::cancel_current_taskFormatFreeLocalMessage
                                                                                                                                                                              • String ID: generic$unknown error
                                                                                                                                                                              • API String ID: 3868770561-3628847473
                                                                                                                                                                              • Opcode ID: e8d06dbb96d60bde5b6a3ca4e3986620b8ffed57dc8f9bb38d4a573771b3e943
                                                                                                                                                                              • Instruction ID: 8e19ffce2ee923c373c67cf8400f0848f708615c9b7053e2f46fb8809209e516
                                                                                                                                                                              • Opcode Fuzzy Hash: e8d06dbb96d60bde5b6a3ca4e3986620b8ffed57dc8f9bb38d4a573771b3e943
                                                                                                                                                                              • Instruction Fuzzy Hash: FF41E4B09003559FDB20AF68D845B6FBBF8EF59314F10062EF45697782DB7899048BB1
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID: C:\Users\user\AppData\Local\Temp\ISVD440.tmp\saBSI\saBSI.exe
                                                                                                                                                                              • API String ID: 0-316269133
                                                                                                                                                                              • Opcode ID: 96d756ad084f7d830de05623a485a8af08b6a35cddbe3864513574ecbb04351f
                                                                                                                                                                              • Instruction ID: eee6fed0531d605c05f79ce4ed081e21e99531d9d2d317e34d71293f8b43b0e3
                                                                                                                                                                              • Opcode Fuzzy Hash: 96d756ad084f7d830de05623a485a8af08b6a35cddbe3864513574ecbb04351f
                                                                                                                                                                              • Instruction Fuzzy Hash: 8831AEB1E00218AFDF21DF9ADD85DAEBBB8EB85310B14006AF406E7251E7719E44CB70
                                                                                                                                                                              APIs
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: H_prolog3_
                                                                                                                                                                              • String ID: /affid$MSAD_Subinfo$affid
                                                                                                                                                                              • API String ID: 2427045233-3897642808
                                                                                                                                                                              • Opcode ID: 2dc13cba820ee73d768af02f7aa5f655fe01c48705cf274647beacfa01a4535c
                                                                                                                                                                              • Instruction ID: 5cc4f69098e36f7310198637b2ca189c19dead2c66d2fa66769b3e752803af12
                                                                                                                                                                              • Opcode Fuzzy Hash: 2dc13cba820ee73d768af02f7aa5f655fe01c48705cf274647beacfa01a4535c
                                                                                                                                                                              • Instruction Fuzzy Hash: 014164B4D05349EECB04DF94D895AEDBBB4FF09314F54406DE405A7281DB309A8ACB75
                                                                                                                                                                              APIs
                                                                                                                                                                              • SHGetKnownFolderPath.SHELL32(00DDD7E8,00000000,00000000,?,6EB998C3), ref: 00D3D75C
                                                                                                                                                                              • CoTaskMemFree.OLE32(00000000), ref: 00D3D7D4
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FolderFreeKnownPathTask
                                                                                                                                                                              • String ID: %s\%s
                                                                                                                                                                              • API String ID: 969438705-4073750446
                                                                                                                                                                              • Opcode ID: 71c233f25f97532da28b0b06395fc19ae32b0ca103bca5dad7f548ede5f5ed4f
                                                                                                                                                                              • Instruction ID: 4ec4736aa911180e5b9ec4631cefa02b65258b29c42867516c10d41431549d48
                                                                                                                                                                              • Opcode Fuzzy Hash: 71c233f25f97532da28b0b06395fc19ae32b0ca103bca5dad7f548ede5f5ed4f
                                                                                                                                                                              • Instruction Fuzzy Hash: 8B2165B1A00249AFDB04DF99DC85FEEB7F9EB48714F50452AE816E3280DB74A904CB70
                                                                                                                                                                              APIs
                                                                                                                                                                              • WaitForMultipleObjects.KERNEL32(00000002,?,00000000,000000FF,6EB998C3,?,?), ref: 00D2A531
                                                                                                                                                                              • __Mtx_unlock.LIBCPMT ref: 00D2A7EC
                                                                                                                                                                              • std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2A989
                                                                                                                                                                                • Part of subcall function 00D2F110: std::ios_base::_Ios_base_dtor.LIBCPMT ref: 00D2F268
                                                                                                                                                                              Strings
                                                                                                                                                                              • Unexpected return value: , xrefs: 00D2A8CC
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Ios_base_dtorstd::ios_base::_$Mtx_unlockMultipleObjectsWait
                                                                                                                                                                              • String ID: Unexpected return value:
                                                                                                                                                                              • API String ID: 1703231451-3613193034
                                                                                                                                                                              • Opcode ID: 6ab28281b40532eac46c24bd6f20344f89eb33d6811d1a42f43fc27481e93ed2
                                                                                                                                                                              • Instruction ID: 53d9570f9906b53f01f7eb935733ea85f9aca514562205a694a60a864bc7d6cb
                                                                                                                                                                              • Opcode Fuzzy Hash: 6ab28281b40532eac46c24bd6f20344f89eb33d6811d1a42f43fc27481e93ed2
                                                                                                                                                                              • Instruction Fuzzy Hash: 6721E570904269ABDF14DBA8EC89AEDB735EF55318F504258E115AB3C2DB309A85CB32
                                                                                                                                                                              APIs
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Mpunct$H_prolog3
                                                                                                                                                                              • String ID: $+xv
                                                                                                                                                                              • API String ID: 4281374311-1686923651
                                                                                                                                                                              • Opcode ID: 50f886c75a774ae1aa9e29b34fc8cbd913e289609032913934f0e790fbd8ab54
                                                                                                                                                                              • Instruction ID: bd35a0f5ebcfe41aa68cb040300d18e8f73c287c9f248a2adb4b462706867077
                                                                                                                                                                              • Opcode Fuzzy Hash: 50f886c75a774ae1aa9e29b34fc8cbd913e289609032913934f0e790fbd8ab54
                                                                                                                                                                              • Instruction Fuzzy Hash: 22215EA1904B526FDB25EF74889077BBFF8EB0C300B04495AE499C7A41E774E605CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3.LIBCMT ref: 00D7DD0E
                                                                                                                                                                                • Part of subcall function 00D77579: _Maklocstr.LIBCPMT ref: 00D77599
                                                                                                                                                                                • Part of subcall function 00D77579: _Maklocstr.LIBCPMT ref: 00D775B6
                                                                                                                                                                                • Part of subcall function 00D77579: _Maklocstr.LIBCPMT ref: 00D775D3
                                                                                                                                                                                • Part of subcall function 00D77579: _Maklocchr.LIBCPMT ref: 00D775E5
                                                                                                                                                                                • Part of subcall function 00D77579: _Maklocchr.LIBCPMT ref: 00D775F8
                                                                                                                                                                              • _Mpunct.LIBCPMT ref: 00D7DD9B
                                                                                                                                                                              • _Mpunct.LIBCPMT ref: 00D7DDB5
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Maklocstr$MaklocchrMpunct$H_prolog3
                                                                                                                                                                              • String ID: $+xv
                                                                                                                                                                              • API String ID: 2939335142-1686923651
                                                                                                                                                                              • Opcode ID: 2b492caa4eca3bb745d7ee2bfcd37b7cd5539ff85097736e98ad3743d95d6b66
                                                                                                                                                                              • Instruction ID: a7b45b2aff2d4f6b7aaae1e632a629ff5bb83d0cef0010e910a9c127a1eac50b
                                                                                                                                                                              • Opcode Fuzzy Hash: 2b492caa4eca3bb745d7ee2bfcd37b7cd5539ff85097736e98ad3743d95d6b66
                                                                                                                                                                              • Instruction Fuzzy Hash: 36214FA1904B526ED725DF74885077BBEF8EB09310F18495AE459C7A41E774E601CBB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetModuleHandleW.KERNEL32(kernel32.dll,00D14E6C,6EB998C3), ref: 00D3D6D5
                                                                                                                                                                              • GetProcAddress.KERNEL32(00000000,SetDefaultDllDirectories), ref: 00D3D6E5
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AddressHandleModuleProc
                                                                                                                                                                              • String ID: SetDefaultDllDirectories$kernel32.dll
                                                                                                                                                                              • API String ID: 1646373207-2102062458
                                                                                                                                                                              • Opcode ID: b132c4f07314dcdc2ec3d9dcdcfda92baf2b2c23df447fb5155e660ce0ac9d0b
                                                                                                                                                                              • Instruction ID: cf16cff27624e5e4923f5cea8e1aafd34cf0a6d8add29bb27b58dbe595cd4e19
                                                                                                                                                                              • Opcode Fuzzy Hash: b132c4f07314dcdc2ec3d9dcdcfda92baf2b2c23df447fb5155e660ce0ac9d0b
                                                                                                                                                                              • Instruction Fuzzy Hash: D2D0126534470B2ADE002BB21D0AF0E37497A41BC2F0C4850B015D61D1CDE4C504EE72
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _strrchr
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 3213747228-0
                                                                                                                                                                              • Opcode ID: 2052368595d85d8921707e714fa8cf7e39a0871388d90fe44b2f9a70ca8f8144
                                                                                                                                                                              • Instruction ID: 4741bc1431cd6dbefcbf633755d629da4a87c1f2222d8920dc1553d533fc0662
                                                                                                                                                                              • Opcode Fuzzy Hash: 2052368595d85d8921707e714fa8cf7e39a0871388d90fe44b2f9a70ca8f8144
                                                                                                                                                                              • Instruction Fuzzy Hash: 78B124329052859FDB15CF2EC8917FEBBE5EF56350F2881AAE8459B241D6349E01CB70
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _strcspn$H_prolog3_ctype
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 838279627-0
                                                                                                                                                                              • Opcode ID: 4ff74f4fd00d5317ad20ec740e8cb72a41391b813ba9ebfc66e31d716cf96354
                                                                                                                                                                              • Instruction ID: e368849db847aa2173404c11ea82830badfb632db940026b668dd355d89fe06d
                                                                                                                                                                              • Opcode Fuzzy Hash: 4ff74f4fd00d5317ad20ec740e8cb72a41391b813ba9ebfc66e31d716cf96354
                                                                                                                                                                              • Instruction Fuzzy Hash: 56B15E7190024AEFDF10DF98C895AEEBBB5FF08310F548059E849AB251E7309E55DBB1
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D1463F: GetProcessHeap.KERNEL32(?,?,?,00D1E97C,6EB998C3,?,?,?,?,00DB9590,000000FF), ref: 00D14676
                                                                                                                                                                              • WideCharToMultiByte.KERNEL32(00000003,00000000,?,000000FF,00000000,00000000,00000000,00000000,?,?,?,?,?,00DBFB28,000000FF), ref: 00DB2BF4
                                                                                                                                                                                • Part of subcall function 00D375F0: FindResourceExW.KERNEL32(00000000,00000006,00000000,?,00000000,?,?,?,?,?,00DB2B5D,?,00000000), ref: 00D37628
                                                                                                                                                                                • Part of subcall function 00D375F0: LoadResource.KERNEL32(00000000,00000000,?,?,?,?,?,00DB2B5D,?,00000000,?,?,?,?,?,00DBFB28), ref: 00D37636
                                                                                                                                                                                • Part of subcall function 00D375F0: LockResource.KERNEL32(00000000,?,?,?,?,?,00DB2B5D,?,00000000,?,?,?,?,?,00DBFB28,000000FF), ref: 00D37641
                                                                                                                                                                                • Part of subcall function 00D375F0: SizeofResource.KERNEL32(00000000,00000000,?,?,?,?,?,00DB2B5D,?,00000000,?,?,?,?,?,00DBFB28), ref: 00D3764F
                                                                                                                                                                              • FindResourceW.KERNEL32(00000000,?,00000006), ref: 00DB2B74
                                                                                                                                                                                • Part of subcall function 00D37580: LoadResource.KERNEL32(?,?,?,80070057,8007000E,80004005,00000000,?,?,?,?,?,?,?,00D3480F,6EB998C3), ref: 00D37589
                                                                                                                                                                                • Part of subcall function 00D37580: LockResource.KERNEL32(00000000,?,80070057,8007000E,80004005,00000000,?,?,?,?,?,?,?,00D3480F,6EB998C3), ref: 00D37594
                                                                                                                                                                                • Part of subcall function 00D37580: SizeofResource.KERNEL32(?,?,?,80070057,8007000E,80004005,00000000,?,?,?,?,?,?,?,00D3480F,6EB998C3), ref: 00D375A8
                                                                                                                                                                              • WideCharToMultiByte.KERNEL32(00000003,00000000,00000002,?,00000000,00000000,00000000,00000000,?,?,00000006), ref: 00DB2BAB
                                                                                                                                                                              • WideCharToMultiByte.KERNEL32(00000003,00000000,?,000000FF,?,00000000,00000000,00000000,?,?,?,?,?,00DBFB28,000000FF), ref: 00DB2C2E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Resource$ByteCharMultiWide$FindLoadLockSizeof$HeapProcess
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2838002939-0
                                                                                                                                                                              • Opcode ID: a659974de1c46e7ff12906642888e8b39d62567d62a72540eb22ea87905f41ba
                                                                                                                                                                              • Instruction ID: 025838f32a18f2cfb5bcb59b51f186d8c87af39d5cacae640d2b87a90af6eeb6
                                                                                                                                                                              • Opcode Fuzzy Hash: a659974de1c46e7ff12906642888e8b39d62567d62a72540eb22ea87905f41ba
                                                                                                                                                                              • Instruction Fuzzy Hash: D051AA72200641EFE7258F18CC89FBABBE8EB54710F24465DB6469B2D5DBB4A800CB74
                                                                                                                                                                              APIs
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: AdjustPointer
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1740715915-0
                                                                                                                                                                              • Opcode ID: 66eddbbd25c4ad78c37880f087becac2a87f0c727005685e076f89a9306c8b61
                                                                                                                                                                              • Instruction ID: 5c624f1b3f5df3446e3c3e6e17f9c9456b743fb4df32f5d0a833bf6aef5c1a33
                                                                                                                                                                              • Opcode Fuzzy Hash: 66eddbbd25c4ad78c37880f087becac2a87f0c727005685e076f89a9306c8b61
                                                                                                                                                                              • Instruction Fuzzy Hash: 7051E172620306DFEB29BF94C885B7AB3A4FF04710F18502AE80557292E731EC40C7B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • _free.LIBCMT ref: 00DB181E
                                                                                                                                                                              • _free.LIBCMT ref: 00DB1847
                                                                                                                                                                              • SetEndOfFile.KERNEL32(00000000,00DB00BA,00000000,00DA7369,?,?,?,?,?,?,?,00DB00BA,00DA7369,00000000), ref: 00DB1879
                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,?,00DB00BA,00DA7369,00000000,?,?,?,?,00000000), ref: 00DB1895
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: _free$ErrorFileLast
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 1547350101-0
                                                                                                                                                                              • Opcode ID: 87e4a957c879e6e97df1c41a4d4f3a06273702f9065c24c32448fe888b0586df
                                                                                                                                                                              • Instruction ID: 7dd029d834f635643c316eb354d3185a7fbaed877865c7c972edcf022eef7613
                                                                                                                                                                              • Opcode Fuzzy Hash: 87e4a957c879e6e97df1c41a4d4f3a06273702f9065c24c32448fe888b0586df
                                                                                                                                                                              • Instruction Fuzzy Hash: AA41A37E900605EBDB11ABB8CC56BDE77AAFF45360FA80520F426E72D1EA34C8448771
                                                                                                                                                                              APIs
                                                                                                                                                                              • RegSetKeySecurity.ADVAPI32(00000000,00000000,00000000,00000000), ref: 00D3EBCB
                                                                                                                                                                              • RegEnumKeyExW.ADVAPI32(00000000,00000000,?,00000100,00000000,00000000,00000000,00000000,?,00000000,00000000), ref: 00D3EC28
                                                                                                                                                                              • RegOpenKeyExW.ADVAPI32(00000000,?,00000000,000F003F,?,?,00000000,00000000), ref: 00D3EC4F
                                                                                                                                                                                • Part of subcall function 00D3EBA0: RegCloseKey.ADVAPI32(?,?,00000000,00000000), ref: 00D3EC7E
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CloseEnumOpenSecurity
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 611561417-0
                                                                                                                                                                              • Opcode ID: 6cdbe83bf4eb0737b9e9acc273a7643f3bdd3afa48f8a2388845c18243c45135
                                                                                                                                                                              • Instruction ID: d2cb65bf5bbcc1593cf2e5d9f39e39397b37832fd9aa72a277df1b2c665b2c0f
                                                                                                                                                                              • Opcode Fuzzy Hash: 6cdbe83bf4eb0737b9e9acc273a7643f3bdd3afa48f8a2388845c18243c45135
                                                                                                                                                                              • Instruction Fuzzy Hash: 853141B2A0021DABDB219F54DD49FEEB7B8EB08700F0445A5F915E61D1DA709E50DBB0
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID:
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID:
                                                                                                                                                                              • Opcode ID: 3a393c2dd1f81897c4aa701e2251539a154272d791673ee0e66790e99b9f96bb
                                                                                                                                                                              • Instruction ID: 2d92238676f20be3a999d21f0d9224e1eb87d572bdbf8758cb3bac861439e401
                                                                                                                                                                              • Opcode Fuzzy Hash: 3a393c2dd1f81897c4aa701e2251539a154272d791673ee0e66790e99b9f96bb
                                                                                                                                                                              • Instruction Fuzzy Hash: CD218BB1604306AFEF20EB62CC8193B77ADEB153647244524F825A6291EB30EC4087B0
                                                                                                                                                                              APIs
                                                                                                                                                                              • WideCharToMultiByte.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000,00000000,00000000,?,00000000,?,00DB5B7C,0000FDE9,?,00000000,?), ref: 00DB5D8B
                                                                                                                                                                              • GetLastError.KERNEL32(?,00DB5B7C,0000FDE9,?,00000000,?), ref: 00DB5D95
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ByteCharErrorLastMultiWide
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 203985260-0
                                                                                                                                                                              • Opcode ID: 237fea83681ddf29588d46b47c23f73498efc42acee28b5265cc7d42f8b15b93
                                                                                                                                                                              • Instruction ID: 5b300cb14c609305b3ea27bb837168e6d357254906ad0f45e46be9c4fb033574
                                                                                                                                                                              • Opcode Fuzzy Hash: 237fea83681ddf29588d46b47c23f73498efc42acee28b5265cc7d42f8b15b93
                                                                                                                                                                              • Instruction Fuzzy Hash: E411C473340305ABE7305F5AFC04F9AB798EB90B71F24452AF659EA2D1E37168209674
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetLastError.KERNEL32(00000008,00000016,00000000,00DA4E01), ref: 00DA1CAE
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1D0B
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1D41
                                                                                                                                                                              • SetLastError.KERNEL32(00000000,00000006,000000FF), ref: 00DA1D4C
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast_free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2283115069-0
                                                                                                                                                                              • Opcode ID: 2628f40d68104881151957c3e1a668eefa0068f14e81cd852421c849417ba9d0
                                                                                                                                                                              • Instruction ID: 7b093ffdfeb507a65b6a6b658de91c5243059b5357b59daba31001570391b669
                                                                                                                                                                              • Opcode Fuzzy Hash: 2628f40d68104881151957c3e1a668eefa0068f14e81cd852421c849417ba9d0
                                                                                                                                                                              • Instruction Fuzzy Hash: 7511A0BB6447012FDA11277A9DC6D3B22AADFC77B4F280224F6219B2D2DA61CC018170
                                                                                                                                                                              APIs
                                                                                                                                                                              • GetLastError.KERNEL32(00E080CC,?,?,00D8D742,00DA21B7,?,?,00D8872D,?,?,00D1A1ED,0000002C,6EB998C3), ref: 00DA1E05
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1E62
                                                                                                                                                                              • _free.LIBCMT ref: 00DA1E98
                                                                                                                                                                              • SetLastError.KERNEL32(00000000,00000006,000000FF,?,00D8D742,00DA21B7,?,?,00D8872D,?,?,00D1A1ED,0000002C,6EB998C3), ref: 00DA1EA3
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorLast_free
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2283115069-0
                                                                                                                                                                              • Opcode ID: b1877e6219339e51e5b77497452c24ffd8bd9ab500f64122f5581dacc5fb7a6b
                                                                                                                                                                              • Instruction ID: 1c7b1fd6416bb096f90c0c18fc951b95120a55da0547205f939ae223a9f36965
                                                                                                                                                                              • Opcode Fuzzy Hash: b1877e6219339e51e5b77497452c24ffd8bd9ab500f64122f5581dacc5fb7a6b
                                                                                                                                                                              • Instruction Fuzzy Hash: 6411E5BAA403012BDA1127799CC6D3B229EDFC77B5F280234F925D72D1DE61CD048130
                                                                                                                                                                              APIs
                                                                                                                                                                              • WriteConsoleW.KERNEL32(00D4860A,6EB998C3,00DFC218,00000000,00D4860A,?,00DAF9C7,00D4860A,00000001,00D4860A,00D4860A,?,00DA5B42,00000000,?,00D4860A), ref: 00DB165E
                                                                                                                                                                              • GetLastError.KERNEL32(?,00DAF9C7,00D4860A,00000001,00D4860A,00D4860A,?,00DA5B42,00000000,?,00D4860A,00000000,00D4860A,?,00DA6096,00D4860A), ref: 00DB166A
                                                                                                                                                                                • Part of subcall function 00DB1630: CloseHandle.KERNEL32(FFFFFFFE,00DB167A,?,00DAF9C7,00D4860A,00000001,00D4860A,00D4860A,?,00DA5B42,00000000,?,00D4860A,00000000,00D4860A), ref: 00DB1640
                                                                                                                                                                              • ___initconout.LIBCMT ref: 00DB167A
                                                                                                                                                                                • Part of subcall function 00DB15F0: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,00DB161F,00DAF9B4,00D4860A,?,00DA5B42,00000000,?,00D4860A,00000000), ref: 00DB1603
                                                                                                                                                                              • WriteConsoleW.KERNEL32(00D4860A,6EB998C3,00DFC218,00000000,?,00DAF9C7,00D4860A,00000001,00D4860A,00D4860A,?,00DA5B42,00000000,?,00D4860A,00000000), ref: 00DB168F
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 2744216297-0
                                                                                                                                                                              • Opcode ID: 76012553760f57f2869a128927df227254b4e409e360bf73a73856c6923d062e
                                                                                                                                                                              • Instruction ID: f7c9bbbda25e9219ae639dcf7e1c7f4f53bbbf1a5a7f68f732e60d69b30b3a80
                                                                                                                                                                              • Opcode Fuzzy Hash: 76012553760f57f2869a128927df227254b4e409e360bf73a73856c6923d062e
                                                                                                                                                                              • Instruction Fuzzy Hash: 48F01C3A401216BFCF221FD5DC05FDA7F26FB493A0F484410FA0A95220C63289209FB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • __EH_prolog3_GS.LIBCMT ref: 00D752F3
                                                                                                                                                                                • Part of subcall function 00D3BDF0: std::_Lockit::_Lockit.LIBCPMT ref: 00D3BE2F
                                                                                                                                                                                • Part of subcall function 00D3BDF0: std::_Lockit::_Lockit.LIBCPMT ref: 00D3BE51
                                                                                                                                                                                • Part of subcall function 00D3BDF0: std::_Lockit::~_Lockit.LIBCPMT ref: 00D3BE71
                                                                                                                                                                                • Part of subcall function 00D3BDF0: std::_Lockit::~_Lockit.LIBCPMT ref: 00D3BFFC
                                                                                                                                                                              • _Find_elem.LIBCPMT ref: 00D754EF
                                                                                                                                                                              Strings
                                                                                                                                                                              • 0123456789ABCDEFabcdef-+Xx, xrefs: 00D7535B
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Lockitstd::_$Lockit::_Lockit::~_$Find_elemH_prolog3_
                                                                                                                                                                              • String ID: 0123456789ABCDEFabcdef-+Xx
                                                                                                                                                                              • API String ID: 3042121994-2799312399
                                                                                                                                                                              • Opcode ID: 50fdd9f47aa5aa745bf0ee21de08724885834b016e5e20414911d3eb874be17c
                                                                                                                                                                              • Instruction ID: 5ff9750e90ccff57e252638c7ab07c6656ee6807ce5b5f5d4fd48ca97be70444
                                                                                                                                                                              • Opcode Fuzzy Hash: 50fdd9f47aa5aa745bf0ee21de08724885834b016e5e20414911d3eb874be17c
                                                                                                                                                                              • Instruction Fuzzy Hash: 08C1A630D046888FDF11DFA4E4507ECBBB2AF55304F688159D8896B28BE7B09D46CB72
                                                                                                                                                                              APIs
                                                                                                                                                                              • __startOneArgErrorHandling.LIBCMT ref: 00D9DEBD
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ErrorHandling__start
                                                                                                                                                                              • String ID: pow
                                                                                                                                                                              • API String ID: 3213639722-2276729525
                                                                                                                                                                              • Opcode ID: 9558f009bd99447b4605f938706ed570a7872971b9dd562c5531d5feaaf9999b
                                                                                                                                                                              • Instruction ID: 4f78db5f3f1e11e7f1eb87a33e528848b3ebd5013a3f79b256cc25d940340af0
                                                                                                                                                                              • Opcode Fuzzy Hash: 9558f009bd99447b4605f938706ed570a7872971b9dd562c5531d5feaaf9999b
                                                                                                                                                                              • Instruction Fuzzy Hash: 42515B71A1820186CF167F18C962379B795DF51B00F3C8959F4D68A2E8EF34CC949A72
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00DB2AF0: FindResourceW.KERNEL32(00000000,?,00000006), ref: 00DB2B74
                                                                                                                                                                                • Part of subcall function 00DB2AF0: WideCharToMultiByte.KERNEL32(00000003,00000000,00000002,?,00000000,00000000,00000000,00000000,?,?,00000006), ref: 00DB2BAB
                                                                                                                                                                                • Part of subcall function 00DB2AF0: WideCharToMultiByte.KERNEL32(00000003,00000000,?,000000FF,?,00000000,00000000,00000000,?,?,?,?,?,00DBFB28,000000FF), ref: 00DB2C2E
                                                                                                                                                                              • WritePrivateProfileStructW.KERNEL32(?,00000000,4752434D,00000024,00000002), ref: 00DB453C
                                                                                                                                                                              • WritePrivateProfileStructW.KERNEL32(?,?,00000000,?,00000002), ref: 00DB4598
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ByteCharMultiPrivateProfileStructWideWrite$FindResource
                                                                                                                                                                              • String ID: MCRG
                                                                                                                                                                              • API String ID: 2178413835-1523812224
                                                                                                                                                                              • Opcode ID: 79761dabff2aa0dce221e8512891f728385cac42779b96abe031f0c2c015b769
                                                                                                                                                                              • Instruction ID: 338e848e5922b9aafee22cbff4c6ee10aacc20a8d744ebcfd2c0dda061f5bb6b
                                                                                                                                                                              • Opcode Fuzzy Hash: 79761dabff2aa0dce221e8512891f728385cac42779b96abe031f0c2c015b769
                                                                                                                                                                              • Instruction Fuzzy Hash: BC615A71901649EFDB11DFA8C844B9EFBF5EF49320F188259F815AB3A1DB709905CBA0
                                                                                                                                                                              APIs
                                                                                                                                                                              • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 00D8C707
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: EncodePointer
                                                                                                                                                                              • String ID: MOC$RCC
                                                                                                                                                                              • API String ID: 2118026453-2084237596
                                                                                                                                                                              • Opcode ID: 2dac0df0adbe871d6b060fff6045f82dd84afd5708e7fe3be74779fd73ba1e5e
                                                                                                                                                                              • Instruction ID: c2f4fadba3411f8829c8b200f15f41d834cbbdc1ffd6ebf0c3b2a09f8c648b3c
                                                                                                                                                                              • Opcode Fuzzy Hash: 2dac0df0adbe871d6b060fff6045f82dd84afd5708e7fe3be74779fd73ba1e5e
                                                                                                                                                                              • Instruction Fuzzy Hash: 9B414472900209EFCF16EF98CC81AAEBBB5EF48300F188159FA14A7211D3359950DFB0
                                                                                                                                                                              APIs
                                                                                                                                                                              • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00D8904B
                                                                                                                                                                              • ___raise_securityfailure.LIBCMT ref: 00D89133
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FeaturePresentProcessor___raise_securityfailure
                                                                                                                                                                              • String ID: Xt
                                                                                                                                                                              • API String ID: 3761405300-1580183047
                                                                                                                                                                              • Opcode ID: 62f6ba090520a980798c7e99c9fcf87028126e25e5b066a1784be0587d6066e5
                                                                                                                                                                              • Instruction ID: caff95650e815fe23e1d6c2611792a23b341076e75dd55d276f47d1af8fe9605
                                                                                                                                                                              • Opcode Fuzzy Hash: 62f6ba090520a980798c7e99c9fcf87028126e25e5b066a1784be0587d6066e5
                                                                                                                                                                              • Instruction Fuzzy Hash: 102114B49183019ED710CF1AFC91A907BA4FB08314F10902AE588EB3B0E3B2B5C9CF65
                                                                                                                                                                              APIs
                                                                                                                                                                              • CLSIDFromString.OLE32(0000007B,?), ref: 00D3E650
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FromString
                                                                                                                                                                              • String ID: @${
                                                                                                                                                                              • API String ID: 1694596556-3118734784
                                                                                                                                                                              • Opcode ID: ee0c6f38c763775dc7271fb3f053051b6bd4e6ae5e016f62382974a5faebe141
                                                                                                                                                                              • Instruction ID: 91a147c946adf7409605e2fde2bf0bc103f3e81adf6b872eade67aa7678023d2
                                                                                                                                                                              • Opcode Fuzzy Hash: ee0c6f38c763775dc7271fb3f053051b6bd4e6ae5e016f62382974a5faebe141
                                                                                                                                                                              • Instruction Fuzzy Hash: CC01A9716002089BCB10DF68D901BDEB3B8FF59710F40819EB846E7150DE70AA84DBA0
                                                                                                                                                                              APIs
                                                                                                                                                                              • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00D89151
                                                                                                                                                                              • ___raise_securityfailure.LIBCMT ref: 00D8920E
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: FeaturePresentProcessor___raise_securityfailure
                                                                                                                                                                              • String ID: Xt
                                                                                                                                                                              • API String ID: 3761405300-1580183047
                                                                                                                                                                              • Opcode ID: 6e82728f5032c39ba81ac456af435817aea0c591340803dda9667019c5567b4f
                                                                                                                                                                              • Instruction ID: b669ea6572702ed1b596b5140968f25d2fb9358ae38c21c315f4754e5740b757
                                                                                                                                                                              • Opcode Fuzzy Hash: 6e82728f5032c39ba81ac456af435817aea0c591340803dda9667019c5567b4f
                                                                                                                                                                              • Instruction Fuzzy Hash: B9119FB4D183459ED700DF1AFC916807BA4FB08304B00506AE888A73B1E772B5CACF65
                                                                                                                                                                              APIs
                                                                                                                                                                              • DloadGetSRWLockFunctionPointers.DELAYIMP ref: 00D72743
                                                                                                                                                                                • Part of subcall function 00D726D0: GetModuleHandleW.KERNEL32(KERNEL32.DLL,?,?,00D72748,00D728F1), ref: 00D726E7
                                                                                                                                                                              • AcquireSRWLockExclusive.KERNEL32(?,00D728F1), ref: 00D72760
                                                                                                                                                                              Strings
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: Lock$AcquireDloadExclusiveFunctionHandleModulePointers
                                                                                                                                                                              • String ID: 8o
                                                                                                                                                                              • API String ID: 3692202576-1074072020
                                                                                                                                                                              • Opcode ID: 390804418acfb6f6dcacf966a332cf0d817c4b57914898fb9bc10bc54b2dd2b6
                                                                                                                                                                              • Instruction ID: 0a8cefe8a4e022e7e3a0fe88118534d8eef9848dc895e105d759469ca054a493
                                                                                                                                                                              • Opcode Fuzzy Hash: 390804418acfb6f6dcacf966a332cf0d817c4b57914898fb9bc10bc54b2dd2b6
                                                                                                                                                                              • Instruction Fuzzy Hash: 13E08C303302A34BCF186F25BF45A3B2345AB41785308407AE50AE32A0EA1498D28AA0
                                                                                                                                                                              APIs
                                                                                                                                                                                • Part of subcall function 00D144F8: InitializeCriticalSectionEx.KERNEL32(00E077A0,00000000,00000000,00E0778C,00D897FC,?,?,?,00D111BA), ref: 00D144FE
                                                                                                                                                                                • Part of subcall function 00D144F8: GetLastError.KERNEL32(?,?,?,00D111BA), ref: 00D14508
                                                                                                                                                                              • IsDebuggerPresent.KERNEL32(?,?,?,00D111BA), ref: 00D89800
                                                                                                                                                                              • OutputDebugStringW.KERNEL32(ERROR : Unable to initialize critical section in CAtlBaseModule,?,?,?,00D111BA), ref: 00D8980F
                                                                                                                                                                              Strings
                                                                                                                                                                              • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00D8980A
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: CriticalDebugDebuggerErrorInitializeLastOutputPresentSectionString
                                                                                                                                                                              • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
                                                                                                                                                                              • API String ID: 3511171328-631824599
                                                                                                                                                                              • Opcode ID: 6f634d5f4692ff5c2c27e89b41db015896b10df9a85a0e17bfed45cf3245a322
                                                                                                                                                                              • Instruction ID: 51cfb49695fbd489fa6585e2434b62c50e22fa3a0b33445531118c729a5842d6
                                                                                                                                                                              • Opcode Fuzzy Hash: 6f634d5f4692ff5c2c27e89b41db015896b10df9a85a0e17bfed45cf3245a322
                                                                                                                                                                              • Instruction Fuzzy Hash: 1AE06D702007128FD320AF24E814752BBF8AF04704F08882DE49AC2750DBB0D4488BB1
                                                                                                                                                                              APIs
                                                                                                                                                                              • MultiByteToWideChar.KERNEL32(?,00000000,?,000000FF,00000000,00000000,?,?,?,00DB59F1,0000FDE9,?,?,?), ref: 00DB5E33
                                                                                                                                                                              • GetLastError.KERNEL32(?,?,00DB59F1,0000FDE9,?,?,?), ref: 00DB5E3D
                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                              • Source File: 00000004.00000002.3662561233.0000000000D01000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00D00000, based on PE: true
                                                                                                                                                                              • Associated: 00000004.00000002.3662528277.0000000000D00000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662641272.0000000000DCE000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662684002.0000000000DFF000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662718900.0000000000E04000.00000008.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662747971.0000000000E06000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              • Associated: 00000004.00000002.3662776412.0000000000E09000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                              • Snapshot File: hcaresult_4_2_d00000_saBSI.jbxd
                                                                                                                                                                              Similarity
                                                                                                                                                                              • API ID: ByteCharErrorLastMultiWide
                                                                                                                                                                              • String ID:
                                                                                                                                                                              • API String ID: 203985260-0
                                                                                                                                                                              • Opcode ID: 095536d456616c87fec582b19175849332a428b8f9292858a18f6fff7a2100ed
                                                                                                                                                                              • Instruction ID: e324434cb2e5349f4fabe05f30932c75cf401480f26d69524902565070ed9333
                                                                                                                                                                              • Opcode Fuzzy Hash: 095536d456616c87fec582b19175849332a428b8f9292858a18f6fff7a2100ed
                                                                                                                                                                              • Instruction Fuzzy Hash: 0611C173300205ABEB209E6AFC40FAAB7A8EB95B71F24483AF555D6291D37198209770